LedgerTitanLedgerTitan
← All articles

Platform architecture

LedgerTitan Is CASA AL1 Certified—What That Means for Your Firm

7 min readPublished September 16, 2026Updated September 16, 2026

Accounting firms should not have to take a vendor’s word for how it handles identity and mailbox data. LedgerTitan has completed CASA Assurance Level 1 (AL1)—the App Defense Alliance Cloud Application Security Assessment level formerly known as CASA Tier 2. An authorized lab reviewed our evidence against the CASA requirements and issued a Letter of Validation. This article explains the program in plain language and what it changes for people who trust LedgerTitan with client work.

What CASA AL1 actually is

CASA (Cloud Application Security Assessment) is the App Defense Alliance framework Google uses to verify that apps requesting restricted Google APIs such as Gmail can handle that data securely. It is mapped to OWASP ASVS (Application Security Verification Standard). The requirements are the same at every assurance level; what changes is how thoroughly they are verified.

Google and the Alliance renamed the old Tier labels to Assurance Levels:

Former nameCurrent nameHow it is verified
CASA Tier 2CASA AL1Developer-tested, lab-reviewed — you submit scans, evidence, and attestations; an ADA-authorized lab reviews them and issues a Letter of Validation
CASA Tier 3CASA AL2Lab-tested — the lab evaluates the running application directly

AL1 is not a self-checked checkbox on a marketing site. A lab must accept the evidence. It is also not a claim that Google “endorses” the product or that the assessment replaces your firm’s own vendor review.

Why LedgerTitan completed AL1

Apps that ask for sensitive OAuth scopes—especially mail—are held to a higher bar: annual assessment, proof that user data can be deleted on request, and verification that the application is built to handle tokens and content securely.

LedgerTitan completed CASA AL1 so that:

  • Gmail workflow and inbox features can meet Google’s restricted-scope requirements
  • Partners have an independent artifact (the Letter of Validation), not only our privacy policy
  • The same engineering controls—encrypted tokens, least-privilege scopes, no mailbox-password collection—are reviewed against a public standard

We still publish how Google and Microsoft user data is used on the privacy policy. CASA does not replace that notice; it tests whether the application can live up to it.

What the assessment looks at

CASA is application-security focused. Typical control areas (aligned to OWASP ASVS) include:

  • Authentication and session handling — how sign-in, tokens, and logout work
  • Access control — tenant and organization isolation so one firm cannot see another firm’s data
  • Cryptography — TLS in transit; encryption of secrets such as OAuth refresh tokens at rest
  • Malicious input — injection, XSS, and related web/API weaknesses
  • Data protection and deletion — including the ability to stop access when you disconnect Gmail or close the account

AL1 verification means we produced scanner output and other evidence; an authorized lab reviewed that package for completeness and sufficiency. It is more rigorous than an internal checklist, and less invasive than AL2 (where the lab tests the live app themselves). Google assigns the required level based on scopes and risk—not the vendor.

What it means if you use LedgerTitan

For partners and staff

  • Connecting a Gmail mailbox for Emails or workflow send is backed by a current CASA AL1 Letter of Validation, renewed on the program’s annual cycle
  • You can disconnect mail integrations in Settings, or revoke LedgerTitan in your Google or Microsoft account; stored tokens are deleted so we can no longer call the API
  • Automated workflow mail and the Emails inbox still send from mailboxes you connect—we do not harvest the mailbox as a data product

For your clients

  • Clients are not asked to OAuth their personal mail into LedgerTitan for the portal. They sign in to view invoices and documents
  • Firm-to-client email still comes from your practice’s connected sender (see workflow emails)
  • Independent assessment of the platform is one input to your due diligence—alongside contracts, the privacy policy, and how you configure roles

What CASA AL1 does not mean

  • It is not SOC 2, ISO 27001, or a penetration-test report (those are separate programs; we describe operational security practices in our privacy notice)
  • It is not a guarantee that no vulnerability will ever exist
  • It does not give LedgerTitan extra rights to your data beyond the scopes you grant

How this shows up in the product

The assessment lines up with behaviors you can already see:

  1. Least privilege — Google Sign-In uses identity scopes only. Mail access is requested only if you connect a mailbox for Emails or the workflow sender.
  2. No passwords — authentication is OAuth with Google or Microsoft.
  3. Tokens encrypted at rest — refresh tokens are not dumped into browser storage for other users to read.
  4. No full mailbox clone — message bodies are fetched to display or send, not kept as a shadow archive of your entire inbox.
  5. Disconnect is real — Settings disconnect plus provider-side revocation both cut off API access.

If you are evaluating vendors that ask for mail scopes, ask for the current assurance level and the date of the Letter of Validation—not a screenshot of a “we are secure” banner.

Trust signals when a practice app asks for mail or Google user data

FeatureCASA AL1 (lab-reviewed)Vendor blog claim onlyNo published assessment
Mapped to OWASP ASVS / CASA requirementsYesNoNo
Authorized lab issues a Letter of ValidationYesNoNo
Annual revalidation expectedYesNoNo
Required by Google for many restricted scopesYesNoNo
Replaces your firm’s own vendor reviewNoNoNo

Quick picks

Best question to ask any mail-connected vendor

Current CASA letter + date

AL1/AL2 and the validation date matter more than a security adjective on a homepage.

Best companion reading

Privacy policy

CASA tests controls; the privacy policy still states what data we access and why.

Best operational habit

Dedicated workflow mailbox

Connect a practice address for automation instead of a partner’s personal inbox.

Bottom line

CASA AL1 (formerly Tier 2) is an independent, lab-reviewed check that LedgerTitan can handle sensitive Google user data to a published standard. It is a concrete trust signal for firms connecting identity and mail—not a substitute for reading the privacy policy or configuring least-privilege access in your own workspace.

Frequently asked questions

Yes in substance. The App Defense Alliance moved from Tier labels to Assurance Levels. CASA AL1 is the lab-reviewed level formerly called CASA Tier 2. CASA AL2 corresponds to the former Tier 3 (direct lab testing of the application).

See LedgerTitan on your own engagements

Start a 7-day free trial with no credit card required—or compare Bronze, Silver, and Gold plans.

All product names, logos, and brands mentioned in this article are property of their respective owners. Use of these names does not imply endorsement or affiliation. Competitor pricing and features change—verify current details on each vendor's website before making a purchase decision.