Platform architecture
LedgerTitan Is CASA AL1 Certified—What That Means for Your Firm
Accounting firms should not have to take a vendor’s word for how it handles identity and mailbox data. LedgerTitan has completed CASA Assurance Level 1 (AL1)—the App Defense Alliance Cloud Application Security Assessment level formerly known as CASA Tier 2. An authorized lab reviewed our evidence against the CASA requirements and issued a Letter of Validation. This article explains the program in plain language and what it changes for people who trust LedgerTitan with client work.
What CASA AL1 actually is
CASA (Cloud Application Security Assessment) is the App Defense Alliance framework Google uses to verify that apps requesting restricted Google APIs such as Gmail can handle that data securely. It is mapped to OWASP ASVS (Application Security Verification Standard). The requirements are the same at every assurance level; what changes is how thoroughly they are verified.
Google and the Alliance renamed the old Tier labels to Assurance Levels:
| Former name | Current name | How it is verified |
|---|---|---|
| CASA Tier 2 | CASA AL1 | Developer-tested, lab-reviewed — you submit scans, evidence, and attestations; an ADA-authorized lab reviews them and issues a Letter of Validation |
| CASA Tier 3 | CASA AL2 | Lab-tested — the lab evaluates the running application directly |
AL1 is not a self-checked checkbox on a marketing site. A lab must accept the evidence. It is also not a claim that Google “endorses” the product or that the assessment replaces your firm’s own vendor review.
Why LedgerTitan completed AL1
Apps that ask for sensitive OAuth scopes—especially mail—are held to a higher bar: annual assessment, proof that user data can be deleted on request, and verification that the application is built to handle tokens and content securely.
LedgerTitan completed CASA AL1 so that:
- Gmail workflow and inbox features can meet Google’s restricted-scope requirements
- Partners have an independent artifact (the Letter of Validation), not only our privacy policy
- The same engineering controls—encrypted tokens, least-privilege scopes, no mailbox-password collection—are reviewed against a public standard
We still publish how Google and Microsoft user data is used on the privacy policy. CASA does not replace that notice; it tests whether the application can live up to it.
What the assessment looks at
CASA is application-security focused. Typical control areas (aligned to OWASP ASVS) include:
- Authentication and session handling — how sign-in, tokens, and logout work
- Access control — tenant and organization isolation so one firm cannot see another firm’s data
- Cryptography — TLS in transit; encryption of secrets such as OAuth refresh tokens at rest
- Malicious input — injection, XSS, and related web/API weaknesses
- Data protection and deletion — including the ability to stop access when you disconnect Gmail or close the account
AL1 verification means we produced scanner output and other evidence; an authorized lab reviewed that package for completeness and sufficiency. It is more rigorous than an internal checklist, and less invasive than AL2 (where the lab tests the live app themselves). Google assigns the required level based on scopes and risk—not the vendor.
What it means if you use LedgerTitan
For partners and staff
- Connecting a Gmail mailbox for Emails or workflow send is backed by a current CASA AL1 Letter of Validation, renewed on the program’s annual cycle
- You can disconnect mail integrations in Settings, or revoke LedgerTitan in your Google or Microsoft account; stored tokens are deleted so we can no longer call the API
- Automated workflow mail and the Emails inbox still send from mailboxes you connect—we do not harvest the mailbox as a data product
For your clients
- Clients are not asked to OAuth their personal mail into LedgerTitan for the portal. They sign in to view invoices and documents
- Firm-to-client email still comes from your practice’s connected sender (see workflow emails)
- Independent assessment of the platform is one input to your due diligence—alongside contracts, the privacy policy, and how you configure roles
What CASA AL1 does not mean
- It is not SOC 2, ISO 27001, or a penetration-test report (those are separate programs; we describe operational security practices in our privacy notice)
- It is not a guarantee that no vulnerability will ever exist
- It does not give LedgerTitan extra rights to your data beyond the scopes you grant
How this shows up in the product
The assessment lines up with behaviors you can already see:
- Least privilege — Google Sign-In uses identity scopes only. Mail access is requested only if you connect a mailbox for Emails or the workflow sender.
- No passwords — authentication is OAuth with Google or Microsoft.
- Tokens encrypted at rest — refresh tokens are not dumped into browser storage for other users to read.
- No full mailbox clone — message bodies are fetched to display or send, not kept as a shadow archive of your entire inbox.
- Disconnect is real — Settings disconnect plus provider-side revocation both cut off API access.
If you are evaluating vendors that ask for mail scopes, ask for the current assurance level and the date of the Letter of Validation—not a screenshot of a “we are secure” banner.
Trust signals when a practice app asks for mail or Google user data
| Feature | CASA AL1 (lab-reviewed) | Vendor blog claim only | No published assessment |
|---|---|---|---|
| Mapped to OWASP ASVS / CASA requirements | Yes | No | No |
| Authorized lab issues a Letter of Validation | Yes | No | No |
| Annual revalidation expected | Yes | No | No |
| Required by Google for many restricted scopes | Yes | No | No |
| Replaces your firm’s own vendor review | No | No | No |
Quick picks
Best question to ask any mail-connected vendor
Current CASA letter + date
AL1/AL2 and the validation date matter more than a security adjective on a homepage.
Best companion reading
Privacy policy
CASA tests controls; the privacy policy still states what data we access and why.
Best operational habit
Dedicated workflow mailbox
Connect a practice address for automation instead of a partner’s personal inbox.
Bottom line
CASA AL1 (formerly Tier 2) is an independent, lab-reviewed check that LedgerTitan can handle sensitive Google user data to a published standard. It is a concrete trust signal for firms connecting identity and mail—not a substitute for reading the privacy policy or configuring least-privilege access in your own workspace.
Frequently asked questions
Related articles
Ledger & workflow
Send LedgerTitan Workflow Emails from Outlook or Gmail
How LedgerTitan sends reminders, client invoices, invites, and workflow steps from a dedicated Outlook or Gmail mailbox—separate from each user’s personal inbox.
Platform architecture
How LedgerTitan Handles Multi-Organization Firms
One subscription, multiple organizations—per-org QuickBooks, Stripe, portal branding, role-based access, templates, reminders, and notifications explained.
Client portal
The LedgerTitan Client Portal: Invoices, Payment Methods, and Low-Friction Access
How clients view invoices, save cards, and pay your firm in the LedgerTitan portal—with minimal setup and no accounting software on their side.
See LedgerTitan on your own engagements
Start a 7-day free trial with no credit card required—or compare Bronze, Silver, and Gold plans.
All product names, logos, and brands mentioned in this article are property of their respective owners. Use of these names does not imply endorsement or affiliation. Competitor pricing and features change—verify current details on each vendor's website before making a purchase decision.
