Mailneo Is CASA Tier 2 Certified. It Took Us Two Attempts.
Google makes every app that touches restricted Gmail scopes pass an independent security assessment. Ours came through on 31 July 2026. What CASA actually checks, why our first attempt never happened, what the lab found when they scanned us, and what any of it changes for you.
Sohail Hussain7 min readMailneo is CASA Tier 2 certified. TAC Security, one of the labs Google authorizes for this, issued our Letter of Validation on 31 July 2026, and Google accepted it the following morning.
If you've ever clicked "Allow" on a Google consent screen and wondered whether anybody actually inspects the app on the other side, CASA is the answer. Somebody does.
Now the part I'd rather leave out. Google pointed us at this same gate back in January, with a deadline of 5 April (a date I still think about more than is healthy), and we didn't make it. Nothing dramatic happened. I read "two to six weeks" in the documentation, filed it mentally under later, and later turned up in March with no lab booked and no scan run. The verification lapsed. We then got to walk the entire scope review again from the top, which is exactly as fun as it sounds.
So, motivated this time.
So what is CASA?
Cloud Application Security Assessment. Catchy.
It's run by the App Defense Alliance, which sounds like a Marvel subplot but is a Linux Foundation project with Google, Meta, and Microsoft on the steering committee. The rulebook is a public document called the CASA Test Guide (currently v2.1.1), and it leans heavily on the OWASP Application Security Verification Standard, so most of it will look familiar to anyone who has done security work before.
Google requires it from any app asking for what they call restricted scopes. Restricted means the data is genuinely sensitive. Your Gmail, obviously, qualifies.
No letter, no access. I'm not sure people outside this world appreciate how absolute that is; there's no appeal, no grandfather clause, no "but we have paying customers." Miss the date and the scope switches off.
Then you do the whole thing again twelve months later.
Tier 1, Tier 2, Tier 3
Three levels. The names changed partway through, so half the documentation calls them tiers and the other half calls them assurance levels. Tier 2 is AL1. Yes, really.
Tier 1 is a self-scan. You run the tooling, you attest, nobody independent looks.
Tier 2 is what we did. An authorized lab scans the live application, reads your evidence against all 48 requirements, and issues the letter once every last item is closed. They're marking your homework.
Tier 3 goes further: an independent penetration test, plus review of your infrastructure and how you store things. That's the one you need to list on the Google Workspace Marketplace.
You don't get to choose. Google assigns your level based on how sensitive the data is, how many users you have, and whatever risk signals they watch. We were assigned Tier 2.
Worth knowing if you're heading into this yourself: the pentest you already paid for doesn't count. Doesn't matter how good the firm was or how recent the report is. Only an ADA-authorized lab can issue a letter Google will accept (a thing I established the expensive way).
Why we couldn't skip it
Mailneo's unified inbox talks to Gmail through a scope called gmail.modify. It's what lets us show you your mail, mark things read, move a message into a folder, file it away. Take it out and the inbox becomes a window you can look through but never touch.
Google would have preferred we use something narrower, and said so three separate times. The alternative they suggested genuinely doesn't work for us; the API calls that move and file mail don't accept those scopes at all, a point I made with more screenshots than I'd like to admit to. They agreed in July.
That cleared scope review. CASA was the next gate, deadline 22 October.
I'd love to tell you what followed was carefully project-managed. What actually happened is that I remembered April, went briefly cold, and booked the lab that week.
What they actually check
Forty-eight checks across six categories: authentication, session management, access control, communications, data validation and sanitization, and configuration. The requirement list is published; the evidence you hand over isn't.
Plenty of it is unglamorous and exactly what you'd hope somebody had already thought about. How passwords are stored. When sessions expire. What's encrypted on the way across. Fine. We had that.
The sharper requirements are the ones about keeping one customer's data away from another's, and those are the checks I'd lose sleep over in any multi-tenant product, ours included. A couple of them changed how we work (for the better, though I wasn't especially gracious about it at the time).
The pass bar surprised me, though. Everything gets closed, down to items the scanner itself files under informational. You either fix it or you write an argument for why it isn't a problem, and a human being reads your argument and decides. There's no column labeled "accepted risk, moving on." I have read a lot of security reports with that column.
What the scan turned up
They scanned the live application in late July. No criticals. No highs.
One medium came back, on one of our public marketing tools; a page with no login, no subscriber data, and no connection to anybody's mailbox. Everything else was low or informational.
Still a bug, though, so we fixed it and wrote tests so it can't sneak back in six months. We also cleaned up a few things we'd caught ourselves while filling in the questionnaire, which is a decent argument for the questionnaire existing at all. Of what remained, some was our hosting platform behaving the way hosting platforms behave, and some was the scanner flagging things that turned out to be fine once a person looked. Each one got a written answer.
They rescanned. The letter landed on the 31st.
What does this mean for you?
Honestly? Mostly that nothing changes, which is rather the point.
But I know how much trust it takes to plug your mailbox into somebody else's software. Mailneo sits on top of the inbox you run your business from, right next to your subscriber list. That's about as much access as you can hand a piece of software. We've never been casual about it, and now we're independently lab-certified, so:
- Your data is secure. How we store passwords, how sessions work, what's encrypted in transit, how one team's data is kept away from another's; all of it checked against a published standard by people who don't work here and had nothing to gain from being generous.
- We meet Google's security requirements for restricted Gmail access. Apps that fall short lose it, usually with very little warning, and the integration breaks for every customer at once. That's off the table for us.
- The one real finding is fixed and covered by tests, so it can't quietly reappear.
None of this is new behavior. Your data was handled this way last month, and the month before that. What changed on 31 July is that somebody with no stake in the answer went and verified it, against a bar that Google, Meta, and Microsoft helped write.
Thank you for trusting us with it. Genuinely.
We do this again next year
The letter runs twelve months, so we'll be back in front of a lab around July 2027. This time it's in the calendar with reminders attached, rather than in my head, which is where it lived last time and look how that went.
If you want the detail underneath the badge: our security overview covers infrastructure and encryption, our GDPR commitment and privacy policy cover data rights, and we'll sign a DPA with anyone who needs one.
Questions are welcome at hi@mailneo.co. That's our security contact too, so if you've found something, same address; we would much rather hear it from you than from a scanner.
New here? Start free.
Explore: Email Compliance
Related Articles
Confidential Email Disclaimer: A Guide for Businesses
A confidential email disclaimer can support handling expectations, but it is not a legal shield by itself. This guide explains when disclaimers help, when they add noise, and how businesses should write and apply them responsibly.
Email Marketing Laws: A Practical Compliance Guide
What CAN-SPAM, GDPR, PECR, and CASL actually require of a marketing team, turned into consent capture, source vetting, suppression, and a pre-send checklist you'll use.
Suppression List Management: How to Stop Bad Sends
Suppression list management is the process of preventing emails from going to people who bounced, complained, unsubscribed, or should not be contacted for compliance reasons. A good suppression system protects deliverability, preserves consent records, and stops old imports from reactivating addresses by mistake.
CAN-SPAM Compliance: The 2026 Guide for US Email Marketers
The CAN-SPAM Act sets seven rules for commercial email sent to US recipients, from accurate headers to a working opt-out honored within 10 business days. This post is general information, not legal advice; the FTC can fine you up to $51,744 per offending email.
Ready to supercharge your email marketing?
Start sending smarter emails with AI-powered campaigns. No credit card required.
Get Started Free