← Blog

What CASA Reviews for Gmail Apps

Connecting an app to Gmail requires a meaningful level of trust. The Cloud Application Security Assessment (CASA) framework provides a standardized way to review security controls used by applications that access Google user data. This article explains what that review covers and how it relates to Premail's local-first design.

What CASA is

CASA is a security assessment framework for applications that access Google user data. Its review areas include authentication, data protection, vulnerability management, and secure development practices.

CASA is distinct from Google OAuth verification. OAuth verification reviews an app's identity, requested permissions, and consent experience, while CASA focuses on the security controls surrounding an integration. Neither process is a guarantee that software is risk-free, and an assessment only reflects the scope and point in time documented by its assessor.

How Premail limits Gmail access

Premail needs Gmail access to classify messages and carry out the actions you configure, such as archiving, labeling, or moving mail. The desktop app connects directly to Gmail; Premail does not operate a cloud inbox that receives or stores your messages.

The assessment does not expand what Premail can access or change the permissions it requests. You remain in control: Google shows the requested access before you approve it, and you can revoke Premail's access from your Google Account at any time.

Security is ongoing work

No assessment or authorization flow replaces ongoing security work. We continue maintaining Premail's controls, dependencies, and development practices as the product evolves. We also explain plainly what data Premail uses, why it needs access, and how users stay in control.

Our Trust Center brings that information together. Visit it for Premail's current security and privacy posture, an overview of external data flows, and links to the policies governing your data.