> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/certifications/certifications-overview/casa-certification-app-defense-alliance.md).

# CASA Certification (App Defense Alliance)

Application security assessment carried out according to the CASA standard, based on the OWASP Application Security Verification Standard (ASVS).

### What it is

Memori has submitted the AIsuru platform to an assessment under **CASA (Cloud Application Security Assessment)**, the framework promoted by the **App Defense Alliance (ADA)** — the initiative that brings together Google and other industry players to define uniform security requirements for cloud applications that handle potentially sensitive user data.

CASA is not an isolated audit: it is a **tiered assurance** process that adapts the depth of the verification to the application's risk profile, the users involved and the scope of the data processed.

***

### Why CASA matters

Unlike a generic penetration test, CASA verifies, in a targeted and documented way, compliance with a set of requirements derived from OWASP ASVS, organized by security domain. Each individual requirement is assessed, supported by technical evidence (automated tests, configurations, code) and tracked with an explicit verdict.

For Memori, a positive CASA outcome means giving customers and partners who integrate AIsuru with other ecosystems (including platforms that require this attestation as a condition for access to their marketplace or APIs) independent, verifiable and up-to-date proof of the application's security posture.

***

### Assessment details

| Item                        | Detail                                                                               |
| --------------------------- | ------------------------------------------------------------------------------------ |
| **Reference specification** | ADA CASA Assessment Specification v2.1.1                                             |
| **Assurance Level**         | AL1                                                                                  |
| **Testing methodology**     | Grey Box, manual testing with Burp Suite Professional + official ADA CASA procedures |
| **Assessor**                | TAC Security (TAC Infosec Ltd.)                                                      |
| **Report type**             | ESOF AppSec ADA CASA – Developer Report                                              |
| **Testing period**          | August 2026                                                                          |
| **Report issue date**       | 24 August 2026                                                                       |
| **Overall result**          | ✅ In Compliance (PASS)                                                               |

***

### Assessment scope

The assessment covered **6 security domains** and a total of **48 individual controls**, all passed with a positive outcome.

* **Authentication** — resistance to brute force, secure management of passwords and activation codes, random, single-use and expiring out-of-band verifiers (recovery links)
* **Session Management** — session invalidation on logout and password change, session cookies with Secure/HttpOnly/SameSite attributes, signed stateless tokens with limited validity
* **Access Control** — server-side enforcement of the principle of least privilege, protection against IDOR, anti-CSRF, OAuth 2.0 with Authorization Code Flow and PKCE, multi-factor authentication on administrative interfaces
* **Communications** — TLS 1.2+/1.3 with A+ rated configuration (SSL Labs), certificates issued by a publicly recognized CA, authenticated encryption (AES-256-GCM)
* **Data Validation and Sanitization** — protection against SSRF, XXE, database injection, command injection, path traversal, file uploads validated on the real binary signature
* **Configuration** — no components with known vulnerabilities (dependency scanning and static code analysis with no findings), debug disabled in production, application secrets encrypted at rest and absent from the source code

***

### Result

None of the 48 checks produced a negative outcome: the report classifies the entire scope as **compliant with level AL1** of the CASA specification, with no open vulnerabilities left to remediate.

This complements, without overlapping, the ISO certifications Memori already holds (ISO 27001, 27017, 27018, 9001, 42001): while ISO certifications attest to the soundness of the management system as a whole, CASA provides a targeted technical verification and specific checks of the security controls implemented at application level.

***

### How to access the full report

The full technical report (ESOF AppSec ADA CASA – Premium Report) is a restricted document, as it contains implementation details that are not disclosed publicly for security reasons — the same practice already adopted by Memori for penetration tests.

To request a summary of the report or more information about the scope of the assessment, write to <privacy@memori.ai> stating your company name and the purpose of the request.

<h4 align="center"><a href="mailto:privacy@memori.ai" class="button primary" data-icon="envelope">Request CASA report</a></h4>
