Atona's handling of Google user data has been independently assessed under CASA. This page records what that assessment covers, who performed it, when it was carried out — and, just as importantly, what it does not claim.
CASA stands for Cloud Application Security Assessment. It is a security assessment framework published by the App Defense Alliance, and it is the route by which applications that request access to sensitive or restricted Google user data demonstrate that they handle it responsibly.
An assessment is carried out against a defined set of requirements at a defined assurance level. When it is completed successfully, the assessor issues a Letter of Validation — a scoped, dated document covering a named application, not an open-ended endorsement of the company that builds it.
The framework, its tiers, and its current requirements are published by the App Defense Alliance: appdefensealliance.dev/casa.
Taken from the Letter of Validation and the assessor's assessment record.
A CASA assessment is deliberately bounded, and being specific about the boundary is part of taking it seriously. CASA is administered by the App Defense Alliance — it is an independent assessment, not a Google certification, endorsement, or partnership.
A point-in-time assessment says that a defined set of requirements was met on a defined date. It does not say nothing will ever go wrong. If you find a security issue, we would rather hear about it — see below.
Report a suspected vulnerability or a compromised account to security@atona.ai. For how data is collected, retained, and deleted, see the privacy policy.