Foundation
- Architecture, design and threat modeling
Independent application security assessment
Review how Wandero protects connected-account data and validates application security through independent assessment.
Cloud Application Security AssessmentTAC Security, an App Defense Alliance authorized assessor, completed a lab-tested and lab-verified Cloud Application Security Assessment for the Wandero application.
Assessment type
Tier 2 (Lab Tested - Lab Verified)
The validation letter states that Wandero satisfied the applicable CASA application security requirements.
This validates the named application against applicable CASA requirements. It is not presented as a SOC 2 report or ISO certification.
Every category listed in Wandero's validation letter received a Pass status.
Wandero requests access only to provide connected product features. Provider permissions remain visible and revocable through the relevant account.
Read the Google API Limited Use DisclosureWandero's published policy identifies the Gmail modify scope for travel synchronization and vendor correspondence. It prohibits advertising, data selling, and generalized AI model training with Google Workspace data.
Manage Google accessConnections to other services are authorized through the provider or an organization administrator. Customers can remove connected access through the relevant provider and Wandero account controls.
These controls are described in Wandero's public Privacy Policy and Google API Limited Use Disclosure.
Customer data is encrypted in transit and at rest.
Access is protected through authentication and access controls.
Wandero uses secure cloud infrastructure and regular security testing.
Employees are bound by confidentiality obligations for customer information.
Public documentation for security, privacy, data use, and service terms.
Issued June 23, 2026. Valid through June 24, 2027.
View PDFData collection, use, retention, rights, and security commitments.
Read policyHow Wandero uses, restricts, and protects Google Workspace data.
Read disclosureThe terms governing access to and use of Wandero services.
Read termsSend suspected vulnerabilities privately. Include the affected URL, reproduction steps, potential impact, and relevant evidence. Do not include passwords, API keys, personal data, or customer records.
Wandero does not currently publish a bug bounty. Please avoid disrupting services or accessing data that is not yours.