Independent application security assessment

Security you can verify

Review how Wandero protects connected-account data and validates application security through independent assessment.

First page of Wandero's CASA Tier 2 validation letterCloud Application Security Assessment
Assessment
CASA Tier 2
Assessor
TAC Security
Status
Complete
Valid through

Independent validation

TAC Security, an App Defense Alliance authorized assessor, completed a lab-tested and lab-verified Cloud Application Security Assessment for the Wandero application.

Assessment type

Tier 2 (Lab Tested - Lab Verified)

The validation letter states that Wandero satisfied the applicable CASA application security requirements.

Application
Wandero
Organization
Wandero Inc
Issued
Expires
Certification ID
ec46ce8f
Assessment status
Complete

This validates the named application against applicable CASA requirements. It is not presented as a SOC 2 report or ISO certification.

What the assessment covered

Every category listed in Wandero's validation letter received a Pass status.

Foundation

  • Architecture, design and threat modeling

Identity and access

  • Authentication
  • Session management
  • Access control

Data and communications

  • Stored cryptography
  • Data protection
  • Communications

Application safeguards

  • Validation, sanitization and encoding
  • Error handling and logging
  • Malicious code
  • Business logic
  • Files and resources
  • API and web services
  • Configuration

Connected-account authorization

Wandero requests access only to provide connected product features. Provider permissions remain visible and revocable through the relevant account.

Read the Google API Limited Use Disclosure

Google Workspace

Wandero's published policy identifies the Gmail modify scope for travel synchronization and vendor correspondence. It prohibits advertising, data selling, and generalized AI model training with Google Workspace data.

Manage Google access

Provider and admin controls

Connections to other services are authorized through the provider or an organization administrator. Customers can remove connected access through the relevant provider and Wandero account controls.

Published security commitments

These controls are described in Wandero's public Privacy Policy and Google API Limited Use Disclosure.

Encryption

Customer data is encrypted in transit and at rest.

Controlled access

Access is protected through authentication and access controls.

Secure infrastructure

Wandero uses secure cloud infrastructure and regular security testing.

Confidential handling

Employees are bound by confidentiality obligations for customer information.

Documents and policies

Public documentation for security, privacy, data use, and service terms.

Report a security concern

Send suspected vulnerabilities privately. Include the affected URL, reproduction steps, potential impact, and relevant evidence. Do not include passwords, API keys, personal data, or customer records.

Wandero does not currently publish a bug bounty. Please avoid disrupting services or accessing data that is not yours.