Skip to content

Commit 9d62f3d

Browse files
committed
docs: Update SECURITY.md with CASA details
1 parent 9f93f93 commit 9d62f3d

File tree

1 file changed

+16
-3
lines changed

1 file changed

+16
-3
lines changed

SECURITY.md

Lines changed: 16 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,23 @@
11
# Thunderbird for Android Security
22

3-
## Security Audit
3+
## CASA Assessment
4+
5+
The [Cloud Application Security Assessment (CASA)](https://appdefensealliance.dev/casa) is an annual security review
6+
required by Google for apps that request access to restricted scopes such as Gmail data. It verifies that an app
7+
follows solid security practices for handling, storing, and accessing user information.
8+
9+
Thunderbird for Android and K-9 Mail have completed the CASA assessment at Tier 2, covering broader access to
10+
Gmail features. The process was carried out by [NetSentries](https://www.netsentries.com/service/casa), an
11+
approved [ADA assessor](https://www.appdefensealliance.org/). We'd like to thank the team for their support. They
12+
have been supportive throughout, communicated clearly at every step, and were generous with their time and guidance.
13+
If your application requires a CASA review as well, please reach out to them.
14+
15+
## OSTIF / 7A Security Audit 2023
416

517
The code in this repository underwent an extensive security audit in collaboration with the Open Source Technology
6-
Improvement Fund ([OSTIF](https://ostif.org/)) and [7ASecurity](https://7asecurity.com/) in the first half of 2023. For
7-
more details, see
18+
Improvement Fund ([OSTIF](https://ostif.org/)) and [7ASecurity](https://7asecurity.com/) in the first half of 2023.
19+
OSTIF and 7ASecurity were amazing partners that provided a helpful guiding hand, and made the process of doing the
20+
audit a breeze. We really appreciated their professionalism and expertise. For more details, see
821
our [blog post](https://blog.thunderbird.net/2023/07/k-9-mail-collaborates-with-ostif-and-7asecurity-security-audit/).
922

1023
## Verifying Fingerprints

0 commit comments

Comments
 (0)