After months of rigorous third‑party testing, Filo has officially passed Google's highest‑level Cloud Application Security Assessment (CASA) Tier 3.
Because Filo is an independent app (not a Chrome extension in the Web Store), you won't see a public badge floating around — but you can take our word for it: we cleared every single Tier 3 control.
A Quick Refresher: What is CASA?
CASA stands for Cloud Application Security Assessment — Google Workspace's independent audit program for third‑party apps that connect to Gmail, Drive, Calendar, and the rest of the Google stack. It has three levels:

If Tier 1 is a driver's‑license eye test, Tier 3 is the race‑track stress test: every safety system is inspected at high speed by specialists who don't work for us.
Why Tier 3 is rare — especially for email apps
- High stakes — Email is a gold mine for attackers. Google only recommends Tier 3 for apps that handle sensitive data at scale.
- No shortcuts — The lab must verify every security control — encryption, access controls, logging, incident response, data‑retention rules — before signing off.
- Annual renewal — Pass once, celebrate briefly, then do it all over again in twelve months.
Filo joins a short list of inbox tools that have met that bar.
What the auditors looked for — and what they found
Turning audit jargon into everyday peace of mind
"Do you keep my emails on your servers?"
Never. Auditors validated that message bodies, attachments, and even cached snippets live only on your phone or desktop. We see headers for routing; that's it.
"Can your AI models 'remember' what I wrote?"
No. Models run stateless requests: they process, respond, and forget. The lab traced every call → auto‑delete timestamp.
"Is my data encrypted the whole way?"
Yes. End‑to‑end TLS from Google to your device, plus device‑level AES storage. Keys rotate automatically; auditors reviewed the rotation logs.
"What if I hit 'Delete Account' in the settings?"
One tap triggers a cascade: revoke OAuth tokens ➜ purge metadata ➜ wipe local cache. The independent auditors verified that this workflow leaves no residual data on Filo servers or in your Google account.
Help Us Spread the Word ❤️
If you've ever hesitated to trust an AI inbox, we hope this blog — and the green shield behind it — earns a little of that trust back. Share this post, tell a friend who still forwards emails to themselves, or drop by our Discord community.
Until the next milestone,
The Filo Team — powered by ☕️ caffeine, curiosity, and now, CASA Tier 3 confidence.



