Back to series
SecuritySection 03 of 3

Axionomy Passes CASA AL1 Security Assessment with TAC Security

Independent Cloud Application Security Assessment validation for OAuth, user data, and agent integrations—and what it means for innovation teams connecting Gmail, Drive, Notion, and LinkedIn.

TAC Security ESOF CASA AL1 verified and secured — ADA CASA Assessor
2026-10-07
5 min read
Axionomy Editorial

Passing CASA AL1 means Axionomy's security controls were tested by a third party—not just self-declared.

We are proud to share that Axionomy has successfully passed the CASA AL1 security assessment, conducted by TAC Security.

CASA—the Cloud Application Security Assessment—is an independent, industry-recognized framework for verifying that cloud applications handle user data securely. AL1 is the foundational tier: it focuses on the controls that matter when your product connects to Gmail, Calendar, Drive, Notion, LinkedIn, Slack, and other OAuth-backed services—the same surface area Axionomy's agent harness uses every day.

Why third-party assessment matters

Innovation leaders connect real inboxes, calendars, and document libraries to agent workspaces. A vendor saying "we take security seriously" is not the same as an assessor validating authentication flows, data handling, and operational practices against a published standard.

Passing CASA AL1 means our controls were tested externally. That aligns with how we build Axionomy: security embedded in design, development, and operations—not bolted on after launch.

What we validated

The assessment covered the security posture of the Axionomy application and its approach to protecting user data across connected integrations. For teams using Setup and Settings → Integrations, this reinforces that OAuth grants, agent approvals, and workspace artifacts are backed by assessed practices—not ad hoc promises.

The same commitment extends to DiPass and other applications we develop at Dipassio X Labs. Shared engineering standards, shared review discipline, and shared expectations for how customer data is handled.

What this means for your program

If you run R&D automation, Cowork vault workflows, or CRM-adjacent agent missions, you need two things: speed and accountability. CASA AL1 does not replace your internal security review, but it gives procurement and IT partners an independent signal that Axionomy meets a recognized cloud application bar.

Human-in-the-loop approvals, revocable integrations, and transparent run history in Mission Observatory remain central—you still control what agents send, publish, or write. CASA validates the platform layer those controls sit on.

What's next

CASA AL1 is one milestone on a longer security journey. SOC 2 is on our roadmap; we will pursue it as customer and regulatory requirements grow.

Thank you to the TAC Security team for a rigorous assessment, and to our engineers for the discipline behind this result.

Learn more about how Axionomy connects tools in Setup, read integration and privacy details at /privacy, or explore the harness on the landing page at axionomy.xyz.

All blog articles · Site index

CASA AL1TAC SecurityApp SecurityOAuthSOC 2

Key takeaways from this section

Independent verification

CASA AL1 is a third-party Cloud Application Security Assessment—not a self-attestation checklist.

Built for connected agents

The assessment context matches Axionomy's OAuth integrations and agent workflows innovation teams rely on.

Shared standards at Dipassio

The same security principles apply across Axionomy, DiPass, and future applications from Dipassio X Labs.

Roadmap beyond AL1

SOC 2 is planned as requirements scale; CASA AL1 establishes the baseline today.

Ready to navigate the transition?

Axionomy connects innovation ecosystems. Join and discover how the tools that open doors are being built today.

Get Started