Trust
Independently assessed, before Google would grant the scopes.
Bolt passed CASA, the security assessment Google requires before any application is allowed restricted access to Gmail data. It was carried out by an authorized third-party lab, not self-certified. This page states exactly what that covers, and exactly what it does not.
What was assessed
The short version: an independent lab checked how Bolt handles Google user data, against a published requirement set, and Google acted on the result.
Why this one is worth something
Most trust badges are paid listings. This one has a gate behind it.
It covers the most sensitive path in the product
It is not granted once and forgotten
It is a real gate, not a listing fee
What it does not prove
Stated here so you do not have to work it out, and so nothing on this page has to be walked back later.
It is not a penetration test
It is not SOC 2, and it is not ISO 27001
It covers the Google data path, not every line of Bolt
It is not an endorsement of Bolt by Google
The part an assessment cannot give you
An assessment is someone else's word. It is better than ours, and it is still a word. For a product whose whole claim is that your data stays on your machine, the stronger answer is that you can check without trusting anyone.
Bolt runs without a Sparcle account and without contacting Sparcle. Point a network monitor at it and watch: the only thing that leaves on its own is an update check. Anything else leaves because you connected it, and it goes to that provider directly rather than through us. The Google integration this assessment covers is one of those, and it is off until you turn it on.
The exact hostnames Bolt contacts are published, as is how to prove your download came from us and what our supply chain does and does not yet cover.
Reviewing Bolt for your organization?
The assessor's report can be shared with your security team on request, alongside the pre-filled security questionnaire and the controls evidence map.