Trust

Independently assessed, before Google would grant the scopes.

Bolt passed CASA, the security assessment Google requires before any application is allowed restricted access to Gmail data. It was carried out by an authorized third-party lab, not self-certified. This page states exactly what that covers, and exactly what it does not.

What was assessed

The short version: an independent lab checked how Bolt handles Google user data, against a published requirement set, and Google acted on the result.

Programme
CASA, the Cloud Application Security Assessment, administered through the App Defense Alliance and built on the OWASP Application Security Verification Standard.
Assessor
TAC Security, an authorized CASA assessment lab. The lab is independent of Sparcle and is not chosen by us for the outcome; Google requires the assessment to be performed by an authorized lab.
Application
Bolt by Sparcle.
Scope
How Bolt requests, handles, stores, and deletes Google user data, across the 48 requirements in the assessment.
Outcome
The lab confirmed our evidence met the requirements and issued a Letter of Validation to Google. Google grants restricted access to Gmail data only on receipt of that letter.

Why this one is worth something

Most trust badges are paid listings. This one has a gate behind it.

It was reviewed by someone other than us

Every one of the 48 requirements was answered with evidence and verified by the lab, not self-attested on a form. The submission included a static analysis report over the Bolt codebase with no findings.

It covers the most sensitive path in the product

Restricted scopes are the ones Google treats as high risk: the contents of a user's mailbox. That is precisely the path an assessment should be pointed at, and it is where CASA was pointed.

It is not granted once and forgotten

Restricted-scope access is re-reviewed on Google's schedule rather than issued permanently. An app that stops meeting the bar loses the scopes.

It is a real gate, not a listing fee

Until the Letter of Validation reached Google, Bolt could not obtain restricted Gmail access at all. The connect flow existed and the scopes did not.

What it does not prove

Stated here so you do not have to work it out, and so nothing on this page has to be walked back later.

It is not a penetration test

CASA verifies that defined security requirements are met with evidence. It does not put a red team against the product. An independent penetration test is a separate engagement, targeted for Q4 2026, and we will publish the summary.

It is not SOC 2, and it is not ISO 27001

Those attest to the operation of a company's controls over time. CASA attests to an application against a requirement set. SOC 2 Type I is targeted for Q4 2026 and Type II for Q2 2027, and we say so plainly rather than implying either today.

It covers the Google data path, not every line of Bolt

Most of Bolt never touches Google data at all: it runs offline on your machine. CASA has nothing to say about those parts, so we do not stretch it to cover them.

It is not an endorsement of Bolt by Google

Google approving restricted scopes means the requirements were met. It is not a review of whether Bolt is good, and no one should read it as one.

The part an assessment cannot give you

An assessment is someone else's word. It is better than ours, and it is still a word. For a product whose whole claim is that your data stays on your machine, the stronger answer is that you can check without trusting anyone.

Bolt runs without a Sparcle account and without contacting Sparcle. Point a network monitor at it and watch: the only thing that leaves on its own is an update check. Anything else leaves because you connected it, and it goes to that provider directly rather than through us. The Google integration this assessment covers is one of those, and it is off until you turn it on.

The exact hostnames Bolt contacts are published, as is how to prove your download came from us and what our supply chain does and does not yet cover.

Reviewing Bolt for your organization?

The assessor's report can be shared with your security team on request, alongside the pre-filled security questionnaire and the controls evidence map.