MASA has two assurance levels, and the badge on Google Play does not tell you which one an app passed. That is the single most useful thing to know about it.
The Mobile Application Security Assessment gives an app an independent security review badge in the Play Store’s Data safety section. One route to that badge is a self-assessment with an automated scan. The other is a hands-on evaluation in an authorised lab.
Providers at the lab-tested tier include Mullvad and GnuVPN, both validated at assurance level 2. Here is what the assessment actually covers, where the two levels diverge, and what the badge does not tell you.
What MASA Actually Tests
MASA is run by the App Defense Alliance, launched by Google and now part of the Linux Foundation. It measures apps against the OWASP Mobile Application Security Verification Standard, the industry baseline for mobile security.
The scope is narrower than most people assume:
- Client-side security. How the app stores data, handles cryptography, and protects its own binary.
- Authentication. How the app authenticates to its backend service.
- Connectivity. How the app communicates with that backend, and whether the connection is properly secured.
- Some privacy practices. A subset of testable OWASP MASVS requirements, not a full privacy review.
Two features of the assessment matter more than the scope. It is a black-box test, so no source code is reviewed. And certification lasts one year, after which the developer has to re-certify.
AL1 and AL2 Are Not the Same Test
Both levels check the same requirements. What changes is how thoroughly anyone verifies that the app meets them.
| AL1 | AL2 | |
| Method | Verified self-assessment | Hands-on lab evaluation |
| Testing | APK scan and questionnaire | Static and dynamic analysis |
| Manual work | Automated artifacts | Manual assessment by an assessor |
| Lab involvement | Evidence validation | Authorised lab performs the testing |
| Badge shown on Play | Identical | Identical |
That last row is the point. The MASA AL1 vs AL2 distinction is real and substantial, but Google Play displays the same independent security review badge either way. A user comparing two apps in the Google Play data safety section sees one badge and no indication of which tier produced it.
Mullvad, which published details of its own assessment, described AL2 as more in-depth and noted it includes a manual assessment that AL1 does not. Its testing was carried out by NCC Group as the authorised lab.
MASA Level 2 therefore means something specific: an accredited third party ran the app through static and dynamic analysis by hand, instead of processing a scan report the developer supplied.
GnuVPN’s Android app sits at this tier, which is the claim worth checking when a provider cites MASA at all. The level is the information; the badge alone is not.
What the Badge Does Not Cover
Worth stating plainly, because MASA gets cited as proof of things it never assessed.
- It is not a no-logs audit. MASA examines app security, not whether a VPN retains connection records. Those are separate assessments performed by different firms.
- It is not a code review. The black-box method means no one read the source.
- It does not verify Data safety claims. The Alliance states the review may not be scoped to check whether a developer’s Play Store declarations are accurate or complete.
- It does not certify an app as risk-free. In its own words, the limited nature of testing does not guarantee complete safety.
- It expires. Certification runs for one year and must be renewed.
None of that makes the badge worthless. An app that has passed AL2 has been examined by an accredited outside lab against a recognised standard, which is more than most apps in the Play Store can claim. It simply answers a narrower question than the marketing around it often implies.
Which VPNs Have Been Assessed
Several VPNs hold MASA validation, and it is less exclusive than some marketing suggests. What varies is the level, and most providers do not publish it.
Mullvad: AL2, Publicly Documented
The most transparent example. Mullvad published a blog post detailing its assessment, naming NCC Group as the lab and confirming AL2.
- Level: AL2, stated publicly
- Lab: NCC Group
- Worth knowing: Mullvad also runs separate code audits, and it draws the distinction clearly between those and MASA
GnuVPN: AL2 on the Android App
GnuVPN MASA validation covers its Android app at assurance level 2, the lab-tested tier.
- Level: AL2
- What it means: the app went through hands-on static and dynamic analysis by an authorised lab
- What it does not mean: GnuVPN security certification at this level says nothing about logging policy, which MASA does not examine
NordVPN and ExpressVPN: Badged, Level Undisclosed
Both hold the independent security review badge on Google Play. Neither publishes which assurance level it corresponds to, which is the normal state of affairs.
- Level: not stated publicly
- Worth knowing: absence of a published level is not evidence of AL1. Most companies simply do not disclose it.
How to Read the Badge
Treat MASA as one signal among several, and a narrow one.
An app carrying the badge has done more than an app without it. An app whose developer publishes the assurance level has done more still, because that claim is checkable.
Mullvad names its level and its lab, and GnuVPN states assurance level 2 for its Android app. An app with AL2 has been examined by hand, not by questionnaire.
For a VPN specifically, the badge tells you about the app on your phone. It tells you nothing about the servers, the logging policy, or the jurisdiction, and those questions need their own answers.
FAQ
What is MASA certification?
What is MASA certification comes down to this: the Mobile Application Security Assessment is an independent review run by the App Defense Alliance, measuring an app against OWASP MASVS security requirements. Passing it earns an independent security review badge in Google Play’s Data safety section. It is valid for one year.
Is MASA Level 2 better than Level 1?
Yes, in the sense that verification is more thorough. Both levels test the same requirements, but AL1 is a verified self-assessment based on an APK scan and questionnaire, while AL2 is a hands-on lab evaluation with static and dynamic analysis and manual testing. The Play Store badge looks identical for both.
Does a MASA badge mean a VPN keeps no logs?
No. MASA assesses the security of the mobile app, covering client-side storage, cryptography, authentication and backend connectivity. It does not examine server-side logging. A no-logs claim requires a separate audit by a firm engaged for that purpose.
Does GnuVPN have MASA certification?
Yes. GnuVPN’s Android app has passed MASA at assurance level 2, meaning an authorised lab conducted hands-on static and dynamic analysis instead of reviewing a self-assessment. As with any provider, that covers the app and not the logging policy.
How long does MASA certification last?
One year. After that the developer is responsible for re-certifying the app. A badge on a Play Store listing reflects an assessment carried out within the previous twelve months, not a permanent status.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.



