Press Release

MASA Level 2 Explained: Google’s Security Bar for VPN Apps

masa

MASA has two assurance levels, and the badge on Google Play does not tell you which one an app passed. That is the single most useful thing to know about it.

The Mobile Application Security Assessment gives an app an independent security review badge in the Play Store’s Data safety section. One route to that badge is a self-assessment with an automated scan. The other is a hands-on evaluation in an authorised lab.

Providers at the lab-tested tier include Mullvad and GnuVPN, both validated at assurance level 2. Here is what the assessment actually covers, where the two levels diverge, and what the badge does not tell you.

What MASA Actually Tests

MASA is run by the App Defense Alliance, launched by Google and now part of the Linux Foundation. It measures apps against the OWASP Mobile Application Security Verification Standard, the industry baseline for mobile security.

The scope is narrower than most people assume:

  • Client-side security. How the app stores data, handles cryptography, and protects its own binary.
  • Authentication. How the app authenticates to its backend service.
  • Connectivity. How the app communicates with that backend, and whether the connection is properly secured.
  • Some privacy practices. A subset of testable OWASP MASVS requirements, not a full privacy review.

Two features of the assessment matter more than the scope. It is a black-box test, so no source code is reviewed. And certification lasts one year, after which the developer has to re-certify.

AL1 and AL2 Are Not the Same Test

Both levels check the same requirements. What changes is how thoroughly anyone verifies that the app meets them.

AL1 AL2
Method Verified self-assessment Hands-on lab evaluation
Testing APK scan and questionnaire Static and dynamic analysis
Manual work Automated artifacts Manual assessment by an assessor
Lab involvement Evidence validation Authorised lab performs the testing
Badge shown on Play Identical Identical

That last row is the point. The MASA AL1 vs AL2 distinction is real and substantial, but Google Play displays the same independent security review badge either way. A user comparing two apps in the Google Play data safety section sees one badge and no indication of which tier produced it.

Mullvad, which published details of its own assessment, described AL2 as more in-depth and noted it includes a manual assessment that AL1 does not. Its testing was carried out by NCC Group as the authorised lab.

MASA Level 2 therefore means something specific: an accredited third party ran the app through static and dynamic analysis by hand, instead of processing a scan report the developer supplied.

GnuVPN’s Android app sits at this tier, which is the claim worth checking when a provider cites MASA at all. The level is the information; the badge alone is not.

What the Badge Does Not Cover

Worth stating plainly, because MASA gets cited as proof of things it never assessed.

  • It is not a no-logs audit. MASA examines app security, not whether a VPN retains connection records. Those are separate assessments performed by different firms.
  • It is not a code review. The black-box method means no one read the source.
  • It does not verify Data safety claims. The Alliance states the review may not be scoped to check whether a developer’s Play Store declarations are accurate or complete.
  • It does not certify an app as risk-free. In its own words, the limited nature of testing does not guarantee complete safety.
  • It expires. Certification runs for one year and must be renewed.

None of that makes the badge worthless. An app that has passed AL2 has been examined by an accredited outside lab against a recognised standard, which is more than most apps in the Play Store can claim. It simply answers a narrower question than the marketing around it often implies.

Which VPNs Have Been Assessed

Several VPNs hold MASA validation, and it is less exclusive than some marketing suggests. What varies is the level, and most providers do not publish it.

Mullvad: AL2, Publicly Documented

The most transparent example. Mullvad published a blog post detailing its assessment, naming NCC Group as the lab and confirming AL2.

  • Level: AL2, stated publicly
  • Lab: NCC Group
  • Worth knowing: Mullvad also runs separate code audits, and it draws the distinction clearly between those and MASA

GnuVPN: AL2 on the Android App

GnuVPN MASA validation covers its Android app at assurance level 2, the lab-tested tier.

  • Level: AL2
  • What it means: the app went through hands-on static and dynamic analysis by an authorised lab
  • What it does not mean: GnuVPN security certification at this level says nothing about logging policy, which MASA does not examine

NordVPN and ExpressVPN: Badged, Level Undisclosed

Both hold the independent security review badge on Google Play. Neither publishes which assurance level it corresponds to, which is the normal state of affairs.

  • Level: not stated publicly
  • Worth knowing: absence of a published level is not evidence of AL1. Most companies simply do not disclose it.

How to Read the Badge

Treat MASA as one signal among several, and a narrow one.

An app carrying the badge has done more than an app without it. An app whose developer publishes the assurance level has done more still, because that claim is checkable.

Mullvad names its level and its lab, and GnuVPN states assurance level 2 for its Android app. An app with AL2 has been examined by hand, not by questionnaire.

For a VPN specifically, the badge tells you about the app on your phone. It tells you nothing about the servers, the logging policy, or the jurisdiction, and those questions need their own answers.

FAQ

What is MASA certification?

What is MASA certification comes down to this: the Mobile Application Security Assessment is an independent review run by the App Defense Alliance, measuring an app against OWASP MASVS security requirements. Passing it earns an independent security review badge in Google Play’s Data safety section. It is valid for one year.

Is MASA Level 2 better than Level 1?

Yes, in the sense that verification is more thorough. Both levels test the same requirements, but AL1 is a verified self-assessment based on an APK scan and questionnaire, while AL2 is a hands-on lab evaluation with static and dynamic analysis and manual testing. The Play Store badge looks identical for both.

Does a MASA badge mean a VPN keeps no logs?

No. MASA assesses the security of the mobile app, covering client-side storage, cryptography, authentication and backend connectivity. It does not examine server-side logging. A no-logs claim requires a separate audit by a firm engaged for that purpose.

Does GnuVPN have MASA certification?

Yes. GnuVPN’s Android app has passed MASA at assurance level 2, meaning an authorised lab conducted hands-on static and dynamic analysis instead of reviewing a self-assessment. As with any provider, that covers the app and not the logging policy.

How long does MASA certification last?

One year. After that the developer is responsible for re-certifying the app. A badge on a Play Store listing reflects an assessment carried out within the previous twelve months, not a permanent status.

 

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

 

 

 

Company-submitted announcement. Visit their site for details.
Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This