Newer Version Available

This content describes an older version of this product. View Latest

Required Materials for Security Review Submission

Learn about the materials to provide, such as test environments and documentation, when submitting your solution for an AppExchange security review. Mobile apps have platform-specific submission requirements. Extension packages undergo security review, and Salesforce requires the same materials for them as for a standalone app.

The security review tests require access to all environments, packages, and external components that your solution uses. We like to see that you’ve done your due diligence in ensuring that your solution meets enterprise security standards. Be sure to include security scan reports, along with explanations of false positives if they appear in your testing results.

Be sure that your submission is a Managed—Released package. We can’t accept an unmanaged or beta package.

Note

The following table summarizes what to submit based on the scope of your architecture. Use the Security Review Submission Requirements Checklist Builder to generate a checklist that is customized for your solution.

Material for Submission Salesforce Native Solution Salesforce Native Solution with Lightning Components Solution with External Web App or Service Solution with a Mobile Client API Only Marketing Cloud App
Salesforce Developer Edition Org X X X X X
URLs & Login Credentials for External Components Requiring Authentication X X X
Managed Package Installed in Developer Edition Org X X X X
Checkmarx Report X X X X
Zap or Chimera Scan Report X X X X
False Positives Documentation (if applicable) X X X X X X
Product Documentation X X X X X
Platform with Installation Link or File X
Credentials to Marketing Cloud Environment X

Mobile Apps

For mobile app testing, provision the app for all the platforms that you plan to distribute on. We accept a test flight or an ad hoc deployment for iOS. For other platforms, we accept the app in a file, such as an Android Packaging (.apk) file.

Extension Packages

An extension package is a package that is an add-on to an app or that integrates the functionality of two apps released by different ISVs. An extension package must pass security review before it can be publicly listed on AppExchange.

The submission requirements for an extension package are the same as for an app that has a similar architecture. For example, if you have an extension package with external callouts, attach separate web scan results for the specific packages with the callouts.

It’s important that the Salesforce security team reviews every extension package. Even small packages can introduce vulnerabilities to the platform.