Newer Version Available
Required Materials for Security Review Submission
The security review tests require access to all environments, packages, and external components that your solution uses. We like to see that you’ve done your due diligence in ensuring that your solution meets enterprise security standards. Be sure to include security scan reports, along with explanations of false positives if they appear in your testing results.
The following table summarizes what to submit based on the scope of your architecture. Use the Security Review Submission Requirements Checklist Builder to generate a checklist that is customized for your solution.
| Material for Submission | Salesforce Native Solution | Salesforce Native Solution with Lightning Components | Solution with External Web App or Service | Solution with a Mobile Client | API Only | Marketing Cloud App |
|---|---|---|---|---|---|---|
| Salesforce Developer Edition Org | X | X | X | X | X | |
| URLs & Login Credentials for External Components Requiring Authentication | X | X | X | |||
| Managed Package Installed in Developer Edition Org | X | X | X | X | ||
| Checkmarx Report | X | X | X | X | ||
| Zap or Chimera Scan Report | X | X | X | X | ||
| False Positives Documentation (if applicable) | X | X | X | X | X | X |
| Product Documentation | X | X | X | X | X | |
| Platform with Installation Link or File | X | |||||
| Credentials to Marketing Cloud Environment | X |
Mobile Apps
For mobile app testing, provision the app for all the platforms that you plan to distribute on. We accept a test flight or an ad hoc deployment for iOS. For other platforms, we accept the app in a file, such as an Android Packaging (.apk) file.
Extension Packages
An extension package is a package that is an add-on to an app or that integrates the functionality of two apps released by different ISVs. An extension package must pass security review before it can be publicly listed on AppExchange.
The submission requirements for an extension package are the same as for an app that has a similar architecture. For example, if you have an extension package with external callouts, attach separate web scan results for the specific packages with the callouts.
It’s important that the Salesforce security team reviews every extension package. Even small packages can introduce vulnerabilities to the platform.