Security Requirements for ISV Partners and AgentExchange Solutions
As a condition of your participation in the ISV Partner Program, you must adhere to the security requirements outlined in this document. These requirements include general requirements applicable to all ISV Partners and Partner Applications, and additional requirements that are specific to Partner Applications that use or connect with specific technology or are intended for use in specific industries. In these requirements, Partner Applications are also referred to as “solutions.” When you create or edit an AgentExchange listing, you’re required to confirm that you complied with these requirements.
The security requirements in this document aren’t exhaustive. We encourage Partners to follow all applicable industry security standards.
General AgentExchange Requirements
- All Partners must comply with the requirements described in Security Policy Requirements.
- All Partner Applications must comply with the requirements described in Prevent Secure Coding Violations.
- All Partner Applications must pass a Salesforce Security Review and Assessment where required under the ISV Partner Program Policies.
B2C Commerce Solution Security Requirements
If your Partner Application is a B2C Commerce Cartridge or Headless Integration, you must also follow the requirements described in Secure Your B2C Commerce Solution. These B2C Commerce specific requirements are in addition to the General AgentExchange Requirements.
Tableau Accelerator Security Requirements
If your Partner Application is a Tableau Accelerator, you must also follow the requirements described in Secure Your Tableau Accelerator. These Tableau specific requirements are in addition to the General AgentExchange Requirements.
Agentforce Security Requirements
If your Partner Application is an Agentforce solution, you must also follow the requirements described in Secure Your Agentforce Solution. These Agentforce specific requirements are in addition to the General AgentExchange Requirements.
Connected App and External Client App Security Requirements
If your Partner Application includes a Connected App and/or an External Client App (ECA), you must also follow the requirements described in Secure Your Connected Apps and External Client Apps. These Connect App and ECA specific requirements are in addition to the General AgentExchange Requirements.