Secure Your Flow Connectors

Custom Flow connectors run in subscriber orgs and must pass the AgentExchange Security Review. This guide helps you write secure DataWeave code that protects customer data and passes review on the first submission. Apply these guidelines to the DataWeave code in your connector's JAR. Before you submit the package for Security Review, run the Salesforce Code Analyzer (SFCA) Custom rules against it. The Custom rules detect security-related issues automatically.