Use Managed Packages to Develop Your AgentExchange Solution
Security Policy Requirements
Secure Your B2C Commerce Solution
Secure Your Tableau Accelerator
Secure Your Connected Apps and External Client Apps
OEM User License Guide
Previous Versions
Requirements: Before you list your solution on AgentExchange, you must have a security program that demonstrates your company’s commitment to security. Also, to help customers evaluate the quality of your solution, you must share your program info with them.
Recommendations: We recommend including these elements in your program.
Protecting your solution from security threats is easier when you integrate security considerations into all stages of development. One of the best ways to ensure that your solution follows security guidelines is to designate a security expert on your development team. Have your entire development team collaborate with the security expert through all stages of development: design, implementation, and testing. Postponing security considerations until the final stages of development increases the likelihood that your team unknowingly propagates security violations as they code. Regular collaboration prevents needless accumulation of security violations and helps avoid delays in preparing a successful AgentExchange security review submission.
Build a corporate security policy that details how your company protects customer assets, such as user data. Inform the customer of the activities that they can do to help secure the solution from end to end.
List the services and artifacts included in your solution such as web and mobile solutions, web services, APIs, and SDKs.
Keep an inventory of the third-party libraries and the versions that are required for your solution to operate correctly.
Provide architecture diagrams that display data touch points, information flows, authentication, authorizations, and other security controls.
Share all applicable certification reports such as:
Have an independent third party conduct a security audit. Share the summary with your customers.
Document company-level security-assurance activities including:
List all sensitive data that your solution processes or stores such as payment instrument data, personal data, and health data.
If your solution stores or processes regulated data, such as personally identifiable data and health data, disclose a list of data storage locations. Identify countries and providers such as Amazon Web Services (AWS), Azure, and Google Cloud Platform (GCP).
Provide a list of third-party suppliers that you share customer data with.
All ISV partners must designate security leadership contacts in the Partner Console and update these contacts whenever necessary to maintain accuracy and completeness. When you log in to the console, you’re prompted to provide contact information for your security leadership team, including names, email addresses, and phone numbers.
Every six months, the console prompts you to review and confirm that these contacts are still accurate. We recommend using a distribution list or shared inbox to ensure continuity if team members change.
To make sure you get our emails, avoid generic email usernames for your distribution lists. For example, security@example.com might get flagged as spam. A username like security+example@example.com is more likely to be delivered. For details, see Role-Based Email Addresses.
Salesforce uses this information only for security incident response and related communications. This information isn’t posted publicly and is separate from the public contact info in the Share Contact Info section.
To make updates to your security contacts at any time, go to Company Info in the Partner Console.
Apps or agents from AgentExchange must pass the Salesforce security review to be installed. After your app is approved, the installation buttons are turned on automatically. Customers who try to install before the security review see a message explaining that installation is blocked until the security review is finished.
This requirement only affects installation from AgentExchange listing pages. Preview functionality for your marketing team remains available.
Publish contact information so that it’s easy for customers to get support and report security incidents.