For an external service endpoint that is a serverless function, the following security documentation and scan results are required as part of the security review process:
1. **Penetration Testing Reports**: Submit pen test reports for the external endpoint to ensure it is secure and follows best practices.
2. **DAST Scan Reports**: Include Dynamic Application Security Test (DAST) scan results, such as ZAP scan reports, to identify vulnerabilities.
3. **False Positives Documentation**: Document any false positives found during scans and provide justifications for why they are considered false positives.
4. **Authentication Credentials**: Provide authentication credentials for the endpoint, if applicable, to allow the security review team to perform necessary tests.
5. **Compliance with Security Guidelines**: Ensure compliance with Salesforce's guidelines for securely transferring credentials and data.
Additionally, if the external endpoint is not owned by you, obtain permission to perform security testing. Follow Salesforce's guidelines for IP addresses and domains to allow during testing.