When scans aren't available for third-party APIs during the AppExchange Security Review, you should submit the authentication credentials and any available API documentation for the third-party integration. Additionally, ensure that sensitive information, like API keys, is securely stored (e.g., in protected custom settings). If the integration involves sensitive data, such as payment details, you must adhere to compliance standards like PCI Compliance.
For external SaaS integrations in the AppExchange Security Review, you should test the full scope of your solution, including all external endpoints that operate independently of the Salesforce platform. Use both manual testing and automated security scanner tools to identify vulnerabilities. Document any false-positive security violations and ensure all code complies with Salesforce security guidelines. Additionally, provide URLs and login credentials for external components requiring authentication as part of your submission.