Is it possible to get a pre-review of my app's architecture and security model before submitting for the official security review?
Answer
Yes, you can get a pre-review of your app's architecture and security model before submitting for the official AppExchange Security Review. Here's how:
1. **Secure Your Solution**: Follow industry best security practices and ensure your app is Lightning Ready if applicable.
2. **Enroll in the Partner Program**: Connect your packaging org to the AppExchange Partner Console.
3. **Use Scanning Tools**: Run automated tools like Salesforce Code Analyzer and Source Code Scanner (Checkmarx) to identify vulnerabilities. Perform manual testing for additional assurance.
4. **Document Issues**: Address flagged issues or document false positives from the scans.
5. **Prepare Materials**: Have a Developer Edition org with your solution installed, along with solution documentation and any necessary credentials or URLs for external components.
6. **Schedule Office Hours**: Use the Partner Security Portal to book an appointment with the Security Review Operations team for guidance and feedback.
These steps will help you refine your app's architecture and security model, ensuring a smoother official review process.
Enhancing FAQ...
Enhancing FAQ with AI recommendations...
AI Recommended Enhancement
Question
Is it possible to get a pre-review of my app's architecture and security model before submitting for the official security review?
Recommended Answer Update
Yes, you can get a pre-review of your app's architecture and security model before submitting for the official AppExchange Security Review. Here's how:
1. **Secure Your Solution**: Follow industry-standard security practices and ensure your app is Lightning Ready if applicable.
2. **Enroll in the Partner Program**: Connect your packaging org to the AppExchange Partner Console.
3. **Use Scanning Tools**: Run automated tools like Salesforce Code Analyzer and Source Code Scanner (Checkmarx) to identify vulnerabilities. Perform manual testing for additional assurance.
4. **Document Issues**: Address flagged issues or document false positives from the scans.
5. **Prepare Materials**: Have a Developer Edition org with your solution installed, along with solution documentation and any necessary credentials or URLs for external components.
6. **Schedule Office Hours**: Use the Partner Security Portal to book an appointment with the Security Review Operations team for guidance and feedback.
These steps will help you refine your app's architecture and security model, ensuring a smoother official review process.
Reasoning
The FAQ content is accurate and well-structured. I made one minor language improvement by changing 'industry best security practices' to 'industry-standard security practices' for better readability and more natural language flow. This change aligns with the brand guidelines to use conversational, clear language while maintaining the same meaning and technical accuracy.
No security rules were selected because this FAQ is procedural in nature - it explains the process for getting a pre-review rather than discussing specific technical security implementations that would be detected by security scanner rules. The FAQ covers administrative and preparatory steps (enrolling in partner programs, scheduling appointments, preparing documentation) rather than code-level security practices that the available rules are designed to detect.