Pass your Salesforce Security Review
Salesforce's Security Review tests your app before it can list on AppExchange. Pentest Today runs the pentest and remediation tracking so you go in with findings already closed.
What a Salesforce Security Review review asks for
AppExchange partners must pass Salesforce's Security Review, which includes scanning and penetration testing of the offering before listing.
Scan
Authenticated and external scans across web, API, and cloud surface the issues before an assessor does — de-duped, triaged, and mapped to CVE/CVSS.
Pentest
Approved-target scans become a client-ready pentest report: validated findings, evidence, reproduction steps, remediation, and the retest letter auditors accept.
Policy Generator
Generate the policies and system architecture diagrams the review expects — access control, cryptography, incident response — pre-mapped to controls.
Lema AI
Lema is an AI-powered third-party risk platform buyers use to assess a vendor's security posture from uploaded evidence and questionnaire answers.
Whistic
Whistic lets vendors publish a Security Profile and respond to customer assessments from a single shared source of evidence.
Vanta
Vanta automates compliance and vendor risk; buyers using Vanta will request evidence of your security controls and tests.
CAIQ
The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ) is a standardized set of yes/no security questions mapped to the Cloud Controls Matrix.
SIG
The Shared Assessments Standardized Information Gathering (SIG) questionnaire is a comprehensive third-party risk questionnaire used across industries.
Vendor Security Questionnaire
Enterprise buyers send a security questionnaire before they'll sign — asking how you test, protect, and monitor their data.
Salesforce Security Review, answered
Does the Salesforce Security Review include a pentest?
Yes — it combines automated scanning with manual penetration testing of your offering. We help you find and fix issues before submission so the review goes smoothly.
Is the pentest a real test or just a scanner dump?
Both scanning and AI triage are scoped to your approved targets, and every finding is reviewed and signed off by a human before delivery — so the report reflects verified findings, not raw scanner noise.
How fast can I get a report?
Most reports turn around in hours, not weeks. You connect an approved target, we scan and verify, and you export a client-ready report and policy pack.
Get the evidence for your Salesforce Security Review review this week.
Start a scan on an approved target and walk in with the report, policies, and diagrams already done.