05 · Build

AppExchange App Development

Managed packages built to pass security review — architecture, packaging, listing and the release train that keeps the app alive after launch.

PACKAGE 2GP LISTED APPEXCHANGE SECURITY REVIEW PUSH UPGRADES · LMA · TRIALFORCE

01

The problem

Why people call us about this.

A

You have a product idea and no route through Salesforce security review.

B

A failed review has stalled your listing and the feedback reads like a wall.

C

An existing package works but every release is a manual scramble.

02

What’s covered

The Salesforce we actually configure.

Building for the AppExchange is a different discipline from building for one org: multi-tenant safety, namespace discipline and a review Salesforce actually enforces.

ISV architecture and namespace design
Second-generation managed packaging
Partner Business Org and LMA setup
Security review preparation and remediation
Checkmarx and code scanner fixes
Subscriber support and debugging
Push upgrades and version strategy
Listing content and demo org
Trialforce and test drive setup
Release automation for the package

03

How it runs

Five phases, and what you see at the end of each.

01 · Week 1

Inventory

What exists, who owns it, and which system is really the source of truth. Almost always surfaces something nobody knew was live.

A written map

02 · Weeks 2–3

Contract

The design in writing, with each decision and its reversal cost named. This is where we argue with the brief — before money is spent.

A signed scope

03 · Middle

Build

Built against the contract and reviewed against it. You see working software every two weeks, in your own sandbox.

Fortnightly demos

04 · Late

Prove

Volume testing at twice expected load, deliberate failure injection, and a replay run with your team watching.

A test evidence pack

05 · Final week

Hand over

Runbook, monitoring, escalation path and a named owner on your side — then a month watching it together before we step back.

Runbook and owner

04

First call

Thirty minutes. Three answers.

You speak to a certified architect, not a sales engineer. No deck, no discovery fee, and no obligation to go further — you leave the call with three things whether you hire us or not.

01

Whether this is even the right line

About a third of the time it is not, and we say so. Usually the ask is custom development when the real problem sits in the data model underneath.

02

A shape and a range

Roughly how long, roughly how many people, and the band it falls in. The firm number follows discovery about two weeks later, and it holds.

03

The two risks we would flag

The things most likely to blow the timeline on a project like yours — named on the call, before anyone has signed anything.

Book it for this week.

Pick a slot directly in the calendar — most questions get answered inside the thirty minutes.

17+ certifications 60+ implementations You own everything we build

05

FAQ

Asked on nearly every call.

Will you get us through security review?

We prepare for it and remediate the findings. Nobody can guarantee a Salesforce decision, but we have not had a listing fail a second review.

How long does review take?

Budget six to ten weeks from submission including remediation. Scanner findings are usually quick to clear; architectural objections are the ones that cost time.

Do we need a Partner Business Org?

Yes, plus the Licence Management App to handle subscriber licences. We set both up if you do not have them, and get the package linked properly before first submission.

Can you take over an existing package?

Yes. We start with a packaging and namespace audit, because that is where the decisions you cannot undo live — and it changes what is realistic afterwards.

Other lines