Verify the submission, not just the build.

Your exact build, read-only App Store Connect configuration, and Apple’s current requirements—checked together before App Review.

See how it works

Your binary and Apple private key stay on your Mac.

Submission readinessAction required
Local artifactBuild 42
App Store ConnectBuild 41
Requirementsv2026.08
Selected build mismatchArtifact 42 does not match the selected build 41.
View evidence
Simulated preview dataRules current · no approval guarantee
1
Build evidence

A local CLI inspects the exact IPA or xcarchive and emits only minimized facts.

2
App Store Connect evidence

A local collector makes allowlisted GET requests and normalizes only supported readiness state.

3
Current requirements

Versioned, test-backed rules preserve source links, verification dates, and historical results.

Three sources. One release decision.

SubmitCheck correlates independent evidence so contradictions surface before the submission reaches Apple.

01

Build evidence

A local CLI inspects the exact IPA or xcarchive and emits only minimized facts.

02

App Store Connect evidence

A local collector makes allowlisted GET requests and normalizes only supported readiness state.

03

Current requirements

Versioned, test-backed rules preserve source links, verification dates, and historical results.

04

Correlated findings

Independent evidence paths produce a status, source, confidence, and remediation—never an approval prediction.

BlockerRiskNeeds EvidenceManual ReviewPassed

Every finding earns its place.

Evidence, an authoritative source, confidence, and a deterministic fix path—without approval theater.

Blocker

Selected build does not match the inspected archive

ConfidenceHigh

Evidence

Local artifactBuild 42Inspected on your Mac
App Store ConnectBuild 41Selected for review

Topology: Artifact ↔ Submission

Remediation

  1. Make build 42 available in App Store Connect.
  2. Select build 42 for App Review.
  3. Collect a fresh snapshot and re-run checks.
Apple App Store Connect Help
SC-CORR-0042ruleset v2026.08Deterministic finding

One workspace for the submission you prepared.

The preview models an App Store submission checklist with blocker-first checks across the build, privacy manifest and permissions, purchases, metadata, reviewer access, and current rules.

01

Artifact and SDK readiness

Identity, versions, privacy manifests, entitlements, permissions, SDK signals, architectures, packaging, and export-related evidence—inspected locally.

02

Submission configuration

Selected build, required metadata, localizations, URLs, IAP and subscription state, age rating, review-information presence, and available declarations.

03

Reviewer path and resubmission

A manual checklist for access, test paths, paywall risk, non-obvious features, and evidence-backed reviewer-note preparation without collecting reviewer credentials.

04

Rules and release history

Ruleset freshness, checked and unchecked coverage, scan comparison, and change attribution across artifact, submission, and requirements evidence.

Clear future boundary: hosted IPA/source/screenshot intake, automatic App Store Connect writes, SARIF/CI, designed PDF exports, and opt-in AI fix prompts are not active capabilities in this preview.

A boundary you can inspect.

Local collection creates a minimized, versioned JSON contract you can review before any explicit upload.

  • Stays local: IPA, xcarchive, source, assets, dSYMs, Apple .p8 key.
  • Never requested: Apple Account password, session cookie, reviewer credentials.
  • No automatic upload and no App Store Connect writes.
Local MacInspect hostile artifacts and collect read-only facts.
{ }Sanitized JSON previewInspect exactly what may leave your machine.
Hosted reportDeterministic findings from minimized evidence.

Common questions.

Does SubmitCheck guarantee App Store approval?

No. SubmitCheck identifies detectable risks using the selected ruleset and available evidence. Apple makes the final review decision.

Do you upload my app?

No. The planned local CLI inspects the IPA or xcarchive on your machine. Raw binaries, source code, assets, dSYMs, and private keys are outside the hosted data boundary.

Do you need my Apple Account password?

Never. The planned collector uses a local App Store Connect API key and allowlisted GET requests. The private key stays on your machine.

Can I use SubmitCheck without App Store Connect?

Yes, with reduced coverage. Artifact checks can still run, while unavailable submission checks are shown as Needs Evidence or Not checked—not as passes.

What counts as a rescan?

Only a successfully committed hosted report. Validation failures, service errors, canceled jobs, and failed jobs do not consume a scan.

How can hosted data be deleted?

The planned account controls include deletion per report, per submission cycle, or for the entire account. Raw artifacts and private keys are never hosted in the first place.

Check what can be checked. Keep the rest honest.

Open the internal preview to explore the evidence model. No artifact, credential, or payment is required.