Build evidence
A local CLI inspects the exact IPA or xcarchive and emits only minimized facts.
Your exact build, read-only App Store Connect configuration, and Apple’s current requirements—checked together before App Review.
Your binary and Apple private key stay on your Mac.
A local CLI inspects the exact IPA or xcarchive and emits only minimized facts.
A local collector makes allowlisted GET requests and normalizes only supported readiness state.
Versioned, test-backed rules preserve source links, verification dates, and historical results.
SubmitCheck correlates independent evidence so contradictions surface before the submission reaches Apple.
A local CLI inspects the exact IPA or xcarchive and emits only minimized facts.
A local collector makes allowlisted GET requests and normalizes only supported readiness state.
Versioned, test-backed rules preserve source links, verification dates, and historical results.
Independent evidence paths produce a status, source, confidence, and remediation—never an approval prediction.
Evidence, an authoritative source, confidence, and a deterministic fix path—without approval theater.
Topology: Artifact ↔ Submission
The preview models an App Store submission checklist with blocker-first checks across the build, privacy manifest and permissions, purchases, metadata, reviewer access, and current rules.
Identity, versions, privacy manifests, entitlements, permissions, SDK signals, architectures, packaging, and export-related evidence—inspected locally.
Selected build, required metadata, localizations, URLs, IAP and subscription state, age rating, review-information presence, and available declarations.
A manual checklist for access, test paths, paywall risk, non-obvious features, and evidence-backed reviewer-note preparation without collecting reviewer credentials.
Ruleset freshness, checked and unchecked coverage, scan comparison, and change attribution across artifact, submission, and requirements evidence.
Clear future boundary: hosted IPA/source/screenshot intake, automatic App Store Connect writes, SARIF/CI, designed PDF exports, and opt-in AI fix prompts are not active capabilities in this preview.
Local collection creates a minimized, versioned JSON contract you can review before any explicit upload.
No. SubmitCheck identifies detectable risks using the selected ruleset and available evidence. Apple makes the final review decision.
No. The planned local CLI inspects the IPA or xcarchive on your machine. Raw binaries, source code, assets, dSYMs, and private keys are outside the hosted data boundary.
Never. The planned collector uses a local App Store Connect API key and allowlisted GET requests. The private key stays on your machine.
Yes, with reduced coverage. Artifact checks can still run, while unavailable submission checks are shown as Needs Evidence or Not checked—not as passes.
Only a successfully committed hosted report. Validation failures, service errors, canceled jobs, and failed jobs do not consume a scan.
The planned account controls include deletion per report, per submission cycle, or for the entire account. Raw artifacts and private keys are never hosted in the first place.
Open the internal preview to explore the evidence model. No artifact, credential, or payment is required.