SubmitCheck product preview
Security model
SubmitCheck is designed around least privilege, local inspection, deterministic rules, and explicit unknown states.
Local artifact handling
The planned CLI treats archives as hostile input and protects against path traversal, symlink escapes, decompression bombs, excessive file counts, nested depth, and unbounded memory use.
App Store Connect access
The planned collector keeps the .p8 key local, mints short-lived JWTs with scoped GET paths, and independently enforces an audited Apple host, method, endpoint, relationship, and field allowlist. SubmitCheck never requests an Apple Account password.
Evidence integrity
Rules are immutable and versioned. The same normalized input and ruleset should produce the same status. Missing evidence becomes Needs Evidence, Manual Review, or Not checked—never Passed.
Preview limitations
This interface uses simulated sample data. It does not run a scanner, contact App Store Connect, create reports, export customer data, or grant product entitlements.