Build it. Package it. Get it past Security Review. List it.
Tenetizer is the technical partner behind Salesforce ISV apps โ from 2GP managed package architecture through a published AppExchange listing, and every release after that.
13+ years Salesforce architecture ยท Certified Technical Architect-led builds ยท Nonprofit, real estate & SaaS ISVs
Currently in: Security Review
Pre-review audit complete โ CRUD/FLS, sharing model and credential storage all cleared.
Listing an app is a technical bar, not a marketing checkbox
Salesforce's Security Review rejects most first submissions โ not for weak ideas, but for gaps most teams don't know to check for: sharing rules that leak data across orgs, missing FLS enforcement, unversioned APIs, credentials stored in plain text. Getting listed means building to that bar from day one, not retrofitting it after a rejection email.
- Namespace & package architecture โ 2GP managed packages, dependency management, and a release process that survives your first major version bump.
- Security posture โ CRUD/FLS enforcement, sharing model design, Named Credentials for external calls, and encrypted custom settings.
- Review readiness โ the exact checklist Salesforce's own reviewers use, run against your codebase before you submit, not after a rejection.
- Listing operations โ Partner Community setup, demo org provisioning, and the release cadence once you're live.
Five stages, one team, no handoffs
Most delays happen at the seams โ when the team that built the app isn't the team managing the listing. We run the whole journey end to end.
Scope & architect
Define the object model, sharing model, and package boundaries before a line of Apex is written.
Build & package
Apex, LWC, and Flow built inside a 2GP managed package with source-driven version control.
Pre-review audit
Run Salesforce's own Security Review checklist internally and close every gap before submission.
Submit & respond
Manage the official submission and any reviewer follow-up questions until it clears.
List & support
Publish the listing, provision the demo org, and hold the release cadence going forward.
Every layer of an AppExchange app, covered by one team
Managed Package Architecture
2GP package design, namespace registration, dependency management, and a version strategy that scales past v1.
Apex, LWC & Flow Build
Custom app logic and UI built to Salesforce coding standards, with test coverage that holds up under Security Review.
Security Review Preparation
CRUD/FLS enforcement, sharing model hardening, encrypted credential storage, and injection-risk remediation.
Third-Party & Platform Integration
Named Credential-based callouts, external API integration, and platform event architecture for real-time apps.
Listing & Partner Community Setup
Demo/trial org provisioning, listing copy, screenshots, walkthrough video, and Partner Community configuration.
Post-Launch Release Management
Ongoing version pushes, upgrade paths for existing installs, and re-certification for future Security Reviews.
Architecture-first, not a dev shop that also does packages
Tenetizer is a 15-person Salesforce consultancy led by a Certified Technical Architect. AppExchange work sits alongside CPQ, Experience Cloud, and Agentforce delivery for nonprofit, real estate, and SaaS clients โ the same rigor, applied to your package.
PowerKnowledge, our own AppExchange-listed knowledge management app, was built and packaged by this same team โ we've been through Security Review as the applicant, not just the consultant.
A Certified Technical Architect scopes the data and sharing model up front, so Security Review isn't a surprise at the end.
Inheriting a package from a prior vendor is common โ we audit it, document what's undocumented, and take ownership of the next release.
The people who architect your package are the same people who write the Apex and manage the submission โ no handoffs between sales and delivery.
Questions ISV partners ask us first
Q. How long does it take to get an app listed?
Most first-time ISV partners move from a packaged app to a live listing in 8โ14 weeks. Security Review is the variable โ a clean first submission can clear in 2โ3 weeks, while gaps in sharing model or CRUD/FLS enforcement can add cycles.
Q. 1GP or 2GP managed package โ which do we need?
Nearly every new app today ships as a 2GP managed package for namespace protection and source-aligned versioning. We only recommend 1GP for legacy packages already built on that model.
Q. Do you handle the Security Review, or just the code?
Both. We run a pre-review audit against Salesforce's own checklist, fix what's flagged, and manage the submission โ including any reviewer follow-up questions.
Q. Can you take over an app someone else built?
Yes โ we regularly inherit existing listings and packages, audit the org and codebase, and take over releases, support, and future re-certifications.
Q. Do you build the listing assets โ demo org, video, screenshots?
Yes. We set up and maintain your Partner Community listing and produce the demo/trial org, screenshots, walkthrough video, and listing copy.
Have an app idea or an existing package stuck in review?
Tell us where you are โ idea, mid-build, or bounced back from Security Review โ and we'll scope the fastest path to a live listing.
Get in Touch โ