Signals StoreShield looks for
The scanner focuses on release-relevant API families that can trigger privacy manifest review.
- ✓ User defaults, disk space, file timestamp, and system boot time API signals.
- ✓ Main app and embedded framework references.
- ✓ Deprecated or risky usage patterns that need manual review.
From API signal to action
A signal alone is not useful unless it becomes a clear release task.
- ✓ Review Room gate summary with risk or block status.
- ✓ Evidence tied to the detected rule and confidence level.
- ✓ Fix Plan markdown ready for the developer doing the release work.
Why local analysis matters
StoreShield is designed for teams that cannot upload unreleased apps to a third-party scanner.
- ✓ Archive stays on the Mac.
- ✓ No App Store Connect API required.
- ✓ No cloud AI call unless the user explicitly chooses it.