Preflight checks your QuickBooks Online app against the exact technical and security requirements Intuit's reviewers grade — and hands you an audit-ready report. It's not another scanner. It's a pass/fail against the gate.
uses: preflight/qbo-review@v1Built for developers publishing on the QuickBooks Online App Store
Intuit's security review runs after the technical review, blocks publishing on any critical, high, or medium issue, and gives you two weeks to fix problems once you're live. You find out what's wrong only after they tell you.
You submit, wait, and get bounced for a requirement nobody surfaced up front — then you're back in the queue starting over.
Cross 500 connected companies and you're re-reviewed every year. Fail and Intuit limits onboarding, then blocks API access entirely.
A full outside pentest costs thousands and takes weeks you don't have before your next submission window opens.
Preflight doesn't try to out-scan Semgrep. It runs the commodity checks invisibly, then does the part a scanner can't: map every finding to Intuit's actual review categories and tell you what will block you.
Findings organized by Intuit's review structure — technical, then security — each requirement marked pass or needs-attention. No generic vulnerability dump.
A timestamped, scoped report shaped to satisfy Intuit's "reputable scan results within two weeks" clause and the security affidavit.
"14 findings — 3 map to Intuit requirements, 11 you can ignore." You see what will actually block your review, not a wall of noise to sort through yourself.
Semgrep finds a generic XSS. It will never tell you your refresh token needs AES encryption with the key in a separate config file — because that's Intuit's rule, not a scanner's.
TLS ≥ 1.1, HTTPS enforced everywhere, TRACE disabled, and Cache-Control set to no-store on sensitive pages.
Refresh token + realmID encrypted with AES, key stored in a separate config, tokens never exposed to third parties.
No QuickBooks data logged or exported beyond functional use, and 302 redirects on any token-bearing endpoint.
XSS, SQLi, XML injection, and access control — run via commodity engines, mapped to Intuit's categories, noise removed.
The same model that made Gitleaks ubiquitous: free on personal repos so it spreads, licensed for organizations shipping a real app.
You can, and Preflight runs those engines for you. What they don't do is know Intuit's rules — the OAuth encryption requirement, the 500-connection re-review, the referer-leak redirect. Preflight is the mapping and the pass/fail, not the raw scan.
No. Preflight is independent, built against Intuit's publicly documented requirements. It isn't operated, endorsed, or reviewed by Intuit.
No tool can. It catches the common, well-documented rejection reasons before you submit, so Intuit isn't the first to find them.
The Action runs inside your own CI. Deep checks need read access to your checked-out code; the report is yours.
Run your first readiness check before you submit to Intuit. Start free on a personal repo, or subscribe for the full review across your org.
We're putting the finishing touches on it. Leave your email and we'll notify you the moment it's ready — early signups get launch pricing on the Organization plan.