Certify an App
A Cribl Certified App meets Cribl’s standards for compatibility, performance, reliability, security remediation, and developer support. The Certified badge indicates that an App is ready for business-critical use.
Certification is version-specific and ongoing. Each newly uploaded version must pass review to retain the Certified badge. Before you pursue certification, publish the App in the Cribl Marketplace.
Support Baselines
As the publisher of a Certified App, provide a contact method and a link to a ticketing system so that you can:
- Monitor reported issues and respond within the applicable support baseline.
- Provide fixes within the required remediation windows for security-related bugs.
- Address critical- and high-severity functionality bugs.
- Keep Cribl informed when an issue requires additional investigation or remediation time.
- Respond to critical customer support issues within 24 hours, five days a week, during your local business hours.
If an App falls outside the applicable service-level agreement (SLA), Cribl sends a warning email. If the issue remains unaddressed after two more follow-ups, Cribl can remove the App’s Certified badge.
Security Remediation SLAs
For security-related bugs in a Cribl Certified App, meet these remediation deadlines. Critical and High windows also apply to any App listed in the Cribl Marketplace. Certified Apps add Medium and Low windows:
| Severity | Required Fix SLA |
|---|---|
| Critical | Within 10 days |
| High | Within 4 weeks |
| Medium | Within 12 weeks |
| Low | Within 25 weeks |
The remediation clock applies to delivering the fix, not only acknowledging or triaging the issue. Remediate newly discovered vulnerabilities within these deadlines to avoid having the App delisted.
Data Expectations
A Certified App must collect, process, and retain only the customer data necessary to provide its documented functionality.
- Keep customer data within the App’s intended processing boundary and the approved Cribl services or destinations that the App requires.
- Do not extract, copy, export, or transmit customer data outside the App for unrelated analytics, debugging, development, marketing, model training, or another secondary purpose.
- Do not send customer data to developer-controlled systems, personal storage, test environments, or third-party services unless the App requires the destination. Document and approve the destination through the applicable configuration and review process.
For the Apps data and credential boundaries, see Runtime, Architecture, and Security.
Responsible Use of AI
If an App uses an AI or machine learning service, use that service safely, transparently, and only for the App’s documented purpose.
- Document the AI provider, model, or service. Include its purpose, data inputs, outputs, retention behavior, processing location, and any subprocessors that handle customer data.
- Send only the minimum data required for the AI feature. Redact credentials, secrets, unnecessary identifiers, and unrelated customer content before submission.
- Do not send raw customer data to an AI service for model training, evaluation, or product improvement unless the customer explicitly authorizes that use and you clearly disclose it.
- Use approved, declared integrations for AI services. Route external calls through the App’s approved proxy configuration, and restrict hosts, paths, headers, and methods to what the App requires.
For how Apps handle external AI services, see Third-Party Services and AI.
Certification Checklist
Before an App can receive the Certified badge, validate the following areas.
Upgrade Compatibility
- Test upgrades across older App versions.
- Preserve expected behavior and supported upgrade paths in the new version.
Backend Functions
If the App uses backend functions, make sure that the functions are appropriately sized, bounded, observable, and limited to the capabilities they need.
Right-Size Compute Allocation
- Declare endpoint-specific
memoryandtimeoutvalues inconfig/backend.ymlbased on representative workload measurements. Do not use the maximum values by default. - Keep the p95 execution duration at or below 80 percent of the declared timeout and peak memory usage at or below 80 percent of the declared memory allocation. Document and justify exceptions.
- Test normal and peak workloads, including invocation frequency, concurrent requests, scheduled jobs per run, payload size, execution duration, and memory usage.
- Bound pagination, batch sizes, fan-out, and concurrency. Make sure that every invocation can finish within its declared timeout.
For configuration details, see Backend Functions in the Builder Guide.
Enforce Least Privilege
- Declare every Cribl API route and HTTP method that the frontend or a backend function requires in
config/policies.yml. - Request the narrowest route and method set that satisfies the App’s behavior. Avoid broad resource wildcards unless they are necessary and documented.
- Remove unused grants, and update
config/policies.ymlwhenever a new function or workflow introduces an API call.
For policy guidance, see Declare In-Product API Permissions Your App Needs in the Builder Guide.
Certify New Versions
Cribl must recertify each new version. Certification applies to a specific App version. A previously certified version does not automatically certify a later upload.
Before you upload a new version:
- Verify compatibility with older App versions and supported upgrade paths.
- Meet the performance thresholds.
- Use the required retry and asynchronous-call behavior.
- Resolve known critical- and high-severity functionality issues within the support baseline.
- Include security fixes within the required remediation SLA.
Retain Certification
Continue to meet the applicable SLA requirements, and successfully recertify every new version that you upload.
If a newly uploaded version fails certification, Cribl does not approve that version. The previously approved Certified version remains in the Cribl Marketplace until you remediate the issues and upload another version for review.
When someone reports the current version, Cribl reviews the report and can:
- Remove the App from the Cribl Marketplace.
- Revoke the App’s Certified badge.
- Reject the report and leave the listing unchanged.