Salesforce Development Company

Salesforce ISV App Development

We take your product vision from prototype to AppExchange,  building scalable, certified Salesforce apps with deep expertise in LWC, Apex, and managed packaging.

SAI-Image
grid

Salesforce ISV App Development

Services

star
Custom App & Managed Package Development

Apex, LWC, Flows, Custom Metadata, we build Salesforce apps architected for performance, upgrade safety, and long term maintainability, whether internal tooling or multi-tenant products serving thousands of orgs.

star
AppExchange Security Review Preparation

We prepare your package from the inside out, CRUD/FLS compliance, secure Apex patterns, Locker Service compatibility, full documentation. Fewer review cycles, faster approval, earlier market entry.

star
App Modernization & Technical Debt Removal

Visualforce or legacy Aura holding you back? We migrate to LWC, restructure outdated codebases, and bring your architecture to current platform standards, improving performance and making your product easier to extend.

star
Integration Architecture for AppExchange Products

REST APIs, Platform Events, Change Data Capture, async processing, we build secure, scalable integration layers that work reliably across every subscriber org your product lands in.

star
Mobile-First Salesforce App Development

Offline support, real-time data access, field-optimized interfaces, built for users who don't work from a desk, delivering a consistent experience in the office or on the move.

star
Post Launch Support & Release Management

CI/CD setup, automated regression testing, version control, controlled deployments, every Salesforce release handled proactively so your app stays stable, compliant, and competitive on AppExchange.

Salesforce Implementation By Astonous

Let's map out your implementation in a free 30-minute strategy call. No pressure. Just clarity.

Book a Call
salesforce toy

When Does Your Business Need

Salesforce ISV App Development

numbers
You Have a Product Idea but No Clear Path to AppExchange

Packaging architecture, security review, compliance standards, if the technical foundation isn't clear, products stall. We take your concept from idea to a certified, market-ready AppExchange listing.

numbers
Your Existing Salesforce App Is Holding You Back

Legacy Visualforce, outdated Aura, ageing codebases, they limit what your product can become. If your app is hard to maintain or losing ground to modern competitors, we modernize the architecture and restore momentum.

numbers
Your Integrations Are Unreliable and Hard to Trust

Broken syncs, silent data errors, failed transactions, they erode customer trust fast. We rebuild your integration layer with the resilience, error handling, and field-level accuracy enterprise buyers expect.

numbers
Standard Salesforce Functionality Isn't Enough

If your teams are working around platform limitations instead of through them, custom development closes the gap, building exactly what your business needs within the Salesforce ecosystem.

numbers
Your App Struggles Under Real-World Data Volumes

Governor limits, bulk failures, degraded performance as your customer base grows, we redesign your processing architecture with async patterns and bulkification strategies built for any volume.

numbers
Every Salesforce Release Puts Your App at Risk

Three platform updates a year means three chances for something to break. Without structured release management, stability is always one update away from a support crisis. We handle it, proactively.

How Astonous Solves these Challenges

stars
Getting Your App Through Security Review, First Time

We write compliance in from day one, proper data access controls, Lightning-safe components, automated vulnerability checks throughout development. By submission, your package is already review-ready.

stars
Taming Complex Business Logic Without Breaking Everything

Modular, service-layered architecture that handles cross-object dependencies, advanced automation, and multi-step approvals, without turning into an unmaintainable tangle. Organized, testable, ready to grow.

stars
Keeping Performance Solid as Data Volumes Grow

Bulk processing patterns, async job frameworks, query optimization, every solution designed with governor limits in mind so your app runs reliably whether it's processing hundreds of records or hundreds of millions.

stars
Building Integrations That Actually Stay Working

Error handling, retry logic, real-time event processing, we build integration architectures that communicate accurately and consistently with every external system, on day one and day three hundred.

stars
Modernizing What You Have Without Starting Over

We progressively migrate Visualforce, legacy Aura, and outdated Apex to current platform standards, preserving the functionality your customers depend on while eliminating the debt that's been slowing you down.

stars
Staying Stable Across Every Salesforce Release

Automated regression testing, structured version control, release impact assessments, every platform update evaluated, tested, and deployed safely. No surprises, no breakages, no scrambling.

A unique approach.

We want to get to know you and your organization, so we listen. Rest assured that you’ll be heard, supported, and empowered throughout projects and beyond.

Strategic clarity
Proven results
Customized solutions
Agile & adaptive approach
Boutique Flexibility
Enterprise-Level Results
Salesforce Navigator
about us image

4.98/5

CSAT Score

Client satisfaction that speaks for itself, earned across every engagement, without exception.

65+

Projects Delivered

Successful Salesforce implementations spanning startups to global enterprises, across industries and time zones.

20+

Certified Experts

Platform specialists, not generalists. Deep Salesforce expertise across every cloud and product family.

80+

Active Certifications

Real, active credentials across every Salesforce cloud, not a one-time badge, continuously renewed as the platform evolves.

Our Salesforce Success Stories

View all

How Car Trackers Eliminated Copy-Paste Shipping and Put FedEx on Autopilot Inside Salesforce

Car Trackers ditched manual FedEx portal workflows by integrating Astonous Ship into Salesforce — automating label creation, customer emails, and shipment tracking for every DMV paperwork transaction.

Ahkiah Hunter
Manager
Read Case Study

How CLS Brands Gave 500+ Suppliers Self-Service Power, Without Overloading Their Internal Team

CLS Brands partnered with Astonous to launch a Salesforce Digital Experience Portal, giving suppliers real-time visibility into orders, shipments, and inventory while dramatically reducing internal support workload.

Ikey Sabbagh
Founder
Read Case Study

How Michael Malul Built a Luxury-Grade Operation to Match Their Luxury-Grade Fragrances

Michael Malul partnered with Astonous to implement a full Salesforce Sales Cloud solution, transforming distributor onboarding, invoicing, shipping, and inventory into one seamless, automated operation.

Kana Sale
Head of Department
Read Case Study
TESTIMONIAL

Real Stories, Real Impact: Hear from Our Satisfied Clients

Discover how our solutions have transformed businesses through innovative technology and dedicated support.

Great solution for creating shipping labels directly from Salesforce!

"We implemented this shipping integration for both FedEx and UPS and it has been a game changer for our operations. It cut our shipping preparation time by more than half, significantly improving efficiency and workflow. The support team is truly five star  they handled the entire setup seamlessly and are extremely responsive whenever assistance is needed."

April Snyder
Head of Department
Great solution for creating shipping labels directly from Salesforce!

"Astonous has been a major upgrade from our previous solution, which was outdated, unreliable, and lacked proper support. It offers a much more intuitive interface, robust tracking, and the flexibility we need for evolving logistics. The seamless integrations and highly responsive support team have significantly improved our shipping efficiency and accuracy for both domestic and international operations."

William Beech
Director
Great solution for creating shipping labels directly from Salesforce!

"Astonous replaced our previous shipping solution with a much better, right-fit system. Their team understood our needs, delivered exactly what we required, and made the transition smooth. Very happy with the results."

Alberto Estrella
Managing Partner
Great solution for creating shipping labels directly from Salesforce!

"The team was highly supportive and worked closely with us to ensure a great app experience. They respond quickly to any issues and continuously roll out new features, making the overall experience even better."

Nikoleta Simpson
Senior Manager
Frequently asked Questions
Here's a list of FAQs that will help you learn more about Astonous Services.
What is a Salesforce ISV app?

A Salesforce ISV app is a reusable product built for Salesforce customers. It may extend Sales Cloud, Service Cloud, Experience Cloud, Revenue Cloud, Data Cloud, Agentforce, or another Salesforce product.

Unlike a customer-specific Salesforce implementation, an ISV app is designed to be installed and used across multiple Salesforce organisations.

What is the difference between a Salesforce ISV app and a custom Salesforce solution?

A custom Salesforce solution is normally built for one company and its specific business processes.

A Salesforce ISV app is a product built for multiple customers. It must account for different Salesforce configurations, security models, editions, data volumes, and business processes. It also requires packaging, licensing, installation, upgrades, documentation, and customer support.

Can Astonous help us turn an app idea into an AppExchange product?

Yes. We can help take a Salesforce app from an initial idea to a production-ready product.

The first step is usually a product discovery exercise where we define:

  • The business problem being solved
  • The target Salesforce customer
  • The minimum viable product
  • Standard Salesforce features that can be reused
  • Required custom development
  • Packaging and licensing approach
  • External integration requirements
  • AppExchange and security review considerations

The outcome is a practical product roadmap rather than a large list of features without clear priorities

How do we know whether our Salesforce app idea has market potential?

Before development begins, we recommend validating the problem with potential customers, Salesforce consultants, administrators, and industry specialists.

We can help assess competing AppExchange products, identify gaps, review the proposed value proposition, and define a focused first release. The goal is to confirm that customers will understand the problem and be willing to pay for the solution before making a significant development investment.

Should we build a minimum viable product or the complete application first?

Most Salesforce ISVs should begin with a focused minimum viable product.

The first version should solve one important customer problem well and include enough functionality to demonstrate its value. Additional workflows, integrations, analytics, and industry-specific features can be introduced after receiving feedback from early customers.

This reduces development risk and helps the product reach the market sooner.

Do we need to become a Salesforce partner before developing an app?

You can begin product planning and development before completing the full AppExchange partner process.

However, commercial distribution through the Salesforce ecosystem involves partner onboarding, business approval, the applicable partner agreement, security review, and AppExchange publishing activities. We can help you understand the technical steps, while final commercial and programme decisions remain between your company and Salesforce.

Can Astonous help with Salesforce ISV partner onboarding and business approval?

Yes. We can help prepare the technical and product information needed during Salesforce ISV onboarding and business approval.

This may include:

  • Product overview and value proposition
  • Target customer and use cases
  • Salesforce products used by the app
  • Application architecture
  • Packaging strategy
  • External systems and integrations
  • Data access and security model
  • Licensing approach
  • Product roadmap

Salesforce makes the final decision on business approval and partner agreements.

What type of Salesforce package should we use?

Commercial AppExchange products are commonly distributed using a managed package because managed packages support versioning, upgrades, namespaces, and protection of managed components.

For new managed applications, Salesforce currently recommends second-generation managed packaging, commonly known as managed 2GP. The correct approach still depends on the application’s architecture, metadata requirements, dependencies, and existing package history.

What is the difference between first-generation and second-generation managed packaging?

First-generation managed packaging, or 1GP, is managed mainly through a packaging organisation.

Second-generation managed packaging, or 2GP, follows a source-driven development model and works more naturally with Salesforce CLI, version control, scratch orgs, and automated build processes.

For a new application, we normally evaluate managed 2GP first. For an existing 1GP application, we review the current package and customer installations before recommending any migration.

Can you migrate an existing 1GP managed package to 2GP?

Yes. We can assess an existing first-generation managed package and determine whether moving to second-generation packaging is appropriate.

The assessment includes package components, dependencies, namespace, version history, extension packages, customer installations, build process, and release strategy. Salesforce now provides a managed package migration path, but it must be planned carefully because existing subscribers and future upgrades need to be protected.

Can our existing Salesforce code be converted into a managed package?

Often, yes, but code written for a single Salesforce org usually needs changes before it is suitable for a commercial managed package.

We review the existing solution for:

  • Hard-coded object and field references
  • Customer-specific configuration
  • Namespace compatibility
  • Security enforcement
  • Package dependencies
  • Upgrade behaviour
  • Data-volume limitations
  • External credentials
  • Test coverage
  • Install and uninstall behaviour

The goal is to make the application configurable and reliable across different customer organisations.

What Salesforce technologies can be included in an ISV app?

A Salesforce ISV application may include:

  • Apex
  • Lightning Web Components
  • Salesforce Flow
  • Custom objects and fields
  • Custom metadata
  • Platform events
  • Permission sets
  • Experience Cloud components
  • Agentforce actions
  • Prompt templates
  • APIs and external integrations
  • Reports and dashboards
  • Setup and configuration pages

The architecture depends on the business problem and the Salesforce products the application supports.

Can you build an Agentforce product or extension for AppExchange?

Yes. We can help develop Salesforce applications that use or extend Agentforce.

This may include agent actions, Apex actions, Flow-based actions, prompt templates, data grounding, external integrations, configuration screens, and managed package components.

We also review how the agent accesses customer data, what actions it can perform, how permissions are enforced, and how the product will behave across different subscriber organisations.

Can a Salesforce managed package integrate with an external application?

Yes. A managed package can connect Salesforce with an external platform through APIs, webhooks, middleware, platform events, named credentials, external credentials, or other supported integration methods.

The design must consider:

  • Customer authentication
  • Credential setup
  • Data ownership
  • API limits
  • Error handling
  • Logging and monitoring
  • Retry behaviour
  • Security review requirements
  • Availability of the external service

We design the integration so each customer can configure their own credentials without exposing sensitive information.

How do you make an AppExchange app configurable for different customers?

A commercial Salesforce app should not assume that every customer follows the same process.

We use configuration options such as custom metadata, permission sets, mapping screens, feature settings, templates, and administrator-controlled rules. This allows customers to adapt the application without changing managed code.

Good configurability reduces customer-specific development and makes future upgrades easier.

How do you handle Salesforce security in ISV app development?

Security is considered from the beginning of the product, not only when the application is ready for AppExchange security review.

We review areas such as:

  • Object and field permissions
  • Record access
  • Sharing rules
  • Apex sharing behaviour
  • CRUD and field-level security enforcement
  • Injection risks
  • Cross-site scripting
  • Sensitive data exposure
  • Authentication and credentials
  • External API security
  • Lightning component security
  • Secure error handling

We also use Salesforce security-scanning tools and perform manual reviews before submitting the application.

What is the Salesforce AppExchange security review?

The AppExchange security review evaluates whether an application follows Salesforce security requirements and protects customer data appropriately.

The review may include managed package components, external applications, APIs, connected applications, authentication flows, mobile applications, and other systems used by the product.

A product generally needs to complete the applicable security review before its public AppExchange listing can be published.

Can Astonous guarantee that our app will pass the security review?

No development company can guarantee Salesforce’s final security review decision.

We can significantly improve readiness by following secure development practices, reviewing the application architecture, running Salesforce Code Analyzer, testing external endpoints, preparing documentation, and resolving known issues before submission.

If Salesforce reports findings, we can help analyse and fix them before resubmission.

Can you help an application that has failed the AppExchange security review?

Yes. We can review the security report, reproduce the findings, and prepare a remediation plan.

Common work may include fixing permission enforcement, injection vulnerabilities, insecure data storage, authentication weaknesses, outdated libraries, missing documentation, or problems in external endpoints.

We can also review the full application rather than addressing only the reported examples, since the same issue may exist in other parts of the codebase.

What information is required for an AppExchange security review submission?

The exact requirements depend on the application, but a submission may require:

  • Managed package details
  • Test environment access
  • Installation and configuration instructions
  • User credentials
  • Architecture documentation
  • External endpoint details
  • Security scan reports
  • Data-flow explanations
  • Authentication steps
  • Test cases
  • Information about connected applications
  • Details of third-party libraries and services

A complete and properly configured submission helps avoid unnecessary review delays.

How long does AppExchange app development take?

A focused Salesforce application may take a few months to design, develop, test, package, and prepare for release.

The timeline depends on:

  • Number of features
  • Salesforce products involved
  • External integrations
  • User interface complexity
  • Packaging requirements
  • Security requirements
  • Customer configuration options
  • Documentation
  • Testing
  • Salesforce review processes

After discovery, we provide a phased plan with milestones, responsibilities, and expected deliverables.

How much does it cost to develop a Salesforce AppExchange app?

The cost depends on the application’s scope, architecture, integrations, packaging complexity, security requirements, and the condition of any existing codebase.

A simple application with a focused workflow will cost less than a platform product supporting multiple Salesforce clouds, external systems, editions, and customer configurations.

We normally begin with discovery and provide an estimate for the minimum viable product, followed by optional phases for additional features.

Salesforce programme fees, security review fees, listing charges, and revenue-sharing obligations are separate from Astonous development fees and should be confirmed directly with Salesforce.

Can Astonous help us choose the right pricing and licensing model?

Yes. We can help you evaluate common models such as:

  • Per-user pricing
  • Organisation-wide pricing
  • Feature-based plans
  • Usage-based pricing
  • Transaction-based pricing
  • Carrier or integration-based pricing
  • Free and paid editions
  • Annual subscriptions
  • Trial licences

The final model should reflect the value delivered, expected customer size, cost to serve, Salesforce commercial terms, and how easily the licence can be managed technically.

Can you configure Salesforce License Management App for our product?

Yes. We can help connect the managed package with the License Management App and design the required licensing process.

This may include trial licences, active licences, expiration dates, seat counts, customer information, and internal automation for onboarding or renewals.

Where the application requires additional feature controls, we can also build product-level entitlement management.

Can we offer a free trial of our AppExchange app?

Yes. Depending on the product and go-to-market approach, customers may be offered an installable trial, a guided demonstration, a test drive, or a dedicated trial organisation.

We can help prepare the trial experience, sample data, onboarding instructions, configuration steps, and follow-up process. The trial should allow a prospect to understand the product’s value without requiring a large implementation effort.

Can Astonous help create our AppExchange listing?

Yes. We can support the technical and product content required for an AppExchange listing.

This may include:

  • Product title and short description
  • Detailed product overview
  • Key features and use cases
  • Installation guidance
  • Documentation links
  • Demo and trial experience
  • Screenshots and video planning
  • Supported Salesforce products
  • Security and compliance information
  • Search-friendly AppExchange copy

Final listing approval and publishing are managed through Salesforce’s partner and publishing processes.

How do you test a Salesforce managed package?

Managed package testing requires more than testing the application in the development environment.

We test:

  • Fresh installation
  • Package upgrades
  • User permissions
  • Different Salesforce configurations
  • Supported editions
  • Data volumes
  • Bulk processing
  • External integrations
  • Error handling
  • Scheduled and asynchronous processes
  • Uninstall behaviour
  • Salesforce release compatibility

Where practical, automated tests and repeatable build processes are included in the development workflow.

How do you prevent an ISV app from reaching Salesforce governor limits?

We design the application for Salesforce’s multi-tenant environment from the beginning.

This includes bulk-safe Apex, efficient queries, asynchronous processing where appropriate, controlled callouts, selective data access, scalable automation, and testing with realistic data volumes.

We also review how the managed package will interact with automation already present in a customer’s Salesforce org.

Can you help improve the user experience of an existing Salesforce app?

Yes. We can review the complete product experience, including installation, setup, navigation, configuration, daily usage, error messages, and customer documentation.

Improvements may include Lightning Web Component redesign, simplified setup screens, guided configuration, clearer validation, fewer manual steps, better mobile support, or more consistent Salesforce design patterns.

Can Astonous take over development of an existing AppExchange app?

Yes. We can take over a product that was built by an internal team, freelancer, or another Salesforce development company.

We normally begin with a technical assessment covering:

  • Source code and version control
  • Managed package structure
  • Packaging organisations and Dev Hub
  • Release history
  • Security review status
  • Customer installations
  • Known defects
  • Technical debt
  • External services
  • Documentation
  • Product roadmap

After the assessment, we propose a transition and release plan that reduces risk for existing customers.

Can you support an app that is already listed on AppExchange?

Yes. We work with existing Salesforce ISVs that need help maintaining, improving, or expanding a listed application.

Support may include:

  • New feature development
  • Bug fixes
  • Package-version creation
  • Upgrade planning
  • Salesforce release readiness
  • Security remediation
  • Performance improvements
  • New integrations
  • Customer-specific requirements
  • Technical support
  • Product documentation
  • AppExchange listing updates
How are upgrades delivered to customers who already installed the app?

New functionality is released through managed package versions.

Depending on the package, release, and customer requirements, customers may install an upgrade themselves or the ISV may use an approved push-upgrade process. Each release should be tested against earlier supported versions and existing customer data.

We help plan package ancestry, versioning, backward compatibility, deprecation, upgrade scripts, and customer communication.

Can an AppExchange app be customised for an individual customer?

Yes, but customer-specific work should be kept separate from the core managed package wherever practical.

Common approaches include:

  • Customer-side Salesforce configuration
  • Extension packages
  • Unmanaged automation
  • Custom metadata settings
  • Public Apex interfaces
  • Platform events
  • APIs
  • Separate integration components

This allows the main product to remain upgradeable while still meeting a customer’s specialised requirements.

What happens when Salesforce releases a platform update?

Salesforce publishes three major platform releases each year. An ISV should review upcoming changes, test the application in preview environments, update affected components, and communicate any required customer actions.

We can manage release-readiness testing and resolve compatibility issues before the Salesforce update reaches customer production organisations.

Can you monitor how customers use our Salesforce app?

Salesforce provides AppExchange partners with tools that can help understand package adoption and usage, subject to the applicable setup and Salesforce policies.

We can also design privacy-conscious product telemetry, error logging, feature adoption reporting, and health monitoring. The product should collect only the information needed and clearly respect customer security and privacy requirements.

How do you troubleshoot issues inside a customer’s Salesforce org?

Managed package code is protected, so troubleshooting must be designed into the product.

We use structured logging, clear error messages, support utilities, configuration checks, subscriber support capabilities, and controlled diagnostic information. When access is required, it should be granted by the customer and limited to the time and purpose needed.

Who owns the application and source code developed by Astonous?

Customer-funded product code and deliverables are owned according to the signed engagement agreement.

We recommend documenting ownership of:

  • Source code
  • Package and namespace
  • Dev Hub and packaging organisations
  • Git repository
  • Product documentation
  • External service accounts
  • Intellectual property
  • Reusable components
  • Third-party libraries

Where practical, product assets should be maintained in accounts controlled by the ISV.

How do you protect our app idea and intellectual property?

We can sign a mutual non-disclosure agreement before reviewing sensitive product information.

Access to source code, customer data, packaging organisations, and business documentation is limited to authorised team members. Repository permissions, credentials, and development environments are managed according to the agreed security process.

Can Astonous work as a development partner for another Salesforce ISV or consulting company?

Yes. We can work as an offshore product-development team, a specialist managed-package team, or an extension of an existing Salesforce engineering organisation.

The engagement can cover architecture, development, testing, packaging, security review preparation, release management, and ongoing maintenance.

Customer communication, branding, intellectual-property ownership, working-hour overlap, and responsibilities are agreed before the engagement begins.

Why choose Astonous for Salesforce ISV app development?

Building a Salesforce product is different from completing a single Salesforce implementation. It requires product thinking, secure architecture, managed packaging, release planning, customer configurability, and long-term platform maintenance.

Astonous combines Salesforce consulting experience with practical ISV product-development experience. We can support the full product lifecycle—from early discovery and managed package development to AppExchange preparation, customer onboarding, upgrades, and ongoing product growth.

View All

We are Excited to Be a Part of Your Next Big Project!

Your big dreams deserve the right strategy. Fill out the form, pick a time that works for you, and let’s connect!
DREAMFORCE 2026 See Astonous Ship live at Dreamforce 2026 September 15–17 · San Francisco Book a Demo →