Fastlane iOS app "Encryption Export Compliance" with exemption

Viewed 1542

I am in the process of setting up Fastlane to simplify submitting updates for my iOS app to App Store Connect. My app only uses encryption for HTTPS requests, so it is considered exempt from providing documentation. (These are the questions that are asked when submitting a new release through the App Store Connect site.)

Fastlane requires more than just these two questions when you specify the encryption export compliance settings. These are set in the upload_to_app_store action, under the submission_information parameter.

This is what I currently have, but I'm not sure if it is correct:

upload_to_app_store(
    submission_information: {
        export_compliance_platform: 'ios',
        export_compliance_uses_encryption: true,
        export_compliance_is_exempt: true,

        # These are the ones I am confused by
        export_compliance_compliance_required: false,
        export_compliance_encryption_updated: false,
        export_compliance_app_type: nil,
        export_compliance_contains_third_party_cryptography: false,
        export_compliance_contains_proprietary_cryptography: false,
        export_compliance_available_on_french_store: false
    }
)

The last 6 fields are extremely unclear to me. Unfortunately Fastlane offers little documentation, because they just copied the fields used by Apple's non-public API.

How can I figure out what the correct values should be?

1 Answers

The Apple app store guidelines for checking off the compliance are documented for Apple, Fastlane is just expediting it by enabling us to pass it along automatically.

If you have updated your "export_compliance_encryption"- a question during the signing and build process. If you have updated (in your code) any encryption, that has compliance regulations or impact, this would be "true".

"When you submit your app to TestFlight or the App Store, you upload your app to a server in the United States. If you distribute your app outside the U.S. or Canada, your app is subject to U.S. export laws, regardless of where your legal entity is based. If your app uses, accesses, contains, implements, or incorporates encryption, this is considered an export of encryption software, which means your app is subject to U.S. export compliance requirements, as well as the import compliance requirements of the countries where you distribute your app.

Every time you submit a new version of your app, App Store Connect asks you questions to guide you through a compliance review. You can bypass these questions and streamline the submission process by providing the required information in your app’s Information Property List file."

https://developer.apple.com/documentation/security/complying_with_encryption_export_regulations?language=objc

Related