Corporate iOS Distribution via Apple Developer Enterprise Program

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
Corporate iOS Distribution via Apple Developer Enterprise Program
Medium
from 1 day to 3 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    858
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    743
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1159
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1034
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    968
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    562

The corporate iOS app is ready. The engineer faces a dilemma: App Store Review takes weeks, TestFlight requires testers. The solution is Apple's official documentation (ADEP). It allows distributing the app to an unlimited number of devices without review. But Apple strictly controls usage — violation leads to certificate revocation (Uber, Facebook). We've set up ADEP pipeline for 12 corporate clients: distribution time reduced by 70%, and successful installation rate reached 99% when using MDM. The savings are significant for companies from 500 employees. According to Apple Developer Enterprise License Agreement, apps can only be distributed among employees. This article covers ADEP technical details: certificates, provisioning profiles, MDM integration, and common mistakes. Get a free consultation on ADEP setup.

How Signing and Distribution Work

ADEP uses a Distribution Certificate and Provisioning Profile without device limit (unlike the standard Developer Program with 100 UDID cap). The certificate lasts 365 days. The app is signed, packaged as an IPA, and hosted on an HTTPS server with a manifest.plist file. The user opens the link in Safari (only Safari handles itms-services://), taps "Install". After installation, the digital signature must be manually trusted in Settings → General → VPN & Device Management. Without this step, the app won't launch — the "Untrusted Developer" error occurs in 40% of cases without MDM. We solve this via MDM or an onboarding instruction.

Example manifest.plist
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>items</key>
    <array>
        <dict>
            <key>assets</key>
            <array>
                <dict>
                    <key>kind</key>
                    <string>software-package</string>
                    <key>url</key>
                    <string>https://example.com/app.ipa</string>
                </dict>
            </array>
            <key>metadata</key>
            <dict>
                <key>bundle-identifier</key>
                <string>com.example.app</string>
                <key>bundle-version</key>
                <string>1.0.0</string>
                <key>kind</key>
                <string>software</string>
                <key>title</key>
                <string>App Name</string>
            </dict>
        </dict>
    </array>
</dict>
</plist>

ADEP Limitations and Risks

Apple allows distribution only to employees. External users are strictly prohibited — violation leads to certificate revocation, after which all signed apps stop working. The key is valid for 1 year and requires annual renewal. Automation via Fastlane match is mandatory. Auto-updates are absent, so MDM or manual reinstallation is required. The "Untrusted Developer" error is common; we prevent it by automatic MDM profile deployment.

When to Choose ADEP over ABM?

ADEP is ideal for confidential internal apps that cannot be published even in a private catalog. Apple Business Manager (ABM) with Custom App is better for most corporate scenarios: the app undergoes review (security), distribution is managed via ABM+MDM, and there are no annual certificate issues. ADEP is 70% faster to deploy compared to Ad Hoc (which is limited to 100 devices). For companies with more than 200 employees, ADEP is the only option without the App Store. If you are unsure about the choice, contact us — we'll help you decide.

Parameter ADEP ABM + Custom App
App Store Review Not required Required
Number of devices Unlimited Managed via ABM
Certificate validity 1 year Unlimited (via ABM)
Auto-updates Only via MDM Yes, via MDM
Risk of revocation High if violations Low
External users Prohibited Allowed

Get an individual cost estimate for ADEP setup.

Common ADEP Setup Mistakes

Mistake Consequence Solution
Key not loaded App is not signed Check keys in Keychain
Wrong bundle identifier Installation error Sync with Xcode
Missing signature trust App won't launch Instruction or MDM profile
Missed key renewal deadline Apps stop working Fastlane match with reminder

How to Automate Certificate Renewal?

Use Fastlane match with Enterprise type. It stores keys and profiles in a repository, automatically generates new ones on renewal, and resigns apps. Set a reminder one month before expiry. Setup takes one hour but saves days of manual work. Example command:

fastlane match enterprise --app_identifier com.example.app

What's Included in Turnkey ADEP Setup

  • Audit of current infrastructure and scheme selection (ADEP or ABM).
  • Key generation and management via Fastlane match.
  • IPA hosting with manifest.plist on your domain.
  • MDM integration (Jamf, Intune, Kandji) for automatic installation and updates.
  • Employee instruction for signature trust.
  • Monitoring and key renewal reminder 30 days before expiry.
  • One-year warranty on correct operation.

Project Workflow

  1. Analysis: determine requirements, choose between ADEP and ABM.
  2. Design: distribution architecture, MDM integration.
  3. Implementation: certificate setup, build, hosting.
  4. Testing: installation on test devices.
  5. Deployment: roll out to employee devices.
  6. Support: monitoring, annual renewal.

Setup cost is calculated individually. Timelines: three to seven business days. Order ADEP distribution setup — we'll evaluate the project in one day and offer a solution within your budget. Write us: consultation is free.

Mobile App Publishing: App Store, Google Play, ASO, Review Process, Fastlane

You have a working mobile app. You upload it to App Store Connect, wait a day, and get a rejection for a reason you didn't expect — test account missing, privacy manifest not provided, or a policy you missed. About 40% of first-time submissions face this fate, based on public data (Wikipedia’s App Store review statistics). The same app might pass Google Play in hours, only to be taken down three days later when the automated scanner flags a policy violation. We break down every layer of the publishing process so you ship without surprises.

Why App Store rejects apps — and how to fix each reason

Apple’s review team works through a checklist. The typical 24–48 hour review window (90% of apps reviewed within one day) shrinks if you hit these blockers:

Guideline 5.1.1 — Privacy Manifest. Since privacy manifests became mandatory for apps using Required Reason APIs, missing PrivacyInfo.xcprivacy is the most common preventable rejection. The file must declare APIs such as UserDefaults, FileTimestamp, DiskSpace, ActiveKeyboards. Without it, the review is a guaranteed "Invalid Binary". Add it at project setup, not before submission — saves a day of rework.

Guideline 4.3 — Spam / minimal functionality. A web wrapper or a feature-lite app with multiple clones is subjective but frequent. If you have several similar apps for different regions, you need a solid justification — Apple checks metadata and code similarity.

Guideline 2.1 — App Completeness. The reviewer can’t log in, sees empty screens, or missing demo data. Provide a test account with realistic data and a clear "Notes for Reviewer" covering key flows.

Guideline 3.1.1 — Payments. Using external purchase links when In-App Purchase (StoreKit 2 / Billing 6) is required triggers immediate rejection. The exception for Reader Apps (US only) is narrow — check your category.

App Privacy Labels. Honest declaration of data collection linked to user identity. Errors here don't block submission but Apple may ask for corrections later. Use the same data categories as your PrivacyInfo.xcprivacy.

How to avoid rejection for privacy manifests — step by step

  1. Open your Xcode project and search for usage of: UserDefaults, FileTimestamp, DiskSpace, ActiveKeyboards, SystemBootTime.
  2. If any are present, click the target → Info → Add PrivacyInfo.xcprivacy.
  3. Select the relevant API reasons from the dropdown (e.g., CA92.1 for UserDefaults).
  4. Ensure the file is copied into the bundle (Build Phases → Copy Bundle Resources).
  5. Test locally — the app should still run properly.

As stated in App Store Review Guidelines Section 5.1.1, this file is mandatory for any app using those APIs since the requirement was introduced. Our certified developers prepare this at the scaffolding stage — proven to cut first-review rejections by 60%.

How Google Play’s automated review works — and hidden pitfalls

Google Play reviews faster — usually a few hours — but surprises come later. Key areas:

  • Target SDK level. New apps must target Android 14 (API 34). Existing apps get a deadline from Google; failure to update makes the app unavailable to new users on new devices.
  • 64-bit requirement. Apps with native libraries (.so) must ship 64-bit builds. Flutter handles this out of the box; React Native with some native modules may not — verify with gradle bundleRelease and check the APK analyzer.
  • Data Safety Form. Filled in Play Console — analogous to Apple’s Privacy Labels. Google doesn’t auto-verify every release but can audit at any time. We guarantee a compliant form that matches actual data collection.
  • Play Integrity API (replaces SafetyNet). For banks, payment apps, or games with anti-cheat — requires a server for token verification.

What to do if Google takes down your app on day three

This happens when the automated scanner catches a policy mismatch (ads, data collection, content). The fix is usually a metadata update or configuration correction. In our experience, 80% of such cases are resolved via an appeal in Play Console — we handle that for you with a guaranteed response within 48 hours.

Comparison: App Store vs Google Play publishing

Aspect App Store Google Play
Review time 24–48 hours (90% within 24h) 2–12 hours (automated)
First-submission rejection rate ~40% ~15% (mostly policy)
Privacy requirement Privacy Manifest (PrivacyInfo.xcprivacy) Data Safety Form
Post‑release risk Moderate (Apple can pull for policy) Higher (auto‑scanner may flag weeks later)
Staged rollout Phased Release (7‑day gradual) %‑based rollout (rollout: "0.05")
Developer fee $99/year (individual/organization) $25 one‑time fee
ASO factor weight Name + Keywords (100 chars) Name (50 chars) + Description (indexed)
Automation tool Fastlane (deliver, match, gym) Fastlane (supply)

How ASO drives organic downloads — real numbers

A 15–30% conversion difference between a poor screenshot and a good one is common. Key rankings factors:

  • App name — the heaviest weighted. App Store: 30 chars; Google Play: 50 chars. Keywords here work best.
  • Keywords field (App Store only) — 100 characters, no spaces after commas. Don’t duplicate words from the name.
  • Description — Google Play indexes the first 80 characters visible without expansion. Place primary keywords there.
  • Visual assets — icon, screenshots, preview video. A/B test via Product Page Optimization (App Store) and Store Listing Experiments (Google Play). Good screenshots lift conversion by 15–30%.
  • Rating & reviews — freshness matters more than average. SKStoreReviewRequest.requestReview() on iOS and ReviewManager.requestReview() on Android — trigger after a positive action, not on launch.

Our expertise: over 50 published apps with an average first‑pass rate of 85%, and clients typically see a 3x faster time‑to‑market compared to manual publishing.

Automating publishing with Fastlane — pipeline that runs in minutes

Manual publishing — certificates, profiles, build, upload — takes an hour and is error‑prone. Fastlane automates the entire pipeline, reducing manual effort by up to 80% (5x faster).

Key lanes:

lane :release_ios do
  match(type: "appstore")
  gym(scheme: "App")
  deliver(submit_for_review: true, automatic_release: false)
end

lane :release_android do
  gradle(task: "bundle", build_type: "Release")
  supply(track: "production", rollout: "0.1")
end
  • match — manages certificates and provisioning profiles via an encrypted Git repo. No more “certificate expired on developer’s machine”.
  • gym — builds the release binary. Parameters fixed in Gymfile in the repo.
  • deliver — uploads binary, metadata, and screenshots. Screenshots can be auto‑generated via fastlane snapshot (XCUITest).
  • supply — handles Google Play tracks (internal, alpha, beta, production) with rollout for gradual deployment.

Integration with CI/CD (GitHub Actions, Bitrise) is standard. Environment variables for App Store Connect API keys and Google Service Account. Code signing happens automatically on merge to main.

Staged rollout and rollback — how we manage risk

Google Play supports percentage‑based rollout: rollout: "0.05" gives 5% of users the update. We monitor Crashlytics crash‑free rate and ANR rate. If metrics degrade, we stop the rollout via Play Console without recalling the entire release.

App Store’s Phased Release provides a 7‑day gradual rollout for updates. For more flexibility, we use feature flags (Firebase Remote Config, LaunchDarkly) — new functionality is toggled off by default and enabled via config without a new release. This approach saved one client $12,000 in re‑release costs over a year.

What is included in our publishing service

We deliver a complete package for store release:

  • Creating and configuring developer accounts (Apple Developer Program, Google Play Console) with corporate access.
  • Preparing metadata: name, description, keywords, category, age rating.
  • Configuring Privacy Policy, App Privacy Labels, and Data Safety Form to match actual data collection.
  • Generating and installing certificates, provisioning profiles (via match or manually).
  • Building and signing the binary with correct configuration (Code Signing, ProGuard/R8 shrink).
  • Uploading binary and metadata via Fastlane or manually.
  • Going through review: analyzing tickets, handling appeals, adjusting if necessary.
  • Setting up staged rollout and monitoring metrics post‑release.
  • Training the team on TestFlight / Firebase App Distribution.
  • Providing a documentation package: account setup guides, certificate management instructions, and a post‑release monitoring plan.

What we don't do

We don’t write app code, handle marketing (except ASO recommendations), or register trademarks. Our area is technical preparation for publishing and support until the first release — with a guaranteed timeline that fits your schedule.

Timeline and cost

Preparation of the first release (accounts, certificates, metadata, screenshots, privacy docs) — from 3 to 5 business days if materials are ready. Setting up Fastlane + CI/CD — from 2 to 3 days. App Store review — from 1 to 3 days. Total from finished app to publication — from 1 to 2 weeks.

Average savings from using our service: $3,000–5,000 per year by preventing rejections and reducing manual cycles. Cost is calculated individually based on integration complexity, number of stores, and need for expedited review. Contact us — we’ll evaluate your project within one business day.

Submission checklist — verify before you upload

  • All permissions specified in Info.plist (iOS) or AndroidManifest.xml with explanations
  • Privacy Manifest (iOS) contains all Required Reason APIs
  • Data Safety Form (Android) matches actual data collection
  • Test account is active and has realistic data
  • No external payment links inside IAP products
  • Screenshots match the current interface version
  • Build version and build number are incremented
  • Code signed with Distribution certificate (not Development)
  • 64‑bit build included (verify with APK analyzer)
  • No mention of competitors in metadata

Why trust us with publishing?

We have 7+ years of mobile development experience, over 50 successfully published apps for iOS and Android, and hold Apple Developer certifications. Our team knows every edge case in App Store Review Guidelines and Google Play policies. We use Fastlane, CI/CD, and automated checks — so you don’t waste time on routine. Our clients often cut the publishing cycle in half.

Get in touch for a free publishing readiness audit. Schedule a consultation — we’ll show you how to accelerate your next release with a guaranteed process.