<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Appian Knowledge Base</title><link>https://community.appian.com/support/w/kb</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2385 Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq</link><pubDate>Wed, 27 May 2026 18:11:29 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Ryan Good</dc:creator><description>Current Revision posted to Appian Knowledge Base by Ryan Good on 5/27/2026 6:11:29 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="BypassReview" href="#BypassReview"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during all submissions of new and updated plugins to Appian. Subsequent reviews are also performed on a routine basis after initial approval.&lt;br /&gt; Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;br /&gt; Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission. Post-approval, additional security reviews are performed regularly.&lt;br /&gt; Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;br /&gt; Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;br /&gt; Plugins which are not updated may be removed from the AppMarket. Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;br /&gt; Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;br /&gt; Approval of a plugin does not guarantee approval of subsequent versions.&lt;br /&gt; Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;br /&gt; If a plug-in requires expedited review, please include that context and justification in the submission.&lt;br /&gt; If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>KB-2384 Appian's Response to AI-Accelerated Threats (Mythos, Daybreak, MDASH)</title><link>https://community.appian.com/support/w/kb/3815/kb-2384-appian-s-response-to-ai-accelerated-threats-mythos-daybreak-mdash</link><pubDate>Wed, 27 May 2026 16:49:21 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f09ad2d2-0775-49e8-9dcf-95ba4bf95069</guid><dc:creator>Kaushal Patel</dc:creator><description>Current Revision posted to Appian Knowledge Base by Kaushal Patel on 5/27/2026 4:49:21 PM&lt;br /&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;&lt;/span&gt;&lt;span style="font-weight:600;"&gt;Executive Summary&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian understands the concerns surrounding new, highly capable frontier models, such as Anthropic&amp;rsquo;s Claude Mythos Preview, and their potential to accelerate the discovery and exploitation of software vulnerabilities. Our position is that the core principles of robust cloud security continue to generate the most effective defense. Appian&amp;#39;s security posture, built upon secure-by-design architecture, strict operational rigor, and deep partnership with Amazon Web Services (AWS), Chainguard, and others is actively managed to mitigate the risks introduced by AI-accelerated threats, ensuring the continued security and compliance of customer environments.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;What is Mythos?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Claude Mythos Preview is a new large language model developed by Anthropic. It has demonstrated advanced capabilities in computer security tasks, particularly in identifying, analyzing, and potentially exploiting vulnerabilities in software. The critical industry insight regarding Mythos is &lt;/span&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;not&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; that it introduces fundamentally new vulnerability classes, but that it significantly reduces the time and expertise required for malicious actors to execute an AI-accelerated offensive, compressing traditional exploitation timelines.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;What is Daybreak?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Daybreak is an OpenAI-developed frontier model, often discussed alongside Anthropic&amp;rsquo;s Mythos, associated with advanced AI reasoning capabilities. It is related to OpenAI&amp;#39;s reasoning models like &amp;quot;o1&amp;quot; and &amp;quot;o3-mini&amp;quot; which are optimized for complex tasks such as programming. Like other frontier models, Daybreak&amp;#39;s significance is its potential to accelerate AI-driven offense by making the discovery and exploitation of software vulnerabilities faster.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;What is MDASH?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;MDASH (which stands for Multi-model Dynamic/Agentic Scanning Harness or Multi-model Agentic Scanning Harness) is a highly advanced, AI-powered vulnerability discovery system developed by &lt;/span&gt;&lt;a href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/"&gt;&lt;span style="font-weight:400;"&gt;Microsoft&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt;. This system is designed for defensive use, rapidly identifying and addressing software vulnerabilities to help organizations &amp;#39;defend at AI speed,&amp;#39; reflecting the industry-wide shift toward using AI to compress vulnerability discovery and exploitation timelines. This is what organizations today are doing relative to vulnerability discovery and remediation in code.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Appian&amp;rsquo;s Perspective&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian&amp;rsquo;s position as a leading security organization is aligned with the community behind the Cloud Security Alliance (CSA) and Amazon Web Services (AWS): The appropriate response to AI-accelerated offense is an increased focus on foundational security controls. The CSA Mythos paper emphasizes that organizations must prioritize &lt;/span&gt;&lt;b&gt;patch management, vulnerability remediation, and continuous monitoring&lt;/b&gt;&lt;span style="font-weight:400;"&gt; to reduce the attack surface. Appian aligns with the AWS view that security is a shared responsibility, and that defense at scale requires continuous evolution of operational rigor, not reactive technology adoption. Our strategy is built on monitoring these developments and immediately integrating defensive learnings.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;We&amp;rsquo;ve gained perspective with the industry surrounding frontier models, including effective use of existing foundational models for security purposes. These tools are good at recursive reading and discovery; their findings &lt;/span&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-weight:400;"&gt;will&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt; reflect your own organization&amp;#39;s security maturity. If you have &amp;ldquo;skeletons&amp;rdquo; in the closet, don&amp;rsquo;t enforce MFA, don&amp;rsquo;t enforce a good SDLC, don&amp;rsquo;t upgrade to the latest patches, these are the equivalent of leaving your home unlocked and windows open for a burglar.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;We are actively engaged using tools available to us today, and take the opportunity that AI presents very seriously on behalf of Appian, you (our customers), and your customers. More on this below.&lt;/span&gt;&lt;/p&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Appian&amp;rsquo;s Position&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian&amp;rsquo;s approach to security is predictive, proactive, systematic, and aligned with the highest industry standards, providing essential mitigation against AI-accelerated threats. We jointly align with customers towards best practices to mitigate potential emergent threats and risks - AI or otherwise.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;Secure-by-Design Infrastructure&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian Cloud leverages the extensive security capabilities of AWS, relying on their expertise in securing the underlying cloud infrastructure. Our deep partnership ensures that Appian environments benefit from AWS&amp;rsquo;s scale, rigorous security controls, and immediate response capabilities. This includes leveraging identity and access management (IAM), network segregation, and continuous configuration checks provided by the cloud service provider. Frontier LLMs are good at finding security flaws within logic and code that when applied to standards, protocols, kernel, and supply-chains are the emergent threat fundamental to system operations; layering mature practices and response actions are required to keep pace.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;Differentiated Platform Architecture&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The Appian Platform architecture is fundamentally designed to reduce inherent risk and exposure:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Zero-Trust: &lt;/b&gt;&lt;span style="font-weight:400;"&gt;Appian&amp;#39;s architecture is built on Zero Trust principles: never trust, assume breach, and verify every access request. This is implemented via a multi-control point lattice, shifting defenses from static perimeters to focus on users, assets, and resources. Core components include strong identity, device health, continuous re-authentication, hyper least privilege, and encryption everywhere. This resilient platform design provides consistent security regardless of user location or data sensitivity.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Identity-Aware Access:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; All customer applications and data interactions are governed by a robust, fine-grained identity and access framework.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Multi-Tenant Controls:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Strong logical separation is enforced across all multi-tenant environments, isolating customer data and reducing the potential impact of a single vulnerability.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Policy Enforcement and Auditability:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; The platform enforces strict security policies at every layer, providing comprehensive audit trails that enhance detection and response capabilities.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Integrated Security Development:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We leverage both deterministic and&amp;nbsp; AI-assisted/agentic tools directly into our continuous integration pipeline to automatically flag and help developers remediate vulnerabilities before code is promoted. We are also adapting the frequency of AI-assisted secure code reviews for our entire code-base to proactively hunt vulnerabilities. Continuous 3rd party White-Hat Hackers and penetration testing are used to further enhance our posture.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Our active investments in &lt;/b&gt;&lt;span style="font-weight:400;"&gt;GenAI-driven security ensure continuous protection at the speed of development:&lt;/span&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;AI-Powered Secure Design:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We are augmenting security tools with additional AI-powered tools for architecture review and threat modeling to identify and fix flaws continuously in the agentic SDLCs, preventing issues before they are coded.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Agentic Code Scanning:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Security services in our SDLC have already been created as agent accessible tools to scan and remediate vulnerabilities directly inside developer environment tooling) and centrally enforced in code pipelines.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Supply Chain Hardening:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We are seeking additional hardened components similar to our use of Chainguard. We are migrating to private, vendor-managed third-party libraries and in our centralized artifact repository which governs all components, ensuring the integrity and provenance of our software supply chain against AI-accelerated attacks.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;Mature Vulnerability Management Program&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian maintains a mature, risk-based vulnerability management program that adheres to industry standards and regulatory expectations:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Prioritization and Remediation:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We leverage systems like CISA&amp;rsquo;s Known Exploited Vulnerabilities (KEV) database, and plan to include additional exploitability and reachability metrics to prioritize remediation based on real-world threat exposure, ensuring a focus on the most critical risks.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Operational Rigor:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Appian is committed to aggressive patching SLAs and maintaining Plan of Action and Milestones (POA&amp;amp;M) discipline. We are continuously improving our ability to rapidly deploy patches, specifically to meet the accelerated timelines suggested by AI-enabled offense.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Supply Chain Security:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; To proactively counter supply chain risks, Appian is migrating to private, curated third-party libraries for components, ensuring all dependencies are current, patched, and malware-free. We partner with industry leading firms on pre-hardened and pre-patched assets in our supply chain where possible.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Scaling Vulnerability Management:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We are preparing for an order-of-magnitude increase in discovered vulnerabilities. Our processes leverage automation and advanced prioritization to streamline triage and enable rapid remediation of high-exposure findings.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;The Appian CSA Assessment&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;In light of the evolving threat landscape, Appian has rigorously evaluated the risks and strategic guidance associated with frontier models, specifically aligning our internal assessments with findings from the &lt;/span&gt;&lt;a href="https://labs.cloudsecurityalliance.org/mythos-ciso/"&gt;&lt;span style="font-weight:400;"&gt;Cloud Security Alliance (CSA) Mythos paper&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt;. We ensure our posture remains anchored in foundational operational rigor (e.g. systems hardening, mature vulnerability remediation, and rapid incident response), while simultaneously incorporating agentic AI technologies to modernize and accelerate our defensive capabilities.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;To reinforce Appian&amp;rsquo;s approach, our security investments (based on our risk assessments) are focused on:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;AI-Enhanced Secure Architecture: &lt;/b&gt;&lt;span style="font-weight:400;"&gt;To ensure issues are mitigated before they reach the codebase, we are reinforcing our agentic SDLCs by integrating AI-driven tools for continuous threat modeling and architectural reviews.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Agent-Integrated Vulnerability Scanning: &lt;/b&gt;&lt;span style="font-weight:400;"&gt;We have transitioned security services into agent-accessible tools that operate directly within developer environments and are strictly enforced via central code pipelines to automate remediation.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Robust Supply Chain Protection: &lt;/b&gt;&lt;span style="font-weight:400;"&gt;Appian is actively strengthening our software supply chain by moving to private, vendor-managed artifact repositories and incorporating hardened components, such as Chainguard, to maintain rigorous integrity against AI-driven exploitation.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Appian&amp;rsquo;s Offensive Defense: Turning AI-Accelerated Risk into Modernization Opportunity&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The greatest defense against AI-accelerated offense is a fundamental shift in application strategy. The Mythos model highlights a critical moment where organizations must move beyond defensive patching toward architectural security by default.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Legacy or &amp;ldquo;vibe&amp;rdquo; code is now unsafe at any speed.&lt;/b&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; The speed of vulnerability discovery (now compressed to hours) means manual custom code development and patching cycles can no longer keep pace. Appian&amp;#39;s low-code platform eliminates vast amounts of custom code, reducing the attack surface and enforcing secure patterns by design.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Due to the insecure nature of AI vibe coding, enterprises should replace it with spec-driven development on secure platforms like Appian.&lt;/b&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; Relying on large language models (LLMs) to generate &amp;quot;vibe code&amp;quot; introduces new supply chain and vulnerability risks from potentially unvetted code. Appian&amp;#39;s low-code, spec-driven approach generates standardized, secure code from certified platform components, ensuring integrity and auditability.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Enterprises need to migrate custom and legacy apps to secure-by-default platforms like Appian.&lt;/b&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; Legacy apps are highly susceptible to this new shift. Appian provides a secure cloud architecture leveraging AWS&amp;#39;s scale and security controls, offering continuous updates and a mature vulnerability management program.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Secure platforms that reduce your attack surface and centralize patching and monitoring are the best way to reduce workload on security teams.&lt;/b&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; Moving applications to Appian Cloud shifts the burden of infrastructure security, patching (aggressive SLAs), and continuous monitoring to Appian and AWS. This drastically reduces the operational overhead and allows internal security teams to focus on core business risks.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;AI Agents need the guardrails and governance of secure process orchestration that Appian provides.&lt;/b&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; As autonomous AI agents become pervasive, constraining their actions is critical. Appian&amp;#39;s process orchestration provides the necessary identity-aware framework, policy enforcement, and auditability to govern AI agents, ensuring they operate within defined, secure business processes.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Customer Changes: Required Actions&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The speed of AI-accelerated threats requires immediate action to solidify your foundational security posture. We recommend customers prioritize the following actions:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Accelerate Platform Updates:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Promptly prioritize and schedule upgrades to the latest Appian platform releases to benefit from our continuous security enhancements and keep pace with vulnerability remediation. Reach out to Appian Support with your organization&amp;#39;s desired posture; we recommend taking the latest release as soon as feasible for your organization. We can patch at the speed of your mission needs.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Enforce MFA for All Accounts:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; With the release of additional MFA features in 26.1, audit your organizational requirements, ensure alignment and reach out to Appian Support if you need assistance. We recommend strong Multi-Factor Authentication (MFA) for &lt;/span&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;all&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; accounts (Appian or otherwise) to strengthen identity controls against AI-driven social engineering and credential misuse.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Modernize on Appian Cloud:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Eliminate critical attack surface by migrating all custom and legacy applications to the latest version of Appian Cloud, which offers secure-by-default architecture, centralized patching, and continuous monitoring.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Adopt New Security Capabilities:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Rapidly adopt key platform security features as they become available, such as Cloud Secure Link (when available) and Log Streaming (24.4/26.4) enhancements to meet your mission needs.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Callout on Further Action:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; If additional, environment-specific action is required for your sites, our Solution Engineering team will reach out directly; ensure your security and admin contacts are up-to-date.&lt;/span&gt;&lt;/p&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Closing Statement&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian&amp;rsquo;s security posture is built keeping in mind the speed and scale of AI-accelerated threat discovery by frontier models. Our response strategy aligns with the industry, shifting to Zero-Trust and high-velocity operational rigor that prioritizes foundational security controls: vulnerability remediation, continuous monitoring, and continuous testing. This architectural approach is the essential alternative to risky &amp;ldquo;AI Vibe coding&amp;rdquo;; replacing ad-hoc code generation with spec-driven development using standardized, certified platform components to ensure security and auditability. Furthermore, Appian&amp;#39;s secure process orchestration provides the necessary guardrails and governance to ensure pervasive AI agents operate securely within defined business processes, using identity-aware access and policy enforcement. Ultimately, our platform enables customers to quickly modernize legacy applications&amp;mdash;which are highly susceptible to this new threat&amp;mdash;on a secure, continuously updated architecture. This accelerated threat landscape requires a joint effort.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;To immediately strengthen your defenses and keep pace with AI-accelerated threats, we urge you to review and implement the &lt;/span&gt;&lt;b&gt;Required Actions&lt;/b&gt;&lt;span style="font-weight:400;"&gt; detailed above: Accelerate Platform Updates, Enforce MFA for All Accounts, Modernize on Appian Cloud, and Adopt New Security Capabilities.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Last reviewed: May&lt;/span&gt;&lt;span&gt;&amp;nbsp;27, 2026&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>KB-2384 Appian's Response to AI-Accelerated Threats (Mythos, Daybreak, MDASH)</title><link>https://community.appian.com/support/w/kb/3815/kb-2384-appian-s-response-to-ai-accelerated-threats-mythos-daybreak-mdash/revision/1</link><pubDate>Wed, 27 May 2026 16:48:50 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f09ad2d2-0775-49e8-9dcf-95ba4bf95069</guid><dc:creator>Kaushal Patel</dc:creator><description>Revision 1 posted to Appian Knowledge Base by Kaushal Patel on 5/27/2026 4:48:50 PM&lt;br /&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;&lt;/span&gt;&lt;span style="font-weight:600;"&gt;Executive Summary&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian understands the concerns surrounding new, highly capable frontier models, such as Anthropic&amp;rsquo;s Claude Mythos Preview, and their potential to accelerate the discovery and exploitation of software vulnerabilities. Our position is that the core principles of robust cloud security continue to generate the most effective defense. Appian&amp;#39;s security posture, built upon secure-by-design architecture, strict operational rigor, and deep partnership with Amazon Web Services (AWS), Chainguard, and others is actively managed to mitigate the risks introduced by AI-accelerated threats, ensuring the continued security and compliance of customer environments.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;What is Mythos?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Claude Mythos Preview is a new large language model developed by Anthropic. It has demonstrated advanced capabilities in computer security tasks, particularly in identifying, analyzing, and potentially exploiting vulnerabilities in software. The critical industry insight regarding Mythos is &lt;/span&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;not&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; that it introduces fundamentally new vulnerability classes, but that it significantly reduces the time and expertise required for malicious actors to execute an AI-accelerated offensive, compressing traditional exploitation timelines.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;What is Daybreak?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Daybreak is an OpenAI-developed frontier model, often discussed alongside Anthropic&amp;rsquo;s Mythos, associated with advanced AI reasoning capabilities. It is related to OpenAI&amp;#39;s reasoning models like &amp;quot;o1&amp;quot; and &amp;quot;o3-mini&amp;quot; which are optimized for complex tasks such as programming. Like other frontier models, Daybreak&amp;#39;s significance is its potential to accelerate AI-driven offense by making the discovery and exploitation of software vulnerabilities faster.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;What is MDASH?&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;MDASH (which stands for Multi-model Dynamic/Agentic Scanning Harness or Multi-model Agentic Scanning Harness) is a highly advanced, AI-powered vulnerability discovery system developed by &lt;/span&gt;&lt;a href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/"&gt;&lt;span style="font-weight:400;"&gt;Microsoft&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt;. This system is designed for defensive use, rapidly identifying and addressing software vulnerabilities to help organizations &amp;#39;defend at AI speed,&amp;#39; reflecting the industry-wide shift toward using AI to compress vulnerability discovery and exploitation timelines. This is what organizations today are doing relative to vulnerability discovery and remediation in code.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Appian&amp;rsquo;s Perspective&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian&amp;rsquo;s position as a leading security organization is aligned with the community behind the Cloud Security Alliance (CSA) and Amazon Web Services (AWS): The appropriate response to AI-accelerated offense is an increased focus on foundational security controls. The CSA Mythos paper emphasizes that organizations must prioritize &lt;/span&gt;&lt;b&gt;patch management, vulnerability remediation, and continuous monitoring&lt;/b&gt;&lt;span style="font-weight:400;"&gt; to reduce the attack surface. Appian aligns with the AWS view that security is a shared responsibility, and that defense at scale requires continuous evolution of operational rigor, not reactive technology adoption. Our strategy is built on monitoring these developments and immediately integrating defensive learnings.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;We&amp;rsquo;ve gained perspective with the industry surrounding frontier models, including effective use of existing foundational models for security purposes. These tools are good at recursive reading and discovery; their findings &lt;/span&gt;&lt;span style="text-decoration:underline;"&gt;&lt;span style="font-weight:400;"&gt;will&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt; reflect your own organization&amp;#39;s security maturity. If you have &amp;ldquo;skeletons&amp;rdquo; in the closet, don&amp;rsquo;t enforce MFA, don&amp;rsquo;t enforce a good SDLC, don&amp;rsquo;t upgrade to the latest patches, these are the equivalent of leaving your home unlocked and windows open for a burglar.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;We are actively engaged using tools available to us today, and take the opportunity that AI presents very seriously on behalf of Appian, you (our customers), and your customers. More on this below.&lt;/span&gt;&lt;/p&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Appian&amp;rsquo;s Position&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian&amp;rsquo;s approach to security is predictive, proactive, systematic, and aligned with the highest industry standards, providing essential mitigation against AI-accelerated threats. We jointly align with customers towards best practices to mitigate potential emergent threats and risks - AI or otherwise.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;Secure-by-Design Infrastructure&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian Cloud leverages the extensive security capabilities of AWS, relying on their expertise in securing the underlying cloud infrastructure. Our deep partnership ensures that Appian environments benefit from AWS&amp;rsquo;s scale, rigorous security controls, and immediate response capabilities. This includes leveraging identity and access management (IAM), network segregation, and continuous configuration checks provided by the cloud service provider. Frontier LLMs are good at finding security flaws within logic and code that when applied to standards, protocols, kernel, and supply-chains are the emergent threat fundamental to system operations; layering mature practices and response actions are required to keep pace.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;Differentiated Platform Architecture&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The Appian Platform architecture is fundamentally designed to reduce inherent risk and exposure:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Zero-Trust: &lt;/b&gt;&lt;span style="font-weight:400;"&gt;Appian&amp;#39;s architecture is built on Zero Trust principles: never trust, assume breach, and verify every access request. This is implemented via a multi-control point lattice, shifting defenses from static perimeters to focus on users, assets, and resources. Core components include strong identity, device health, continuous re-authentication, hyper least privilege, and encryption everywhere. This resilient platform design provides consistent security regardless of user location or data sensitivity.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Identity-Aware Access:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; All customer applications and data interactions are governed by a robust, fine-grained identity and access framework.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Multi-Tenant Controls:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Strong logical separation is enforced across all multi-tenant environments, isolating customer data and reducing the potential impact of a single vulnerability.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Policy Enforcement and Auditability:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; The platform enforces strict security policies at every layer, providing comprehensive audit trails that enhance detection and response capabilities.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Integrated Security Development:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We leverage both deterministic and&amp;nbsp; AI-assisted/agentic tools directly into our continuous integration pipeline to automatically flag and help developers remediate vulnerabilities before code is promoted. We are also adapting the frequency of AI-assisted secure code reviews for our entire code-base to proactively hunt vulnerabilities. Continuous 3rd party White-Hat Hackers and penetration testing are used to further enhance our posture.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Our active investments in &lt;/b&gt;&lt;span style="font-weight:400;"&gt;GenAI-driven security ensure continuous protection at the speed of development:&lt;/span&gt;&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;AI-Powered Secure Design:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We are augmenting security tools with additional AI-powered tools for architecture review and threat modeling to identify and fix flaws continuously in the agentic SDLCs, preventing issues before they are coded.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Agentic Code Scanning:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Security services in our SDLC have already been created as agent accessible tools to scan and remediate vulnerabilities directly inside developer environment tooling) and centrally enforced in code pipelines.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Supply Chain Hardening:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We are seeking additional hardened components similar to our use of Chainguard. We are migrating to private, vendor-managed third-party libraries and in our centralized artifact repository which governs all components, ensuring the integrity and provenance of our software supply chain against AI-accelerated attacks.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:500;"&gt;Mature Vulnerability Management Program&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian maintains a mature, risk-based vulnerability management program that adheres to industry standards and regulatory expectations:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Prioritization and Remediation:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We leverage systems like CISA&amp;rsquo;s Known Exploited Vulnerabilities (KEV) database, and plan to include additional exploitability and reachability metrics to prioritize remediation based on real-world threat exposure, ensuring a focus on the most critical risks.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Operational Rigor:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Appian is committed to aggressive patching SLAs and maintaining Plan of Action and Milestones (POA&amp;amp;M) discipline. We are continuously improving our ability to rapidly deploy patches, specifically to meet the accelerated timelines suggested by AI-enabled offense.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Supply Chain Security:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; To proactively counter supply chain risks, Appian is migrating to private, curated third-party libraries for components, ensuring all dependencies are current, patched, and malware-free. We partner with industry leading firms on pre-hardened and pre-patched assets in our supply chain where possible.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Scaling Vulnerability Management:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; We are preparing for an order-of-magnitude increase in discovered vulnerabilities. Our processes leverage automation and advanced prioritization to streamline triage and enable rapid remediation of high-exposure findings.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;The Appian CSA Assessment&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;In light of the evolving threat landscape, Appian has rigorously evaluated the risks and strategic guidance associated with frontier models, specifically aligning our internal assessments with findings from the &lt;/span&gt;&lt;a href="https://labs.cloudsecurityalliance.org/mythos-ciso/"&gt;&lt;span style="font-weight:400;"&gt;Cloud Security Alliance (CSA) Mythos paper&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt;. We ensure our posture remains anchored in foundational operational rigor (e.g. systems hardening, mature vulnerability remediation, and rapid incident response), while simultaneously incorporating agentic AI technologies to modernize and accelerate our defensive capabilities.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;To reinforce Appian&amp;rsquo;s approach, our security investments (based on our risk assessments) are focused on:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;AI-Enhanced Secure Architecture: &lt;/b&gt;&lt;span style="font-weight:400;"&gt;To ensure issues are mitigated before they reach the codebase, we are reinforcing our agentic SDLCs by integrating AI-driven tools for continuous threat modeling and architectural reviews.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Agent-Integrated Vulnerability Scanning: &lt;/b&gt;&lt;span style="font-weight:400;"&gt;We have transitioned security services into agent-accessible tools that operate directly within developer environments and are strictly enforced via central code pipelines to automate remediation.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Robust Supply Chain Protection: &lt;/b&gt;&lt;span style="font-weight:400;"&gt;Appian is actively strengthening our software supply chain by moving to private, vendor-managed artifact repositories and incorporating hardened components, such as Chainguard, to maintain rigorous integrity against AI-driven exploitation.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Appian&amp;rsquo;s Offensive Defense: Turning AI-Accelerated Risk into Modernization Opportunity&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The greatest defense against AI-accelerated offense is a fundamental shift in application strategy. The Mythos model highlights a critical moment where organizations must move beyond defensive patching toward architectural security by default.&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Legacy or &amp;ldquo;vibe&amp;rdquo; code is now unsafe at any speed.&lt;/b&gt;&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; The speed of vulnerability discovery (now compressed to hours) means manual custom code development and patching cycles can no longer keep pace. Appian&amp;#39;s low-code platform eliminates vast amounts of custom code, reducing the attack surface and enforcing secure patterns by design.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Due to the insecure nature of AI vibe coding, enterprises should replace it with spec-driven development on secure platforms like Appian.&lt;/b&gt;&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; Relying on large language models (LLMs) to generate &amp;quot;vibe code&amp;quot; introduces new supply chain and vulnerability risks from potentially unvetted code. Appian&amp;#39;s low-code, spec-driven approach generates standardized, secure code from certified platform components, ensuring integrity and auditability.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Enterprises need to migrate custom and legacy apps to secure-by-default platforms like Appian.&lt;/b&gt;&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; Legacy apps are highly susceptible to this new shift. Appian provides a secure cloud architecture leveraging AWS&amp;#39;s scale and security controls, offering continuous updates and a mature vulnerability management program.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Secure platforms that reduce your attack surface and centralize patching and monitoring are the best way to reduce workload on security teams.&lt;/b&gt;&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; Moving applications to Appian Cloud shifts the burden of infrastructure security, patching (aggressive SLAs), and continuous monitoring to Appian and AWS. This drastically reduces the operational overhead and allows internal security teams to focus on core business risks.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;AI Agents need the guardrails and governance of secure process orchestration that Appian provides.&lt;/b&gt;&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;Why &amp;amp; How with Appian:&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; As autonomous AI agents become pervasive, constraining their actions is critical. Appian&amp;#39;s process orchestration provides the necessary identity-aware framework, policy enforcement, and auditability to govern AI agents, ensuring they operate within defined, secure business processes.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Customer Changes: Required Actions&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The speed of AI-accelerated threats requires immediate action to solidify your foundational security posture. We recommend customers prioritize the following actions:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Accelerate Platform Updates:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Promptly prioritize and schedule upgrades to the latest Appian platform releases to benefit from our continuous security enhancements and keep pace with vulnerability remediation. Reach out to Appian Support with your organization&amp;#39;s desired posture; we recommend taking the latest release as soon as feasible for your organization. We can patch at the speed of your mission needs.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Enforce MFA for All Accounts:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; With the release of additional MFA features in 26.1, audit your organizational requirements, ensure alignment and reach out to Appian Support if you need assistance. We recommend strong Multi-Factor Authentication (MFA) for &lt;/span&gt;&lt;i&gt;&lt;span style="font-weight:400;"&gt;all&lt;/span&gt;&lt;/i&gt;&lt;span style="font-weight:400;"&gt; accounts (Appian or otherwise) to strengthen identity controls against AI-driven social engineering and credential misuse.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Modernize on Appian Cloud:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Eliminate critical attack surface by migrating all custom and legacy applications to the latest version of Appian Cloud, which offers secure-by-default architecture, centralized patching, and continuous monitoring.&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;b&gt;Adopt New Security Capabilities:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; Rapidly adopt key platform security features as they become available, such as Cloud Secure Link (when available) and Log Streaming (24.4/26.4) enhancements to meet your mission needs.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Callout on Further Action:&lt;/b&gt;&lt;span style="font-weight:400;"&gt; If additional, environment-specific action is required for your sites, our Solution Engineering team will reach out directly; ensure your security and admin contacts are up-to-date.&lt;/span&gt;&lt;/p&gt;
&lt;h1&gt;&lt;span style="font-weight:600;"&gt;Closing Statement&lt;/span&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian&amp;rsquo;s security posture is built keeping in mind the speed and scale of AI-accelerated threat discovery by frontier models. Our response strategy aligns with the industry, shifting to Zero-Trust and high-velocity operational rigor that prioritizes foundational security controls: vulnerability remediation, continuous monitoring, and continuous testing. This architectural approach is the essential alternative to risky &amp;ldquo;AI Vibe coding&amp;rdquo;; replacing ad-hoc code generation with spec-driven development using standardized, certified platform components to ensure security and auditability. Furthermore, Appian&amp;#39;s secure process orchestration provides the necessary guardrails and governance to ensure pervasive AI agents operate securely within defined business processes, using identity-aware access and policy enforcement. Ultimately, our platform enables customers to quickly modernize legacy applications&amp;mdash;which are highly susceptible to this new threat&amp;mdash;on a secure, continuously updated architecture. This accelerated threat landscape requires a joint effort.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;To immediately strengthen your defenses and keep pace with AI-accelerated threats, we urge you to review and implement the &lt;/span&gt;&lt;b&gt;Required Actions&lt;/b&gt;&lt;span style="font-weight:400;"&gt; detailed above: Accelerate Platform Updates, Enforce MFA for All Accounts, Modernize on Appian Cloud, and Adopt New Security Capabilities.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Last reviewed: May&lt;/span&gt;&lt;span&gt;&amp;nbsp;27, 2026&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/5</link><pubDate>Wed, 27 May 2026 15:36:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Ryan Good</dc:creator><description>Revision 5 posted to Appian Knowledge Base by Ryan Good on 5/27/2026 3:36:59 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="BypassReview" href="#BypassReview"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during all submissions of new and updated plugins to Appian. Subsequent reviews are also performed on a routine basis after initial approval.&lt;br /&gt; Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;br /&gt; Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission. Post-approval, additional security reviews are performed regularly.&lt;br /&gt; Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;br /&gt; Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;br /&gt; Plugins which are not updated may be removed from the AppMarket. Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;br /&gt; Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;br /&gt; Approval of a plugin does not guarantee approval of subsequent versions.&lt;br /&gt; Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;br /&gt; If a plug-in requires expedited review, please include that context and justification in the submission.&lt;br /&gt; If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>KB-2383 Interactive SAIL Examples in Appian Documentation Fail to Execute</title><link>https://community.appian.com/support/w/kb/3805/kb-2383-interactive-sail-examples-in-appian-documentation-fail-to-execute</link><pubDate>Tue, 26 May 2026 16:01:08 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ccf3435c-4466-4a35-a246-630f8545aec3</guid><dc:creator>pauline.delacruz</dc:creator><description>Current Revision posted to Appian Knowledge Base by pauline.delacruz on 5/26/2026 4:01:08 PM&lt;br /&gt;
&lt;h2&gt;&lt;span&gt;Symptoms&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Interactive SAIL expression examples embedded in Appian documentation pages fail to execute. The browser displays the following error message:&lt;/span&gt;&lt;/p&gt;
&lt;pre&gt;&lt;span style="font-weight:400;"&gt;The connection is blocked because it was initiated by a public page to connect to devices or servers on your local network.&lt;/span&gt;&lt;/pre&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This issue occurs in&amp;nbsp;networks where the AWS API Gateway endpoint used by the documentation resolves to a private IP address.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian documentation pages use an AWS API Gateway endpoint with the domain&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.us-east-1.amazonaws.com&lt;/span&gt;&lt;/code&gt;&lt;span style="font-weight:400;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to support execution of SAIL expressions. In enterprise networks AWS service endpoints&amp;nbsp;may resolve to a private IP address. Modern browsers block requests where the originating page is treated as public and the target endpoint resolves to a private or local IP address. This is intentional browser behavior designed to prevent DNS rebinding and local network attacks.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Action&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This is a known limitation that affects enterprise networks with private AWS networking configurations. Appian has added an enhancement to the documentation backlog to address this issue&amp;nbsp;(Reference ticket:&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;LCP-49998&lt;/b&gt;&lt;span style="font-weight:400;"&gt;). No estimated time of availability is currently provided for this enhancement.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Workaround&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Organizations may allow&amp;nbsp;&lt;span&gt;&lt;code&gt;*.execute-api.us-east-1.amazonaws.com&lt;/code&gt; domains to resolve using public DNS controls to ensure the page loads properly.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1hstuq7rk4"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last Reviewed: May 2026&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web browser, infrastructure, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-2640] Interactive SAIL Examples in Appian Documentation Fail to Execute</title><link>https://community.appian.com/support/w/kb/3805/kb-2383-interactive-sail-examples-in-appian-documentation-fail-to-execute/revision/7</link><pubDate>Wed, 20 May 2026 19:06:41 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ccf3435c-4466-4a35-a246-630f8545aec3</guid><dc:creator>pauline.delacruz</dc:creator><description>Revision 7 posted to Appian Knowledge Base by pauline.delacruz on 5/20/2026 7:06:41 PM&lt;br /&gt;
&lt;h2&gt;&lt;span&gt;Symptoms&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Interactive SAIL expression examples embedded in Appian documentation pages fail to execute. The browser displays the following error message:&lt;/span&gt;&lt;/p&gt;
&lt;pre&gt;&lt;span style="font-weight:400;"&gt;The connection is blocked because it was initiated by a public page to connect to devices or servers on your local network.&lt;/span&gt;&lt;/pre&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This issue occurs in&amp;nbsp;networks where the AWS API Gateway endpoint used by the documentation resolves to a private IP address.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian documentation pages use an AWS API Gateway endpoint with the domain&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.us-east-1.amazonaws.com&lt;/span&gt;&lt;/code&gt;&lt;span style="font-weight:400;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to support execution of SAIL expressions. In enterprise networks AWS service endpoints&amp;nbsp;may resolve to a private IP address. Modern browsers block requests where the originating page is treated as public and the target endpoint resolves to a private or local IP address. This is intentional browser behavior designed to prevent DNS rebinding and local network attacks.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Action&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This is a known limitation that affects enterprise networks with private AWS networking configurations. Appian has added an enhancement to the documentation backlog to address this issue&amp;nbsp;(Reference ticket:&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;LCP-49998&lt;/b&gt;&lt;span style="font-weight:400;"&gt;). No estimated time of availability is currently provided for this enhancement.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Workaround&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Organizations may allow&amp;nbsp;&lt;span&gt;&lt;code&gt;*.execute-api.us-east-1.amazonaws.com&lt;/code&gt; domains to resolve using public DNS controls to ensure the page loads properly.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1hstuq7rk4"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last Reviewed: May 2026&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;/b&gt;&lt;/h2&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web browser, infrastructure, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-2640] Interactive SAIL Examples in Appian Documentation Fail to Execute</title><link>https://community.appian.com/support/w/kb/3805/kb-2383-interactive-sail-examples-in-appian-documentation-fail-to-execute/revision/6</link><pubDate>Wed, 20 May 2026 18:58:57 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ccf3435c-4466-4a35-a246-630f8545aec3</guid><dc:creator>Zack Mateja</dc:creator><description>Revision 6 posted to Appian Knowledge Base by Zack Mateja on 5/20/2026 6:58:57 PM&lt;br /&gt;
&lt;h2&gt;&lt;span&gt;Symptoms&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Interactive SAIL expression examples embedded in Appian documentation pages fail to execute. The browser displays the following error message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The connection is blocked because it was initiated by a public page to connect to devices or servers on your local network.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This issue occurs in&amp;nbsp;networks where the AWS API Gateway endpoint used by the documentation resolves to a private IP address.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Cause&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian documentation pages use an AWS API Gateway endpoint with the domain&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.us-east-1.amazonaws.com&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to support execution of SAIL expressions. In enterprise networks AWS service endpoints&amp;nbsp;may resolve to a private IP address. Modern browsers block requests where the originating page is treated as public and the target endpoint resolves to a private or local IP address. This is intentional browser behavior designed to prevent DNS rebinding and local network attacks.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Action&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This is a known limitation that affects enterprise networks with private AWS networking configurations. Appian has added an enhancement to the documentation backlog to address this issue&amp;nbsp;(Reference ticket:&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;LCP-49998&lt;/b&gt;&lt;span style="font-weight:400;"&gt;). No estimated time of availability is currently provided for this enhancement.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Workaround&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Organizations may allow&amp;nbsp;&lt;span&gt;*.execute-api.us-east-1.amazonaws.com domains to resolve using public DNS controls to ensure the page loads properly.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b style="font-family:inherit;"&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last Reviewed: May 2026&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;/b&gt;&lt;/h2&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web browser, infrastructure, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-2640] Interactive SAIL Examples in Appian Documentation Fail to Execute</title><link>https://community.appian.com/support/w/kb/3805/kb-2383-interactive-sail-examples-in-appian-documentation-fail-to-execute/revision/5</link><pubDate>Wed, 20 May 2026 15:36:33 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ccf3435c-4466-4a35-a246-630f8545aec3</guid><dc:creator>Zack Mateja</dc:creator><description>Revision 5 posted to Appian Knowledge Base by Zack Mateja on 5/20/2026 3:36:33 PM&lt;br /&gt;
&lt;h1&gt;&lt;b&gt;&lt;/b&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;/h1&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Interactive SAIL expression examples embedded in Appian documentation pages fail to execute. The browser displays the following error message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The connection is blocked because it was initiated by a public page to connect to devices or servers on your local network.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This issue occurs in&amp;nbsp;networks where the AWS API Gateway endpoint used by the documentation resolves to a private IP address.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian documentation pages use an AWS API Gateway endpoint with the domain &lt;/span&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.us-east-1.amazonaws.com&lt;/span&gt;&lt;span style="font-weight:400;"&gt; to support execution of SAIL expressions. In enterprise networks AWS service endpoints&amp;nbsp;may resolve to a private IP address. Modern browsers block requests where the originating page is treated as public and the target endpoint resolves to a private or local IP address. This is intentional browser behavior designed to prevent DNS rebinding and local network attacks.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This is a known limitation that affects enterprise networks with private AWS networking configurations. Appian has added an enhancement to the documentation backlog to address this issue&amp;nbsp;(Reference ticket: &lt;/span&gt;&lt;b&gt;LCP-49998&lt;/b&gt;&lt;span style="font-weight:400;"&gt;). No estimated time of availability is currently provided for this enhancement.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Workaround&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Organizations may allow&amp;nbsp;&lt;span&gt;*.execute-api.us-east-1.amazonaws.com domains to resolve using public DNS controls to ensure the page loads properly.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last Reviewed: May 2026&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;/b&gt;&lt;/h2&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web browser, infrastructure, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-2640] Using Interactive SAIL Boxes in Appian Documentation</title><link>https://community.appian.com/support/w/kb/3805/kb-2383-interactive-sail-examples-in-appian-documentation-fail-to-execute/revision/4</link><pubDate>Wed, 20 May 2026 15:35:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ccf3435c-4466-4a35-a246-630f8545aec3</guid><dc:creator>Zack Mateja</dc:creator><description>Revision 4 posted to Appian Knowledge Base by Zack Mateja on 5/20/2026 3:35:59 PM&lt;br /&gt;
&lt;h1&gt;&lt;b&gt;Interactive SAIL Examples in Appian Documentation Fail to Execute&amp;nbsp;&lt;/b&gt;&lt;/h1&gt;
&lt;h2&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Interactive SAIL expression examples embedded in Appian documentation pages fail to execute. The browser displays the following error message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The connection is blocked because it was initiated by a public page to connect to devices or servers on your local network.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This issue occurs in&amp;nbsp;networks where the AWS API Gateway endpoint used by the documentation resolves to a private IP address.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian documentation pages use an AWS API Gateway endpoint with the domain &lt;/span&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.us-east-1.amazonaws.com&lt;/span&gt;&lt;span style="font-weight:400;"&gt; to support execution of SAIL expressions. In enterprise networks AWS service endpoints&amp;nbsp;may resolve to a private IP address. Modern browsers block requests where the originating page is treated as public and the target endpoint resolves to a private or local IP address. This is intentional browser behavior designed to prevent DNS rebinding and local network attacks.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This is a known limitation that affects enterprise networks with private AWS networking configurations. Appian has added an enhancement to the documentation backlog to address this issue&amp;nbsp;(Reference ticket: &lt;/span&gt;&lt;b&gt;LCP-49998&lt;/b&gt;&lt;span style="font-weight:400;"&gt;). No estimated time of availability is currently provided for this enhancement.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Workaround&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Organizations may allow&amp;nbsp;&lt;span&gt;*.execute-api.us-east-1.amazonaws.com domains to resolve using public DNS controls to ensure the page loads properly.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last Reviewed: May 2026&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;/b&gt;&lt;/h2&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web browser, infrastructure, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-2640] Using Interactive SAIL Boxes in Appian Documentation</title><link>https://community.appian.com/support/w/kb/3805/kb-2383-interactive-sail-examples-in-appian-documentation-fail-to-execute/revision/3</link><pubDate>Wed, 20 May 2026 15:35:42 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ccf3435c-4466-4a35-a246-630f8545aec3</guid><dc:creator>Zack Mateja</dc:creator><description>Revision 3 posted to Appian Knowledge Base by Zack Mateja on 5/20/2026 3:35:42 PM&lt;br /&gt;
&lt;h1&gt;&lt;b&gt;Interactive SAIL Examples in Appian Documentation Fail to Execute&amp;nbsp;&lt;/b&gt;&lt;/h1&gt;
&lt;h2&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Interactive SAIL expression examples embedded in Appian documentation pages fail to execute. The browser displays the following error message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The connection is blocked because it was initiated by a public page to connect to devices or servers on your local network.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This issue occurs in&amp;nbsp;networks where the AWS API Gateway endpoint used by the documentation resolves to a private IP address.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian documentation pages use an AWS API Gateway endpoint with the domain &lt;/span&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.us-east-1.amazonaws.com&lt;/span&gt;&lt;span style="font-weight:400;"&gt; to support execution of SAIL expressions. In enterprise networks AWS service endpoints&amp;nbsp;may resolve to a private IP address. Modern browsers block requests where the originating page is treated as public and the target endpoint resolves to a private or local IP address. This is intentional browser behavior designed to prevent DNS rebinding and local network attacks.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This is a known limitation that affects enterprise networks with private AWS networking configurations. Appian has added an enhancement to the documentation backlog to address this issue&amp;nbsp;(Reference ticket: &lt;/span&gt;&lt;b&gt;LCP-49998&lt;/b&gt;&lt;span style="font-weight:400;"&gt;). No estimated time of availability is currently provided for this enhancement.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Workaround&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Organizations may allow&amp;nbsp;&lt;span&gt;*.execute-api.us-east-1.amazonaws.com domains to resolve using public DNS controls to ensure the page loads properly.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Preventative Actions&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Be aware that interactive SAIL execution examples in Appian documentation rely on direct client-side calls to &lt;/span&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.amazonaws.com&lt;/span&gt;&lt;span style="font-weight:400;"&gt;. These examples may fail in environments where those domains resolve privately or are blocked by the browser due to enterprise DNS and security configurations.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last Reviewed: May 2026&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;/b&gt;&lt;/h2&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web browser, infrastructure, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-2640] Using Interactive SAIL Boxes in Appian Documentation</title><link>https://community.appian.com/support/w/kb/3805/kb-2383-interactive-sail-examples-in-appian-documentation-fail-to-execute/revision/2</link><pubDate>Wed, 20 May 2026 15:35:09 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ccf3435c-4466-4a35-a246-630f8545aec3</guid><dc:creator>Zack Mateja</dc:creator><description>Revision 2 posted to Appian Knowledge Base by Zack Mateja on 5/20/2026 3:35:09 PM&lt;br /&gt;
&lt;h1&gt;&lt;b&gt;Interactive SAIL Examples in Appian Documentation Fail to Execute&amp;nbsp;&lt;/b&gt;&lt;/h1&gt;
&lt;h2&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Interactive SAIL expression examples embedded in Appian documentation pages fail to execute. The browser displays the following error message:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The connection is blocked because it was initiated by a public page to connect to devices or servers on your local network.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This issue occurs in&amp;nbsp;networks where the AWS API Gateway endpoint used by the documentation resolves to a private IP address.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian documentation pages use an AWS API Gateway endpoint with the domain &lt;/span&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.us-east-1.amazonaws.com&lt;/span&gt;&lt;span style="font-weight:400;"&gt; to support execution of SAIL expressions. In enterprise networks AWS service endpoints&amp;nbsp;may resolve to a private IP address. Modern browsers block requests where the originating page is treated as public and the target endpoint resolves to a private or local IP address. This is intentional browser behavior designed to prevent DNS rebinding and local network attacks.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This is a known limitation that affects enterprise networkswith private AWS networking configurations. Appian has added an enhancement to the documentation backlog to address this issue&amp;nbsp;(Reference ticket: &lt;/span&gt;&lt;b&gt;LCP-49998&lt;/b&gt;&lt;span style="font-weight:400;"&gt;). No estimated time of availability is currently provided for this enhancement.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;Workaround&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Organizations may allow&amp;nbsp;&lt;span&gt;*.execute-api.us-east-1.amazonaws.com domains to resolve using public DNS controls to ensure the page loads properly.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;Preventative Actions&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Be aware that interactive SAIL execution examples in Appian documentation rely on direct client-side calls to &lt;/span&gt;&lt;span style="font-weight:400;"&gt;*.execute-api.amazonaws.com&lt;/span&gt;&lt;span style="font-weight:400;"&gt;. These examples may fail in environments where those domains resolve privately or are blocked by the browser due to enterprise DNS and security configurations.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last Reviewed: May 2026&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;b&gt;&lt;/b&gt;&lt;/h2&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: web browser, infrastructure, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/4</link><pubDate>Wed, 20 May 2026 14:15:38 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Daniel DeVeau</dc:creator><description>Revision 4 posted to Appian Knowledge Base by Daniel DeVeau on 5/20/2026 2:15:38 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;p&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="BypassReview" href="#BypassReview"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during all submissions of new and updated plugins to Appian. Subsequent reviews are also performed on a routine basis after initial approval.&lt;br /&gt; Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;br /&gt; Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission. Post-approval, additional security reviews are performed regularly.&lt;br /&gt; Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;br /&gt; Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;br /&gt; Plugins which are not updated may be removed from the AppMarket. Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;br /&gt; Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;br /&gt; Approval of a plugin does not guarantee approval of subsequent versions.&lt;br /&gt; Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;br /&gt; If a plug-in requires expedited review, please include that context and justification in the submission.&lt;br /&gt; If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/3</link><pubDate>Wed, 20 May 2026 14:12:16 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Daniel DeVeau</dc:creator><description>Revision 3 posted to Appian Knowledge Base by Daniel DeVeau on 5/20/2026 2:12:16 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;p&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during all submissions of new and updated plugins to Appian. Subsequent reviews are also performed on a routine basis after initial approval.&lt;br /&gt; Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;br /&gt; Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission. Post-approval, additional security reviews are performed regularly.&lt;br /&gt; Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;br /&gt; Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;br /&gt; Plugins which are not updated may be removed from the AppMarket. Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;br /&gt; Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;br /&gt; Approval of a plugin does not guarantee approval of subsequent versions.&lt;br /&gt; Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;br /&gt; If a plug-in requires expedited review, please include that context and justification in the submission.&lt;br /&gt; If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1654] Plugin Review &amp; Security Scanning FAQ</title><link>https://community.appian.com/support/w/kb/3709/kb-2385-plugin-review-security-scanning-faq/revision/2</link><pubDate>Wed, 20 May 2026 14:07:51 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7ea018d-4e92-4d29-9ed5-70cdc006dba9</guid><dc:creator>Daniel DeVeau</dc:creator><description>Revision 2 posted to Appian Knowledge Base by Daniel DeVeau on 5/20/2026 2:07:51 PM&lt;br /&gt;
&lt;p&gt;All plugins submitted to Appian for use on Appian Cloud require review and approval. This article aims to answer common questions about the plugin review process.&lt;/p&gt;
&lt;p&gt;For more information on plugin and AppMarket policies, refer to the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt; documentation and the &lt;a href="/p/appmarket-submission-agreement"&gt;AppMarket Submissions Agreement&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;p&gt;&lt;a title="HowAreReviewsPerformed" href="#HowAreReviewsPerformed"&gt;How are plugin security reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="WhatTooling" href="#WhatTooling"&gt;What specific tooling is used?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowOften" href="#HowOften"&gt;How often are reviews performed?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="ProvideScanResults" href="#ProvideScanResults"&gt;Can Appian provide the scan results?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PrivatePlugins" href="#PrivatePlugins"&gt;What happens to plugins that are flagged by security scans?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="FlaggedPlugins" href="#FlaggedPlugins"&gt;How long do I have to remediate a finding in my plugin?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="HowLongDoIHave" href="#HowLongDoIHave"&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a title="PreviouslyApproved" href="#PreviouslyApproved"&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowAreReviewsPerformed"&gt;&lt;/a&gt;How are plugin security reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Security scanning is first performed during the submission of new and updated plugins to Appian.&lt;/p&gt;
&lt;p&gt;Subsequent reviews are also performed on a routine basis after initial approval.&lt;/p&gt;
&lt;p&gt;Scans such as Static Application Security Testing (SAST), Software composition analysis (SCA), and other security related checks are in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="WhatTooling"&gt;&lt;/a&gt;What specific tooling is used?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian utilizes custom tooling, open source software, and commercial off the shelf software to perform the automated security scanning.&lt;/p&gt;
&lt;p&gt;Appian does not publish the specific software used to review plugins.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowOften"&gt;&lt;/a&gt;How often are reviews performed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Reviews are always performed upon plugin submission.&amp;nbsp;Post-approval, additional security reviews are performed regularly .&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Appian reserves the right to perform security reviews at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="ProvideScanResults"&gt;&lt;/a&gt;Can Appian provide the scan results?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian does not publish or share the results of security scans.&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PrivatePlugins"&gt;&lt;/a&gt;Do security reviews apply to private plugins?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Yes. As stated in the &lt;a href="https://docs.appian.com/suite/help/latest/Shared_Components.html"&gt;AppMarket Submission Policies&lt;/a&gt;, All plug-ins, whether intended for public use on the AppMarket or private use within an organization, must receive approval before deployment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="FlaggedPlugins"&gt;&lt;/a&gt;What happens to plugins that are flagged by security scans?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin authors are notified directly when one of their submissions is flagged by a security scan.&lt;/p&gt;
&lt;p&gt;Plugins which are not updated may be removed from the AppMarket.&lt;/p&gt;
&lt;p&gt;Appian reserves the right to reject or stop hosting plug-ins at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="HowLongDoIHave"&gt;&lt;/a&gt;How long do I have to remediate a finding in my plugin?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Appian will provide a timeline for remediation when notifying you of a finding.&lt;/p&gt;
&lt;p&gt;Appian reserves the right to modify plug-in remediation timelines at any time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="PreviouslyApproved"&gt;&lt;/a&gt;My plugin submission was previously approved. Why is my latest update not approved?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every submitted version of a plugin is reviewed in full.&lt;/p&gt;
&lt;p&gt;Approval of a plugin does not guarantee approval of subsequent versions.&lt;/p&gt;
&lt;p&gt;Appian reserves the right to modify plugin security policies at any time.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a id="BypassReview"&gt;&lt;/a&gt;I need to use my plugin on Appian Cloud ASAP. Can I bypass security review temporarily?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Plugin submissions cannot bypass security review; only fully approved submissions can be deployed on Appian Cloud.&lt;/p&gt;
&lt;p&gt;If a plug-in requires expedited review, please include that context and justification in the submission.&lt;/p&gt;
&lt;p&gt;If you subscribe to a Signature Appian Success Plan, let your Lead Engineer know of your urgent request.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1jp2rd10e5"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: May 2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: FAQ, plugins&lt;/div&gt;
</description></item><item><title>KB-2382 Information about the Axios Supply Chain Compromise</title><link>https://community.appian.com/support/w/kb/3810/kb-2382-information-about-the-axios-supply-chain-compromise</link><pubDate>Wed, 13 May 2026 20:18:13 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:d49276b2-ef34-4bae-a832-6fb52350b0d5</guid><dc:creator>Kaushal Patel</dc:creator><description>Current Revision posted to Appian Knowledge Base by Kaushal Patel on 5/13/2026 8:18:13 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 11 May 2026, a coordinated supply chain attack was launched against the npm and PyPI ecosystems, targeting high-value developer tools and enterprise platforms. The campaign compromised a wide range of popular packages, including the @tanstack namespace (such as &lt;/span&gt;&lt;span style="font-weight:400;"&gt;@tanstack/react-router&lt;/span&gt;&lt;span style="font-weight:400;"&gt;), the official mistralai clients for TypeScript and Python, and AI safety tools like guardrails-ai.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated this vulnerability and affected services, and determined that it is &lt;/span&gt;&lt;b&gt;not impacted&lt;/b&gt;&lt;span style="font-weight:400;"&gt;, as no vulnerable versions of the packages are used in the Appian Cloud environment or any of Appian&amp;rsquo;s products. We will continue to monitor the situation and provide any updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1jl7jgb3u1"&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised"&gt;&lt;span style="font-weight:400;"&gt;https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack"&gt;&lt;span style="font-weight:400;"&gt;https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"&gt;&lt;span style="font-weight:400;"&gt;https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="mcetoc_1jl7jgb3u2"&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span&gt;May 13, 2026&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>KB-2381 How to fix a corrupted database table index using phpMyAdmin</title><link>https://community.appian.com/support/w/kb/3795/kb-2381-how-to-fix-a-corrupted-database-table-index-using-phpmyadmin</link><pubDate>Thu, 07 May 2026 15:22:49 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:bbdad8ba-b20c-4c50-8c64-f110744d3ff8</guid><dc:creator>Kaushal Patel</dc:creator><description>Current Revision posted to Appian Knowledge Base by Kaushal Patel on 5/7/2026 3:22:49 PM&lt;br /&gt;
&lt;h2 id="mcetoc_1jmas36970"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;A corrupted index can make the associated table inaccessible. This can cause any queries, applications, or automated processes that rely on the table to fail until the index is repaired.&amp;nbsp;&lt;span&gt;This article outlines how to repair&amp;nbsp;the affected index.&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1jmas36971"&gt;Instructions&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span&gt;Open the &lt;a href="https://docs.appian.com/suite/help/latest/appian-cloud-database-administration.html#accessing-the-appian-cloud-database"&gt;phpMyAdmin interface&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Using the index definition from the table, drop and recreate the affected index using the following commands.&lt;br /&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;Check the table to confirm the affected index:&lt;code&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;span&gt;CHECK TABLE &amp;lt;table_name&amp;gt;;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/2273.check-table.png" /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Identify the affected index and column information:&amp;nbsp;&lt;code&gt;SHOW CREATE TABLE &amp;lt;table_name&amp;gt;;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/3542.show-create-table.png" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Drop the affected index:&amp;nbsp;&lt;code&gt;&lt;span style="font-weight:400;"&gt;ALTER TABLE &amp;lt;table_name&amp;gt; DROP INDEX &amp;lt;index_name&amp;gt;;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/1261.drop-index.png" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Recreate the&amp;nbsp;affected index:&amp;nbsp;&lt;code&gt;&lt;span style="font-weight:400;"&gt;ALTER TABLE &amp;lt;table_name&amp;gt; ADD INDEX &amp;lt;index_name&amp;gt;(cols);&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/7801.add-index.png" /&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span&gt;Confirm the issue was resolved:&amp;nbsp;&lt;code&gt;CHECK TABLE &amp;lt;table_name&amp;gt;;&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/0257.check-table-at-the-end.png" /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="mcetoc_1jmas36972"&gt;&lt;span style="font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This article applies to all versions of Appian Cloud.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Last Reviewed: April&amp;nbsp;2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: phpmyadmin, database, how-to, index&lt;/div&gt;
</description></item><item><title>KB-2381 How to fix a corrupted database table index using phpMyAdmin</title><link>https://community.appian.com/support/w/kb/3795/kb-2381-how-to-fix-a-corrupted-database-table-index-using-phpmyadmin/revision/16</link><pubDate>Thu, 07 May 2026 15:22:49 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:bbdad8ba-b20c-4c50-8c64-f110744d3ff8</guid><dc:creator>Kaushal Patel</dc:creator><description>Revision 16 posted to Appian Knowledge Base by Kaushal Patel on 5/7/2026 3:22:49 PM&lt;br /&gt;
&lt;h2 id="mcetoc_1jmas36970"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;A corrupted index can make the associated table inaccessible. This can cause any queries, applications, or automated processes that rely on the table to fail until the index is repaired.&amp;nbsp;&lt;span&gt;This article outlines how to repair&amp;nbsp;the affected index.&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1jmas36971"&gt;Instructions&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span&gt;Open the &lt;a href="https://docs.appian.com/suite/help/latest/appian-cloud-database-administration.html#accessing-the-appian-cloud-database"&gt;phpMyAdmin interface&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Using the index definition from the table, drop and recreate the affected index using the following commands.&lt;br /&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;Check the table to confirm the affected index:&lt;code&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;span&gt;CHECK TABLE &amp;lt;table_name&amp;gt;;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/2273.check-table.png" /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Identify the affected index and column information:&amp;nbsp;&lt;code&gt;SHOW CREATE TABLE &amp;lt;table_name&amp;gt;;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/3542.show-create-table.png" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Drop the affected index:&amp;nbsp;&lt;code&gt;&lt;span style="font-weight:400;"&gt;ALTER TABLE &amp;lt;table_name&amp;gt; DROP INDEX &amp;lt;index_name&amp;gt;;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/1261.drop-index.png" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Recreate the&amp;nbsp;affected index:&amp;nbsp;&lt;code&gt;&lt;span style="font-weight:400;"&gt;ALTER TABLE &amp;lt;table_name&amp;gt; ADD INDEX &amp;lt;index_name&amp;gt;(cols);&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/7801.add-index.png" /&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span&gt;Confirm the issue was resolved:&amp;nbsp;&lt;code&gt;CHECK TABLE &amp;lt;table_name&amp;gt;;&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/0257.check-table-at-the-end.png" /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="mcetoc_1jmas36972"&gt;&lt;span style="font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This article applies to all versions of Appian Cloud.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Last Reviewed: April&amp;nbsp;2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: phpmyadmin, database, how-to, index&lt;/div&gt;
</description></item><item><title>[DRAFT][NEW] KB-XXXX How to fix a corrupted database table index using phpMyAdmin</title><link>https://community.appian.com/support/w/kb/3795/kb-2381-how-to-fix-a-corrupted-database-table-index-using-phpmyadmin/revision/15</link><pubDate>Thu, 07 May 2026 14:16:14 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:bbdad8ba-b20c-4c50-8c64-f110744d3ff8</guid><dc:creator>Kaushal Patel</dc:creator><description>Revision 15 posted to Appian Knowledge Base by Kaushal Patel on 5/7/2026 2:16:14 PM&lt;br /&gt;
&lt;h2 id="mcetoc_1jmas36970"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;A corrupted index can make the associated table inaccessible. This can cause any queries, applications, or automated processes that rely on the table to fail until the index is repaired.&amp;nbsp;&lt;span&gt;This article outlines how to repair&amp;nbsp;the affected index.&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1jmas36971"&gt;Instructions&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span&gt;Open the &lt;a href="https://docs.appian.com/suite/help/latest/appian-cloud-database-administration.html#accessing-the-appian-cloud-database"&gt;phpMyAdmin interface&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Using the index definition from the table, drop and recreate the affected index using the following commands.&lt;br /&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;Check the table to confirm the affected index:&lt;code&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;span&gt;CHECK TABLE &amp;lt;table_name&amp;gt;;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/2273.check-table.png" /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Identify the affected index and column information:&amp;nbsp;&lt;code&gt;SHOW CREATE TABLE &amp;lt;table_name&amp;gt;;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/3542.show-create-table.png" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Drop the affected index:&amp;nbsp;&lt;code&gt;&lt;span style="font-weight:400;"&gt;ALTER TABLE &amp;lt;table_name&amp;gt; DROP INDEX &amp;lt;index_name&amp;gt;;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/1261.drop-index.png" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Recreate the&amp;nbsp;affected index:&amp;nbsp;&lt;code&gt;&lt;span style="font-weight:400;"&gt;ALTER TABLE &amp;lt;table_name&amp;gt; ADD INDEX &amp;lt;index_name&amp;gt;(cols);&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/7801.add-index.png" /&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span&gt;Confirm the issue was resolved:&amp;nbsp;&lt;code&gt;CHECK TABLE &amp;lt;table_name&amp;gt;;&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/0257.check-table-at-the-end.png" /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="mcetoc_1jmas36972"&gt;&lt;span style="font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This article applies to all versions of Appian Cloud.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Last Reviewed: April&amp;nbsp;2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>[DRAFT][NEW] KB-XXXX How to fix a corrupted database table index using phpMyAdmin</title><link>https://community.appian.com/support/w/kb/3795/kb-2381-how-to-fix-a-corrupted-database-table-index-using-phpmyadmin/revision/14</link><pubDate>Thu, 07 May 2026 14:15:36 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:bbdad8ba-b20c-4c50-8c64-f110744d3ff8</guid><dc:creator>Kaushal Patel</dc:creator><description>Revision 14 posted to Appian Knowledge Base by Kaushal Patel on 5/7/2026 2:15:36 PM&lt;br /&gt;
&lt;h2 id="mcetoc_1jmas36970"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;A corrupted index can make the associated table inaccessible. This can cause any queries, applications, or automated processes that rely on the table to fail until the index is repaired.&amp;nbsp;&lt;span&gt;This article outlines how to repair&amp;nbsp;the affected index.&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1jmas36971"&gt;Instructions&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span&gt;Open the phpMyAdmin interface.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Using the index definition from the table, drop and recreate the affected index using the following commands.&lt;br /&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;Check the table to confirm the affected index:&lt;code&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;span&gt;CHECK TABLE &amp;lt;table_name&amp;gt;;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/2273.check-table.png" /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Identify the affected index and column information:&amp;nbsp;&lt;code&gt;SHOW CREATE TABLE &amp;lt;table_name&amp;gt;;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/3542.show-create-table.png" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Drop the affected index:&amp;nbsp;&lt;code&gt;&lt;span style="font-weight:400;"&gt;ALTER TABLE &amp;lt;table_name&amp;gt; DROP INDEX &amp;lt;index_name&amp;gt;;&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/1261.drop-index.png" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;Recreate the&amp;nbsp;affected index:&amp;nbsp;&lt;code&gt;&lt;span style="font-weight:400;"&gt;ALTER TABLE &amp;lt;table_name&amp;gt; ADD INDEX &amp;lt;index_name&amp;gt;(cols);&lt;br /&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/7801.add-index.png" /&gt;&lt;/span&gt;&lt;/code&gt;&lt;br /&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/code&gt;&lt;span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;code&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span&gt;Confirm the issue was resolved:&amp;nbsp;&lt;code&gt;CHECK TABLE &amp;lt;table_name&amp;gt;;&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;img alt=" " border="0" src="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/0257.check-table-at-the-end.png" /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="mcetoc_1jmas36972"&gt;&lt;span style="font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This article applies to all versions of Appian Cloud.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Last Reviewed: April&amp;nbsp;2026&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>KB-1831 Cloning Appian Cloud Sites FAQ</title><link>https://community.appian.com/support/w/kb/1280/kb-1831-cloning-appian-cloud-sites-faq</link><pubDate>Thu, 30 Apr 2026 13:55:25 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:c0d18e22-7d8e-4b4f-a566-647074efb4c0</guid><dc:creator>Kaushal Patel</dc:creator><description>Current Revision posted to Appian Knowledge Base by Kaushal Patel on 4/30/2026 1:55:25 PM&lt;br /&gt;
&lt;div&gt;
&lt;h2 id="mcetoc_1jmouqmqe0"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;The purpose of this article is to answer common questions involved with cloning an Appian Cloud site for troubleshooting purposes.&lt;/p&gt;
&lt;h2&gt;Table of Contents:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#a"&gt;What is a clone?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#b"&gt;Why does Appian Support request to create a clone?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#c"&gt;What data will be cloned?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#d"&gt;Who has access to the code/data hosted in the clone?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#e"&gt;Do clones have any impact on the host Appian Cloud site or other existing environments?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#f"&gt;How long is the clone and its data persisted?&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;&lt;strong&gt;&lt;a id="a"&gt;&lt;/a&gt;What is a clone?&lt;br /&gt;&lt;/strong&gt;A clone is a replica of an existing Appian Cloud site. A new AWS instance is started, and a snapshot from an existing (host) Appian Cloud site is used to populate data on the new instance(s) creating a new separate site. All Appian Cloud clones are hosted in the same secure infrastructure as other Appian Cloud sites and are subject to the same security compliance protocols and controls.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;&lt;strong&gt;&lt;a id="b"&gt;&lt;/a&gt;Why does Appian Support request to create a clone?&lt;br /&gt;&lt;/strong&gt;Appian Support requests to clone a site for troubleshooting purposes. When investigating certain issues, it is sometimes necessary to&amp;nbsp;test and debug directly to better understand the nature and scope of the behavior. In order to eliminate the risk of impact to an actual Appian Cloud site, it is necessary to run these tests on a clone of the environment.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
&lt;div&gt;&lt;strong&gt;&lt;a id="c"&gt;&lt;/a&gt;What data will be cloned?&lt;br /&gt;&lt;/strong&gt;As a clone is created from a snapshot of a host site, all data as it exists at the time of the snapshot on the host site will be copied and present on the clone. For example, all Appian objects will be included, but not data hosted externally in customer databases.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;a id="d"&gt;&lt;/a&gt;Who has access to the code/data hosted in the clone?&lt;br /&gt;&lt;/strong&gt;Access to the code/data hosted in the clone is restricted to the following groups and is never shared with any third parties to ensure data integrity:&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Those who have access to the original Appian Cloud site.&lt;/li&gt;
&lt;li&gt;Team members from Appian Support and/or Appian&amp;#39;s Product team that are involved in diagnosing and troubleshooting the issue(s) reported by the customer.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;&lt;strong&gt;&lt;a id="e"&gt;&lt;/a&gt;Do clones have any impact on the host Appian Cloud site or other existing environments?&lt;br /&gt;&lt;/strong&gt;No, clone sites exist separately outside of the host site and other existing Appian Cloud environments. Furthermore, outbound activity (emails, traffic, etc.) will be disabled as to not interfere with external systems.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;a id="f"&gt;&lt;/a&gt;&lt;/strong&gt;&lt;strong&gt;How long is the clone and its data persisted?&lt;br /&gt;&lt;/strong&gt;The clone is persisted as long as the investigation into the current issue persists. Once the investigation is complete or no longer requires access to the clone, Appian will shut down the clone and delete its corresponding data. The clone can also be shut down at any time at the customer&amp;#39;s discretion.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;
&lt;h2 id="mcetoc_1jmouqmqe1"&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian Cloud.&lt;/p&gt;
&lt;p&gt;Last Reviewed: April 2026&lt;/p&gt;
&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: administration, Security, infrastructure, Cloud&lt;/div&gt;
</description></item></channel></rss>