> For the complete documentation index, see [llms.txt](https://docs.emseapea.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.emseapea.ai/builder-guide/deploying.md).

# Deploying through the gate

When you're ready to ship, trigger a deploy from the app page (or your CI). Every deploy passes through the same gate:

1. **Scans** — secret scanning and Semgrep run against your repo. A failure blocks the deploy and stores the findings on your app's Scans tab; fix and redeploy. These are the same scanners that gate emseapea's own code. Honestly: these checks look for known patterns, and a pass is not a guarantee nothing was missed — see your app's Scans tab for exactly what ran.
2. **Sensitive sign-off** — if your app declared commercially sensitive, personal, financial, or health information, an approver confirms before anything ships. You'll see the deployment in `awaiting approval` until they do. This is separate from — and doesn't change — which systems and accounts your app can reach; see [The two kinds of access](/builder-guide/kinds-of-access.md) for what actually decides that.
3. **Deploy** — your app ships to the org's deploy target, and the deployment (with its URL) joins your app's permanent record.

Nothing about the gate is optional, and that's the point: passing it is the proof your app shipped safely.
