Securing an app involves these steps:
Uploading an app
Creating profiles for the policies you want to apply (Defining security policies (API))
Choosing a code signing type and signing profile (Code signing (API))
Securing the app with those policies and profiles, optionally code signing in the policy console (Wrapping an app (API))
Downloading or exporting the app, optionally code signing outside the console