It's not my expectation.
It's their advertisement.
"The App Store gives people around the world a safe and trusted place to discover apps that meet our high standards for privacy, security, and content."
Their review process has been known for a while to be a bit of a joke.
This is not a flaw that can be detected by Apple's "code review" process. Apps are fully allowed to store content in cloud storage. The flaw here was that the developer failed to have sufficient validation that those requests are valid. Simply relying on a phone number to access Amazon-stored files is a serious breach of software design ethics. This has nothing to do with Apple's review process or principles. The developer is at fault, plain and simple.