I can hide any private API usage already for normal store submission. If I am the tiniest bit careful, I will get away with most private stuff that is still not protected by the kernel using entitlements. For example,
https://github.com/LeoNatan/LNExtensionExecutor
This is a framework I obfuscate API usage, and is present in several App Store apps that I know of.
Apple security comes from kernel hardening, not static API analysis.