QAST
A ranked HNDL register
Exposure windows, harvestability, reachability, and Mosca assumptions stay visible beside the result.

RelixQ Enterprise
RelixQ connects application evidence, HNDL exposure, safe validation, the RelixQ Score, governance, reports, integrations, retests, and release controls for one Enterprise portfolio.
QAST
Exposure windows, harvestability, reachability, and Mosca assumptions stay visible beside the result.

Who it is for
Each team gets the operating artifact it needs without creating a separate spreadsheet or losing the technical source behind the claim.
Portfolio posture, HNDL trends, score drivers, owners, and board-ready evidence.
View solutionExact findings, context, recommendations, signed-RoE validation, and retest state.
View solutionAPIs, pipelines, integrations, ownership routing, and release controls.
View solutionPolicies, exceptions, audit history, reports, and procurement material.
View solutionPilot scope and deliverables
Start with a bounded application portfolio, data class, TLS surface, and operating integration. Finish with artifacts teams can continue using.
RelixQ Score, HNDL assets, attack paths, owners, assumptions, and priority remediation tracks.
Code, dependency, TLS, certificate, and protocol evidence with severity, confidence, status, and migration target.
Approved read-only validation behind a signed Rules of Engagement record, with explicit exclusions and proof boundaries.
Baseline-aware gates, retests, exceptions, tickets, and integration paths that keep exposure from returning.
SaaS delivery and data handling
RelixQ is delivered as SaaS. Connected sources, managed scans, submitted evidence, and customer-enabled integrations are governed by explicit processing, retention, and access boundaries.
Organization-scoped application workflows, connected sources, reports, integrations, and administration are delivered through the RelixQ service.
Repository access, scan scope, evidence fields, retention, and deletion boundaries are agreed during evaluation and documented in the service terms.
Source, identity, SIEM, ticketing, alerting, and AI-provider behavior depends on the customer-enabled connection.
Security and governance proof
RelixQ is designed to make the authorization, assumptions, evidence, and outcome behind each action visible.
Signed project-specific Rules of Engagement, allowed scope, exclusions, rate ceilings, blackout windows, and emergency stop.
Observed protocol posture and proven classical breaks stay separate from modeled quantum risk. No decryption claim.
The Trust Center labels controls as product capability, verification required, planned, or not claimed.
Coverage, integrations, and alerts
RelixQ connects the source and delivery systems that produce evidence, covers the languages and infrastructure in the portfolio, and routes ownership and state changes into the operating stack.
GitHub, GitLab, Bitbucket, Azure Repos, CI pipelines, CLI, REST API, SBOM import, and runtime telemetry.
Microsoft Entra ID, Okta, Ping Identity, and standards-based OIDC, SAML 2.0, and SCIM 2.0 connections.
Splunk, Microsoft Sentinel, Elastic Security, CrowdStrike, OCSF, and generic webhooks.
Datadog, OpenTelemetry, Dynatrace, New Relic, Grafana, and metric/change-event delivery.
ServiceNow, Jira, Azure Boards, Linear, PagerDuty, Opsgenie, Slack, Teams, email, and other chat destinations.
Evaluation process
Start passive and bounded. Add active validation only after authority and scope are recorded. Finish by wiring the evidence into ongoing controls.
Request Enterprise access and tell us which QAST, RelixQ Score, PR gate, or reporting workflow you want to evaluate.
Pick one app portfolio, data class, TLS surface, and integration path for a controlled assessment.
Start passive HNDL mapping, then add signed-RoE active validation only for approved targets.
Turn results into score tracking, tickets, SIEM events, retests, and engineering release gates.
Enterprise FAQ
QAST means Quantum Application Security Testing. In RelixQ, it is the workflow that turns cryptography inventory into HNDL exposure windows, attack paths, safe validation, score impact, reports, and release gates.
No. RelixQ does not claim to decrypt quantum-vulnerable ciphertext. QAST proves exposure, reachability, classical breaks, and modeled quantum risk boundaries.
Inventory finds cryptography. RelixQ adds data lifetime, harvestability, attack paths, safe validation, RelixQ Score impact, retests, alerts, tickets, and developer gates.
Request a demo
Tell us whether the evaluation should lead with QAST, the RelixQ Score, inventory, PQC Lab, governance, developer gates, or integrations.
Before you submit