Skip to main content
RelixQ
Menu

Final-state integrations and alerts

Connect cryptographic evidence to the systems that run the enterprise.

This product-direction catalog shows the intended RelixQ SaaS operating model, including roadmap connections. Bring source, identity, build, artifact, endpoint, cloud, and runtime evidence into RelixQ, then route prioritized posture back to the teams and systems that act on it.

Evidence route

Connected operations

Final-state SaaS
  1. 01

    Connect

    Repositories · identity · CI · APIs · cloud · runtime

  2. 02

    Normalize

    Evidence · provenance · confidence · ownership

  3. 03

    Route

    Policy · priority · deduplication · escalation

  4. 04

    Operate

    SIEM · tickets · on-call · chat · webhooks

Product-direction view

This page intentionally includes the final-state roadmap. The Developer Guide documents the currently configurable surfaces and calls out where setup remains API-first, preview, or planned.

Final-state roadmap

One operating layer

The evidence moves. The context stays attached.

RelixQ keeps provenance, confidence, scope, ownership, policy, and remediation state connected as data moves between tools. Teams see the same decision record without rebuilding context in every destination.

Catalog connections
41
Operating categories
8
Policy signal families
8
Lifecycle synchronization
2-way

Connection catalog

From the first signal to the last mile.

Each connection declares its direction, delivery path, and evidence contract so security, engineering, and platform teams can design the complete operating workflow.

InboundOutboundBidirectionalTarget delivery: RelixQ SaaS

Connect the estate

Source and repository systems

Authorize organization-scoped discovery, select repositories, and keep cryptographic evidence current as code changes.

Operating outcome

Repository context, ownership, branches, pull requests, and change events enter one evidence graph.

GitHub

Bidirectional

Connect organizations and repositories, trigger analysis on pushes and pull requests, and return gate results to delivery workflows.

Evidence exchanged

  • Repository metadata
  • Push and pull-request events
  • Checks and gate results
RelixQ SaaS targetRepository appWebhookCI/CD

GitLab

Bidirectional

Discover projects and groups, analyze merge-request changes, and publish policy and remediation context into GitLab workflows.

Evidence exchanged

  • Project metadata
  • Push and merge-request events
  • Pipeline and policy results
RelixQ SaaS targetRepository appWebhookCI/CD

Bitbucket

Bidirectional

Connect workspaces and repositories, receive change events, and carry cryptographic policy into pull-request and pipeline decisions.

Evidence exchanged

  • Workspace metadata
  • Push and pull-request events
  • Build and gate results
RelixQ SaaS targetRepository appWebhookCI/CD

Azure Repos

Bidirectional

Map projects and repositories, analyze branch and pull-request activity, and feed posture decisions into Azure delivery workflows.

Evidence exchanged

  • Project and repository metadata
  • Push and pull-request events
  • Policy evaluations
RelixQ SaaS targetNative connectorWebhookCI/CD

Govern access

Identity and lifecycle provisioning

Federate workforce access and automate user and group lifecycle through enterprise identity standards.

Operating outcome

Authentication, role assignment, provisioning, and deprovisioning remain organization-scoped and auditable.

Microsoft Entra ID

Inbound

Federate workforce sign-in and synchronize users and groups from Microsoft Entra ID into governed RelixQ organizations.

Evidence exchanged

  • OIDC and SAML 2.0 sign-in
  • SCIM 2.0 users and groups
  • Role and lifecycle attributes
RelixQ SaaS targetNative connectorStandards-basedREST API

Okta

Inbound

Connect Okta federation and lifecycle management to organization access, group mapping, and deprovisioning policy.

Evidence exchanged

  • OIDC and SAML 2.0 sign-in
  • SCIM 2.0 users and groups
  • Access and lifecycle attributes
RelixQ SaaS targetNative connectorStandards-basedREST API

Ping Identity

Inbound

Use Ping federation and provisioning for enterprise sign-in, organization membership, and governed account lifecycle.

Evidence exchanged

  • OIDC and SAML 2.0 sign-in
  • SCIM 2.0 provisioning
  • Group and role attributes
RelixQ SaaS targetNative connectorStandards-basedREST API

Standards-based identity provider

Inbound

Connect another enterprise identity provider through documented OIDC, SAML 2.0, and SCIM 2.0 contracts.

Evidence exchanged

  • Federated identity assertions
  • Users and groups
  • Provisioning and deprovisioning events
RelixQ SaaS targetStandards-basedREST API

Bring the evidence

CI, API, artifact, endpoint, and cloud ingress

Use the connection pattern that matches each evidence source—from a developer pipeline to an enterprise inventory feed.

Operating outcome

Every input retains provenance, collection time, scope, confidence, and the organization or project it belongs to.

CI and release pipelines

Bidirectional

Run baseline-aware scans and policy gates from GitHub Actions, GitLab CI/CD, Azure Pipelines, Bitbucket Pipelines, or Jenkins.

Evidence exchanged

  • Source and build evidence
  • Policy decisions
  • SARIF and gate results
RelixQ SaaS targetCI/CDCLIREST API

RelixQ API and CLI

Bidirectional

Automate projects, scans, evidence upload, queries, exports, and release decisions with organization-scoped credentials.

Evidence exchanged

  • Projects and assets
  • Scan and finding data
  • Reports and policy results
RelixQ SaaS targetREST APICLI

SBOM artifacts

Inbound

Ingest software inventories and preserve direct and transitive package evidence for cryptographic analysis and correlation.

Evidence exchanged

  • CycloneDX SBOM
  • SPDX SBOM
  • Package identities and relationships
RelixQ SaaS targetFile uploadREST APIStandards-based

CBOM artifacts

Bidirectional

Ingest, enrich, and export cryptographic inventories with normalized components, relationships, provenance, and migration context.

Evidence exchanged

  • CycloneDX 1.6 CBOM
  • Cryptographic components and relationships
  • Evidence and migration context
RelixQ SaaS targetFile uploadREST APIStandards-based

SARIF findings

Bidirectional

Accept and emit standard static-analysis results so cryptographic findings remain portable across engineering systems.

Evidence exchanged

  • SARIF 2.1.0
  • Locations and fingerprints
  • Rules and remediation context
RelixQ SaaS targetFile uploadREST APIStandards-based

TLS and certificate endpoints

Inbound

Observe authorized endpoints and certificate inventories to track negotiation posture, expiry, weak cryptography, and PQC readiness.

Evidence exchanged

  • Handshake observations
  • Certificates and chains
  • Protocol and cipher posture
RelixQ SaaS targetNative connectorREST API

Cloud inventory connectors

Inbound

Correlate cloud key, certificate, listener, gateway, service, identity, and configuration signals with code and asset evidence.

Evidence exchanged

  • Cloud asset and service identity
  • Key and certificate inventory
  • Configuration and traffic bindings
RelixQ SaaS targetNative connectorREST API

Operationalize findings

SIEM and security operations

Deliver normalized findings and posture changes into the systems security teams already use to investigate and respond.

Operating outcome

Security operations receives stable event identities, evidence links, severity, confidence, ownership, and lifecycle state.

Splunk

Outbound

Stream findings, score changes, policy events, and connector health into Splunk searches, dashboards, and detections.

Evidence exchanged

  • HEC events
  • Finding lifecycle
  • Posture and health signals
RelixQ SaaS targetNative connectorREST API

Microsoft Sentinel

Outbound

Publish normalized RelixQ evidence into Sentinel for analytics, hunting, workbooks, and incident automation.

Evidence exchanged

  • Data Collection Rules
  • Security findings
  • Posture-change events
RelixQ SaaS targetNative connectorREST API

Elastic Security

Outbound

Index cryptographic exposure and governance events for Elastic search, detection, visualization, and case workflows.

Evidence exchanged

  • Finding documents
  • Asset and project context
  • Status changes
RelixQ SaaS targetNative connectorREST API

CrowdStrike

Outbound

Share exposure signals and asset context with Falcon workflows to support unified investigation and prioritization.

Evidence exchanged

  • Exposure events
  • Asset context
  • Evidence links
RelixQ SaaS targetNative connectorREST API

OCSF event stream

Outbound

Export vendor-neutral security events for downstream lakes, analytics platforms, and enterprise detection pipelines.

Evidence exchanged

  • OCSF-normalized events
  • Findings and observations
  • Governance changes
RelixQ SaaS targetREST APIWebhookStandards-based

Measure posture

Observability and engineering analytics

Put readiness, exposure, scan health, and change signals beside the reliability data platform teams monitor every day.

Operating outcome

Teams can graph posture trends, correlate releases with exposure, and alert on service-level crypto risk.

OpenTelemetry

Bidirectional

Ingest runtime observations and export vendor-neutral posture metrics, logs, traces, and change events through standard OTLP pipelines.

Evidence exchanged

  • Runtime observations and trace context
  • Posture metrics
  • Scan health and change events
RelixQ SaaS targetOTLPStandards-based

Datadog

Outbound

Send readiness metrics and events into dashboards, monitors, service views, and incident workflows.

Evidence exchanged

  • Metrics and events
  • Service and project tags
  • Health signals
RelixQ SaaS targetNative connectorREST API

Dynatrace

Outbound

Correlate crypto posture with monitored services, releases, ownership, and runtime dependencies.

Evidence exchanged

  • Metrics and events
  • Entity context
  • Release annotations
RelixQ SaaS targetNative connectorREST APIOTLP

New Relic

Outbound

Deliver crypto exposure and readiness signals for dashboards, NRQL analysis, alerts, and service context.

Evidence exchanged

  • Metrics and events
  • Project and service attributes
  • Posture deltas
RelixQ SaaS targetNative connectorREST APIOTLP

Grafana and Prometheus

Outbound

Power organization, portfolio, and service-level readiness dashboards using time-series posture metrics.

Evidence exchanged

  • Prometheus metrics
  • Labels and ownership
  • Health and trend data
RelixQ SaaS targetRemote writeREST API

Put work in motion

Ticketing and engineering work

Create owned remediation work with evidence, recommended action, due dates, and synchronized lifecycle state.

Operating outcome

A finding remains connected to its work item from assignment through verified remediation.

Jira and Jira Service Management

Bidirectional

Create issues or service requests from routed findings and synchronize assignee, status, comments, and resolution.

Evidence exchanged

  • Issues and requests
  • Evidence and remediation
  • Assignment and status
RelixQ SaaS targetNative connectorREST APIWebhook

ServiceNow

Bidirectional

Open governed remediation records and keep risk, change, ownership, and closure evidence synchronized.

Evidence exchanged

  • Incidents and tasks
  • Risk and evidence context
  • Ownership and resolution
RelixQ SaaS targetNative connectorREST APIWebhook

GitHub Issues

Bidirectional

Turn actionable findings into repository-native work with precise code locations and verification state.

Evidence exchanged

  • Issues
  • Code and evidence links
  • Labels and status
RelixQ SaaS targetNative connectorREST APIWebhook

Azure Boards

Bidirectional

Create and synchronize work items within Azure projects while preserving evidence and policy context.

Evidence exchanged

  • Work items
  • Evidence and recommendations
  • Assignment and state
RelixQ SaaS targetNative connectorREST APIWebhook

Linear

Bidirectional

Route prioritized remediation into engineering team workflows and follow progress through verified closure.

Evidence exchanged

  • Issues
  • Priority and ownership
  • Lifecycle state
RelixQ SaaS targetNative connectorREST APIWebhook

Escalate what matters

Incident and on-call response

Page the right team when exposure crosses policy, evidence regresses, or a critical service changes posture.

Operating outcome

Routing policy controls urgency, deduplication, escalation, acknowledgement, and resolution synchronization.

PagerDuty

Bidirectional

Trigger deduplicated incidents with urgency, service, runbook, evidence, and ownership context.

Evidence exchanged

  • Incidents and alerts
  • Acknowledgement
  • Resolution state
RelixQ SaaS targetNative connectorREST APIWebhook

Opsgenie

Bidirectional

Route critical exposure and platform-health events through team schedules and escalation policies.

Evidence exchanged

  • Alerts
  • Acknowledgement and notes
  • Close and reopen state
RelixQ SaaS targetNative connectorREST APIWebhook

Splunk On-Call

Bidirectional

Deliver policy-based alerts to on-call teams with stable incident keys and direct evidence links.

Evidence exchanged

  • Incidents
  • Acknowledgement
  • Resolution state
RelixQ SaaS targetNative connectorREST APIWebhook

Grafana OnCall

Bidirectional

Connect crypto posture alerts to Grafana escalation chains, schedules, and incident response workflows.

Evidence exchanged

  • Alert groups
  • Escalation context
  • Acknowledgement and resolution
RelixQ SaaS targetNative connectorWebhook

ServiceNow Event Management

Bidirectional

Feed prioritized events into enterprise correlation and response while synchronizing operational state.

Evidence exchanged

  • Events and alerts
  • Correlation keys
  • Incident state
RelixQ SaaS targetNative connectorREST APIWebhook

Keep teams informed

Chat, email, and webhooks

Send concise, actionable notifications to team channels or compose custom automation around signed events.

Operating outcome

Every message links back to the governed finding, affected asset, owner, policy, and recommended action.

Slack

Bidirectional

Route rich alerts and posture summaries to channels with actions for assignment, acknowledgement, and investigation.

Evidence exchanged

  • Channel messages
  • Interactive actions
  • Threaded lifecycle updates
RelixQ SaaS targetNative connectorWebhook

Microsoft Teams

Bidirectional

Deliver actionable cards and portfolio summaries to the teams responsible for services and remediation.

Evidence exchanged

  • Channel cards
  • Interactive actions
  • Lifecycle updates
RelixQ SaaS targetNative connectorWebhook

Google Chat

Outbound

Send project and service alerts into spaces with direct links to evidence and next actions.

Evidence exchanged

  • Space messages
  • Finding summaries
  • Resolution updates
RelixQ SaaS targetNative connectorWebhook

Mattermost and Discord

Outbound

Reach engineering and operations channels through structured webhook notifications and lifecycle updates.

Evidence exchanged

  • Channel messages
  • Evidence links
  • Lifecycle updates
RelixQ SaaS targetWebhook

Email

Outbound

Send immediate alerts, scheduled digests, executive summaries, and ownership reminders to governed recipient groups.

Evidence exchanged

  • Alerts and digests
  • Reports and summaries
  • Reminder notifications
RelixQ SaaS targetEmail

Signed webhooks

Outbound

Build custom workflows from versioned, signed events with retries, delivery history, and idempotency keys.

Evidence exchanged

  • Finding and posture events
  • Governance changes
  • Connector and scan health
RelixQ SaaS targetWebhookREST API

Control plane

Connection health is part of the evidence.

Test credentials and delivery, inspect the most recent success, trace failures, replay signed events, and monitor freshness across source and destination connections from one managed SaaS surface.

Integration control plane

One place to connect, route, and operate

Configure sources and destinations, test connections, apply routing policies, and inspect delivery health from one SaaS workspace.

Product UI
RelixQ integrations catalog showing connected security and engineering destinations.

Alert intelligence

Alert on decisions, not raw scanner noise.

RelixQ evaluates evidence changes in context, groups related observations, and routes one actionable record with the affected asset, policy, owner, confidence, and recommended next step.

Exposure

HNDL exposure crosses policy

Long-lived data becomes harvestable, reachable, or falls inside its migration window.

Posture

RelixQ Score changes

A project, business unit, or portfolio crosses a readiness threshold or moves unexpectedly.

Finding

A finding appears or regresses

New critical evidence is discovered or a verified finding returns after a code or configuration change.

Protocol

Protocol posture changes

A TLS endpoint changes negotiation behavior, loses hybrid support, or accepts a prohibited classical path.

Certificate

Certificate risk increases

A certificate approaches expiry, uses disallowed cryptography, or breaks an expected trust relationship.

Governance

Governance drifts

A policy fails, an exception approaches expiry, ownership is missing, or a remediation SLA is breached.

Delivery

A release gate decides

A pipeline is warned or blocked by net-new risk, score, severity, HNDL, or regression policy.

Health

Collection health degrades

A repository, scanner, endpoint, feed, or destination stops producing expected evidence.

Lifecycle

Detect, correlate, route, acknowledge, and verify.

The same alert identity follows the issue through every connected system, preserving a complete operational and audit trail.

  1. 01

    Detect

    Evaluate new evidence and state changes against organization, project, asset, and release policies.

    A typed signal with evidence and policy context.

  2. 02

    Correlate

    Group related observations by stable fingerprint, asset, service, owner, and time window.

    One incident instead of repeated notification noise.

  3. 03

    Route

    Apply severity, confidence, business criticality, ownership, schedules, and escalation rules.

    The right destination, urgency, and response team.

  4. 04

    Acknowledge

    Synchronize assignment, acknowledgement, comments, and workflow state across RelixQ and connected tools.

    A visible owner and governed response trail.

  5. 05

    Verify

    Retest changed evidence, close the alert when policy passes, and reopen it automatically on regression.

    Evidence-backed closure with complete history.

Routing policy

Match every signal to its business context.

Compose routing rules from evidence, risk, ownership, and timing—not from a one-size-fits-all severity label. Policies are organization-scoped, versioned, testable, and visible in the decision history.

Scope
Organization, business unit, project, repository, environment, asset, or service
Signal
Finding type, HNDL exposure, protocol posture, score, policy, gate, or platform health
Priority
Severity, confidence, data lifetime, reachability, business criticality, and SLA
Ownership
Service owner, engineering team, security function, on-call schedule, or escalation group
Timing
Immediate, grouped window, scheduled digest, reminder, or exception-expiry cadence
Destination
SIEM, observability, ticket, incident, on-call, chat, email, or signed webhook

Connection governance

Enterprise control around every data path.

RelixQ treats integrations as governed SaaS connections. Administrators control scope, credentials, routing, retention, and delivery while operators retain the evidence needed to understand every action.

SaaS control

Scoped authorization

Connect only the organizations, projects, repositories, services, and destinations that each workflow requires.

SaaS control

Managed credentials

Store and rotate connection credentials independently, with masked values and auditable administrative changes.

SaaS control

Delivery assurance

Use connection tests, signed payloads, retries, idempotency keys, delivery history, and health alerts.

SaaS control

Traceable decisions

Preserve rule version, evidence link, destination, delivery outcome, acknowledgement, and resolution history.

Design the operating path

Bring your source, security, engineering, and response stack.

We will map the evidence inputs, routing policy, destination workflows, ownership model, and success criteria for a RelixQ evaluation.