Skip to main content
RelixQ
Menu
Trust CenterCompliance
Trust Center
Public summaryAssurance roadmap

Trust Center

Compliance, standards, and assurance—without ambiguity.

RelixQ separates technical standards, customer evidence support, and vendor assurance. Product alignment is not customer certification, and assurance roadmap items are not achieved audits.

Access
Public
Scope
RelixQ product standards, evidence exports, customer control mappings, vendor control program, independent reports, and certifications.
Last reviewed
Aug 17, 2026
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer
Evidence posture
Public summary

Evidence posture

Public summary

Public evidence

Technical mappings and claim boundaries are public; independent assurance evidence is gated and not yet claimed as achieved.

Evidence artifacts

  • Public standards mapping
  • Customer evidence boundary
  • Vendor assurance roadmap

Framework relationships

Alignment is not the same as certification.

NIST FIPS 203 — ML-KEM

Technical alignment

Final NIST post-quantum key-encapsulation standard used as a structured migration target.

Official reference

NIST FIPS 204 — ML-DSA

Technical alignment

Final NIST post-quantum digital-signature standard used as a structured migration target.

Official reference

NIST FIPS 205 — SLH-DSA

Technical alignment

Final NIST stateless hash-based signature standard used as a structured migration target.

Official reference

NIST IR 8547 — Initial Public Draft

Technical alignment

Draft transition guidance used for planning context. It is not represented as a final NIST publication.

Official reference

AICPA Trust Services Criteria / SOC 2

Assurance roadmap

Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

ISO/IEC 27001

Assurance roadmap

Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Customer security and resilience programs

Customer evidence support

RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

Claim register

Public wording tied to evidence and review state.

Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.

Published claim

Three different claims

RelixQ can align product analysis to a technical standard, produce artifacts that support a customer control program, and operate its own vendor-assurance program. None of those statements automatically certifies a customer or converts a roadmap milestone into an achieved audit.

Verified claim
Scope
All public RelixQ compliance, standards, assurance, and customer-evidence language.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer
  • Technical alignment
  • Customer evidence support
  • Vendor control mapping
  • Independent assurance

Evidence

Public summary

The claim boundary is encoded in the public catalog and Trust Center.

Review evidence artifacts
  • Public status vocabulary
  • Framework relationship taxonomy
  • Non-certification statement

Framework context

  • Customer security and resilience programs

    Customer evidence supportRelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Post-quantum standards and transition guidance

RelixQ uses FIPS 203, FIPS 204, and FIPS 205 as final NIST migration targets. NIST IR 8547 is presented accurately as an Initial Public Draft used for transition-planning context.

Verified claim
Scope
Algorithm classification, migration targets, technical reports, and post-quantum transition context.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer

Evidence

Design evidence

Rules, findings, and reports carry named standards and source references.

Review evidence artifacts
  • Migration-target catalog
  • Finding metadata
  • Standards-linked technical reports

Framework context

  • NIST FIPS 203 — ML-KEM

    Technical alignmentFinal NIST post-quantum key-encapsulation standard used as a structured migration target.

  • NIST FIPS 204 — ML-DSA

    Technical alignmentFinal NIST post-quantum digital-signature standard used as a structured migration target.

  • NIST FIPS 205 — SLH-DSA

    Technical alignmentFinal NIST stateless hash-based signature standard used as a structured migration target.

  • NIST IR 8547 — Initial Public Draft

    Technical alignmentDraft transition guidance used for planning context. It is not represented as a final NIST publication.

Published claim

Evidence for customer programs

Inventory, CBOM, findings, policies, exceptions, release decisions, retests, and audit history can support customer assessments. RelixQ does not certify the customer, determine legal compliance, or replace the customer assessor.

Documented practice
Scope
RelixQ-generated customer reports, exports, control records, and technical evidence.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer

Evidence

Gated evidence

Customer artifacts are reviewable within the customer scope and are not vendor certifications.

Review evidence artifacts
  • Executive and technical reports
  • CBOM and findings exports
  • Policy and exception history
  • Retest and release records

Framework context

  • Customer security and resilience programs

    Customer evidence supportRelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

  • NIS2 and DORA

    Customer evidence supportRisk-management evidence support only; not legal advice or certification.

  • PCI DSS, HIPAA, and GDPR security programs

    Customer evidence supportTechnical evidence support only; applicability and compliance remain the customer responsibility.

Published claim

RelixQ vendor assurance roadmap

SOC 2 Type II, ISO/IEC 27001, independent penetration testing, continuity testing, CAIQ, and expanded security questionnaires are roadmap work. Achieved reports or certifications will be published only with exact scope, period, and issuing party.

Roadmap
Scope
RelixQ managed SaaS vendor controls and independent assurance program.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer

Evidence

Not available

No completed SOC 2 Type II report or ISO/IEC 27001 certificate is claimed.

Framework context

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

Documented controls, operating evidence, independent testing, and formal assurance appropriate to enterprise procurement.

Roadmap work is not a completed examination, certification, penetration test, or contractual warranty.

Published claim

Certifications not claimed

RelixQ does not currently claim SOC 2 completion or ISO/IEC 27001 certification. Product standards support and customer evidence mappings must not be read as vendor certification.

Not claimed
Scope
Public procurement, sales, Trust Center, and compliance representations.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer

Evidence

Public summary

The non-claim is explicit and reviewable.

Review evidence artifacts
  • Public assurance status
  • Certification claim boundary

Framework context

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Publication boundary

Status applies only to the scope and evidence shown above.

This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .