NIST SP 800-218 Secure Software Development Framework
Vendor control mappingSecure-development practice mapping for evidence review; not an attestation.
Official referenceTrust Center
Review how RelixQ intends to govern design, code change, dependency risk, testing, release approval, and vulnerability remediation for the managed SaaS service.
Evidence posture
Public practices are summarized here; repositories, pipelines, test results, and remediation records are restricted.
Framework relationships
Secure-development practice mapping for evidence review; not an attestation.
Official referenceControl-language mapping for buyer review; not a certification.
Official referenceControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
Changes to RelixQ are intended to pass documented review, automated checks, scoped approval, and traceable release workflows. Production evidence is being assembled before this is represented as a mature assurance control.
Evidence
Gated evidenceChange records and approval evidence are restricted to approved review.
Framework context
NIST SP 800-218 Secure Software Development Framework
Vendor control mapping — Secure-development practice mapping for evidence review; not an attestation.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
The secure-development roadmap includes dependency inventory, vulnerability intake, severity and exposure triage, remediation ownership, retesting, and exception expiry.
Evidence
Not availableA complete production operating record has not yet been approved for claim publication.
Framework context
NIST SP 800-218 Secure Software Development Framework
Vendor control mapping — Secure-development practice mapping for evidence review; not an attestation.
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Roadmap distinction
A measured vulnerability-management program with owners, remediation targets, exception expiry, retesting, and management reporting.
The roadmap does not imply a completed audit, a guaranteed remediation SLA, or absence of vulnerabilities.
Published claim
RelixQ plans layered static, dependency, configuration, API, and authorized independent testing, with findings tracked to evidence-backed closure.
Evidence
Not availableIndependent test scope and final reports are not yet published.
Framework context
NIST SP 800-218 Secure Software Development Framework
Vendor control mapping — Secure-development practice mapping for evidence review; not an attestation.
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
Repeatable internal security testing and periodic independent penetration testing.
Planned testing is not equivalent to a completed independent assessment.
Published claim
The target delivery program includes protected release workflows, artifact provenance, controlled credentials, rollback planning, and separation of duties appropriate to team size.
Evidence
Not availableRelease-integrity evidence is being defined and is not yet available as an assurance package.
Framework context
NIST SP 800-218 Secure Software Development Framework
Vendor control mapping — Secure-development practice mapping for evidence review; not an attestation.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
Documented, reviewable release provenance and deployment approval records.
Architecture intent is not an attestation of operating effectiveness.
Publication boundary
This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .