Skip to main content
RelixQ
Menu
Trust CenterSecure Development
Trust Center
Public summaryProgram evidence review

Trust Center

Secure development as an evidence-backed program.

Review how RelixQ intends to govern design, code change, dependency risk, testing, release approval, and vulnerability remediation for the managed SaaS service.

Access
Public
Scope
RelixQ SaaS software development lifecycle, source changes, dependencies, CI and release workflows, testing, and vulnerability remediation.
Last reviewed
Aug 17, 2026
Evidence owner
Engineering security owner
Approval role
Security publication reviewer
Evidence posture
Gated evidence

Evidence posture

Gated evidence

Gated artifacts

Public practices are summarized here; repositories, pipelines, test results, and remediation records are restricted.

Evidence artifacts

  • Secure-development policy draft
  • Change-review records
  • Dependency and vulnerability evidence
  • Release and test evidence

Framework relationships

Alignment is not the same as certification.

NIST SP 800-218 Secure Software Development Framework

Vendor control mapping

Secure-development practice mapping for evidence review; not an attestation.

Official reference

NIST Cybersecurity Framework 2.0

Vendor control mapping

Control-language mapping for buyer review; not a certification.

Official reference

AICPA Trust Services Criteria / SOC 2

Assurance roadmap

Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

ISO/IEC 27001

Assurance roadmap

Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Claim register

Public wording tied to evidence and review state.

Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.

Published claim

Design and change control

Changes to RelixQ are intended to pass documented review, automated checks, scoped approval, and traceable release workflows. Production evidence is being assembled before this is represented as a mature assurance control.

Under review
Scope
Application, API, scanner, infrastructure, and website changes that affect the RelixQ SaaS service.
Last reviewed
Evidence owner
Engineering security owner
Approval role
Security publication reviewer

Evidence

Gated evidence

Change records and approval evidence are restricted to approved review.

Review evidence artifacts
  • Pull-request review records
  • CI checks
  • Release approvals
  • Change history

Framework context

  • NIST SP 800-218 Secure Software Development Framework

    Vendor control mappingSecure-development practice mapping for evidence review; not an attestation.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Dependency and vulnerability management

The secure-development roadmap includes dependency inventory, vulnerability intake, severity and exposure triage, remediation ownership, retesting, and exception expiry.

Roadmap
Scope
First-party code, third-party packages, build dependencies, container components, and deployed SaaS services.
Last reviewed
Evidence owner
Engineering security owner
Approval role
Security publication reviewer

Evidence

Not available

A complete production operating record has not yet been approved for claim publication.

Framework context

  • NIST SP 800-218 Secure Software Development Framework

    Vendor control mappingSecure-development practice mapping for evidence review; not an attestation.

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

Roadmap distinction

A measured vulnerability-management program with owners, remediation targets, exception expiry, retesting, and management reporting.

The roadmap does not imply a completed audit, a guaranteed remediation SLA, or absence of vulnerabilities.

Published claim

Security testing

RelixQ plans layered static, dependency, configuration, API, and authorized independent testing, with findings tracked to evidence-backed closure.

Roadmap
Scope
RelixQ SaaS application, APIs, scanners, integrations, and cloud configuration.
Last reviewed
Evidence owner
Engineering security owner
Approval role
Security publication reviewer

Evidence

Not available

Independent test scope and final reports are not yet published.

Framework context

  • NIST SP 800-218 Secure Software Development Framework

    Vendor control mappingSecure-development practice mapping for evidence review; not an attestation.

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

Repeatable internal security testing and periodic independent penetration testing.

Planned testing is not equivalent to a completed independent assessment.

Published claim

Release integrity and provenance

The target delivery program includes protected release workflows, artifact provenance, controlled credentials, rollback planning, and separation of duties appropriate to team size.

Roadmap
Scope
Build, package, image, infrastructure, and production release paths for RelixQ SaaS.
Last reviewed
Evidence owner
Engineering security owner
Approval role
Security publication reviewer

Evidence

Not available

Release-integrity evidence is being defined and is not yet available as an assurance package.

Framework context

  • NIST SP 800-218 Secure Software Development Framework

    Vendor control mappingSecure-development practice mapping for evidence review; not an attestation.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

Documented, reviewable release provenance and deployment approval records.

Architecture intent is not an attestation of operating effectiveness.

Publication boundary

Status applies only to the scope and evidence shown above.

This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .