Skip to main content
RelixQ
Menu
Trust CenterSecurity
Trust Center
Public summaryControl review in progress

Trust Center

Security controls with explicit evidence boundaries.

Review the RelixQ SaaS security design, product controls, production-verification status, and evidence available to enterprise buyers.

Access
Public
Scope
RelixQ managed SaaS application, APIs, organization data paths, active-validation controls, and administrative workflows.
Last reviewed
Aug 17, 2026
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer
Evidence posture
Gated evidence

Evidence posture

Gated evidence

Gated artifacts

Public control summaries are available now; production architecture evidence and detailed test material are shared through controlled review when approved.

Evidence artifacts

  • Public security control summary
  • Rules of Engagement control records
  • Organization-scoped audit records
  • Architecture and test evidence by request

Framework relationships

Alignment is not the same as certification.

NIST Cybersecurity Framework 2.0

Vendor control mapping

Control-language mapping for buyer review; not a certification.

Official reference

AICPA Trust Services Criteria / SOC 2

Assurance roadmap

Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

ISO/IEC 27001

Assurance roadmap

Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Claim register

Public wording tied to evidence and review state.

Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.

Published claim

Tenant and authorization boundaries

RelixQ is designed around organization-scoped sessions, requests, stored artifacts, jobs, and reports. Database and runtime enforcement remain under production control review; no certification-level isolation claim is made from design alone.

Under review
Scope
Authenticated SaaS application and API access, stored artifacts, and background processing.
Last reviewed
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer
  • Organization-scoped session context
  • Membership and role checks
  • Organization context on jobs and reports
  • Production database-boundary verification

Evidence

Design evidence

Architecture and control tests are being reconciled with the production service.

Review evidence artifacts
  • Organization-scope design
  • Route and membership checks
  • RLS verification workpaper

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Identity and access controls

The product supports organization membership, roles, session revocation, and scoped API credentials. OIDC and SAML federation plus SCIM provisioning remain roadmap capabilities and will depend on customer configuration and service plan.

Verified claim
Scope
User authentication, organization membership, administrative roles, sessions, and API credentials.
Last reviewed
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer
  • OIDC and SAML federation roadmap
  • SCIM lifecycle provisioning roadmap
  • Scoped API credentials
  • Administrative audit trail

Evidence

Operational evidence

Product workflows generate reviewable access and credential records.

Review evidence artifacts
  • Role and membership records
  • Session-revocation events
  • API-key scope, expiry, hash, and revocation records

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

Published claim

Consent-gated active validation

Active QAST workflows require a persisted, signed Rules of Engagement record with authorized targets, explicit exclusions, rate and concurrency ceilings, blackout windows, named contacts, and emergency stop controls.

Verified claim
Scope
Customer-authorized active protocol and posture validation performed through RelixQ SaaS.
Last reviewed
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer
  • Authority attestation
  • Project-specific allowed scope
  • Exclusions override allowed targets
  • Read-only validation boundary
  • Emergency stop

Evidence

Operational evidence

The product records authorization and enforcement state for every active run.

Review evidence artifacts
  • Signed Rules of Engagement
  • Allowed and excluded scope
  • Rate and blackout policy
  • Kill-switch and run audit events

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • Customer security and resilience programs

    Customer evidence supportRelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

Published claim

Encryption and secrets management

RelixQ targets encrypted service transport and managed secret references for SaaS credentials. Exact production protocols, key custody, rotation, backup encryption, and service-to-service controls remain evidence-review items.

Under review
Scope
RelixQ SaaS transport, integration credentials, service credentials, backups, and stored artifacts.
Last reviewed
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer

Evidence

Gated evidence

Detailed cryptographic configuration and key-management evidence is restricted to approved review.

Review evidence artifacts
  • Transport configuration review
  • Secret-reference design
  • Key and credential rotation evidence

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Workforce and privileged access

RelixQ intends to restrict workforce and production access by role, business need, approved elevation, strong authentication, time-bound access where practical, and reviewable administrative activity. Exact production enforcement and review cadence remain under evidence review.

Under review
Scope
RelixQ personnel and approved service providers with administrative, support, cloud, database, deployment, or security-tool access.
Last reviewed
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer
  • Least-privilege role design
  • Strong authentication target
  • Joiner, mover, and leaver review
  • Support and emergency access accountability

Evidence

Gated evidence

Workforce identity, privileged-role, approval, and periodic-review evidence is restricted to approved review.

Review evidence artifacts
  • Workforce identity inventory
  • Privileged-role matrix
  • Access approval and removal records
  • Administrative access review

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Security logging and monitoring

The target security program records material authentication, authorization, administrative, integration, scanning, and delivery events and routes actionable health or security signals for review. Coverage, retention, alert ownership, and response testing remain production-review items.

Under review
Scope
RelixQ SaaS authentication, privileged actions, customer administration, active scans, integrations, jobs, and service health.
Last reviewed
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer

Evidence

Gated evidence

Event schemas and selected audit records exist; end-to-end production coverage and operating review require confirmation.

Review evidence artifacts
  • Audit-event catalog
  • Authentication and administration events
  • Connector and job health events
  • Monitoring coverage review

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Vulnerability management

RelixQ plans a measured vulnerability-management lifecycle covering intake, dependency and configuration findings, prioritization, ownership, remediation, exceptions, retesting, and management reporting.

Roadmap
Scope
RelixQ SaaS application, APIs, scanners, integrations, cloud configuration, dependencies, and public website.
Last reviewed
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer

Evidence

Not available

A complete production operating record and independently reviewed program are not yet available for claim publication.

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • NIST SP 800-218 Secure Software Development Framework

    Vendor control mappingSecure-development practice mapping for evidence review; not an attestation.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

A documented program with intake channels, risk-based prioritization, owners, remediation targets, exception expiry, retesting, and trend reporting.

The roadmap does not imply that all vulnerabilities are known, that remediation is guaranteed by a fixed date, or that independent testing is complete.

Published claim

Cloud, network, and provider inheritance

RelixQ SaaS inherits physical and foundational cloud controls from its providers while retaining responsibility for tenant configuration, identity, network exposure, application security, data handling, monitoring, and vendor oversight. A provider certification does not certify RelixQ.

Under review
Scope
Cloud infrastructure, network boundaries, managed platform services, website hosting, and security-relevant service providers.
Last reviewed
Evidence owner
Security control owner
Approval role
Security and Trust publication reviewer

Evidence

Gated evidence

Provider evidence and the RelixQ shared-responsibility mapping require final production and contract review.

Review evidence artifacts
  • Provider assurance material
  • Cloud service inventory
  • Network and exposure review
  • Shared-responsibility mapping

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Publication boundary

Status applies only to the scope and evidence shown above.

This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .