NIST Cybersecurity Framework 2.0
Vendor control mappingControl-language mapping for buyer review; not a certification.
Official referenceTrust Center
Review the RelixQ SaaS security design, product controls, production-verification status, and evidence available to enterprise buyers.
Evidence posture
Public control summaries are available now; production architecture evidence and detailed test material are shared through controlled review when approved.
Framework relationships
Control-language mapping for buyer review; not a certification.
Official referenceControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
RelixQ is designed around organization-scoped sessions, requests, stored artifacts, jobs, and reports. Database and runtime enforcement remain under production control review; no certification-level isolation claim is made from design alone.
Evidence
Design evidenceArchitecture and control tests are being reconciled with the production service.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
The product supports organization membership, roles, session revocation, and scoped API credentials. OIDC and SAML federation plus SCIM provisioning remain roadmap capabilities and will depend on customer configuration and service plan.
Evidence
Operational evidenceProduct workflows generate reviewable access and credential records.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Published claim
Active QAST workflows require a persisted, signed Rules of Engagement record with authorized targets, explicit exclusions, rate and concurrency ceilings, blackout windows, named contacts, and emergency stop controls.
Evidence
Operational evidenceThe product records authorization and enforcement state for every active run.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Published claim
RelixQ targets encrypted service transport and managed secret references for SaaS credentials. Exact production protocols, key custody, rotation, backup encryption, and service-to-service controls remain evidence-review items.
Evidence
Gated evidenceDetailed cryptographic configuration and key-management evidence is restricted to approved review.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
RelixQ intends to restrict workforce and production access by role, business need, approved elevation, strong authentication, time-bound access where practical, and reviewable administrative activity. Exact production enforcement and review cadence remain under evidence review.
Evidence
Gated evidenceWorkforce identity, privileged-role, approval, and periodic-review evidence is restricted to approved review.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
The target security program records material authentication, authorization, administrative, integration, scanning, and delivery events and routes actionable health or security signals for review. Coverage, retention, alert ownership, and response testing remain production-review items.
Evidence
Gated evidenceEvent schemas and selected audit records exist; end-to-end production coverage and operating review require confirmation.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
RelixQ plans a measured vulnerability-management lifecycle covering intake, dependency and configuration findings, prioritization, ownership, remediation, exceptions, retesting, and management reporting.
Evidence
Not availableA complete production operating record and independently reviewed program are not yet available for claim publication.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
NIST SP 800-218 Secure Software Development Framework
Vendor control mapping — Secure-development practice mapping for evidence review; not an attestation.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
A documented program with intake channels, risk-based prioritization, owners, remediation targets, exception expiry, retesting, and trend reporting.
The roadmap does not imply that all vulnerabilities are known, that remediation is guaranteed by a fixed date, or that independent testing is complete.
Published claim
RelixQ SaaS inherits physical and foundational cloud controls from its providers while retaining responsibility for tenant configuration, identity, network exposure, application security, data handling, monitoring, and vendor oversight. A provider certification does not certify RelixQ.
Evidence
Gated evidenceProvider evidence and the RelixQ shared-responsibility mapping require final production and contract review.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Publication boundary
This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .