Skip to main content
RelixQ
Menu
Trust CenterSubprocessors
Trust Center
Public summaryRegister under review

Trust Center

A configuration-aware subprocessor register.

Review the current processing categories, configuration-dependent services, and the work required before a legal subprocessor list and notice process are final.

Access
Public
Scope
Third parties that may process customer personal data or customer content for RelixQ SaaS, the public website, forms, support, integrations, and optional AI.
Last reviewed
Aug 17, 2026
Evidence owner
Vendor and privacy program owner
Approval role
Privacy and legal reviewer
Evidence posture
Gated evidence

Evidence posture

Gated evidence

Gated artifacts

Public categories are available; contracts, regions, transfer mechanisms, and final legal roles require approved review.

Evidence artifacts

  • Draft subprocessor inventory
  • Provider contract review
  • Data-location and transfer review
  • Customer notice process draft

Framework relationships

Alignment is not the same as certification.

AICPA Trust Services Criteria / SOC 2

Assurance roadmap

Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

ISO/IEC 27001

Assurance roadmap

Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Claim register

Public wording tied to evidence and review state.

Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.

Published claim

Managed SaaS cloud infrastructure

Microsoft Azure is the intended managed SaaS infrastructure provider. The final register must name the relevant services, processing purpose, regions, backup locations, support access, legal entity, and transfer mechanism.

Under review
Scope
RelixQ SaaS hosting, storage, networking, processing, backups, and operational access.
Last reviewed
Evidence owner
Vendor and privacy program owner
Approval role
Privacy and legal reviewer

Evidence

Gated evidence

The production service and contractual scope require final reconciliation.

Review evidence artifacts
  • Azure service inventory
  • Region and backup review
  • Provider contract and transfer review

Framework context

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Public website services

The public website is hosted on Vercel. Form routing is enabled only when a third-party endpoint is configured; the selected provider and fields must be added to the final register before production use.

Documented practice
Scope
relixq.com hosting, public form routing, and website operational delivery.
Last reviewed
Evidence owner
Vendor and privacy program owner
Approval role
Privacy and legal reviewer

Evidence

Public summary

The hosting provider and configuration-dependent form boundary are publicly documented.

Review evidence artifacts
  • Website hosting configuration
  • Form endpoint configuration

Framework context

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Customer-enabled connected services

Source, identity, notification, observability, ticketing, incident, chat, and customer-selected AI services may receive data when a customer enables that connection. Roles and processing depend on the provider and configuration.

Customer configured
Scope
Customer-enabled third-party integrations and destination services.
Last reviewed
Evidence owner
Vendor and privacy program owner
Approval role
Privacy and legal reviewer

Evidence

Operational evidence

Connection and routing state identify enabled customer data paths.

Review evidence artifacts
  • Connection catalog
  • Enabled connection state
  • Routing and delivery records

Framework context

  • Customer security and resilience programs

    Customer evidence supportRelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Subprocessor change notice

The customer-notice channel, advance-notice period, objection process, and effective-date record remain roadmap items until approved contract language and operational ownership are established.

Roadmap
Scope
Changes to subprocessors that process customer personal data under an applicable agreement.
Last reviewed
Evidence owner
Vendor and privacy program owner
Approval role
Privacy and legal reviewer

Evidence

Not available

No public advance-notice commitment is currently claimed.

Framework context

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

A versioned public register and contract-aligned material-change notice process.

The roadmap does not create a current notice period or objection right.

Publication boundary

Status applies only to the scope and evidence shown above.

This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .