AICPA Trust Services Criteria / SOC 2
Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Trust Center
Review the current processing categories, configuration-dependent services, and the work required before a legal subprocessor list and notice process are final.
Evidence posture
Public categories are available; contracts, regions, transfer mechanisms, and final legal roles require approved review.
Framework relationships
Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
Microsoft Azure is the intended managed SaaS infrastructure provider. The final register must name the relevant services, processing purpose, regions, backup locations, support access, legal entity, and transfer mechanism.
Evidence
Gated evidenceThe production service and contractual scope require final reconciliation.
Framework context
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
The public website is hosted on Vercel. Form routing is enabled only when a third-party endpoint is configured; the selected provider and fields must be added to the final register before production use.
Evidence
Public summaryThe hosting provider and configuration-dependent form boundary are publicly documented.
Framework context
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
Source, identity, notification, observability, ticketing, incident, chat, and customer-selected AI services may receive data when a customer enables that connection. Roles and processing depend on the provider and configuration.
Evidence
Operational evidenceConnection and routing state identify enabled customer data paths.
Framework context
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
The customer-notice channel, advance-notice period, objection process, and effective-date record remain roadmap items until approved contract language and operational ownership are established.
Evidence
Not availableNo public advance-notice commitment is currently claimed.
Framework context
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
A versioned public register and contract-aligned material-change notice process.
The roadmap does not create a current notice period or objection right.
Publication boundary
This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .