Skip to main content
RelixQ
Menu
Trust CenterVulnerability Disclosure
Trust Center
Public summaryDraft process

Trust Center

Report a security vulnerability responsibly.

RelixQ welcomes good-faith reports that help protect customers and the SaaS service, within a process that is still being staffed and tested.

Access
Public
Scope
Good-faith security research and vulnerability reports concerning RelixQ-controlled public website and SaaS assets.
Last reviewed
Aug 17, 2026
Evidence owner
Security response owner
Approval role
Security and legal reviewer
Evidence posture
Public summary

Evidence posture

Public summary

Public evidence

The public reporting boundary is documented; response metrics and a secure-transfer workflow are not yet claimed.

Evidence artifacts

  • Reporting address
  • Good-faith scope
  • Out-of-scope activities
  • Public response-boundary statement

Framework relationships

Alignment is not the same as certification.

NIST Cybersecurity Framework 2.0

Vendor control mapping

Control-language mapping for buyer review; not a certification.

Official reference

ISO/IEC 27001

Assurance roadmap

Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Claim register

Public wording tied to evidence and review state.

Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.

Published claim

How to report

Email security@relixq.com with the affected surface, reproduction steps, impact, and supporting evidence. Do not include customer data, credentials, or secrets unless RelixQ provides an approved secure-transfer method.

Under review
Scope
Initial vulnerability intake for RelixQ-controlled assets.
Last reviewed
Evidence owner
Security response owner
Approval role
Security and legal reviewer

Evidence

Public summary

The mailbox is public; operational ownership and secure-transfer handling require final verification.

Review evidence artifacts
  • Public reporting address
  • Required report fields

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

Published claim

Good-faith research

Limit testing to accounts and data you own, stop when customer or confidential data is encountered, avoid disruption and privacy impact, and allow reasonable investigation time before disclosure.

Documented practice
Scope
Security research conducted against RelixQ-controlled assets under this policy.
Last reviewed
Evidence owner
Security response owner
Approval role
Security and legal reviewer

Evidence

Public summary

The expected researcher boundary is publicly stated.

Review evidence artifacts
  • Good-faith research terms
  • Out-of-scope activity list

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

Published claim

Response expectations

Acknowledgment, triage, remediation, and disclosure-coordination targets will be published only after the response process is staffed and tested.

Roadmap
Scope
RelixQ security-response operations for accepted vulnerability reports.
Last reviewed
Evidence owner
Security response owner
Approval role
Security and legal reviewer

Evidence

Not available

No guaranteed response or remediation timeline is currently claimed.

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

A staffed intake, triage, communication, remediation, and coordinated-disclosure process with measured targets.

A target process is not a current SLA or guaranteed remediation date.

Published claim

No bounty promise

This process does not promise a bounty, payment, safe-harbor outcome, or immunity for activity outside the stated good-faith scope.

Not claimed
Scope
Public vulnerability-disclosure and researcher communications.
Last reviewed
Evidence owner
Security response owner
Approval role
Security and legal reviewer

Evidence

Public summary

The non-claim is explicit.

Review evidence artifacts
  • Public disclosure-policy boundary

Framework context

No framework relationship is asserted for this claim.

Publication boundary

Status applies only to the scope and evidence shown above.

This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .