Skip to main content
RelixQ
Menu

Developer Guide

One platform. Documented end to end.

RelixQ Enterprise is a managed multi-tenant service for post-quantum exposure management: seven scan surfaces, the banded RelixQ Score, QAST quantum exposure assessment, governance, and the integrations that carry evidence to the rest of your stack. Every page below assumes only what came before it.

Start here

Provisioning, your first scan, and how findings move from a scan surface through scoring into the workflow your teams already run.

Go deeper

HNDL exposure windows, attack-path projection, consent-gated validation, the score that leadership tracks, governance, CBOM, and SIEM egress.

New to the threat model? Start with post-quantum concepts ->

Browse the Developer Guide

Overview

The post-quantum threat model RelixQ is built on, and the finding contract every scan surface normalizes to.

RelixQ Enterprise

The managed SaaS: onboarding, the RelixQ Score, quantum exposure assessment, governance, the API, and integrations.

Getting started with RelixQ Enterprise

Sign in to your managed tenant, create an organization and a project, connect a source, run your first scan, and learn what each surface is for.

Access your managed tenantWhat Enterprise addsSign inCreate a project and connect a source

How RelixQ Enterprise works

What gets scanned, how your estate is organized into scopes, how the managed service processes evidence, and what happens when a signal is missing.

Seven attack surfacesManaged SaaS processing boundariesThe scope hierarchyWhat you can rely on

Scans, findings and reports

The day-to-day working loop: run a scan, read the live progress stream, filter and triage findings, save views, and export evidence.

Ways to trigger a scanThe Scans pageScan detail and live progressThe findings list

Enterprise detection coverage

What the managed scanners read across seven evidence input surfaces: source, configuration, dependencies, TLS, cloud keys, cloud TLS infrastructure, and runtime telemetry—plus readiness-graph correlation.

Source codeThe curated PQC Rule PackWhat the rules detectDependencies and SBOM

The RelixQ Score and the three dashboards

What the 0–100 readiness score means and deliberately does not mean, the five bands, the score hero anatomy, and the Engineering, Executive and Security dashboards built around it.

What the score isThe five bands"Not yet assessed" — never a fake 100The score hero, piece by piece

Crypto asset inventory and CBOM export

How observations from every scanner dedupe onto canonical crypto assets, what the evidence ledger records, and how to export a deterministic CycloneDX Cryptographic Bill of Materials.

One asset, many witnessesThe inventory pageEmpty is not the same as unavailableAsset detail and the evidence ledger

TLS endpoint and certificate posture

The read-only TLS surface: endpoint posture rows, certificate inventory, derived issue severities, the honest-empty contract, and the recognized PQC hybrid groups.

The honest-empty contractEndpoint postureHow issues are derivedCertificate inventory

QAST: Quantum Exposure Assessment

The adversary-validation layer: HNDL exposure classification via the Mosca inequality, attack-path projection, consent-gated read-only probing, remediation lifecycle, PTES/NIST reports, retest, and the PQC compatibility lab.

The question QAST answersThe honesty stanceThree disjoint bucketsThe exposure register

Governance, policies and exceptions

The policy engine that renders release-gate decisions, the TTL-bounded exception workflow, and the tamper-evident audit chain that makes both defensible to an auditor.

Why governance is a first-class surfaceThe policy engineThe exception workflowThe tamper-evident audit chain

CLI: platform and QAST commands

The commands that talk to your tenant — login, org, use, remote-scan, submit, report, rules — plus the `pentest` group for quantum exposure assessment and the release gate.

Local commands vs platform commandsAuthentication and configurationSession and workspace commandsGetting results into your tenant

Release gates, PR comments and the GitHub App

Three escalating enforcement layers, a copy-paste GitHub Actions workflow, baselines, the eight-condition QAST release gate, and what the GitHub App does today.

The three enforcement layersQuick start: GitHub ActionsBaselines and base-versus-head diffsThe QAST release gate

REST API reference

The endpoint map for the Enterprise REST API: authentication, tenancy, per-service endpoint tables, honest-empty semantics, and the internal endpoints you should never call directly.

How to call the APIIdentity, organizations and API keysProjects, services and repositoriesScans and schedules

Integrations: SIEM export, alerting and ticketing

The current configuration guide for SIEM and observability export, incidents, tickets, notifications, and status sync; the public catalog separately shows the final-state SaaS roadmap.

The egress modelObservability and SIEM exportConnecting and testing a destinationDelivery semantics

Accounts, organizations and administration

The account lifecycle, authentication methods and their honest UI-versus-API status, organizations and the switcher, invitations, members and roles, and project administration.

Conventions used on this pageAccount lifecycleAuthentication methodsOrganizations

Security model, tenancy and data handling

The intended tenant-isolation design, the two collection paths into the managed SaaS service, credential handling, active-probing consent, and the boundary between product architecture and production-verified assurance claims.

Tenant isolationTwo collection paths into RelixQ SaaSCredential handlingInbound request verification

Reference

Compliance mapping, troubleshooting by symptom, frequently asked questions, and the glossary.