Developer Guide
One platform. Documented end to end.
RelixQ Enterprise is a managed multi-tenant service for post-quantum exposure management: seven scan surfaces, the banded RelixQ Score, QAST quantum exposure assessment, governance, and the integrations that carry evidence to the rest of your stack. Every page below assumes only what came before it.
Start here
Provisioning, your first scan, and how findings move from a scan surface through scoring into the workflow your teams already run.
Go deeper
HNDL exposure windows, attack-path projection, consent-gated validation, the score that leadership tracks, governance, CBOM, and SIEM egress.
New to the threat model? Start with post-quantum concepts ->
Browse the Developer Guide
Overview
The post-quantum threat model RelixQ is built on, and the finding contract every scan surface normalizes to.
Post-quantum concepts
The cryptography and threat model RelixQ is built on: what Shor and Grover break, why harvest-now-decrypt-later is a present-day problem, the Mosca inequality, and the NIST algorithms that replace what breaks.
What quantum computing actually breaksHarvest now, decrypt laterThe Mosca inequalityWhat replaces what
The CryptoFinding contract
The single schema every scanner normalizes to before its output crosses a boundary — the reason evidence from code, dependencies, TLS, cloud, and runtime composes instead of fragmenting.
Why one shapeThe schemaQuantum-safety classificationFindings carry no source code
RelixQ Enterprise
The managed SaaS: onboarding, the RelixQ Score, quantum exposure assessment, governance, the API, and integrations.
Getting started with RelixQ Enterprise
Sign in to your managed tenant, create an organization and a project, connect a source, run your first scan, and learn what each surface is for.
Access your managed tenantWhat Enterprise addsSign inCreate a project and connect a source
How RelixQ Enterprise works
What gets scanned, how your estate is organized into scopes, how the managed service processes evidence, and what happens when a signal is missing.
Seven attack surfacesManaged SaaS processing boundariesThe scope hierarchyWhat you can rely on
Scans, findings and reports
The day-to-day working loop: run a scan, read the live progress stream, filter and triage findings, save views, and export evidence.
Ways to trigger a scanThe Scans pageScan detail and live progressThe findings list
Enterprise detection coverage
What the managed scanners read across seven evidence input surfaces: source, configuration, dependencies, TLS, cloud keys, cloud TLS infrastructure, and runtime telemetry—plus readiness-graph correlation.
Source codeThe curated PQC Rule PackWhat the rules detectDependencies and SBOM
The RelixQ Score and the three dashboards
What the 0–100 readiness score means and deliberately does not mean, the five bands, the score hero anatomy, and the Engineering, Executive and Security dashboards built around it.
What the score isThe five bands"Not yet assessed" — never a fake 100The score hero, piece by piece
Crypto asset inventory and CBOM export
How observations from every scanner dedupe onto canonical crypto assets, what the evidence ledger records, and how to export a deterministic CycloneDX Cryptographic Bill of Materials.
One asset, many witnessesThe inventory pageEmpty is not the same as unavailableAsset detail and the evidence ledger
TLS endpoint and certificate posture
The read-only TLS surface: endpoint posture rows, certificate inventory, derived issue severities, the honest-empty contract, and the recognized PQC hybrid groups.
The honest-empty contractEndpoint postureHow issues are derivedCertificate inventory
QAST: Quantum Exposure Assessment
The adversary-validation layer: HNDL exposure classification via the Mosca inequality, attack-path projection, consent-gated read-only probing, remediation lifecycle, PTES/NIST reports, retest, and the PQC compatibility lab.
The question QAST answersThe honesty stanceThree disjoint bucketsThe exposure register
Governance, policies and exceptions
The policy engine that renders release-gate decisions, the TTL-bounded exception workflow, and the tamper-evident audit chain that makes both defensible to an auditor.
Why governance is a first-class surfaceThe policy engineThe exception workflowThe tamper-evident audit chain
CLI: platform and QAST commands
The commands that talk to your tenant — login, org, use, remote-scan, submit, report, rules — plus the `pentest` group for quantum exposure assessment and the release gate.
Local commands vs platform commandsAuthentication and configurationSession and workspace commandsGetting results into your tenant
Release gates, PR comments and the GitHub App
Three escalating enforcement layers, a copy-paste GitHub Actions workflow, baselines, the eight-condition QAST release gate, and what the GitHub App does today.
The three enforcement layersQuick start: GitHub ActionsBaselines and base-versus-head diffsThe QAST release gate
REST API reference
The endpoint map for the Enterprise REST API: authentication, tenancy, per-service endpoint tables, honest-empty semantics, and the internal endpoints you should never call directly.
How to call the APIIdentity, organizations and API keysProjects, services and repositoriesScans and schedules
Integrations: SIEM export, alerting and ticketing
The current configuration guide for SIEM and observability export, incidents, tickets, notifications, and status sync; the public catalog separately shows the final-state SaaS roadmap.
The egress modelObservability and SIEM exportConnecting and testing a destinationDelivery semantics
Accounts, organizations and administration
The account lifecycle, authentication methods and their honest UI-versus-API status, organizations and the switcher, invitations, members and roles, and project administration.
Conventions used on this pageAccount lifecycleAuthentication methodsOrganizations
Security model, tenancy and data handling
The intended tenant-isolation design, the two collection paths into the managed SaaS service, credential handling, active-probing consent, and the boundary between product architecture and production-verified assurance claims.
Tenant isolationTwo collection paths into RelixQ SaaSCredential handlingInbound request verification
Reference
Compliance mapping, troubleshooting by symptom, frequently asked questions, and the glossary.
Compliance evidence: what RelixQ produces
Which artifact answers which requirement, what RelixQ emits, and where the evidence boundary sits. For the mandates and deadlines themselves, see Post-quantum concepts.
Formats consumed and emittedWhat RelixQ names as a migration targetMapping a mandate requirement to a RelixQ artifactWhy the honesty stance matters for audit
Troubleshooting
Symptom, cause and fix — organized by surface, so you can go straight from what you are seeing to why it happens and what to do about it.
The diagnostic orderRelixQ Enterprise — empty surfacesRelixQ Enterprise — sign-in and accessRelixQ Enterprise — scanning and gates
Frequently asked questions
Product differences, quantum basics, scanning behaviour, how the score works, what QAST proves, and platform questions — answered without overclaiming.
Product and licensingQuantum basicsScanningScores and QAST
Glossary
Every term the products use — quantum concepts, NIST algorithms, RelixQ constructs, formats, and platform mechanics — defined precisely, with the product each applies to.
Quantum and cryptographyRelixQ constructsFormats and standardsPlatform mechanics
The reading order
Read one track, or jump to what you own.
21 pages in total, 15 of them covering the platform itself. Each page assumes only what came before it.
- 01Post-quantum concepts
- 02The finding contract
- 03Getting started
- 04How it works
- 05Scans & findings
- 06Detection coverage
- 07RelixQ Score & dashboards
- 08Inventory & CBOM
- 09TLS & certificates
- 10QAST — quantum exposure
- 11Governance & policy
- 12CLI — platform commands
- 13Release gates
- 14REST API
- 15Integrations & alerts
- 16Accounts & organizations
- 17Security & tenancy
- 18Compliance evidence
- 19Troubleshooting
- 20FAQ
- 21Glossary