NIST AI Risk Management Framework
Vendor control mappingAI governance reference for transparency, human oversight, data boundaries, and provider review.
Official referenceTrust Center
Review where AI may assist RelixQ users, what data may be sent, how providers are governed, and which no-training or retention claims are not yet made.
Evidence posture
The public boundary is documented; provider contracts, data fields, retention, and configuration evidence remain under review.
Framework relationships
AI governance reference for transparency, human oversight, data boundaries, and provider review.
Official referenceControl-language mapping for buyer review; not a certification.
Official referenceControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
AI-assisted explanations and drafting are intended to help users interpret evidence. They do not authorize scans, change scope, approve exceptions, close findings, or replace customer review.
Evidence
Design evidenceFeature boundaries distinguish suggestions from governed product actions.
Framework context
NIST AI Risk Management Framework
Vendor control mapping — AI governance reference for transparency, human oversight, data boundaries, and provider review.
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
Published claim
The final policy must identify the feature, provider, fields sent, purpose, retention, region, customer controls, and deletion behavior. RelixQ does not represent full source files as a default AI input.
Evidence
Gated evidenceThe data map and provider configuration require final production confirmation.
Framework context
NIST AI Risk Management Framework
Vendor control mapping — AI governance reference for transparency, human oversight, data boundaries, and provider review.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
No broad no-training or zero-retention claim is made until the selected provider, contract, API configuration, retention behavior, and customer option are verified and published.
Evidence
Public summaryThe claim boundary is explicit while provider review is incomplete.
Framework context
NIST AI Risk Management Framework
Vendor control mapping — AI governance reference for transparency, human oversight, data boundaries, and provider review.
Published claim
When a customer enables or supplies an AI-provider connection, the resulting data flow is customer configured and must be included in that customer processing and subprocessor review.
Evidence
Operational evidenceEnabled connection state and routing are governed SaaS records.
Framework context
NIST AI Risk Management Framework
Vendor control mapping — AI governance reference for transparency, human oversight, data boundaries, and provider review.
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Publication boundary
This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .