Skip to main content
RelixQBEYOND QUANTUM
Menu
Trust CenterCompliance
Trust Center
Public summaryAssurance roadmap

Trust Center

Compliance, standards, and assurance—without ambiguity.

RelixQ separates technical standards, customer evidence support, and vendor assurance. Product alignment is not customer certification, and assurance roadmap items are not achieved audits.

Access
Public
Scope
RelixQ product standards, evidence exports, customer control mappings, vendor control program, independent reports, and certifications.
Last reviewed
Sep 18, 2026
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer
Evidence posture
Public summary

Evidence posture

Public summary

Public evidence

Technical mappings and claim boundaries are public; independent assurance evidence is gated and not yet claimed as achieved.

Evidence artifacts

  • Public standards mapping
  • Customer evidence boundary
  • Vendor assurance roadmap

Framework relationships

Alignment is not the same as certification.

NIST FIPS 203 — ML-KEM

Technical alignment

Final NIST post-quantum key-encapsulation standard used as a structured migration target.

Official reference

NIST FIPS 204 — ML-DSA

Technical alignment

Final NIST post-quantum digital-signature standard used as a structured migration target.

Official reference

NIST FIPS 205 — SLH-DSA

Technical alignment

Final NIST stateless hash-based signature standard used as a structured migration target.

Official reference

NIST IR 8547 — Initial Public Draft

Technical alignment

Draft transition guidance used for planning context. It is not represented as a final NIST publication.

Official reference

NSA CNSA 2.0

Technical alignment

A control-mapping pack and six dated algorithm profiles from 2025 to 2035. Citation and verdict content only; nothing asserts that CNSA 2.0 binds the scanned organization.

NIST SP 800-131A, 800-57, 800-56A/B, 800-38A/D, 800-52, 800-208, and national guidance

Technical alignment

Mapped to detection rules because each names an algorithm, key length, mode, or protocol. National guidance covers BSI TR-02102, ANSSI PG-083, CCCS ITSP.40.062 and .111, CRYPTREC LS-0001, NCA NCS-1:2020, and ICP-Brasil DOC-ICP-01.01.

NIST SP 800-53 Rev. 5, SP 800-171 Rev. 3, and CSF 2.0 (customer control packs)

Customer evidence support

Signed packs relate finding evidence to SC-12, SC-13, SC-8(1), SC-28(1); 03.13.08, 03.13.10, 03.13.11; and PR.DS-01, PR.DS-02. Every mapping is background evidence for a customer control. None is an assessment result, an authorization, or a tier determination.

HIPAA Security Rule, 45 CFR § 164.312 (customer control pack)

Customer evidence support

Relates finding evidence to the two addressable encryption specifications. Whether a system holds electronic protected health information is never visible to a scanner, so applicability is always the customer determination.

AICPA Trust Services Criteria CC6.1 and CC6.7 (customer control pack)

Customer evidence support

Relates a customer finding to criteria the customer is examined against. This is product content for a customer SOC 2 program. It is unrelated to RelixQ vendor assurance, and RelixQ does not claim a completed SOC 2 examination.

ISO/IEC 27001 and 27002, PCI DSS v4.0.1, and sector packs (customer control packs)

Customer evidence support

ISO controls are cited by identifier only. PCI DSS maps Requirement 4 alone, because the other requirements are process obligations a scanner cannot observe. Sector packs cover financial services, government and critical infrastructure, UAE instruments, and ETSI quantum-safe reports.

AICPA Trust Services Criteria / SOC 2

Assurance roadmap

Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

ISO/IEC 27001

Assurance roadmap

Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Customer security and resilience programs

Customer evidence support

RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

Claim register

Public wording tied to evidence and review state.

Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.

Published claim

Three different claims

RelixQ can align product analysis to a technical standard, produce artifacts that support a customer control program, and operate its own vendor-assurance program. None of those statements automatically certifies a customer or converts a roadmap milestone into an achieved audit.

Verified claim
Scope
All public RelixQ compliance, standards, assurance, and customer-evidence language.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer
  • Technical alignment
  • Customer evidence support
  • Vendor control mapping
  • Independent assurance

Evidence

Public summary

The claim boundary is encoded in the public catalog and Trust Center.

Review evidence artifacts
  • Public status vocabulary
  • Framework relationship taxonomy
  • Non-certification statement

Framework context

  • Customer security and resilience programs

    Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Post-quantum standards and transition guidance

RelixQ uses FIPS 203, FIPS 204, and FIPS 205 as final NIST migration targets. NIST IR 8547 is presented accurately as an Initial Public Draft used for transition-planning context.

Verified claim
Scope
Algorithm classification, migration targets, technical reports, and post-quantum transition context.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer

Evidence

Design evidence

Rules, findings, and reports carry named standards and source references.

Review evidence artifacts
  • Migration-target catalog
  • Finding metadata
  • Standards-linked technical reports

Framework context

  • NIST FIPS 203 — ML-KEM

    Technical alignment — Final NIST post-quantum key-encapsulation standard used as a structured migration target.

  • NIST FIPS 204 — ML-DSA

    Technical alignment — Final NIST post-quantum digital-signature standard used as a structured migration target.

  • NIST FIPS 205 — SLH-DSA

    Technical alignment — Final NIST stateless hash-based signature standard used as a structured migration target.

  • NIST IR 8547 — Initial Public Draft

    Technical alignment — Draft transition guidance used for planning context. It is not represented as a final NIST publication.

Published claim

Evidence for customer programs

Inventory, CBOM, findings, policies, exceptions, release decisions, retests, and audit history can support customer assessments. RelixQ does not certify the customer, determine legal compliance, or replace the customer assessor.

Documented practice
Scope
RelixQ-generated customer reports, exports, control records, and technical evidence.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer

Evidence

Gated evidence

Customer artifacts are reviewable within the customer scope and are not vendor certifications.

Review evidence artifacts
  • Executive and technical reports
  • CBOM and findings exports
  • Policy and exception history
  • Retest and release records

Framework context

  • Customer security and resilience programs

    Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

  • NIS2 and DORA

    Customer evidence support — Risk-management evidence support only; not legal advice or certification.

  • PCI DSS, HIPAA, and GDPR security programs

    Customer evidence support — Technical evidence support only; applicability and compliance remain the customer responsibility.

Published claim

Signed control-mapping packs a customer activates for itself

RelixQ ships signed standards packs that relate cryptographic findings to customer-owned controls: NIST SP 800-53 Rev. 5, SP 800-171 Rev. 3, CSF 2.0, the HIPAA Security Rule, the AICPA Trust Services Criteria, ISO/IEC 27001 and 27002, PCI DSS v4.0.1, CNSA 2.0, and narrow sector packs. A pack contributes nothing until an organization owner activates it with a written statement of why it applies, and the signature is verified again at that moment. Control-mapping packs are non-blocking: they can warn but never fail a release. A pack that matches nothing reports insufficient evidence, which is never treated as a pass. No pack asserts that a regulation binds the customer or that a control is satisfied.

Documented practice
Scope
Standards packs, per-organization activation records, and per-finding verdicts in RelixQ SaaS. Excludes any determination of regulatory applicability, which remains with the customer.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer
  • Opt-in per organization
  • Written applicability statement required
  • Signature re-verified at activation
  • Non-blocking by design
  • Insufficient evidence is never a pass

Evidence

Design evidence

Pack content, signing, activation, and verdict rules are product source and test evidence. Availability in a given tenant follows the managed-service release, and production operating evidence is not yet claimed.

Review evidence artifacts
  • Signed pack manifests and detached signatures
  • Signature verification at registration and at activation
  • Per-organization activation record with applicability statement
  • Finding verdict records with override reasons

Framework context

  • NIST SP 800-53 Rev. 5, SP 800-171 Rev. 3, and CSF 2.0 (customer control packs)

    Customer evidence support — Signed packs relate finding evidence to SC-12, SC-13, SC-8(1), SC-28(1); 03.13.08, 03.13.10, 03.13.11; and PR.DS-01, PR.DS-02. Every mapping is background evidence for a customer control. None is an assessment result, an authorization, or a tier determination.

  • HIPAA Security Rule, 45 CFR § 164.312 (customer control pack)

    Customer evidence support — Relates finding evidence to the two addressable encryption specifications. Whether a system holds electronic protected health information is never visible to a scanner, so applicability is always the customer determination.

  • AICPA Trust Services Criteria CC6.1 and CC6.7 (customer control pack)

    Customer evidence support — Relates a customer finding to criteria the customer is examined against. This is product content for a customer SOC 2 program. It is unrelated to RelixQ vendor assurance, and RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001 and 27002, PCI DSS v4.0.1, and sector packs (customer control packs)

    Customer evidence support — ISO controls are cited by identifier only. PCI DSS maps Requirement 4 alone, because the other requirements are process obligations a scanner cannot observe. Sector packs cover financial services, government and critical infrastructure, UAE instruments, and ETSI quantum-safe reports.

  • NSA CNSA 2.0

    Technical alignment — A control-mapping pack and six dated algorithm profiles from 2025 to 2035. Citation and verdict content only; nothing asserts that CNSA 2.0 binds the scanned organization.

Published claim

A citation catalog that says what it does not map

RelixQ maintains a catalog of 204 standards, regulations, and guidance documents. A reference is mapped to detection rules only when it names something a scanner can observe, such as an algorithm, a key length, a mode, or a protocol; 34 are mapped on that basis. 138 are deliberately left unmapped, including principles-based instruments such as GDPR, NIS2, DORA, LGPD, and POPIA, because matching them to rules would be a guess. An organization selects one of eight compliance regions to scope which citations it sees. The region is a display filter and is never a determination that a regulation applies.

Documented practice
Scope
The standards citation catalog, its rule mappings, its generated coverage report, and the organization compliance-region setting.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer
  • Global
  • United States
  • Canada
  • European Union and United Kingdom
  • Middle East
  • Asia-Pacific
  • Latin America
  • Africa

Evidence

Design evidence

The counts are taken from the generated coverage report, and each record carries a verification flag and date. Nine records are marked unverified because the issuing body blocks automated retrieval, and unverified records are never mapped.

Review evidence artifacts
  • Generated citation coverage report
  • Per-record verification flag and date
  • Documented reason for every unmapped record
  • Organization compliance-region setting

Framework context

  • NIST SP 800-131A, 800-57, 800-56A/B, 800-38A/D, 800-52, 800-208, and national guidance

    Technical alignment — Mapped to detection rules because each names an algorithm, key length, mode, or protocol. National guidance covers BSI TR-02102, ANSSI PG-083, CCCS ITSP.40.062 and .111, CRYPTREC LS-0001, NCA NCS-1:2020, and ICP-Brasil DOC-ICP-01.01.

  • NIST IR 8547 — Initial Public Draft

    Technical alignment — Draft transition guidance used for planning context. It is not represented as a final NIST publication.

  • Customer security and resilience programs

    Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

Published claim

RelixQ vendor assurance roadmap

SOC 2 Type II, ISO/IEC 27001, independent penetration testing, continuity testing, CAIQ, and expanded security questionnaires are roadmap work. Achieved reports or certifications will be published only with exact scope, period, and issuing party.

Roadmap
Scope
RelixQ managed SaaS vendor controls and independent assurance program.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer

Evidence

Not available

No completed SOC 2 Type II report or ISO/IEC 27001 certificate is claimed.

Framework context

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

Documented controls, operating evidence, independent testing, and formal assurance appropriate to enterprise procurement.

Roadmap work is not a completed examination, certification, penetration test, or contractual warranty.

Published claim

Certifications not claimed

RelixQ does not currently claim SOC 2 completion or ISO/IEC 27001 certification. Product standards support and customer evidence mappings must not be read as vendor certification.

Not claimed
Scope
Public procurement, sales, Trust Center, and compliance representations.
Last reviewed
Evidence owner
Assurance program owner
Approval role
Executive and legal reviewer

Evidence

Public summary

The non-claim is explicit and reviewable.

Review evidence artifacts
  • Public assurance status
  • Certification claim boundary

Framework context

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Publication boundary

Status applies only to the scope and evidence shown above.

This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .