AICPA Trust Services Criteria / SOC 2
Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Trust Center
RelixQ separates customer-operated submissions, managed repository processing, product telemetry, and customer-controlled integration egress within the SaaS service.
Evidence posture
The public data-flow summary is available; the final production data inventory, retention schedule, and contractual terms remain under review.
Framework relationships
Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
Customer-operated CLI and CI workflows can submit findings and selected artifacts without deploying the RelixQ service. Separately, a customer-authorized repository connection lets RelixQ SaaS retrieve source for the requested managed scan.
Evidence
Public summaryThe two processing paths and their different source-handling boundaries are explicitly documented.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Published claim
Normalized findings carry the location, classification, confidence, and matched evidence needed for investigation. Customers choose which supported artifacts to submit; managed-source processing follows the authorized connection scope.
Evidence
Design evidenceSchemas and collection contracts identify expected data fields and provenance.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Published claim
Repository, identity, destination, service, and API credentials are intended to be scoped, referenced through managed secret handling, masked from ordinary display, rotated or revoked when required, and separated from non-secret connection records. Exact provider and rotation evidence remains under review.
Evidence
Gated evidenceSecret-reference design and credential lifecycle evidence are restricted to approved review.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
RelixQ targets encrypted transport and managed encryption for supported SaaS storage and backups. Storage services, key ownership, cryptographic configuration, field-level treatment, and backup coverage must be verified against the production data inventory before stronger wording is published.
Evidence
Gated evidenceThe storage and cryptographic data map is under production review.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
Supported processing regions, data-residency options, remote support locations, backup locations, transfer mechanisms, and customer-choice boundaries will be published only after infrastructure and contract review.
Evidence
Not availableFinal residency commitments and transfer-mechanism statements are not yet published.
Framework context
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
A region and transfer matrix aligned to the production architecture, subprocessor register, DPA, backups, and support model.
A planned region or architecture does not create a current residency or transfer commitment.
Published claim
Account, source-processing, finding, report, integration, log, support, and backup retention periods require an approved schedule. Deletion behavior must state what is deleted immediately, what expires asynchronously, and what remains for legal, security, or backup purposes.
Evidence
Not availableThe final retention schedule, deletion workflow, and backup-expiry evidence are not yet published.
Framework context
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
An approved retention schedule, customer deletion workflow, legal-hold boundary, and tested backup-expiry process.
The target policy is not a contractual deletion deadline until approved and incorporated into the applicable agreement.
Published claim
Customer-content access by RelixQ personnel or approved providers is intended to be limited to authorized support, security, reliability, or legal needs with role restrictions and reviewable activity. Exact approval, masking, emergency-access, and review controls remain under evidence review.
Evidence
Gated evidenceSupport-access roles, approvals, and audit evidence require production confirmation.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
RelixQ intends to support governed customer exports and a documented process for applicable access, correction, deletion, and other privacy requests. Available formats, identity verification, tenant authorization, response scope, and timelines remain under product, privacy, and legal review.
Evidence
Not availableA complete export and privacy-request operating record is not yet published.
Framework context
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
Documented export formats, authorization checks, privacy-request intake, identity verification, fulfillment, exception handling, and audit records.
The roadmap does not create a response deadline beyond applicable law or an executed agreement.
Published claim
Source, identity, SIEM, observability, ticketing, alerting, chat, email, webhook, and AI-provider data flows occur only when the corresponding customer connection or feature is enabled.
Evidence
Operational evidenceConnection scope, credentials, routing, and delivery outcomes are represented as governed SaaS records.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Publication boundary
This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .