Skip to main content
RelixQ
Menu
Trust CenterData
Trust Center
Public summaryData map under review

Trust Center

Know what data enters RelixQ and why.

RelixQ separates customer-operated submissions, managed repository processing, product telemetry, and customer-controlled integration egress within the SaaS service.

Access
Public
Scope
Customer content, finding metadata, submitted artifacts, managed repository scans, telemetry, integrations, retention, deletion, and residency.
Last reviewed
Aug 17, 2026
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer
Evidence posture
Gated evidence

Evidence posture

Gated evidence

Gated artifacts

The public data-flow summary is available; the final production data inventory, retention schedule, and contractual terms remain under review.

Evidence artifacts

  • Public data-flow summary
  • Processing inventory
  • Retention schedule draft
  • DPA and subprocessor review

Framework relationships

Alignment is not the same as certification.

AICPA Trust Services Criteria / SOC 2

Assurance roadmap

Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

ISO/IEC 27001

Assurance roadmap

Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Customer security and resilience programs

Customer evidence support

RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

Claim register

Public wording tied to evidence and review state.

Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.

Published claim

Two collection paths into RelixQ SaaS

Customer-operated CLI and CI workflows can submit findings and selected artifacts without deploying the RelixQ service. Separately, a customer-authorized repository connection lets RelixQ SaaS retrieve source for the requested managed scan.

Documented practice
Scope
CLI and CI submissions plus customer-authorized managed repository connections.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer
  • Submission occurs only when instructed
  • Managed source access requires customer authorization
  • Scope and provenance remain attached
  • The RelixQ service remains managed SaaS

Evidence

Public summary

The two processing paths and their different source-handling boundaries are explicitly documented.

Review evidence artifacts
  • Public collection-path description
  • Submission contract
  • Connected-source workflow

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • Customer security and resilience programs

    Customer evidence supportRelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

Published claim

Finding and artifact minimization

Normalized findings carry the location, classification, confidence, and matched evidence needed for investigation. Customers choose which supported artifacts to submit; managed-source processing follows the authorized connection scope.

Documented practice
Scope
Finding records, matched evidence snippets, SBOM and CBOM artifacts, reports, and managed scan inputs.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer

Evidence

Design evidence

Schemas and collection contracts identify expected data fields and provenance.

Review evidence artifacts
  • Finding schema
  • Artifact contracts
  • Managed connector scope model

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

Published claim

Credentials and secrets

Repository, identity, destination, service, and API credentials are intended to be scoped, referenced through managed secret handling, masked from ordinary display, rotated or revoked when required, and separated from non-secret connection records. Exact provider and rotation evidence remains under review.

Under review
Scope
Customer-provided integration credentials, service credentials, API keys, signing material, and administrative secrets used by RelixQ SaaS.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer

Evidence

Gated evidence

Secret-reference design and credential lifecycle evidence are restricted to approved review.

Review evidence artifacts
  • Credential field inventory
  • Secret-reference model
  • Masking and revocation behavior
  • Rotation evidence review

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Storage and encryption boundaries

RelixQ targets encrypted transport and managed encryption for supported SaaS storage and backups. Storage services, key ownership, cryptographic configuration, field-level treatment, and backup coverage must be verified against the production data inventory before stronger wording is published.

Under review
Scope
Customer content, findings, reports, configuration, credentials, logs, artifacts, queues, caches, and backups processed by RelixQ SaaS.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer

Evidence

Gated evidence

The storage and cryptographic data map is under production review.

Review evidence artifacts
  • Storage-service inventory
  • Transport and storage configuration review
  • Key ownership map
  • Backup encryption review

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Residency and international transfers

Supported processing regions, data-residency options, remote support locations, backup locations, transfer mechanisms, and customer-choice boundaries will be published only after infrastructure and contract review.

Roadmap
Scope
Customer personal data and customer content processed, stored, backed up, or accessed across regions by RelixQ and applicable providers.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer

Evidence

Not available

Final residency commitments and transfer-mechanism statements are not yet published.

Framework context

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

A region and transfer matrix aligned to the production architecture, subprocessor register, DPA, backups, and support model.

A planned region or architecture does not create a current residency or transfer commitment.

Published claim

Deletion, retention, and backup expiry

Account, source-processing, finding, report, integration, log, support, and backup retention periods require an approved schedule. Deletion behavior must state what is deleted immediately, what expires asynchronously, and what remains for legal, security, or backup purposes.

Roadmap
Scope
Customer content, findings, reports, logs, integration records, support material, deleted accounts, and backups.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer

Evidence

Not available

The final retention schedule, deletion workflow, and backup-expiry evidence are not yet published.

Framework context

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

An approved retention schedule, customer deletion workflow, legal-hold boundary, and tested backup-expiry process.

The target policy is not a contractual deletion deadline until approved and incorporated into the applicable agreement.

Published claim

Support and operational access

Customer-content access by RelixQ personnel or approved providers is intended to be limited to authorized support, security, reliability, or legal needs with role restrictions and reviewable activity. Exact approval, masking, emergency-access, and review controls remain under evidence review.

Under review
Scope
RelixQ workforce and approved provider access to customer content, findings, reports, configuration, and service telemetry.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer

Evidence

Gated evidence

Support-access roles, approvals, and audit evidence require production confirmation.

Review evidence artifacts
  • Support-role matrix
  • Access approval workflow
  • Administrative audit events
  • Emergency-access review

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • AICPA Trust Services Criteria / SOC 2

    Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Published claim

Customer exports and privacy requests

RelixQ intends to support governed customer exports and a documented process for applicable access, correction, deletion, and other privacy requests. Available formats, identity verification, tenant authorization, response scope, and timelines remain under product, privacy, and legal review.

Roadmap
Scope
Customer-authorized data exports and applicable requests concerning personal data processed through the website or RelixQ SaaS.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer

Evidence

Not available

A complete export and privacy-request operating record is not yet published.

Framework context

  • Customer security and resilience programs

    Customer evidence supportRelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

  • ISO/IEC 27001

    Assurance roadmapInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.

Roadmap distinction

Documented export formats, authorization checks, privacy-request intake, identity verification, fulfillment, exception handling, and audit records.

The roadmap does not create a response deadline beyond applicable law or an executed agreement.

Published claim

Customer-controlled integration egress

Source, identity, SIEM, observability, ticketing, alerting, chat, email, webhook, and AI-provider data flows occur only when the corresponding customer connection or feature is enabled.

Customer configured
Scope
Customer-enabled third-party connections and destination routing.
Last reviewed
Evidence owner
Privacy and data-governance owner
Approval role
Privacy and legal reviewer

Evidence

Operational evidence

Connection scope, credentials, routing, and delivery outcomes are represented as governed SaaS records.

Review evidence artifacts
  • Connection configuration
  • Routing policy
  • Delivery history
  • Credential-reference state

Framework context

  • NIST Cybersecurity Framework 2.0

    Vendor control mappingControl-language mapping for buyer review; not a certification.

  • Customer security and resilience programs

    Customer evidence supportRelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.

Publication boundary

Status applies only to the scope and evidence shown above.

This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .