AICPA Trust Services Criteria / SOC 2
Assurance roadmapControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Trust Center
Public summaries stay open. Detailed questionnaires, architecture material, contractual documents, and available assessment evidence are shared only when appropriate and approved.
Evidence posture
Availability and disclosure scope are confirmed per requester and document.
Framework relationships
Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
Security, data, AI, reliability, compliance, subprocessor, scanning, and disclosure summaries remain accessible without a document request.
Evidence
Public summaryThe public Trust Center is the evidence artifact.
Framework context
No framework relationship is asserted for this claim.
Published claim
Completed questionnaires, detailed architecture, contractual material, and independent reports are shared only when available, appropriate, and approved for the requester.
Evidence
Gated evidenceEach document retains an owner, status, scope, review date, and access decision.
Framework context
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
A request does not imply that a report, certification, completed questionnaire, or contractual term exists. RelixQ confirms availability, current status, disclosure scope, and any required agreement before delivery.
Evidence
Operational evidenceRequest status and disclosure decisions are recorded.
Framework context
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Published claim
Raw penetration-test findings, secrets, detailed network topology, incident runbooks, exploit instructions, customer data, and internal remediation records are not public website assets.
Evidence
Public summaryThe public exclusion boundary is explicit.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Gated request catalog
This is a catalog of request types, not a public document room. No sensitive artifact is stored behind a guessable website URL, and preparing a request does not grant access or promise that an artifact is available.
A scoped response for qualified customer security and procurement evaluations, including the control owner and evidence boundary where applicable.
The response is prepared for the requester and may require clarification of the questionnaire, product scope, and review deadline.
A review track for data-processing terms, customer roles, approved service scope, and applicable transfer or privacy requirements.
A request starts commercial and legal review. A public draft or request acknowledgement is not an executed agreement.
An approved discussion of the managed SaaS architecture, tenant boundaries, service flows, and security responsibilities.
Sensitive topology, secrets, exploit detail, customer information, and internal runbooks are never distributed from the public website.
Current public service-provider information plus clarification for the products, regions, and customer-enabled integrations in scope.
The public Trust Center currently provides a service-provider summary. RelixQ confirms the approved register and applicable contractual scope during review.
A scoped review of relevant data classes, deletion paths, backup expiry, contractual requirements, and legal-preservation exceptions.
The approved policy and customer agreement control. The request process does not create a new retention commitment.
Applicable independent testing, audit, or assessment material whose scope and reporting period have been verified for disclosure.
Availability varies by artifact and period. Disclosure may require a qualified evaluation, confidentiality terms, redaction, or a guided review.
Publication boundary
This public page describes the controlled-access process. It does not assert that every requested artifact exists or can be disclosed. The catalog entry was last reviewed on .