NIST Cybersecurity Framework 2.0
Vendor control mappingControl-language mapping for buyer review; not a certification.
Official referenceTrust Center
Review the RelixQ SaaS reliability design, continuity roadmap, incident communication approach, and the service commitments that are not yet claimed.
Evidence posture
Architecture summaries are public; detailed recovery, incident, and availability evidence is shared only after testing and approval.
Framework relationships
Control-language mapping for buyer review; not a certification.
Official referenceControl mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
RelixQ is delivered as managed SaaS and is designed for monitored service health, bounded failure handling, queue and delivery observability, and controlled change.
Evidence
Design evidenceThe architecture and health surfaces can be reviewed, but no uptime percentage is inferred from design.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Published claim
Backup coverage, restoration procedures, recovery objectives, backup expiry, and recovery testing remain roadmap commitments until they are approved and exercised against the production data map.
Evidence
Not availableApproved recovery objectives and completed recovery-test evidence are not yet published.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
Approved backup scope, recovery objectives, restoration runbooks, and periodic recovery tests.
Planned recovery capabilities do not create a current RTO, RPO, uptime, or durability commitment.
Published claim
The roadmap includes severity classification, named response ownership, evidence preservation, customer communication criteria, post-incident review, and a public status channel.
Evidence
Not availableResponse targets and tested incident evidence are not yet published.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
A staffed, tested incident process with approved notification criteria and response targets.
The roadmap is not a guaranteed response or notification timeline.
Published claim
RelixQ does not claim a public uptime percentage, service credit, recovery objective, or support response SLA on this page. Applicable commitments must be stated in an approved order form, SLA, or Enterprise agreement.
Evidence
Public summaryThe absence of a public SLA claim is explicit.
Framework context
Contractual service commitments
Not applicable — Only an executed agreement can establish service-level obligations.
Publication boundary
This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .