NIST Cybersecurity Framework 2.0
Vendor control mappingControl-language mapping for buyer review; not a certification.
Official referenceTrust Center
RelixQ welcomes good-faith reports that help protect customers and the SaaS service, within a process that is still being staffed and tested.
Evidence posture
The public reporting boundary is documented; response metrics and a secure-transfer workflow are not yet claimed.
Framework relationships
Control-language mapping for buyer review; not a certification.
Official referenceInformation-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
Email security@relixq.com with the affected surface, reproduction steps, impact, and supporting evidence. Do not include customer data, credentials, or secrets unless RelixQ provides an approved secure-transfer method.
Evidence
Public summaryThe mailbox is public; operational ownership and secure-transfer handling require final verification.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
Published claim
Limit testing to accounts and data you own, stop when customer or confidential data is encountered, avoid disruption and privacy impact, and allow reasonable investigation time before disclosure.
Evidence
Public summaryThe expected researcher boundary is publicly stated.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
Published claim
Acknowledgment, triage, remediation, and disclosure-coordination targets will be published only after the response process is staffed and tested.
Evidence
Not availableNo guaranteed response or remediation timeline is currently claimed.
Framework context
NIST Cybersecurity Framework 2.0
Vendor control mapping — Control-language mapping for buyer review; not a certification.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
A staffed intake, triage, communication, remediation, and coordinated-disclosure process with measured targets.
A target process is not a current SLA or guaranteed remediation date.
Published claim
This process does not promise a bounty, payment, safe-harbor outcome, or immunity for activity outside the stated good-faith scope.
Evidence
Public summaryThe non-claim is explicit.
Framework context
No framework relationship is asserted for this claim.
Publication boundary
This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .