Compliance & Controls

AskTQ Control Readiness Report

SOC 2 readiness and SOX-style financial control alignment for the AskTQ application environment.

Status: Control-aligned and audit-readiness work in progress. This page is not an independent SOC 2 examination report, CPA attestation, certification, or SOX audit opinion.
Report date
September 22, 2026
Scope
AskTQ application
Framework focus
SOC 2 + SOX-style controls

Control matrix

What is implemented and what still needs external evidence.

Access control
Implemented
Role-based admin restrictions are enforced for privileged functions. Sensitive administrative changes use server-side functions rather than direct client writes.
Privileged change logging
Implemented
A dedicated compliance audit log records actor, target, reason, before/after state, source, timestamp, and outcome for selected privileged and financial changes. Audit records are append-only at the application permission layer.
Subscription override control
Implemented
Manual subscription overrides require administrator access and a documented business reason, and are executed server-side with audit evidence.
Affiliate financial controls
Implemented
Affiliate approval requires verified tax documentation and accepted terms. Payouts use a 30-day validation period, $100 minimum threshold, documented payout states, and audit logging for processing, cancellation, and payment.
Payment integrity
Implemented
Stripe webhook processing requires signature verification. $0 trial invoices do not create affiliate commissions, and refund/payment validation is performed before commission approval.
Self-referral / fraud controls
Implemented
Self-referrals are blocked or rejected where affiliate and purchaser identities match, with fraud status retained on referral records.
Incident register
Implemented
A restricted security incident register exists for documenting severity, systems/data affected, containment, root cause, corrective actions, and closure.
Privacy + user scoping
Implemented / partial
The application uses user-scoped and admin-scoped record permissions for many data entities and publishes privacy and responsible-technology information. Infrastructure-level encryption and hosting controls require provider evidence.
Availability + disaster recovery
External evidence required
Application build validation is performed, but formal uptime evidence, backup restoration testing, disaster-recovery objectives, and infrastructure continuity controls require hosting-provider evidence and documented operating tests.
Vulnerability management + penetration testing
External evidence required
Independent penetration testing, recurring vulnerability scanning evidence, remediation SLAs, and third-party security testing are not represented as completed by this report.
MFA / identity assurance
External evidence required
Application role controls are implemented. Organization-wide MFA enforcement and identity-provider evidence must be confirmed at the hosting/authentication layer.
Segregation of duties
Partial
Sensitive changes are logged and reason-gated. A single-administrator operating model cannot provide full segregation of duties; independent periodic review is still required.

SOC 2 readiness

AskTQ has application-level controls supporting the Security, Processing Integrity, Confidentiality, Privacy, and change/audit evidence objectives commonly examined in a SOC 2 engagement. Formal SOC 2 status requires an independent CPA examination of the defined system and controls over an observation period.

SOX-style financial controls

The application now includes stronger controls around payment events, manual subscription changes, affiliate eligibility, commission validation, payout processing, documented reasons, and audit trails. Whether SOX legally applies depends on the reporting entity and use of the system; formal compliance also requires entity-level governance, financial reporting controls, testing, and management/auditor assessment outside this application.

Next assurance steps

Before AskTQ should describe itself as SOC 2 compliant or certified, obtain infrastructure/security evidence from Base44 and other critical vendors, document access reviews and backup/restore testing, complete a risk assessment and vendor review, perform independent vulnerability/penetration testing, establish recurring incident-response testing, and engage a qualified CPA firm for a SOC 2 readiness review and examination. If SOX applies to a reporting entity using AskTQ, have management and the external auditor determine the system's role in internal control over financial reporting.

Security or compliance questions: asktq@tequionbrookins.com