AskTQ Control Readiness Report
SOC 2 readiness and SOX-style financial control alignment for the AskTQ application environment.
Control matrix
What is implemented and what still needs external evidence.
SOC 2 readiness
AskTQ has application-level controls supporting the Security, Processing Integrity, Confidentiality, Privacy, and change/audit evidence objectives commonly examined in a SOC 2 engagement. Formal SOC 2 status requires an independent CPA examination of the defined system and controls over an observation period.
SOX-style financial controls
The application now includes stronger controls around payment events, manual subscription changes, affiliate eligibility, commission validation, payout processing, documented reasons, and audit trails. Whether SOX legally applies depends on the reporting entity and use of the system; formal compliance also requires entity-level governance, financial reporting controls, testing, and management/auditor assessment outside this application.
Next assurance steps
Before AskTQ should describe itself as SOC 2 compliant or certified, obtain infrastructure/security evidence from Base44 and other critical vendors, document access reviews and backup/restore testing, complete a risk assessment and vendor review, perform independent vulnerability/penetration testing, establish recurring incident-response testing, and engage a qualified CPA firm for a SOC 2 readiness review and examination. If SOX applies to a reporting entity using AskTQ, have management and the external auditor determine the system's role in internal control over financial reporting.
Security or compliance questions: asktq@tequionbrookins.com