ASKTQ CONTROL READINESS REPORT Report date: September 22, 2026 Scope: AskTQ application Framework focus: SOC 2 readiness and SOX-style financial control alignment IMPORTANT STATUS STATEMENT This is an internal/public control-readiness report. It is not an independent SOC 2 examination report, CPA attestation, certification, or SOX audit opinion. IMPLEMENTED APPLICATION CONTROLS - Role-based restrictions for privileged administrative functions. - Server-side execution for sensitive manual subscription overrides. - Required business reason for manual subscription overrides. - Compliance audit log capturing actor, target, reason, before/after state, source, timestamp, and outcome for selected privileged/financial changes. - Affiliate approval conditioned on verified W-9 and accepted program terms. - 30-day affiliate commission validation hold and $100 minimum payout threshold. - Audit logging for affiliate W-9 review, approval, payout processing, cancellation, and payment. - Stripe webhook signature verification. - No affiliate commission on $0 trial invoices. - Self-referral prevention/rejection controls. - Security incident register. - User/admin record permissions across application entities. - Published Privacy, Responsible Technology, Terms, and Compliance pages. PARTIAL OR EXTERNAL-EVIDENCE AREAS - Infrastructure encryption, physical security, and hosting controls require provider evidence. - Formal MFA enforcement requires authentication-provider confirmation. - Uptime, backup restoration, disaster recovery, RTO/RPO testing, and continuity evidence require documented operating tests/provider evidence. - Independent vulnerability scanning and penetration testing evidence is not represented as completed. - Single-administrator operation does not provide full segregation of duties; independent periodic review is required. - Formal vendor risk review, recurring access certification, and incident-response exercises should be documented. SOC 2 Application-level controls support SOC 2 readiness. Formal SOC 2 status requires an independent CPA examination of the defined system and controls over an observation period. SOX AskTQ includes stronger financial-system controls around payment events, manual access/subscription changes, affiliate commission validation, payout processing, and audit evidence. Whether SOX legally applies depends on the reporting entity and use of the system. Formal SOX compliance also requires entity-level governance, financial reporting controls, testing, and management/auditor assessment outside this application. NEXT ASSURANCE STEPS 1. Obtain Base44 and other critical vendor security/compliance evidence. 2. Document quarterly access reviews. 3. Document backup/restore and disaster-recovery tests. 4. Perform an independent security risk assessment and penetration test. 5. Establish vendor risk management evidence. 6. Test the incident response plan. 7. Engage a qualified CPA firm for SOC 2 readiness and examination. 8. If SOX applies, have management and external auditors scope AskTQ within ICFR. Contact: asktq@tequionbrookins.com