Summary of all required licenses, registrations, privacy frameworks, security standards, and filing obligations as of March 24, 2026. Supporting certificates and documentation are held in the Compliance subfolder of the secure data room.
US Federal Corporate Tax (FY2025) — extension filed
Future
Q4 2026 / 2027
SOC 2 Type II audit initiation (post-Scale Round)
Future
March 1, 2027
Delaware Franchise Tax (FY2026)
Future
2027+
ISO 27001 evaluation
Business Licenses & Registrations
Delaware C-Corporation Registration
State of Delaware · USA
Active
Next Deadline / Cadence
Annual franchise tax — March 1, 2027
Notes & Evidence Location
Corporation in good standing. Certificate on file. Annual franchise tax filing due March 1 each year.
Foreign Qualification — Other States/Provinces
State / Provincial Authorities · TBD
Not yet required
Next Deadline / Cadence
— (as applicable)
Notes & Evidence Location
No current requirement for foreign qualification outside Delaware. Review triggered at first US office or employee hire.
Privacy & Data Protection
GDPR (General Data Protection Regulation)
EU Data Protection Authorities · European Union
Compliant
Next Deadline / Cadence
Ongoing — annual policy review
Notes & Evidence Location
Privacy Policy and Terms of Service drafted with GDPR compliance. No EU office or DPO required at current scale. DPA agreements in place for processors (OpenAI, Stripe). Annual review cadence.
CCPA (California Consumer Privacy Act)
California AG / CPPA · USA — California
Compliant
Next Deadline / Cadence
Ongoing — annual policy review
Notes & Evidence Location
CCPA disclosures included in Privacy Policy. Opt-out mechanisms in place. Review triggered annually or upon material change in data practices.
PIPEDA / Canadian Privacy Law
Office of the Privacy Commissioner of Canada · Canada
Compliant
Next Deadline / Cadence
Ongoing
Notes & Evidence Location
Canadian privacy obligations addressed in Privacy Policy. Breach notification obligations noted.
Apple App Store Privacy Nutrition Labels
Apple Inc. · Global
Complete
Next Deadline / Cadence
Update required with each material data practice change
Notes & Evidence Location
Privacy nutrition labels submitted and approved with iOS app. Updated at each app release when data practices change.
EU AI Act Compliance (Transparency)
EU AI Office · European Union
In progress
Next Deadline / Cadence
Q3 2026 — compliance review
Notes & Evidence Location
Mira AI transparency and human oversight requirements being assessed. No high-risk AI classification expected. Formal compliance review planned Q3 2026.
Security & Infrastructure Standards
SOC 2 Type II
AICPA — Independent Auditor · USA / Global
Planned — not yet initiated
Next Deadline / Cadence
Q4 2026 or 2027
Notes & Evidence Location
SOC 2 audit planned for post-Scale Round when enterprise B2B contracts require it. Evidence collection (access logs, policies, monitoring) begins Q2 2026. Auditor TBD.
ISO 27001 (Information Security)
ISO Certification Body (TBD) · Global
Not yet — future roadmap
Next Deadline / Cadence
2027+ target
Notes & Evidence Location
ISO 27001 certification not planned for 2026. Will be evaluated at Series A scale. Internal information security policies drafted and maintained.
PCI DSS (Payment Card Industry)
PCI Security Standards Council · Global
Compliant via Stripe
Next Deadline / Cadence
Annual SAQ / attestation via Stripe
Notes & Evidence Location
VIBEUP processes payments exclusively through Stripe, which is PCI Level 1 certified. VIBEUP does not store, transmit, or process raw card data directly. Stripe handles PCI scope. Annual SAQ-A or equivalent as applicable.
HTTPS / TLS Encryption
Internal / Infrastructure Provider · All
Active
Next Deadline / Cadence
Certificate renewal — auto-managed
Notes & Evidence Location
All platform traffic encrypted via TLS 1.2+. SSL certificates managed via infrastructure provider. Auto-renewal enabled.
App Store & Platform Compliance
Apple App Store Review Guidelines
Apple Inc. · Global
Compliant — app approved
Next Deadline / Cadence
Ongoing — each app release
Notes & Evidence Location
iOS app reviewed and approved. Compliance maintained per Apple Human Interface Guidelines and App Store Review policies.
Google Play Developer Policies
Google LLC · Global
Compliant — app approved
Next Deadline / Cadence
Ongoing — each app release
Notes & Evidence Location
Android app reviewed and approved. Compliance maintained per Google Play Developer Program policies.
Financial & Tax Filings
US Federal Corporate Income Tax (Form 1120)
IRS · USA
Current
Next Deadline / Cadence
October 15, 2026 (FY2025) — extension filed
Notes & Evidence Location
Annual federal corporate return due October 15, 2026 (extension filed). Prepared by QINVST financial strategy team.
Delaware Franchise Tax
State of Delaware · USA
Current
Next Deadline / Cadence
March 1 annually
Notes & Evidence Location
Franchise tax calculated using Assumed Par Value Capital Method. Filed and paid by General Counsel.
Sales Tax / VAT / GST Registration
Various · USA / Canada / EU (as applicable)
Pre-revenue
Next Deadline / Cadence
Q3 2026 — threshold review
Notes & Evidence Location
No sales tax or VAT obligation at current pre-revenue stage. Registration thresholds to be monitored from June 2026 revenue launch. Review triggered at $10K+ monthly revenue per jurisdiction.
All current team members on contractor agreements. 1099-NEC forms issued for US contractors. Cyprus and Canadian contractors comply with local requirements.
Employment Law Compliance (Future FTEs)
Applicable State / Federal Authorities · TBD at hiring
Not yet applicable — all contractors
Next Deadline / Cadence
At first FTE hire (planned Q2 2026)
Notes & Evidence Location
All current engagements are contractor-based. Full employment compliance framework (workers' comp, payroll tax, benefits) to be established prior to first FTE hire.
Compliance Ownership
Regulatory and compliance oversight is the responsibility of Pat Veilleux, General Counsel (ex-Shopify Senior Counsel), in coordination with QINVST (financial filings) and the Director of Technology (security standards). Certificates, licenses, and supporting documents are maintained in the Compliance subfolder of the data room. Contact pat@vibeup.io for access.
Compliance Subfolder: Certificates, filed returns, privacy policies, App Store approvals, and security attestations are filed in the Compliance subfolder of the secure data room. Placeholders marked above will be updated as documents are obtained. Access via luke@vibeup.io under NDA.