⚖️ Compliance Roadmap
Compliance Roadmap
Effective date: 17 August 2026 · Version 1.4
This page lists the regulatory, legal and operational requirements that touch (or could touch) the Seedfor project, along with how Seedfor handles each requirement today in its pre-launch / pre-incorporation phase and the trigger that will activate the next obligation plus the planned action. The companion Terms of Use and Privacy Notice contain the binding user-facing legal copy; this page is an internal-style transparency document for prospective partners, regulators and contributors.
Status — Pre-launch, pre-incorporation. Seedfor is operated as a research project by an individual operator pending choice of incorporation jurisdiction. No regulated financial, payment, e-money, investment, crypto-asset, lending or insurance service is offered in any market. Every "Today" item below should be read in that context. The "Plan" items describe what Seedfor will do once a home jurisdiction is selected and the relevant trigger fires — they are not commitments to a specific regime.
Conventions used in this page: TODAY = current state · TRIGGER = the event that activates the next step · PLAN = what Seedfor will do when the trigger fires.
01 —Entity & Corporate Housekeeping
Becoming a legal entity, choosing the jurisdiction, filing the imprint
Incorporation
TodaySeedfor operates as a project on a pre-launch, pre-incorporation basis run by an individual operator. Privacy §02 and Terms §02 disclose the pre-incorporation status. No revenue is taken; no regulated service is offered in any market.
TriggerFirst paid user, first material partnership, first equity / token raise — whichever comes first.
PlanIncorporate the operating entity in the chosen home jurisdiction under the appropriate corporate form (private company limited by shares / SRL / SpA / LLC / Ltd / equivalent). Update Privacy §02, Terms §02 and every footer imprint with: registered name, registered office, the local company-registry identifier (e.g. REA / Companies House / DIFC / ADGM number), tax identifier, share capital, certified electronic mail or equivalent. File the constitutional documents with the competent registry; set up tax + accounting; appoint a statutory auditor if the relevant size threshold is crossed.
Jurisdiction selection
TodayThe home jurisdiction is intentionally kept open. Candidate hubs under review include EU/EEA member states, the United Kingdom, Switzerland, Singapore, the UAE (DIFC / ADGM), and selected common-law and offshore centres. No public commitment has been made and this Roadmap is deliberately jurisdiction-agnostic.
TriggerTerm sheet, founder agreement, or first material partnership / regulator interaction that requires jurisdictional clarity.
PlanComparative analysis of candidate jurisdictions against: (i) corporate-tax and R&D-credit regime, (ii) crypto-asset / fintech authorisation track record and timing (e.g. MiCA CASP in the EU; FCA cryptoasset registration / future regime in the UK; FINMA in CH; MAS PSA in Singapore; VARA / DFSA / FSRA in the UAE), (iii) talent and banking access, (iv) IP holding structure and double-tax treaty network, (v) substance requirements and operating-cost profile. Lock the choice before any third-party commitment and update this page accordingly.
Imprint & statutory filings
TodayEmail contact and pre-incorporation status disclosed in Privacy §02 and Terms §02. No full imprint card yet — the formal imprint waits on incorporation in the chosen jurisdiction.
TriggerIncorporation date.
PlanPublish the full imprint required by the local equivalent of the EU eCommerce Directive (2000/31/EC) — i.e. legal name, registered office, company-registry identifier, tax identifier, contact channel and (where applicable) director list — linked from every footer. Update the lead-supervisory-authority line in Privacy §02 to reflect the home-jurisdiction data-protection authority. Evaluate voluntary appointment of a Data Protection Officer or equivalent — not mandatory at current scale but useful once the user count grows.
02 —Financial-Services Perimeter (Candidate Regimes)
Frameworks Seedfor must stay outside until it is authorised under whichever regime applies in the chosen home jurisdiction or in any market it actively targets. The EU regime is described in the most detail because most of the published research is produced under European data and methodology conventions, but every item flags the equivalent obligation in other candidate hubs.
Two-pool architecture — SRT classification, token offering & the read-only layer
TodaySRT (Risk Transfer). The SRT is a parametric, reference-triggered risk-transfer instrument keyed to a risk index — not to the realised losses of an identified loan pool. It is therefore not a securitisation (no tranched underlying pool) and, being parametric with no indemnity of actual loss, not insurance; economically it is a derivative (or, tokenised and fungible, a transferable security) — i.e. a MiFID financial instrument, which sits outside MiCA (Art. 2(4)(a)) on the MiFID / Prospectus track rather than the CASP track. Insurance-vs-derivative and transferable-security-vs-OTC-derivative are participant-level classifications (the latter drives EMIR treatment).
TodayTokens (SfC / SdT / SfT). Seedfor's own utility / governance tokens are non-economic (identity, fee-currency, vote-weight — no yield, profit-share or distribution; see the counsel brief token stack) and are offered solely to qualified investors — the MiCA Art. 4 exemption route. This is enforced on-site as an acquire gate (sfd_investor_class, documented in Privacy §12) that blocks acquisition by non-qualified users and blurs the actionable buy surfaces until the wallet is verified.
TodayRead-only layer. The website reads public on-chain state and displays it; it never constructs, routes, or signs a transaction — enforced at source by a write kill-switch (the live signer is gutted). Users transact from their own wallets, directly against the contracts. Accordingly Seedfor performs no MiFID investment service (no reception/transmission, dealing on own account, placing, or MTF/OTF operation) and no MiCA CASP service. SeCR is a substitutable risk-analytics feed; the settlement pricing reference is external / user-configurable, so Seedfor does not administer a settlement benchmark (EU Benchmarks Regulation).
TriggerDecision to (i) let the site itself construct / route / sign transactions, (ii) offer SfC / SdT / SfT beyond qualified investors, (iii) make SeCR the mandated settlement reference for the SRT, or (iv) launch a live SRT distribution or a secondary trading venue.
PlanObtain the per-market legal opinion confirming (a) the SRT's financial-instrument classification and its EMIR treatment (securitised transferable security vs bilateral OTC derivative), (b) the qualified-investor offering exemption for the tokens, and (c) that the read-only + self-custody architecture keeps Seedfor outside investment-services and CASP authorisation. Where any on-site placing / dealing / venue function is later added, obtain MiFID authorisation or operate under an authorised partner (tied-agent / outsourcing). Retain the write kill-switch and the qualified-investor gate until those authorisations and offering documents are in place.
MiFID II / MiFIR — investment services and investment research
TodayNo investment service is offered (reception/transmission/execution of orders, portfolio management, investment advice, underwriting, placing, MTF/OTF operation). The four published charts are research demonstrations only; the disclaimers in Terms §08 ("Not investment research") and the help-tip on each chart make this explicit. No personalised recommendations are generated.
TriggerDecision to (i) take orders from users, (ii) manage portfolios, (iii) publish personalised buy/hold/sell recommendations, (iv) operate a trading venue.
PlanApply for MiFID II authorisation (or use an authorised partner under a tied-agent / outsourcing arrangement). Adopt the COBS-equivalent conduct rules, suitability / appropriateness assessments, best-execution policy, complaints handling, and product-governance (POG) framework. Move the research output behind the Delegated Regulation (EU) 2016/958 "investment research" exemption controls if applicable.
MiCA — Regulation (EU) 2023/1114
TodayNo crypto-asset is issued, exchanged, custodied or managed for users. The tokens, mint-token, lendingmarket, ai-marketplace and dao pages are pre-launch demonstrations behind a "WIP / unlock" overlay. Terms §09 explicitly disclaims any regulated crypto-asset activity in the EU. Note: whitepaper.html is positioned as a product / technical paper for prospective partners; it is NOT a MiCA Art. 6 issuer white paper. A MiCA-compliant issuer paper (Annex I content for crypto-assets other than ART/EMT, Annex II/III for ART/EMT) would be prepared separately if and when the trigger fires.
TriggerDecision to (i) issue a SeCR-linked token or any other crypto-asset, (ii) operate a trading platform, (iii) custody crypto-assets for users, (iv) operate portfolio management or advice on crypto-assets, (v) place / receive / transmit crypto-asset orders.
PlanClassify the instrument (utility-token vs ART vs EMT in the EU; payment / utility / security token under FINMA; "specified investment" / "qualifying cryptoasset" under FCA; digital payment token / capital-markets product under MAS; virtual asset under VARA / FSRA / DFSA) with a legal opinion in each market that will be marketed into. EU route: if ART/EMT, publish a MiCA-compliant white paper, secure issuer authorisation, and build the reserve / redemption / governance rights required by Titles III / IV; if operating a crypto-asset service, apply for CASP authorisation under MiCA Art. 59 in the chosen EU home Member State and passport across the EEA under Art. 65. Equivalent routes if the home jurisdiction sits outside the EU: FCA registration / future-regime authorisation in the UK; FINMA category-specific authorisation in Switzerland; MAS Payment Services Act / Securities and Futures Act in Singapore; VARA / DFSA / FSRA virtual-asset rules in the UAE, etc. Whichever route is taken, the operational controls (capital, custody segregation, market-abuse prevention, complaints, ICT resilience) are broadly equivalent.
DORA — Regulation (EU) 2022/2554
TodayNot in scope (DORA applies only to listed categories of financial entity). Operationally, Seedfor already maintains an audit-log / rate-limit / signed-JWT stack on the access portal (described in Privacy §13), which is broadly consistent with DORA's ICT-risk-management spirit.
TriggerThe day Seedfor becomes a regulated financial entity (CASP, payment institution, e-money institution, investment firm, AIFM, credit institution, etc.).
PlanImplement the five DORA pillars: (1) ICT risk-management framework signed off by the board, (2) ICT-related incident classification + reporting to the lead competent authority, (3) digital operational resilience testing programme (incl. TLPT every 3 years if classified as significant), (4) ICT third-party risk register + DORA contract clauses with every cloud/ICT provider, (5) information-sharing arrangements. Start a lightweight ICT third-party register today so it doesn't have to be reconstructed retroactively.
Prospectus Regulation — Regulation (EU) 2017/1129
TodayNo transferable securities are offered to the public. Pre-launch fundraising (if any) will use exempt private-placement channels (qualified investors / fewer than 150 non-qualified investors per Member State / minimum-denomination > €100k).
TriggerDecision to make a public offering of equity, bonds, convertible instruments, or a token classified as a "transferable security" under MiFID II Art. 4(1)(44).
PlanObtain legal opinion on the classification of the instrument. If a transferable security: prepare and file the appropriate prospectus / offering document with the competent authority of the home jurisdiction (e.g. an EU Prospectus or EU Growth Prospectus approved by the local NCA; an FCA-approved prospectus in the UK; a FINMA-recognised prospectus in Switzerland; the equivalent registration in the chosen common-law jurisdiction). Comply with the parallel marketing-communication rules and ongoing-disclosure regime (insider lists, manager-transactions, ad-hoc disclosure under MAR or the local equivalent).
Benchmarks Regulation (BMR) — Regulation (EU) 2016/1011
TodayThe SeCR and the per-cluster default-rate / Excess Credit Premium series are illustrative model outputs published for research and discussion. Terms §08 explicitly disclaims any benchmark status. No financial contract is priced off these values; no UCITS or AIF measures performance against them.
TriggerFirst counterparty (asset manager, bank, structured-product issuer) wants to reference the SeCR contractually. The announced SeCR-oracle subscription (a signed per-cluster feed sold to fund instances, shown as a demo on Pool Settings) is this trigger in product form: selling the feed contractually requires the plan below before launch.
PlanApply for BMR authorisation as a benchmark administrator (or transfer administration to an authorised partner). Implement a benchmark statement, methodology document with input-data / hierarchy / discretion controls, oversight committee, conflict-of-interest policy, complaints-handling procedure, code of conduct for input-data submitters, transition / cessation policies. ESMA register filing.
PSD2 / PSD3 — payment services
TodaySeedfor does not route funds, initiate payments, hold customer money, or issue payment instruments. The Marketplace and Lending pages are pre-launch demonstrations only.
TriggerDecision to facilitate money movement between users, payment initiation, account information services, or e-money issuance.
PlanPartner with a regulated Payment Institution or Electronic Money Institution under an agent / distributor model — avoid in-house authorisation unless volume justifies it. If in-house: apply for PI / EMI authorisation under PSD2 (or PSD3 once in force), implement SCA, safeguarding of client funds, incident reporting under EBA RTS.
AML / CFT — Regulation (EU) 2024/1624, Directive (EU) 2024/1640, Travel Rule (Reg. 2023/1113)
TodayNo obliged-entity activity. KYC / KYB pages on the platform are unwired placeholders — see sfd_kyc_status in Privacy §12, and the explicit "no identity verification occurs at this stage" disclaimer.
TriggerFirst on-boarding of a real user into a regulated workflow (CASP customer, lending borrower, payment-flow recipient).
PlanAdopt a proportional AML programme aligned to the home-jurisdiction obliged-entity regime (EU AMLR/AMLD6 + AMLA; UK MLR 2017 + JMLSG guidance; FINMA AMLO + AMLA in CH; MAS PSN02 / NRA in Singapore; CBUAE / DFSA / FSRA / VARA rules in the UAE; FinCEN BSA + state MTL in the US). Common components in every regime: business-wide risk assessment, customer due diligence (standard / simplified / enhanced), beneficial-owner identification (UBO), ongoing transaction monitoring, sanctions screening at on-boarding and periodically, suspicious-transaction reporting to the relevant FIU. For crypto-asset transfers in any regime, implement Travel Rule-equivalent originator / beneficiary information sharing (Reg. (EU) 2023/1113 in the EU; FATF Recommendation 16 elsewhere). Designate an AML officer / MLRO; train all staff annually.
EU AI Act — Regulation (EU) 2024/1689
TodaySeedfor uses AI-assisted features (business-model classifier, multiplier rescaling between primary-source anchors, partial methodology drafting). None constitute a "high-risk AI system" under Annex III. The Art. 50 transparency duty is honoured: each feature is labelled in the help-tip texts and in Terms §10, and in Privacy §15. The announced Beat AI SbT (work-in-progress on the Who page) surfaces an AI-selected strategic option explicitly for human challenge — human-in-the-loop by design; it enters the same Art. 50 labelling regime, per Terms §10, before it ships.
TriggerAdoption of a feature that meets the Annex III criteria — e.g. (i) AI system used to evaluate the creditworthiness of natural persons for the purpose of granting credit (Annex III §5(b)), (ii) biometric identification, (iii) AI used for recruitment, etc.
PlanRun the Annex III gap analysis before launching the feature. If high-risk: implement risk-management system (Art. 9), data-and-data-governance controls (Art. 10), technical documentation (Art. 11 / Annex IV), record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy / robustness / cybersecurity (Art. 15), conformity assessment with notified body, CE marking, EU database registration. Maintain a lightweight "AI usage register" today (model, vendor, training-data note, human-review step) so it's ready when an auditor asks.
Prudential framework — Basel III / CRR / CRD (no direct application today)
TodaySeedfor is not a credit institution, investment firm or insurance undertaking, so the Basel III framework (transposed in the EU via Regulation (EU) 575/2013 "CRR" and Directive 2013/36/EU "CRD") does not apply. The ACRB and SeCR constructs are described as protocol-level risk reserves, not regulatory capital. No counterparty bank currently relies on the ACRB for credit-risk mitigation (CRR Part Three Title II Chapter 4) or significant-risk-transfer relief (CRR Art. 244–245).
Trigger(i) Seedfor itself applies for credit-institution / investment-firm authorisation; (ii) a regulated bank counterparty seeks to treat ACRB cover as eligible unfunded credit protection under CRR Art. 213–217; (iii) a securitisation-style structuring of credit exposures references the SeCR for tranche pricing or for significant risk transfer (BCBS Standards on the revised securitisation framework — BCBS d393, July 2016).
PlanShould any trigger above crystallise: align the ACRB documentation with the eligibility criteria for unfunded credit protection (CRR Art. 213) and with the recognition rules in the Basel III post-crisis reforms package (BCBS d424, December 2017); for any securitisation use-case, follow the simple-transparent-standardised criteria of Regulation (EU) 2017/2402 and the related EBA Guidelines on the STS criteria for non-ABCP and ABCP securitisations (EBA STS guidelines hub); for IFRS 9 expected-credit-loss interaction with the ACRB, follow the EBA Guidelines on credit institutions' credit risk management practices (EBA/GL/2017/06). Equivalent frameworks in other candidate hubs: UK CRR / PRA Rulebook; FINMA Capital Adequacy Ordinance (CAO) in CH; MAS Notice 637 in Singapore; CBUAE / DFSA / FSRA capital rules in the UAE.
03 —Home-Jurisdiction Housekeeping (to be determined)
Local-law obligations that crystallise once the home jurisdiction is chosen — listed as generic categories rather than tied to a specific regime, so the page does not pre-commit to any of the candidate hubs.
Domestic licensing perimeter (banking / investment / payment / insurance)
TodayNo "banking business", "deposit-taking", "investment service", "consumer-credit", "payment service" or "insurance distribution" is conducted in any market. Terms §09 disclaims regulated activity across the EU, UK, Switzerland, the US, Canada, Singapore and any other jurisdiction with an analogous regime.
TriggerMirrors the §02 triggers — once Seedfor crosses an authorisation threshold in §02, the equivalent domestic regime in the chosen home jurisdiction bites.
PlanAuthorisation by the relevant domestic regulator (e.g. an EU NCA + ESMA / EBA passport for cross-border activity; the FCA / PRA in the UK; FINMA in Switzerland; MAS in Singapore; CBUAE / SCA / DFSA / FSRA / VARA in the UAE; the SEC / FINRA / CFTC + state regulators in the US). Enrolment in the appropriate registers; adoption of the regulator's conduct rules; appointment of a compliance officer / MLRO; capital and governance arrangements as required.
eCommerce / Information-Society-Service disclosure
TodayOperator identification (email + reference to pre-incorporation status) is disclosed in Privacy §02 and Terms §02. The Website is free-tier and does not transact.
TriggerIncorporation date in the chosen home jurisdiction. Launch of the announced private-credit fund SaaS (B2B software subscriptions per the Pool Settings demo) makes this concrete: commercial availability requires the full disclosure set, VAT treatment and professional-client subscription terms.
PlanPublish the full set of mandatory operator information required by the local equivalent of Article 5 of the EU eCommerce Directive 2000/31/EC (legal name, registered office, company-registry identifier, tax identifier, electronic contact, supervisory body where applicable). Add an accessible imprint card linked from every footer.
Consumer protection
TodayNo paid transaction with consumers occurs. Mandatory consumer rights are nevertheless preserved by Terms §13 / §14 / §19 (no exclusion of unavoidable liability; EU and other-jurisdiction consumer-protection carve-out).
TriggerCharging consumers for any product / service (subscription, marketplace fees, premium analytics, etc.). Launch of the announced Beat AI mechanic (staked rewards, outcome-contingent payouts) additionally triggers a prize-promotion / prize-competition review — free-to-enter by design, but national prize and gambling statutes vary by jurisdiction (see Terms, “Announced — not yet offered”).
PlanUpdate Terms with the pre-contractual information required by the home-jurisdiction consumer-protection regime (e.g. EU Consumer Rights Directive 2011/83 + the Italian Codice del Consumo / French Code de la consommation / UK Consumer Rights Act 2015 / the UAE Consumer Protection Law / Singapore CPFTA — whichever applies). Add the relevant right-of-withdrawal information, implement a complaints-handling channel, and file with the home-jurisdiction online-dispute-resolution mechanism if any.
Data-protection supervisory authority
TodayThe Privacy Notice (v2.3) identifies a lead supervisory authority commensurate with the operator's current residence. The cookies / localStorage table in Privacy §12 is comprehensive and re-versioned on every change.
TriggerIncorporation in a different jurisdiction; any new feature that collects new categories of personal data, introduces a new processor, or changes a retention period.
PlanRe-confirm the lead data-protection authority for the chosen home jurisdiction (e.g. the relevant EU member-state DPA under GDPR Art. 56; the ICO in the UK; the FDPIC in Switzerland; the PDPC in Singapore; the UAE Data Office or the relevant free-zone equivalent). Update Privacy §02 and §09. Maintain the Privacy Notice as the single source of truth — every new sf_* key, processor or retention setting updates §03, §06, §08, §12 before deployment.
04 —Cross-Border & Marketing Triggers
Triggers and plans for every market into which Seedfor may actively market or onboard users, irrespective of the home-jurisdiction choice. Each item describes the local marketing / regulated-activity boundary that bites as soon as Seedfor targets that market.
UK — FCA financial-promotions regime (FSMA s.21 + cryptoasset FinProm 2023)
TodayNo UK-targeted marketing is conducted. The Website is reachable from the UK but does not solicit UK users for any regulated product. Terms §09 disclaims UK regulated activity.
TriggerFirst UK-targeted campaign for a crypto-asset, financial instrument, or related service.
PlanApproval of every UK financial promotion by an FCA-authorised person under FSMA s.21, with the four-route framework (authorised firm, exempt person, registered cryptoasset firm with FCA approval, MLR-registered firm). Add the FCA risk warning, 24-hour cooling-off period, and appropriateness assessment for cryptoasset promotions per FCA PS23/6 (October 2023) and any subsequent policy statements / consultation outcomes published in the FCA's cryptoasset-promotions work plan — verify the latest position on the FCA website before any UK-targeted campaign.
US — Howey + Reves tests on any tokenised credit product
TodayNo token is offered or sold. The Website is reachable from the US but does not solicit US residents for any token or security. Terms §09 disclaims US regulated activity; §12 includes a sanctions-screening representation.
TriggerDecision to offer a token to US persons.
PlanLegal opinion on Howey (investment contract) and Reves (note) tests. If a security: register under the Securities Act of 1933 or rely on Reg D (private placement), Reg S (offshore), Reg A+ (mini-IPO), or Reg CF (crowdfunding) — with the corresponding investor / disclosure / resale restrictions. Geofence US visitors out of the issuance flow until cleared by counsel. Evaluate FinCEN money-services-business registration and state money-transmitter licensing on a per-state basis (see below).
US — state money transmitter licences (BSA / state law)
TodaySeedfor does not move money for US users.
TriggerAny feature that moves customer funds in or out of US states (fiat or crypto).
PlanPartner with a US-licensed PI / money transmitter that has the state-by-state coverage (e.g. Stripe Treasury, Modern Treasury, or a regulated crypto on-ramp). Avoid in-house state-by-state licensing unless volume justifies the multi-year cost. Register with FinCEN as MSB if classified as money transmitter; comply with BSA / OFAC / state AML programmes.
Switzerland — FinSA / FinIA
TodayNo CH-targeted marketing or product offer. Terms §09 disclaims Swiss regulated activity.
TriggerFirst Swiss user on-boarded into a regulated workflow, or first product offer to Swiss retail.
PlanFINMA classification of any token (security / payment / utility) per FINMA's ICO guidelines. Apply FinSA conduct rules for the offer of financial instruments (KIDs, suitability/appropriateness). If portfolio-management activity: FinIA authorisation under SROs or directly with FINMA.
Singapore — MAS PSA / SFA
TodayNo SG-targeted marketing or product offer. Terms §09 disclaims regulated activity in Singapore.
TriggerFirst SG user onboarded into a regulated workflow, or first product offer to Singapore retail / accredited investors.
PlanClassify under the MAS Payment Services Act 2019 (digital-payment-token service) or the Securities and Futures Act 2001 (capital-markets product), as applicable. Apply for the corresponding licence (Major Payment Institution licence under PSA; CMS licence under SFA); appoint a resident director and a compliance officer; align AML programme to MAS PSN02 and the NRA.
UAE — VARA (Dubai) / DFSA (DIFC) / FSRA (ADGM) / SCA (federal)
TodayNo UAE-targeted marketing or product offer. Terms §09 disclaims regulated activity in the UAE and its free zones.
TriggerFirst UAE user onboarded, first product offer to UAE residents, or any establishment of a UAE-based affiliate / operations entity.
PlanMap the activity to the right authority and rulebook: VARA in onshore Dubai for virtual-asset services (issuance, custody, exchange, transfer, broker-dealer, management, advisory); DFSA in the DIFC free zone (investment business, money services, crypto-token regime); FSRA in the ADGM free zone (financial-services permissions + virtual-asset framework); SCA at federal level for non-free-zone investment activity; CBUAE for payment and stored-value-facility activity. Secure the relevant permission before any commercial launch and align AML programme to CBUAE / DFSA / FSRA / VARA expectations.
Other markets (Canada, Hong Kong, Japan, Australia, Brazil, India, MEA & LATAM hubs)
TodayNo active marketing or product offer in any of these markets. Terms §09 disclaims regulated activity in every jurisdiction with an analogous regime.
TriggerFirst targeted campaign or first user onboarded from the market into a regulated workflow.
PlanLocal-counsel opinion before any market entry. Map the activity to the local regime (CSA / OSC + provincial regulators in Canada; SFC / HKMA in Hong Kong; FSA / JFSA in Japan; ASIC / AUSTRAC in Australia; CVM / BACEN in Brazil; SEBI / RBI in India; and the equivalent authority in any other target market). Either secure local authorisation, operate under a recognised exemption, or geofence the market until cleared.
05 —Privacy & Data Protection
GDPR, processors, Web3 personal data, eIDAS 2
GDPR — Regulation (EU) 2016/679
TodayThe Privacy Notice v2.3 (effective 7 June 2026) covers data categories, purposes, legal bases, recipients, transfers (SCCs), retention, rights, complaints, security, AI-assisted features, user-submitted content, and forward-looking statements. The lead supervisory authority will be confirmed on incorporation in line with §03 above.
TriggerAny new feature collecting new personal data categories, any new processor, any new retention setting, any change in cross-border transfer mechanism.
PlanRe-version the Privacy Notice (v2.x → v2.y) on every such change; refresh the cookies / localStorage table; re-sign DPAs / SCCs with the processor; conduct a transfer-impact assessment when a new third-country transfer is introduced; consider a DPIA under Art. 35 when the change is large-scale, sensitive, or systematic.
Web3 personal data — EDPB Guidelines 06/2024
TodayNo on-chain personal-data processing occurs. Privacy §16 foreshadows a dedicated Web3 addendum prior to any wallet / token launch.
TriggerFirst feature that writes to a public chain or accepts a wallet address from a user.
PlanPublish the Web3 addendum, applying EDPB Guidelines 06/2024 on personal data on blockchains: keep personal data OFF-chain where possible, use hashed identifiers / commitments on-chain, document the impossibility of erasure / rectification on immutable ledgers, justify under Art. 17(3)(b) GDPR (legal obligation) where applicable, design rotation of pseudonymous identifiers, and prefer permissioned-write / zero-knowledge solutions for sensitive data.
eIDAS 2 / European Digital Identity Wallet (EUDIW) — Reg. (EU) 2024/1183
TodayNot yet used. KYC pages are placeholders.
TriggerDecision to integrate EUDIW for KYC, KYB, or qualified-signature workflows.
PlanOnboard as a Relying Party in the EUDIW framework; pass the LSP (Large-Scale Pilot) acceptance test; align attribute requests to the minimum-disclosure principle (proof-of-age, proof-of-domicile, etc.); store no more than the verifiable presentation hash where business logic does not require the full attribute set.
Data Processing Agreements (DPAs) with processors
TodayActive DPAs / SCC-Module-2 are in place with Vercel, Beehiiv, Resend, Upstash, hCaptcha and Google Workspace (see Privacy §06 for the full table).
TriggerA processor publishes a new SCC release, changes sub-processors, or has a transfer-impact-assessment-relevant change in its legal regime.
PlanRe-sign / re-accept the new SCC version within a reasonable period (typically < 90 days). Update Privacy §06 if recipients / locations / DPA links change. Subscribe to each processor's "trust" newsletter so changes are not missed.
06 —IP & Content
Database right, trademarks, open-source licences, DSA hosting-provider duties
Database-right — EU Directive 96/9/EC (and national implementations) + EU Open Data Directive 2019/1024
TodayThe calibrated chart-data files (/data/*.json) and the references registry are protected by database right by operation of law. No explicit per-file licence header is published yet.
TriggerFirst commercial re-use request from a third party, OR decision to publish the data under an open licence.
PlanAdd a top-level LICENSE file (CC-BY-4.0 for the methodology + chart-data, MIT for the code, "All rights reserved" for proprietary models). Per-dataset README.md with provenance, last-updated date, and a per-source licence notice. Update Terms §06 to reference the asserted database right.
Trademarks — "Seedfor", "SeCR", "ACRB", "SfT", "SdT", "SfC", "SeRT/SRT"
TodayUnregistered. Terms §06 asserts them as unregistered marks.
TriggerIncorporation and / or first commercial use / first launch announcement.
PlanSearch the EUIPO + UKIPO + USPTO + IPI registers for conflicting marks. File at least the EU word mark "Seedfor" via EUIPO; consider Madrid Protocol designation for UK / US / CH. File "SeCR" if the index is publicly named in any commercial offering.
Open-source licence inventory
TodayThe project bundles Chart.js (MIT), chartjs-plugin-annotation (MIT), Leaflet (BSD-2-Clause), Inter font (SIL OFL 1.1), and a small set of Vercel runtime dependencies. No SPDX header on Seedfor source files.
TriggerFirst external distribution of the source (open-sourcing a repo, embedding a Seedfor widget elsewhere).
PlanPublish a THIRD_PARTY_LICENSES.md at repo root listing every third-party dependency with its SPDX identifier and licence text reference. Add SPDX-License-Identifier: headers to Seedfor-authored .js / .html files. Run a Software Composition Analysis (SCA) job in CI.
Digital Services Act (DSA) — Regulation (EU) 2022/2065
TodayFlag-a-bug content is stored only in the user's own browser localStorage; no backend hosting yet, so the DSA hosting-provider liability and obligations do not bite.
TriggerThe day Flag-a-bug (or any user-comment feature) goes server-side, OR the day Dataroom uploads are accepted into a shared workspace.
PlanPublish a "notice and action" mechanism (Art. 16), a single point of contact for authorities (Art. 11) and users (Art. 12), terms-of-service amendments per Art. 14, a transparency report once a year (Art. 15). Designate a legal representative in the EU if Seedfor's establishment moves outside.
07 —Marketing & Forward-Looking Statements
Endorsement honesty, forward-looking language, newsletter compliance
Third-party endorsements / awards honesty
TodayThe landing-page footer references items such as "WEF Global Innovator 2026 / OECD SME Policy Platform / IFC SME Finance Forum / CoinDesk feature" inside a hidden ref-track block (kept for layout-CSS reasons). These read as third-party endorsements.
TriggerEither of: (i) any of these become genuinely granted — in which case update wording with verifiable date + URL; (ii) confirmation that they are not granted — in which case remove them.
PlanAudit every "as featured in / partner / award" claim across landing.html, aboutus.html and pitchdeck.html. Remove any unverifiable claim. For verifiable claims, link to the public source. Same audit for "Coming soon" provider logos (e.g. LinkedIn coming soon icon). This protects against defamation and unfair / misleading-commercial-practices risk under the home-jurisdiction consumer-protection regime — e.g. the EU Unfair Commercial Practices Directive 2005/29/EC and its national transpositions; the UK Digital Markets, Competition and Consumers Act 2024; the FTC Act §5 in the US; the equivalent provisions of Singapore CPFTA, the UAE Consumer Protection Law, etc.
Forward-looking statements (FLS)
TodayMultiple "Coming soon" and "Q3 2026" labels appear across the demonstration pages. Terms §09 contains an explicit FLS disclaimer ("inherently uncertain and should not be treated as predictions or commitments").
TriggerAny pitch deck, investor memo, press release, or public announcement that contains a forward-looking statement.
PlanEvery external document carries the same FLS disclaimer (one-paragraph safe-harbour). Avoid specific dates and quantitative targets unless internally committed. Distinguish "plan" from "commitment" in language.
Newsletter compliance (Beehiiv)
TodayWaitlist subscription uses a Beehiiv-embedded form (consent checkbox + double opt-in). Beehiiv is contractually obliged to provide unsubscribe links in every email. Privacy basis disclosed in Privacy §05.
TriggerFirst newsletter sent to subscribers (post-launch announcement).
PlanEach newsletter includes (i) a working unsubscribe link, (ii) the postal address of the operator (CAN-SPAM requirement for US subscribers; GDPR Art. 21(2) + ePrivacy Art. 13 right to object for EU/UK subscribers; equivalent rights under PDPA in Singapore, the UAE PDPL, etc.), (iii) a clear identification of the sender. Maintain consent records (date, source, IP, double-opt-in confirmation timestamp) for the GDPR / home-jurisdiction accountability principle.
08 —Cookies & Analytics
ePrivacy / strictly-necessary exemption + home-jurisdiction DPA cookie guidance + service workers
ePrivacy Art. 5(3) — strictly necessary exemption
TodayNo advertising, analytics, or cross-context behavioural-tracking cookies. The three first-party cookies (sf_otp, sf_auth, sf_status) are strictly necessary for the authenticated portal. The localStorage keys in Privacy §12 are user-preference / draft data. No cookie banner is shown — defensible under Art. 5(3).
TriggerAny decision to add a non-strictly-necessary cookie or storage technology (analytics, A/B testing, retargeting, fingerprinting, session-replay, advertising tags).
PlanImplement a granular consent banner (per-category opt-in, "Reject all" prominent, granular toggles, no dark patterns) compliant with the cookie / tracker guidance of the home-jurisdiction data-protection authority (e.g. EDPB Guidelines 03/2022 on deceptive design at EU level, plus each member-state DPA's national cookie guidance; ICO cookie guidance in the UK; PDPC advisory guidelines in Singapore; UAE Data Office guidance), and with TCF v2.2 if working with an ad-tech vendor. Block scripts until consent. Re-prompt on material change.
Home-jurisdiction DPA cookie / tracker guidance
TodayNot currently triggered (no non-essential tracker is loaded). The Privacy Notice §12 already mirrors the disclosure pattern expected by EU member-state DPAs (purpose, duration, HttpOnly flag) and is portable to the equivalent requirements of the ICO, the PDPC, the UAE Data Office, etc.
TriggerSame as the ePrivacy 5(3) trigger above.
PlanIn the consent banner: (1) "Accept all" + "Reject all" with equal prominence and same number of clicks, (2) no implicit consent through scroll / continued browsing, (3) max 6-month memory of the consent decision, (4) re-prompt on material change, (5) per-category granular controls, (6) easy revocation via a persistent "Cookie preferences" link in the footer.
Service workers + localStorage
TodayService worker is used for cache + offline + immediate security-fix propagation (described in Privacy §13). LocalStorage holds UI preferences and demo drafts only — never personal data of third parties.
TriggerAny service-worker or localStorage usage that goes beyond "strictly necessary".
PlanApply the same consent mechanism designed for cookies — service workers and localStorage count as "storage" under Art. 5(3) ePrivacy. Update Privacy §12 with any new key.
09 —Security & Incident Response
Breach notification, NIS2, baseline hygiene
GDPR Art. 33 — 72-hour breach notification
TodaySecurity controls in place: HMAC-SHA-256 signed JWTs, HttpOnly + Secure + SameSite=Strict cookies, IP-keyed brute-force counters, optional hCaptcha, audit logs with SHA-256-hashed email addresses, strict CSP. Breach-notification policy is described in Privacy §13 but no formal runbook published.
TriggerAny suspected personal-data breach (unauthorised access, accidental disclosure, loss of integrity / availability) — or a feature that materially increases the attack surface.
PlanAdopt an Incident Response Runbook: (1) Detection & classification within 24h, (2) containment + forensics, (3) impact assessment (data subjects, categories, risk level), (4) notification to the lead supervisory authority of the home jurisdiction via its online portal within 72h of awareness if risk-to-rights is established (GDPR Art. 33 in the EU/UK/CH; equivalent breach-notification clocks under PDPA in Singapore, the UAE PDPL, US state breach-notification laws, etc.), (5) notification to data subjects (Art. 34 / local equivalent) without undue delay if high risk, (6) post-mortem & control hardening within 30d. Maintain an incident register per Art. 33(5) / local equivalent.
NIS2 — Directive (EU) 2022/2555
TodayNot in scope (Seedfor is not classified as essential / important entity at current scale and sector). The 18 cybersecurity-risk-management measures of Art. 21 are nevertheless useful targets.
TriggerCrossing the medium-enterprise size threshold (≥50 employees or €10m turnover) AND operating in an Annex I or Annex II sector — currently neither applies.
PlanPre-emptively adopt the NIS2-Art-21 baseline: risk-analysis policy, incident-handling, business continuity, supply-chain security, vulnerability handling & disclosure, basic cyber-hygiene + training, cryptography & encryption policy, HR security, access control, MFA. Document the ICT third-party register (also useful for DORA when triggered).
Baseline hygiene (SCA / dependency scanning / secret scanning)
TodayNo automated SCA or secret scanning in CI; the dependency surface is small (Chart.js + plugins + Leaflet served from CDN).
TriggerAdding a server-side build pipeline OR self-hosting third-party libraries OR accepting external contributions.
PlanEnable GitHub Dependabot (already free) for dependency alerts, GitHub Secret Scanning + Push Protection, weekly SCA via Snyk / Trivy on the build, npm audit on every release, automatic CSP reporting endpoint. Publish a security.txt with vuln-disclosure contact (per RFC 9116).
10 —Operational Backlog
Housekeeping items that don't fit a regulatory category but matter for credibility. Target buckets: Pre-launch (before first public commercial activity), Year 1 (within 12 months of incorporation), Year 2+ (post-traction).
Footer placeholders
Today"Careers" has been renamed "Work With Us" and wired to management@seedfor.io. "Terms" links to terms.html. "Compliance" links to this page. "Media Center", "Contact", "FAQ" remain greyed-out placeholders.
TriggerWhen each feature has its own page / content / contact channel.
PlanEither build a real page (Contact form integrated with Resend, FAQ as a static page, Media Center as a press-resources hub) or remove the placeholder. No item should stay greyed-out indefinitely.
security.txt and humans.txt
TodayNeither file is published at the site root.
TriggerPublic launch.
PlanAdd /.well-known/security.txt per RFC 9116 with: Contact: mailto:management@seedfor.io, Preferred-Languages: en, it, Expires: …, optionally a PGP key, optionally a vulnerability-disclosure-policy URL. Add /humans.txt crediting contributors.
Email authentication — SPF / DKIM / DMARC
TodayOutbound email goes through Google Workspace and Resend; both publish SPF / DKIM records by default when domain ownership is verified. DMARC posture not yet audited.
TriggerFirst newsletter blast OR first reports of spoofing attempts against seedfor.io.
PlanVerify SPF + DKIM at the DNS layer (use dig or MX Toolbox), publish a DMARC record at p=none with rua=mailto:postmaster@seedfor.io, monitor reports for one quarter, escalate to p=quarantine then p=reject. Add BIMI later for inbox-branding once DMARC is at p=reject.
LICENSE + per-dataset README
TodayNo top-level LICENSE file; methodology documents carry copyright notices ("© 2026 Seedfor SRL — pre-incorporation").
TriggerFirst public source-code release, first commercial re-use request, or repo open-sourcing.
PlanAdd top-level LICENSE (CC-BY-4.0 for methodology + data; MIT for code). Per-dataset data/README.md with provenance, last-updated date, refresh cadence, contact for corrections.
"Coming soon" placeholders (LinkedIn, partner / award logos)
TodayVarious "coming soon" or hidden placeholder elements remain in the design (LinkedIn icon at the footer, the hidden ref-track block on the landing page).
TriggerWhen the resource actually exists (LinkedIn page published, partnership signed, award granted) — or when a comms / legal review confirms they cannot be substantiated.
PlanReplace each placeholder with a real link OR remove the element entirely. This protects against unfair-commercial-practices risk and avoids misleading prospective partners.