FEHA Logo
FEHA

FEHA International Consulting B.V

Welcome to FEHA

AI-Powered Security & Compliance Platform for Startups and SMBs

At FEHA, we believe that security and compliance should be proactive, continuous, and scalable — not a one-time checkbox.

That's why we've built a modern, AI-powered platform to help growing businesses around the world stay secure, audit-ready, and compliant with local and global standards. 


Security as a Culture, Not Just a Tool

At FEHA, we don't just build tools, we help shape your organization's security culture. 
 

Contact us
contact@feha.io
IT Services & Consulting
ISO 27001:2022 Certified
ISO 42001:2023 Certified

Completed Compliance

Frameworks verified by consultant

ISO 27001:2022

ISO 27001:2022

123 measures implemented

ISO 42001:2023

ISO 42001:2023

70 measures implemented

Resources

Responsible Disclosure Policy

This policy encourages security researchers and users to report vulnerabilities in FEHA’s systems responsibly and in good faith. Outlines safe channels for disclosure and ensures reporters will not face legal action if they follow the guidelines.

Approved at 24th Feb, 2026 at 05:48:42
Public

AI Governance Policy

This AI Governance Policy establishes a structured framework for the ethical and responsible development, deployment, and use of Artificial Intelligence (AI) within FEHA.

Approved at 2nd Jul, 2026 at 11:39:40
Public

FEHA ISO 27001 Certificate

ISO 27001 Certificate demonstrates our commitment to maintaining a robust Information Security Management System (ISMS) and protecting information assets through a systematic, risk-based approach to information security.

Approved at 13th Aug, 2026 at 08:22:44
Public

In Progress Compliance

This score is determined through an assessment performed by our FEHAGRC Consultant tes.

PDPASingaporeCOMPLIANCEMONITOREDBY FEHA

PDPA Singapore

11 of 30 measures implemented

SOC 2COMPLIANCEMONITOREDBY FEHA

SOC 2

46 of 121 measures implemented

1 Measures

Encryption / Cryptography

Encryption Policy
1 Measures

Correction

Nonconformity and Corrective Action Register
2 Measures

Internal Audit

Internal Audit Programme
Internal Audit Report
2 Measures

Business Continuity

Business Continuity Plan
Disaster Recovery Plan
3 Measures

Incident Management

Tabletop Exercise
Incident Report
Incident Response Plan
3 Measures

Vulnerability Management

Threat Assessment Report
Vulnerability Scanning Report
Penetration Testing Report
2 Measures

Source Code

Code of Conduct
Access Control Configurations for Source Code Repositories
1 Measures

Secure Development

Software Development Life Cycle
2 Measures

Backups

Information Backup Policy
Clock Synchronization Documentation
1 Measures

Endpoint Security

Device Configuration Standards or Baselines
2 Measures

Data Masking

Data Masking Documentation
Data Masking Policy
1 Measures

Secure Authentication

Multi-Factor Authentication (MFA) Implementation Records
4 Measures

Logging & Monitoring

Logging and Monitoring Policy
Performance Test Results
Monitoring activities documentation
2 Measures

Network Security

Network Diagram
Network Security Policy
3 Measures

Access Control

Records of Privileged Account Inventory
Access Reviews Documentation
Access Control Policy
3 Measures

Data Protection

Data Classification Policy
Data Protection Policy
Retention Schedule
2 Measures

Inventory

Asset Management Policy
Asset Register
2 Measures

Remote Working

Examples of Security Reminders
Remote Working Policy
2 Measures

Training

Certifications and Qualifications
Training Records
1 Measures

Onboarding/Offboarding

Acceptable Use Policy
2 Measures

Recruitment

Template Employment Contract
Personnel Background Verification
2 Measures

Objectives

Information Security Objectives
AI Objective Action Plan
1 Measures

Management Documentation

Management Review Meeting
2 Measures

Change Management

Change Request Forms / Change Log
Change Management Policy
3 Measures

Risk Management

Risk Assessment Policy
Risk Assessment Input
Risk Assessment Report
6 Measures

Interested Parties

Register of Interested Parties and Their Requirements
Customer Contracts/SLAs
List of contact special interest groups
2 Measures

Legal & Regulatory

Applicable Laws and Regulations
List of relevant authorities
2 Measures

Roles & Responsibilities

RACI Matrix
Organizational Charts
4 Measures

Management System Documentations

Internal Communications
Context Analysis Document
Statement of Applicability