Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Join Identity Week America to explore secure credentials, biometrics, and digital identity solutions while connecting with industry experts. Save 20% on your ticket with code CSASAVE20

CSA STAR Registry

Security, Trust, Assurance, and Risk Registry

Listings for FEHA International B.V.

Listings for FEHA International B.V.

FEHA is a technology company that provides an integrated ecosystem for risk and compliance management. Our suite includes multi-framework compliance platforms, AI-driven audit assistants, third-party risk management (TPRM), and technical security monitoring tools. FEHA aims to democratize risk and compliance management and achieve continuous compliance efficiently.

3rdcomply

Makes managing third-party cybersecurity risks easier, reducing manual tasks by up to 90%

Listed Since: 2026-04-22

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

FEHA GRC

Simplifies and centralizes cybersecurity and privacy compliance across global and local regulations.

Listed Since: 2026-04-22

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

GuardRisk

Provides intelligent tools for IT auditors and GRC professionals.

Listed Since: 2026-04-22

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

TraceRisk

Uses AI to filter out irrelevant threats and improve security monitoring.

Listed Since: 2026-04-22

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).