Company-wide governance

Trust Hub

HEOSSI's governance layer for security, responsible AI, cryptographic assurance, privacy, legal requirements and evidence across every HEOSSI solution.

Tentative: Q4 2026 or Q1 2027 · Subject to funding

Our Compliance Frameworks

HEOSSI has selected three standards for its focused assurance programme. Work is planned; no certification, validation or conformity assessment is currently represented as complete.

HEOSSI (PTE.) LTD. owns and administers the company compliance programme and is the prospective certificate holder. BEE, QNSI, and other HEOSSI solutions may be included within the documented organisational or technical scope; they are not separate certificate holders.

ISO/IEC 27001:2022

Information Security

HEOSSI plans to evaluate and align its information security management system against this standard.

Management-system implementation and independent certification readiness

ISO/IEC 42001:2023

AI Governance & Safety

HEOSSI plans to develop and maintain its AI management system against this standard.

AI governance implementation and independent certification readiness

ISO/IEC 19790:2025

Cryptographic Module Security

HEOSSI plans to evaluate technically applicable core cryptographic modules against this standard.

Module-level validation or conformity assessment when an appropriate route is available

ISO/IEC 27001 and ISO/IEC 42001 are management-system standards. ISO/IEC 19790 applies to cryptographic modules and is therefore pursued at the applicable module boundary, not as a company-wide management-system certificate. Timelines remain subject to scope, readiness, budget and independent assessor availability.

Internal framework posture; accredited certification and independent conformity assessment are not currently claimed. ISO/IEC 19790 applies only to specifically identified cryptographic modules or components.

Evidence-led assurance

Claims follow issued evidence

Policies, mappings and readiness work support assurance, but they are not certificates. HEOSSI will update public status only after the relevant independent evidence has been issued and its scope has been confirmed.

Review the assurance programme

Defined scopes, asset and system inventories

Risk, control and evidence registers

AI governance, impact and lifecycle records

Cryptographic module boundaries and test evidence where applicable

Internal review, corrective-action and management-review records

Independent assessment evidence when issued

Governance library

Policies and legal controls

These materials define HEOSSI's operating expectations and disclosure boundaries. They do not independently constitute certification.

Request trust materials

Qualified customers, partners and investors may request scoped security, governance and diligence materials following an initial fit discussion and, where appropriate, confidentiality arrangements.

trust@heossi.com