# The Security Certification Gate
## Foreman receives trade secrets as data, and the company disclosed no certification
Foreman receives manufacturing parameters, defect records, standard operating procedures, equipment data and captured expert know-how. This is trade-secret data and not personal data. A leak has a very bad commercial effect for customers in semiconductor and electronics supply chains. Contracts in this sector have large liquidated-damages clauses.
| Framework | Why it matters | Status given |
| --- | --- | --- |
| ISO/IEC 27001 | Customers usually want it from suppliers in electronics and semiconductor supply chains. | None |
| SEMI E187 | Primary foundries cause the use of this cybersecurity standard for fab equipment. | None |
| SOC 2 Type II | US enterprise buyers want it. | None |
| ISO/IEC 42001 and adversarial-testing certifications | It is a new gate for buyers who know governance (see [[AI Agent Vertical SaaS DD MOC]]). | Not examined |
> [!warning] Missing structure
> A Foreman leader has cybersecurity as one duty. The company has no owned function for it. No document describes encryption, key management, role-based access, audit logging, penetration testing or dependency scanning.
## LLM risks
- **Attack through input documents**: the agents read procedures and PDFs. The agents can use tools, for example database queries. Guardrails help. A check must show that the credentials are read-only and that the tool allow-lists are in use.
- **Leakage between customers**: on single-tenant deployments the risk is structural. No document describes the risk for the hosted tiers or for the shared domain database.
- **External model APIs**: the question is if customer data goes to a third-party provider. The second question is which data goes there.
> [!important] Certification is a gate to sales
> For semiconductor-tier buyers and US enterprise buyers, certification is not paperwork. These buyers do not buy without certification. The usual sequence is ISO 27001 first for the home market. Then SOC 2 before the overseas sales.
## Why it matters
Cybersecurity is a condition for the customers of highest value in the pipeline. It also has an effect on each deployment. A certified platform layer that an auditor can examine needs the shared-codebase discipline. The claim of the company about the platform layer assumes this discipline. [[ISO Standards Security x DC]] gives the treatment of standards in the vault.
## Related
- [[Foreman MOC]]
- [[Deployment Model Versus Target Buyer]]
- [[Cyber Security Market]]