# The Security Certification Gate ## Foreman receives trade secrets as data, and the company disclosed no certification Foreman receives manufacturing parameters, defect records, standard operating procedures, equipment data and captured expert know-how. This is trade-secret data and not personal data. A leak has a very bad commercial effect for customers in semiconductor and electronics supply chains. Contracts in this sector have large liquidated-damages clauses. | Framework | Why it matters | Status given | | --- | --- | --- | | ISO/IEC 27001 | Customers usually want it from suppliers in electronics and semiconductor supply chains. | None | | SEMI E187 | Primary foundries cause the use of this cybersecurity standard for fab equipment. | None | | SOC 2 Type II | US enterprise buyers want it. | None | | ISO/IEC 42001 and adversarial-testing certifications | It is a new gate for buyers who know governance (see [[AI Agent Vertical SaaS DD MOC]]). | Not examined | > [!warning] Missing structure > A Foreman leader has cybersecurity as one duty. The company has no owned function for it. No document describes encryption, key management, role-based access, audit logging, penetration testing or dependency scanning. ## LLM risks - **Attack through input documents**: the agents read procedures and PDFs. The agents can use tools, for example database queries. Guardrails help. A check must show that the credentials are read-only and that the tool allow-lists are in use. - **Leakage between customers**: on single-tenant deployments the risk is structural. No document describes the risk for the hosted tiers or for the shared domain database. - **External model APIs**: the question is if customer data goes to a third-party provider. The second question is which data goes there. > [!important] Certification is a gate to sales > For semiconductor-tier buyers and US enterprise buyers, certification is not paperwork. These buyers do not buy without certification. The usual sequence is ISO 27001 first for the home market. Then SOC 2 before the overseas sales. ## Why it matters Cybersecurity is a condition for the customers of highest value in the pipeline. It also has an effect on each deployment. A certified platform layer that an auditor can examine needs the shared-codebase discipline. The claim of the company about the platform layer assumes this discipline. [[ISO Standards Security x DC]] gives the treatment of standards in the vault. ## Related - [[Foreman MOC]] - [[Deployment Model Versus Target Buyer]] - [[Cyber Security Market]]