Records for the AI that watches your security
Inventory, measure and control each detector, with a person deciding.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| GOVERN 1.6 | An AI system inventory. | Detector states. → |
| MAP 3.5 | Human oversight defined. | Authorization outcomes. → |
| MEASURE 2.5 | Validity and reliability shown. | Replay measures. → |
| MANAGE 2.4 | Systems superseded or disengaged. | Recorded rollback. → |
| MANAGE 4.1 | Post-deployment monitoring. | Telemetry health beside each finding. → |
Inventory
Know every detector and its state
Cyberdroid AI Detection runs 21 detectors. Each is disabled, shadow or production, and promotion and rollback are recorded.
Oversight
Keep a person in the decision
Cyberdroid AI Investigation records every request as Task, Pending approval, Refused or Rate-limited, with an operation id and a reason. Approval and delivery are separate authorities.
Measurement
Measure before you promote
Shadow findings go to a separate channel, and replay measures precision, recall, stability and volume. Every finding shows observed value, baseline, score, threshold and evidence timeline.
Control
Roll back a detector
Any detector returns to shadow or disabled, and the change is recorded.
Residency
Keep inference in your environment
Inference runs in your environment by default. Any external fallback is a policy you set and can see.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
MAP 1.1
Intended context of use. That is your organization’s own work.
MAP 5.1
Likelihood and size of impacts. That stays with your risk assessment.
GOVERN 6.1
Third-party AI documentation. ARRTECH does not yet publish documentation for its models.
Data provenance
Training data sources. ARRTECH does not yet publish model sources.
By rule
Naming a clause is not a claim of certification.
GOVERN 1.6
Maintain an inventory of AI systems. ARRTECH: 21 detectors, each disabled, shadow or production.
MAP 3.5
Define and document processes for human oversight. ARRTECH: every AI Investigation request recorded with an outcome and a reason.
MEASURE 2.5
Demonstrate that the system is valid and reliable. ARRTECH: replay measures precision, recall, stability and volume.
MANAGE 2.4
Mechanisms to supersede, disengage or deactivate AI systems. ARRTECH: promotion and rollback recorded per detector.
MANAGE 4.1
Monitor AI systems after deployment. ARRTECH: each finding shows telemetry health beside it.
Questions
Is the AI RMF mandatory?
No. NIST says it is intended for voluntary use.
Does inference leave our environment?
Not by default. Any external fallback is a policy you set and can see.
Is AI Investigation available?
In early access. It requires Cyberdroid AI Detection.
Does AI close a case on its own?
No. Delegated work ends in review, and a person decides.
Sources
Guide
What is the NIST AI RMF?
A voluntary NIST framework for managing the risks of AI systems, organized as Govern, Map, Measure and Manage.
What is AI 600-1?
The NIST profile that applies the AI RMF to generative AI, published in July 2024.
Is there an AI RMF certification?
No. The framework is voluntary and nobody certifies against it.
Next steps

Every detector on the record. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Every request on the record. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.