Records for your assessment that prove themselves
Collect, sign and keep the logs PCI DSS asks for, and see plainly what stays with you.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| PCI DSS 10.2.1 | Audit logs enabled on every system component. | Status and last read time per source. → |
| PCI DSS 10.3.4 | Log data cannot change without an alert. | A signature chain that breaks on change. → |
| PCI DSS 10.5.1 | At least 12 months of log history. | Retention set per source. → |
| PCI DSS 10.7.2 | Failed security controls detected and alerted. | A silent-source alert. → |
| PCI DSS 12.5.2 | Scope confirmed, with every place card data sits. | DLP discovery by classification. → |
| PCI DSS 12.10.1 | An incident response plan ready to activate. | A playbook execution history. → |
Integrity
Prove nobody changed your logs
ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.
Retention
Keep a year of log history
PCI DSS asks for at least 12 months of audit log history. In ARRTECH SIEM, retention is set per source or per group. Archived logs stay searchable and export as CSV or files.
Completeness
Show every source is still sending
An assessor asks whether the logs are complete. The Data Sources page shows each source’s status, last read time and a silent-source alert, so a missing source is visible before your assessor finds it.
Discovery
Find card data before you set scope
You cannot scope what you have not found. ARRTECH DLP discovery scans endpoints, file servers and SQL databases and inventories what it finds. Card numbers are checked by algorithm, not only matched by pattern.
Response
Respond with a person deciding
ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits. Your incident response plan stays yours.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
PCI DSS 3.5.1
Stored card numbers made unreadable. DLP company-key encryption is not claimed as validated cryptography. The record comes from your storage encryption.
PCI DSS 8.4.2
MFA for all access into the cardholder data environment. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.
PCI DSS 10.6.1
System clocks synchronized. No ARRTECH product sets or records time synchronization. The record comes from your time servers’ configuration.
By rule
Naming a clause is not a claim of certification.
PCI DSS 10.2.1
Audit logs enabled and active for all system components. ARRTECH: the Data Sources page shows each source’s status, last read time and a silent-source alert.
PCI DSS 10.3.4
Existing log data cannot change without generating alerts. ARRTECH: a signature chain that breaks on any change or missing file. The non-repudiation report highlights faulty files.
PCI DSS 10.5.1
Retain audit log history for at least 12 months. ARRTECH: retention set per source or per group, with archived logs searchable.
PCI DSS 10.7.2
Failures of critical security controls detected and alerted. ARRTECH: a silent-source alert, and a system summary report of source and agent status.
PCI DSS 12.5.2
Scope documented and confirmed, including where account data is stored. ARRTECH: DLP discovery that inventories endpoints, file servers and SQL databases by classification.
PCI DSS 12.10.1
An incident response plan ready to be activated. ARRTECH: SOAR incidents with an execution history of playbook runs.
Questions
Does ARRTECH make us PCI DSS compliant?
No product can. PCI SSC does not issue compliance certificates. Your QSA, or your own questionnaire, decides whether each requirement is in place.
Does the SIEM come into scope?
Yes, if it stores account data. It then sits in your cardholder data environment and must meet the requirements itself.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Is there a ready PCI DSS report?
Yes. Ready reports and dashboards cover PCI DSS, and any saved query becomes a scheduled report.
Sources
Guide
What is PCI DSS?
The security standard for every organization that stores, processes or transmits payment card data. Version 4.0.1 is current.
What is a ROC or SAQ?
A Report on Compliance is written by a Qualified Security Assessor. A Self-Assessment Questionnaire is completed by the organization. Both come with an Attestation of Compliance.
What does Requirement 10 ask?
Log and monitor all access to system components and cardholder data, protect the logs from change, and keep at least 12 months of history.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep card data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.