SOC 2 with ARRTECH

Records for the criteria in your control matrix.

Schedule a meeting

2017 Trust Services Criteria · Mapped Sep 24, 2026

Records for your SOC 2 examination

Detect, evaluate and respond as the criteria ask, and see plainly what stays with you.

Requirements

ClauseWhat it asksARRTECH
CC6.7Transmission of information restricted.DLP response actions. →
CC7.1Changes detected.Inventory with changes. →
CC7.2System components monitored for anomalies.Classified events and correlation. →
CC7.3Security events evaluated.Case records. →
CC7.4Incidents responded to.Playbook history. →

Transmission

Check data before it leaves

Each ARRTECH DLP rule blocks, allows and logs, asks a manager, asks the user for a justification, encrypts, quarantines or notifies.

Changes

See every change on each computer

The ARRTECH DLP agent records hardware and software inventory with changes, network configuration changes, and local user and group changes.

Anomalies

Spot anomalies across sources

ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.

Response

Respond with a person deciding

A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits.

Integrity

Prove nobody changed your logs

ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.

Limits

Know what stays with you

No ARRTECH product produces the record for these requirements.

CC7.5

Recovery from incidents. ARRTECH sells no backup product.

CC6.8

Malicious software prevented. The DLP process block list is not anti-malware.

CC1

Control environment. That is your organization’s own work.

CC9.2

Vendor risk management. That stays with you.

By rule

Naming a clause is not a claim of certification.

CC6.7

Restrict the transmission and movement of information. ARRTECH: DLP rules block, ask a manager, encrypt, quarantine or notify.

CC7.1

Detect configuration changes and new vulnerabilities. ARRTECH: DLP hardware and software inventory with changes.

CC7.2

Monitor components for anomalies that indicate malicious acts. ARRTECH: classified events, MITRE columns and correlation across sources.

CC7.3

Evaluate events to decide whether they are incidents. ARRTECH: case records with severity, assignee and history.

CC7.4

Respond to identified incidents with a defined program. ARRTECH: SOAR incidents with an execution history of playbook runs.

Questions

Is SOC 2 a certification?

No. It is a CPA’s report on an examination of a service organization’s controls.

Does this page describe ARRTECH’s own SOC 2 report?

No. It maps your criteria to records ARRTECH products produce.

Can our assessor check the logs without ARRTECH?

Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.

Is there a ready SOC 2 report?

No ready report is named. A saved query becomes a report, on a schedule.

Sources

Guide

What is SOC 2?

A report by a CPA on the controls at a service organization, against the Trust Services Criteria.

What are the Trust Services Criteria?

Security, availability, processing integrity, confidentiality and privacy. Security is always in scope.

What is the difference between Type I and Type II?

Type I reports on control design at a point in time. Type II also tests how controls operated over a period.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.