Security built for the defense industrial base
Keep audit evidence inside your own environment and let assessors check it without us.
Requirements
| Requirement | Short form | Points | ARRTECH |
|---|---|---|---|
| 3.3.1 | Create and retain audit logs. | 5 | SIEM collection and retention per source. → |
| 3.3.5 | Correlate review and reporting. | 5 | Correlation across sources. → |
| 3.3.8 | Protect audit information. | 1 | Signed chain and console audit log. → |
| 3.6.1 | Incident handling capability. | 5 | SIEM cases with MITRE context. → |
| 3.8.7 | Control removable media. | 5 | DLP device control by serial number. → |
| 3.1.3 | Control the flow of CUI. | Per method | DLP inspection of web, FTP and mail. → |
| 3.14.7 | Identify unauthorized use. | 3 | Detection baselines per user and host. → |
32 CFR 170.19
Keep CMMC scope from growing
Under 32 CFR 170.19, security tools count as Security Protection Assets in your CMMC assessment, while an outside cloud service brings its own requirements. ARRTECH runs inside your environment, so it counts as a security tool, not a new cloud provider.
NIST SP 800-171 3.3
Produce audit evidence assessors can verify
NIST SP 800-171 family 3.3 asks you to create, keep, review and protect audit logs. ARRTECH signs every log and exports it with a verification tool, so an assessor can check the record without us.
NIST SP 800-171 3.8.7
Stop technical data leaving on USB or email
Requirement 3.8.7 asks you to control removable media, and it is worth 5 points in your SPRS score. ARRTECH DLP allows or blocks each USB device by serial number and checks files leaving by web or email.
NISPOM 117.7
Support your insider threat program
The NISPOM requires cleared contractors to run an insider threat program. ARRTECH covers part of it: file activity, sign-ins, device use, and behavior compared with each person’s history. It does not record keystrokes or screens.
By rule
3.3.1
Create and retain audit logs. ARRTECH: SIEM collection and retention per source.
3.3.5
Correlate review and reporting. ARRTECH: Correlation across sources.
3.3.8
Protect audit information. ARRTECH: Signed chain and console audit log.
3.6.1
Incident handling capability. ARRTECH: SIEM cases with MITRE context.
3.8.7
Control removable media. ARRTECH: DLP device control by serial number.
3.1.3
Control the flow of CUI. ARRTECH: DLP inspection of web, FTP and mail.
3.14.7
Identify unauthorized use. ARRTECH: Detection baselines per user and host.
Questions
Does it add a cloud provider to our scope?
No. ARRTECH SIEM and ARRTECH DLP run on your servers, and Cyberdroid AI Detection runs in your environment on ordinary CPUs. Each is listed as a security tool in your assessment, not as an outside provider.
Can technical data leave?
ARRTECH DLP controls which USB devices can connect, inspects files leaving by web, FTP or email from any application, and recognizes copies of protected files even when they are partly changed. A screen watermark shows who was viewing and when.
Does it support our insider threat program?
It covers part of it: file and network activity, sign-ins, device use, and behavior compared with each person’s history. It does not record keystrokes or screens.
What stays with you?
Your CMMC assessment, approval of any classified system, and FIPS-validated encryption for CUI. Cyberdroid AI Detection reports about once an hour and never blocks.
Sources
Guide
What is CMMC Level 2?
CMMC Level 2 applies the 110 requirements of NIST SP 800-171 to contractors that handle controlled unclassified information (CUI).
What does DFARS 252.204-7012 require?
Adequate security under NIST SP 800-171, incident reports to DoD within 72 hours, and 90 days of preserved monitoring data.
Do security tools count in CMMC scope?
Yes. Under 32 CFR 170.19, security tools are Security Protection Assets. Tools that run on your own servers avoid adding a cloud provider.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.