Security built for federal agencies
See every log source, prove your logs are intact, and keep it all inside your own authorization.
Controls
| Source | Requirement | Asks | ARRTECH evidence |
|---|---|---|---|
| M-26-14 | Level 2 | Logs regularly hashed for veracity. | Every write hashed, signed and chained. → |
| Coverage | Share of systems at each level. | Every source listed with status and last read time. → | |
| Level 4 | Detections tuned with machine learning. | 21 detectors in shadow or production, with replay. → | |
| SP 800-53 Rev. 5 | AU-5 | Alert on audit logging failure. | Silent-source and health alerts. → |
| AU-6(3) | Correlate across repositories. | Correlation across sources and sequences. → | |
| AU-9(3) | Protect audit information cryptographically. | Signed chain and role-based rights per source. → | |
| IR-4 to IR-6 | Handle, track and report incidents. | SIEM cases and SOAR incidents with history. → | |
| M-25-21 | Oversight | Human oversight of high-impact AI. | Detection never acts; SOAR waits for a person. → |
FISMA
Close IG logging findings
Inspectors general test agency logging under FISMA against NIST SP 800-53. ARRTECH lists every log source and when it last reported, so gaps show up before the audit.
OMB M-26-14
Keep logs searchable and intact
OMB M-26-14, issued May 22, 2026, replaced M-21-31. It asks agencies to keep logs searchable for six months and retrievable for twelve. ARRTECH signs every log as it is written, so you can show it has not changed.
RMF
Stay inside your ATO boundary
Under the Risk Management Framework, every system runs inside an authorization boundary. ARRTECH runs on servers you operate, so it sits inside your own ATO and needs no new cloud authorization.
OMB M-25-21
Keep AI under human oversight
OMB M-25-21 asks agencies to keep human oversight over high-impact AI. Cyberdroid AI Detection never acts on its own, and ARRTECH SOAR waits for a person to approve each response.
By rule
SP 800-53 Rev. 5 AU-5
Alert on audit logging failure. ARRTECH: Silent-source and health alerts.
SP 800-53 Rev. 5 AU-6(3)
Correlate across repositories. ARRTECH: Correlation across sources and sequences.
SP 800-53 Rev. 5 AU-9(3)
Protect audit information cryptographically. ARRTECH: Signed chain and role-based rights per source.
SP 800-53 Rev. 5 IR-4 to IR-6
Handle, track and report incidents. ARRTECH: SIEM cases and SOAR incidents with history.
Questions
Where does it run?
On Linux servers your agency operates. Cyberdroid AI Detection runs beside them on ordinary CPUs, and its analysis stays local by default. Both are covered by your own authorization to operate.
What does it collect?
Directory, VPN, firewall, DNS, proxy, endpoint, database, Microsoft 365, Azure, Windows and network traffic logs. Anything else can arrive by syslog, API or file, and we write the connector at no charge under support.
Is the AI accountable?
Yes. Cyberdroid AI Detection never blocks or changes anything, and its score helps you prioritize; it is not a verdict. ARRTECH SOAR asks a person to choose before it acts and records who chose what.
What stays with you?
Your authorization, your reports to CISA and OMB, and procurement questions, which we answer with you directly. Cyberdroid AI Detection reports about once an hour.
Sources
Guide
What is OMB M-26-14?
M-26-14 is the federal logging memo OMB issued on May 22, 2026, replacing M-21-31. It sets maturity levels and deadlines and asks agencies to keep logs searchable for six months and retrievable for twelve.
What logging does FISMA require?
FISMA requires agency security programs with incident detection and response. Inspectors general test logging against NIST SP 800-53 AU controls.
Does on-premises software need FedRAMP?
No. FedRAMP covers cloud services. Software on agency-operated servers is authorized through the agency’s own ATO.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.