Federal Government

Logging is now reported as a percentage.

Schedule a meeting

Civilian agencies under FISMA, OMB M-26-14 and SP 800-53

Security built for federal agencies

See every log source, prove your logs are intact, and keep it all inside your own authorization.

Controls

SourceRequirementAsksARRTECH evidence
M-26-14Level 2Logs regularly hashed for veracity.Every write hashed, signed and chained. →
CoverageShare of systems at each level.Every source listed with status and last read time. →
Level 4Detections tuned with machine learning.21 detectors in shadow or production, with replay. →
SP 800-53 Rev. 5AU-5Alert on audit logging failure.Silent-source and health alerts. →
AU-6(3)Correlate across repositories.Correlation across sources and sequences. →
AU-9(3)Protect audit information cryptographically.Signed chain and role-based rights per source. →
IR-4 to IR-6Handle, track and report incidents.SIEM cases and SOAR incidents with history. →
M-25-21OversightHuman oversight of high-impact AI.Detection never acts; SOAR waits for a person. →

FISMA

Close IG logging findings

Inspectors general test agency logging under FISMA against NIST SP 800-53. ARRTECH lists every log source and when it last reported, so gaps show up before the audit.

OMB M-26-14

Keep logs searchable and intact

OMB M-26-14, issued May 22, 2026, replaced M-21-31. It asks agencies to keep logs searchable for six months and retrievable for twelve. ARRTECH signs every log as it is written, so you can show it has not changed.

RMF

Stay inside your ATO boundary

Under the Risk Management Framework, every system runs inside an authorization boundary. ARRTECH runs on servers you operate, so it sits inside your own ATO and needs no new cloud authorization.

OMB M-25-21

Keep AI under human oversight

OMB M-25-21 asks agencies to keep human oversight over high-impact AI. Cyberdroid AI Detection never acts on its own, and ARRTECH SOAR waits for a person to approve each response.

By rule

SP 800-53 Rev. 5 AU-5

Alert on audit logging failure. ARRTECH: Silent-source and health alerts.

SP 800-53 Rev. 5 AU-6(3)

Correlate across repositories. ARRTECH: Correlation across sources and sequences.

SP 800-53 Rev. 5 AU-9(3)

Protect audit information cryptographically. ARRTECH: Signed chain and role-based rights per source.

SP 800-53 Rev. 5 IR-4 to IR-6

Handle, track and report incidents. ARRTECH: SIEM cases and SOAR incidents with history.

Questions

Where does it run?

On Linux servers your agency operates. Cyberdroid AI Detection runs beside them on ordinary CPUs, and its analysis stays local by default. Both are covered by your own authorization to operate.

What does it collect?

Directory, VPN, firewall, DNS, proxy, endpoint, database, Microsoft 365, Azure, Windows and network traffic logs. Anything else can arrive by syslog, API or file, and we write the connector at no charge under support.

Is the AI accountable?

Yes. Cyberdroid AI Detection never blocks or changes anything, and its score helps you prioritize; it is not a verdict. ARRTECH SOAR asks a person to choose before it acts and records who chose what.

What stays with you?

Your authorization, your reports to CISA and OMB, and procurement questions, which we answer with you directly. Cyberdroid AI Detection reports about once an hour.

Sources

Guide

What is OMB M-26-14?

M-26-14 is the federal logging memo OMB issued on May 22, 2026, replacing M-21-31. It sets maturity levels and deadlines and asks agencies to keep logs searchable for six months and retrievable for twelve.

What logging does FISMA require?

FISMA requires agency security programs with incident detection and response. Inspectors general test logging against NIST SP 800-53 AU controls.

Does on-premises software need FedRAMP?

No. FedRAMP covers cloud services. Software on agency-operated servers is authorized through the agency’s own ATO.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.