Security built for every school district
Run security as a shared service, with each district kept separate.
Fit
| District need | ARRTECH | Not covered |
|---|---|---|
| Shared service | Tenants with their own users, sources, policies, reports and alerts. → | Hosting; it runs on your servers. |
| Dated record for state reports | Cases with SLA tracking and signed logs. → | Filing the report. |
| Filter evidence | Content filter logs, signed and chained. → | The filter itself. |
| Staff credentials | AD, LDAP, VPN and Microsoft 365, with a risk score per user. → | Profiling of students. |
| Staff machines | DLP on Windows and macOS, email gateway, device control. → | ChromeOS. |
| Student accounts | — → | Google Workspace collection is not documented. |
Shared service
Run security for many districts at once
Many districts share security through a BOCES, an education service center or a state network. ARRTECH gives each district its own data, rules and reports, run from one place.
NY Ed Law 2-d
Meet New York’s student data rules
New York Education Law 2-d and Part 121 require districts to protect student data and report breaches within set deadlines. ARRTECH keeps a dated record of every incident for your state report.
CIPA
Keep internet filter logs for E-rate
CIPA requires internet filtering for E-rate funding, and E-rate records must be kept for 10 years. ARRTECH collects and signs your content filter logs.
Student privacy
Stop student data leaving staff computers
Staff computers hold grades, health notes and family details. ARRTECH DLP checks email and uploads and controls USB drives on Windows and Mac computers.
By rule
Dated record for state reports
ARRTECH: Cases with SLA tracking and signed logs.
Filter evidence
ARRTECH: Content filter logs, signed and chained.
Staff credentials
ARRTECH: AD, LDAP, VPN and Microsoft 365, with a risk score per user.
Staff machines
ARRTECH: DLP on Windows and macOS, email gateway, device control.
Student accounts
Student accounts. Not covered: ARRTECH does not document Google Workspace or Chromebook activity.
Questions
Is each district kept apart?
Yes. Each district gets its own users, data sources, rules, reports and alerts, and ARRTECH DLP can run the same way for many districts.
Can student data leave staff computers?
ARRTECH DLP checks web uploads and email, including in Outlook, and controls USB drives on Windows and Mac computers.
Can we control classroom video?
Yes. ARRTECH DLP allows YouTube videos by category or channel, blocks Shorts, and applies per group. It is not a content filter.
What stays with you?
Chromebooks, Google Workspace and your content filter. The products run on servers you operate.
Sources
Guide
What is NY Ed Law 2-d?
New York’s student data privacy law, set out in 8 NYCRR Part 121, requires NIST CSF-aligned security and breach notice within set days.
How can small districts afford security monitoring?
Many districts share a service through a BOCES, ESC or state network, with each district kept separate.
What does CIPA require for logs?
CIPA requires internet safety policies and filtering, and E-rate records must be kept for 10 years.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.