Retail and E-commerce

Your QSA can pick any day of the year.

Schedule a meeting

Retailers under PCI DSS v4.0.1 and GDPR

Security built for stores and online retail

Review logs automatically, get alerted when logging fails, and keep a signed record.

Requirements

PCI DSSWhat the QSA testsARRTECH evidence
10.3.2Audit logs protected from modification.Signed, chained logs and role-based rights. →
10.4.1.1Automated audit log review.Classification, correlation and a scheduled PCI DSS report. →
10.7.2Alert when audit logging fails.A silent-source alert. →
12.5.2All locations of account data confirmed.DLP discovery of endpoints, file servers and SQL databases. →
12.10.7Response to PAN found where not expected.A case opened for each finding. →
6.4.3, 11.6.1Payment page scripts.Not covered. →

PCI DSS 10.4.1.1

Automate PCI DSS daily log review

Since March 31, 2025, PCI DSS 10.4.1.1 requires automated audit log reviews. ARRTECH SIEM reviews logs automatically and runs a ready PCI DSS report.

PCI DSS 10.7.2

Get alerted when logging fails

PCI DSS 10.7.2 requires detecting and alerting on failures of critical security controls, including audit logging. ARRTECH SIEM alerts when any store or system stops sending.

PCI DSS 12.5.2

Find card data where it should not be

PCI DSS 12.5.2 requires you to confirm every place account data is stored, at least once a year. ARRTECH DLP scans computers, file servers and databases for real card numbers.

Social engineering

Spot accounts taken over through the help desk

Some 2025 attacks on retailers began with a call to the help desk to reset an account. Cyberdroid AI Detection flags accounts that act differently after a reset.

By rule

10.3.2

Audit logs protected from modification. ARRTECH: Signed, chained logs and role-based rights.

10.7.2

Alert when audit logging fails. ARRTECH: A silent-source alert.

12.5.2

All locations of account data confirmed. ARRTECH: DLP discovery of endpoints, file servers and SQL databases.

12.10.7

Response to PAN found where not expected. ARRTECH: A case opened for each finding.

6.4.3, 11.6.1

Payment page scripts. ARRTECH: Not covered.

Questions

Where is card data we did not expect?

ARRTECH DLP scans computers, file servers and databases, recognizes real card numbers, reads text inside images, and labels what it finds.

What if a store loses its connection?

The agent holds logs and sends them when the link returns, and an alert shows any store that stopped reporting.

Can customer records leave?

ARRTECH DLP recognizes rows copied from your customer database wherever they go, and inspects uploads from any application.

What stays with you?

Payment page scripts, point-of-sale systems, tokenization, integrity monitoring of system files, and clock sync. The DLP agent runs on Windows and macOS.

Sources

Guide

What changed in PCI DSS 4.0.1 for logging?

Since March 31, 2025, audit log reviews must be automated (10.4.1.1) and logging failures must be detected and alerted (10.7.2).

How long must PCI DSS logs be kept?

12 months, with the most recent three months immediately available (10.5.1).

How do retailers find stray card data?

Scan endpoints, file servers and databases for card numbers, as PCI DSS 12.5.2 scoping requires.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.