Security built for companies that build software
Give customers and auditors proof they can check without access to your systems.
Frameworks
| Framework | Criterion | Asks | ARRTECH |
|---|---|---|---|
| SOC 2 | CC7.2 | Monitor components for anomalies. | Correlation, per-user risk score and Detection baselines. → |
| CC7.2 focus | Monitor detection tools. | Silent-source and health alerts. → | |
| CC7.3 | Evaluate security events. | Cases with SLA tracking and history. → | |
| ISO 27001 | 8.15, 8.16 | Logging and monitoring. | A ready ISO/IEC report. → |
| EU | 2024/2690 3.2.5 | Logs protected from change. | Signed, chained storage. → |
| GDPR 28(3)(h) | Information and audits for controllers. | Export with a standalone verifier. → |
SOC 2 CC7.2
Give auditors SOC 2 evidence they can check
SOC 2 criterion CC7.2 asks you to monitor systems for anomalies and analyze them as possible security events. ARRTECH signs every log and exports it with a verification tool, so auditors can check the evidence.
Shadow AI
Stop source code going into AI tools
Developers paste code into AI tools, and secrets can go with it. ARRTECH DLP catches source code and API keys in prompts and uploads.
Account takeover
Catch stolen sessions and credentials
Stolen session tokens and passwords let attackers sign in as real users. Cyberdroid AI Detection flags accounts acting unlike their own history.
GDPR Article 28
Avoid adding a sub-processor
A security vendor that processes your customers’ personal data becomes a sub-processor you must disclose under GDPR Article 28. ARRTECH runs on your own servers, so no customer data comes to us.
By rule
ISO 27001 8.15, 8.16
Logging and monitoring. ARRTECH: A ready ISO/IEC report.
EU 2024/2690 3.2.5
Logs protected from change. ARRTECH: Signed, chained storage.
Questions
Can source code leave through AI tools?
ARRTECH DLP checks prompts, file uploads and API requests sent to AI tools, and detects source code and secrets such as API keys, even inside ZIP and RAR files.
Would we see a stolen session?
Cyberdroid AI Detection compares every user and host with its own history across sign-in, network, DNS, process and firewall data, and shows the evidence behind each finding.
Does it add a sub-processor?
No. ARRTECH SIEM runs on your own Linux servers, and Cyberdroid AI Detection runs beside it on your CPUs, with analysis kept local by default.
What stays with you?
There is no ready SOC 2 report, no stated AWS or Google Cloud connector, and no DLP agent for Linux build servers. Cyberdroid AI Detection reports about once an hour and never blocks.
Sources
Guide
What does SOC 2 CC7.2 require?
Monitoring system components for anomalies and analyzing them as possible security events.
How do you stop source code leaking into AI tools?
Inspect prompts, uploads and API requests to AI services for source code and secrets.
What logging does NIS2 require of cloud providers?
Implementing Regulation 2024/2690 requires logs kept for a set period and protected from change.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.