Security built for the networks that connect us
Collect router, switch and access logs at carrier volume and sign everything you keep.
Guidance
| Source | What it asks | ARRTECH |
|---|---|---|
| Telecommunications Security Regulations | Monitor access to Security Critical Functions. | Collection from routers, switches and AAA. → |
| Ofcom | Evidence over 13 months. | Retention set per source. → |
| CISA, December 2024 | Centralized logging with correlation. | Correlation rules across sources. → |
| CISA, December 2024 | Monitor logins for anomalies. | Detection’s identity, network and DNS families. → |
| FCC CPNI | Notice within 7 business days. | A case timeline. → |
Salt Typhoon
Detect state actors on your routers
Salt Typhoon, a state-backed campaign, breached several telecom networks and took call records and lawful intercept data. ARRTECH collects router, switch and access logs and flags unusual sign-ins.
UK TSR
Keep 13 months of provable evidence
Under the UK Telecommunications Security Act, Ofcom expects providers to keep 13 months of evidence on access to security critical functions. ARRTECH sets retention per source and signs every log.
Log volume
Handle carrier-scale log volume
Carrier networks produce very large volumes of logs. ARRTECH pricing is based on daily volume, with no limit on the number of sources.
Ofcom
Answer Ofcom information requests
Ofcom can ask providers for information about their security measures. ARRTECH keeps ready reports and signed exports on hand.
By rule
Telecommunications Security Regulations
Monitor access to Security Critical Functions. ARRTECH: Collection from routers, switches and AAA.
CISA, December 2024
Centralized logging with correlation. ARRTECH: Correlation rules across sources.
CISA, December 2024
Monitor logins for anomalies. ARRTECH: Detection’s identity, network and DNS families.
FCC CPNI
Notice within 7 business days. ARRTECH: A case timeline.
Questions
Will it handle our volume?
Routers, switches, wireless and firewalls send their logs and traffic data in the standard formats they already use. Pricing is based on daily volume, with no limit on sources.
Would we see a change made outside change control?
Rules can flag changes in the logs your devices send. There is no separate feature that compares device configurations.
Who acts?
A person. ARRTECH SOAR emails the approver up to five options and waits. The history shows who chose what and when.
What stays with you?
Signalling protocols, and sizing at carrier scale, which we plan with you. Cyberdroid AI Detection reports about once an hour and never blocks.
Sources
Guide
What is the UK Telecommunications Security Act?
It requires providers to monitor access to Security Critical Functions. Ofcom expects 13 months of evidence.
What was Salt Typhoon?
A state-backed campaign that breached several telecom networks, stealing call records and lawful intercept data.
What does CISA recommend for telecom logging?
Central logging that correlates large volumes from routers and switches, stored so it cannot be changed.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.