Security built for everything that moves
Keep collecting logs when a site loses its connection and know the moment it goes quiet.
Regulators
| Mode | Rule | Measure | ARRTECH |
|---|---|---|---|
| Rail | TSA 1580/82-2022-01 | Continuous monitoring and detection. | Correlation and behavioral baselines. → |
| TSA 1580-21-01 | Report to CISA within 24 hours. | A signed case timeline. → | |
| Aviation | TSA EA 23-01 | Monitoring and detection. | SIEM correlation across sites. → |
| EU Part-IS | Deviations from baselines; 5-year records. | Detection baselines; retention set per source. → | |
| All modes | NIS2 Art. 32 | Audits and the underlying evidence. | Signed exports with a verifier. → |
Distributed sites
Monitor every station, depot and terminal
Rail, aviation and logistics networks span hundreds of stations, depots and terminals. ARRTECH has no limit on sources, and an alert shows any site that goes quiet.
TSA directives
Meet TSA continuous monitoring rules
TSA security directives for rail and aviation require continuous monitoring and detection. ARRTECH SIEM correlates events across sites, and Cyberdroid AI Detection flags unusual behavior.
EASA Part-IS
Keep aviation security records
EASA Part-IS requires aviation organizations to keep security records for at least five years and protect them from change. ARRTECH signs every log.
Multi-tenant
Separate operators and subsidiaries
Operators and subsidiaries often need separate views. ARRTECH gives each its own data, rules and reports.
By rule
Rail TSA 1580/82-2022-01
Continuous monitoring and detection. ARRTECH: Correlation and behavioral baselines.
Rail TSA 1580-21-01
Report to CISA within 24 hours. ARRTECH: A signed case timeline.
Aviation TSA EA 23-01
Monitoring and detection. ARRTECH: SIEM correlation across sites.
All modes NIS2 Art. 32
Audits and the underlying evidence. ARRTECH: Signed exports with a verifier.
Questions
What happens when a site loses its connection?
The agent holds logs and sends them later, and you get an alert when a site stops reporting.
Can each operator or subsidiary be kept separate?
Yes. Each gets its own users, data sources, rules, reports and alerts.
Who acts?
A person. ARRTECH SOAR emails the approver up to five options and waits. The history shows who chose what and when.
What stays with you?
Signalling, train control and radio systems, and any TSA or Part-IS reports.
Sources
Guide
What do TSA rail security directives require?
Report incidents to CISA within 24 hours and run continuous monitoring and detection.
What is EASA Part-IS?
The EU aviation information security rule, requiring records kept five years and protected from change.
How do you monitor hundreds of remote sites?
Use agents that buffer through outages and alert when a site stops reporting.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.