Location
This page lists where each product runs and the connections that reach outside your environment.
ContactLocations
Your servers.
ARRTECH SIEM runs on Debian, Ubuntu or Red Hat Linux on your servers. Processing, search, correlation, reporting and management run on separate servers, with redundancy and failover.
Beside the SIEM.
Cyberdroid AI Detection runs beside the SIEM in your environment, on CPUs only. It reads the SIEM export from a read-only network share and never blocks or changes anything.
Local inference.
Cyberdroid AI Investigation serves its language models in your environment, and inference stays local by default. An optional online fallback exists. It is a policy you configure and can see.
Your deployment.
ARRTECH DLP deploys on premises, as SaaS, hybrid, or multi-tenant for service providers. You choose the model.
Verify
Routing metadata.
Routing metadata shows which local model served each Cyberdroid AI Investigation request. The online fallback is a policy you configure and can see.
Outbound actions.
Email, SMS, Jira tickets, Python scripts and SOAR integrations send data out when you configure them. Each action type can be restricted per module.
Limits
Other connections.
ARRTECH DLP as SaaS or hybrid runs partly outside your environment. The daily log timestamp contacts a timestamp authority. Threat intelligence feeds refresh on a schedule, and Store packages install from the console.
Page scope.
This page describes our products as of Sep 24, 2026. It is not a certification, an audit report or a contract term. Ask us about anything it does not cover.