Frequently asked questions
The most common questions about 5651, KVKK, ISO 27001, products and support.
Any legal entity that provides internet access — cafés, hotels, hospitals, universities, offices, factories. If you offer Wi-Fi or wired internet to guests or employees, you are an 'access provider' under 5651 and must keep logs.
BTK can issue administrative fines of ₺10,000–₺100,000 per violation. In serious cases, the legal representative may face criminal liability. Logs may also be requested by courts in civil and criminal proceedings.
Access records are made tamper-evident with a SHA-256 hash chain, the daily root is signed with an RFC 3161 TSA, and an audit produces a signed, independently verifiable evidence pack.
Native adds TSA timestamping and 730-day retention. Premium adds inline capture (HTTP Host, TLS SNI, DNS without MitM) and up to 3,650-day retention.
Encrypted storage (LUKS + TLS 1.3), configurable retention with automated deletion (Art. 7), role-based access control, tamper-evident audit trails, data residency in Türkiye, and export/deletion APIs for data-subject requests (Art. 11).
Yes. Anchor products map to key Annex A controls: A.8.5 (authentication), A.8.22 (network segmentation), A.8.15 (logging), A.8.8 (vulnerability management), A.5.15 (access control) and A.8.10 (data deletion).
SMS OTP, WhatsApp, social login (Google / Microsoft via OIDC), e-mail verification, voucher/ticket codes, sponsor approval and SAML 2.0 SSO. You can assign different methods per SSID or venue.
An optional feature that ties each guest session to a Turkish national ID number, meeting the identity-verification requirements of Law 5651.
Yes. Cisco Catalyst, Aruba CX, FortiGate, MikroTik and Huawei VRP are certified; you can start without replacing your hardware.
No. Cloud-managed, edge appliance, or fully on-premises (air-gapped) options are available. Sovereign and AnchorLog run entirely on-premises.
The AnchorNAC edge keeps RADIUS authentication running locally for up to 4 hours; on-premises deployments provide full continuity.
The posture module checks disk encryption (BitLocker, LUKS, FileVault) and patch state on Windows, Linux and macOS. Non-compliant devices can be quarantined and auto-remediated via signed scripts.
In the cloud option, in the Türkiye/EU region; with on-prem and Sovereign, entirely on your own infrastructure. KVKK-compliant deletion and audit trail are supported.
In Türkiye, the SiperOne (ED Danışmanlık) team provides deployment, integration and technical support.
AnchorLog goes beyond log collection: it includes a built-in captive portal for guest Wi‑Fi, plus hash chaining and RFC 3161 TSA for legally defensible, independently verifiable evidence.