Frequently asked questions
The most common questions about 5651, KVKK, ISO 27001, products and support.
Any legal entity that provides internet access — cafés, hotels, hospitals, universities, offices, factories. If you offer Wi-Fi or wired internet to guests or employees, you are an 'access provider' under 5651 and must keep logs.
BTK can issue administrative fines of ₺10,000–₺100,000 per violation. In serious cases, the legal representative may face criminal liability. Logs may also be requested by courts in civil and criminal proceedings.
Access records are made tamper-evident with a SHA-256 hash chain, the daily root is signed with an RFC 3161 TSA, and an audit produces a signed, independently verifiable evidence pack.
Native adds TSA timestamping and 730-day retention. Premium adds inline capture (HTTP Host, TLS SNI, DNS without MitM) and up to 3,650-day retention.
Encrypted storage (LUKS + TLS 1.3), configurable retention with automated deletion (Art. 7), role-based access control, tamper-evident audit trails, data residency in Türkiye, and export/deletion APIs for data-subject requests (Art. 11).
Yes. Anchor products map to key Annex A controls: A.8.5 (authentication), A.8.22 (network segmentation), A.8.15 (logging), A.8.8 (vulnerability management), A.5.15 (access control) and A.8.10 (data deletion).
SMS OTP, WhatsApp, social login (Google / Microsoft via OIDC), e-mail verification, voucher/ticket codes, sponsor approval and SAML 2.0 SSO. You can assign different methods per SSID or venue.
An optional feature that ties each guest session to a Turkish national ID number, meeting the identity-verification requirements of Law 5651.
Yes. Cisco Catalyst, Aruba CX, FortiGate, MikroTik and Huawei VRP are certified; you can start without replacing your hardware.
No. Cloud-managed, edge appliance, or fully on-premises (air-gapped) options are available. Sovereign and AnchorLog run entirely on-premises.
Guest sessions already authorised on the Edge appliance stay up, and 5651 connection records keep being written locally, then sync to the cloud once the link returns. New guest logins need the cloud portal, so they are unavailable during the outage. On-premises (Sovereign) deployments have no cloud dependency — authentication included, everything keeps running on site.
The posture module checks disk encryption (BitLocker, LUKS, FileVault) and patch state on Windows, Linux and macOS. Non-compliant devices can be quarantined and auto-remediated via signed scripts.
In the cloud option, in the Türkiye/EU region; with on-prem and Sovereign, entirely on your own infrastructure. KVKK-compliant deletion and audit trail are supported.
In Türkiye, the SiperOne team provides deployment, integration and technical support.
AnchorLog goes beyond log collection: it includes a built-in captive portal for guest Wi‑Fi, plus hash chaining and RFC 3161 TSA for legally defensible, independently verifiable evidence.
AnchorSpot can be up and running in as little as 5 minutes using your existing MikroTik device. AnchorNAC basic deployment — including Edge appliance setup, first policy and test authentication — typically takes 1–2 hours. A full enterprise rollout across multiple sites and VLANs usually takes 1–2 weeks depending on network size and the number of switch vendors involved.
No. Anchor products are designed to work with your current network infrastructure. Cisco Catalyst, Aruba CX, FortiGate, MikroTik and Huawei VRP are all certified and managed from one console. You can start immediately without purchasing new switches or access points.
The Edge appliance is a fanless Intel N100-based mini-PC with 16 GB RAM, 1 TB NVMe SSD and two Gigabit Ethernet ports. On a hardened Linux image it runs captive-portal enforcement (nftables), 5651 connection logging, walled-garden management and corporate AD/LDAP authentication ON SITE — the corporate password never leaves the appliance. The RADIUS service runs in the cloud, not on the box. During an outage, authorised sessions and local logging continue.
Yes. The SiperOne console supports multi-site management out of the box. Each site can have its own policies, captive-portal branding and VLAN configuration, while you maintain a single overview dashboard. Per-site policies allow you to tailor access rules to each branch without duplicating effort.
AnchorNAC supports EAP-TLS for certificate-only authentication, EAP-TEAP for combined certificate-and-password scenarios, and PEAP for password-based enterprise Wi-Fi. For headless devices such as printers, IP phones and IoT sensors, MAC Authentication Bypass (MAB) is available to allow network access without a supplicant.
AnchorNAC includes a built-in PKI with SCEP enrolment. iOS devices receive certificates via an MDM profile, Android devices can onboard using DPP QR codes, and macOS devices are provisioned through configuration profiles. Once enrolled, the device authenticates automatically via 802.1X EAP-TLS without the user needing to enter credentials again.
AnchorLog adds several capabilities that FortiLogger does not provide: a SHA-256 hash chain that makes every log batch tamper-evident, RFC 3161 TSA timestamps from a qualified trust-service provider for legal proof of integrity, and a built-in captive portal for guest Wi-Fi with session analytics. Together, these features turn simple log collection into legally defensible evidence.
Yes. AnchorLog supports syslog forwarding in RFC 5424 format over UDP, TCP and TLS, so you can stream logs to any SIEM that accepts standard syslog input. A REST API is also available for programmatic log queries and exports, allowing integration with platforms like Elasticsearch, Splunk or Grafana.
The cloud-managed SiperOne console offers a 99.9% uptime SLA. If the cloud connection is lost, authorised guest sessions on the Edge appliance stay up and 5651 records keep being written locally, syncing once the link returns. New guest logins are unavailable for the duration of the outage. On-premises Sovereign deployments have no cloud dependency, so this outage scenario does not arise.
We accept credit card payments processed securely through iyzico and PayTR, as well as bank transfer and EFT. All packages are billed annually. Invoicing for customers in Türkiye is issued in TRY with VAT added at the applicable legal rate.
Make your guest Wi-Fi professional.
Let's assess your existing infrastructure and logging needs together and turn them into a workable deployment.
