Public institutions and municipalities are obliged to retain the traffic records generated by the internet access they provide to citizens and staff under Law No. 5651, and to be able to prove that these records have not been altered. SignLogger collects access records for both guest (hotspot) and staff traffic on public and municipal networks, signs those records every day with a TÜBİTAK Kamu SM timestamp and e-signature, and keeps all data on the institution's own infrastructure.
This content is for general information only and does not constitute legal advice. For your institution's exact obligations, consult current legislation and your legal counsel.
Where does the Law 5651 obligation come from for public bodies?
When a municipality offers free internet in its service buildings, cultural centers, libraries, parks or social facilities, it legally becomes the party providing that access. The internal staff network also produces internet egress and therefore falls within logging scope as well. For this reason, public institutions usually need to consider two separate networks together:
- Guest network: Hotspot/captive portal traffic that citizens and visitors connect to.
- Staff network: Corporate traffic through which employees reach the internet.
Records on both networks are expected to be preserved with their integrity intact throughout the legal retention period and to remain producible to authorities when required. For the details of the signing process, see the Law 5651 log signing solution page.
Guest network vs. staff network: two different needs
Both networks fall under Law 5651, but their identification and management approaches differ. SignLogger consolidates both scenarios on a single platform:
| Criterion | Guest network (hotspot) | Staff network |
|---|---|---|
| Identification | Captive portal (SMS/sponsor/form verification) | Domain / corporate account, via NAC |
| Authentication method | RADIUS (PAP only) | 802.1x (EAP) or NAC policies |
| Purpose | Visitor access + audit trail | Access control + audit trail |
| Log signing | Daily, with Kamu SM | Daily, with Kamu SM |
Captive portal verification on the guest side works with PAP only in SignLogger; on the staff side, NAC policies can be used to govern internal device access.
Why is daily signed logging essential?
A log's legal value depends on being able to prove when it was produced and that it has not been altered afterward. SignLogger provides this assurance not by accumulating plain-text files, but by signing records every day with a timestamp and e-signature from TÜBİTAK Kamu SM, an authorized certification service provider. Each day's log is thus sealed the moment it is closed and becomes tamper-evident from that point on.
The Kamu SM timestamp service operates on a credit (kontör) model; as long as the institution's credit balance is not exhausted, the signing process continues without interruption. SignLogger makes credit consumption observable, so the IT team can plan balance management in advance.
On your own infrastructure, without data leaving the institution
For the confidentiality of public and municipal data, it matters that logs stay in the institution's own environment rather than in the cloud. SignLogger runs as a virtual machine on the institution's existing virtualization infrastructure (VMware or Hyper-V). Access records are never sent to any third party at any stage; the data stays entirely on-premises. This model supports operation aligned with data protection and institutional confidentiality requirements.
Deployment and brand independence
SignLogger is brand-independent; it works with any firewall or wireless controller that supports RADIUS. This lets a municipality or institution gain logging and signing capability without replacing its existing network hardware. For managing the guest network and captive portal scenarios, the hotspot management solution and, for staff access, the NAC module can be used together on the same platform.
Frequently Asked Questions
If a municipality offers free Wi-Fi, is it within Law 5651 scope?
Yes. When public internet access is offered to citizens, the institution becomes the party providing access and is obliged to retain traffic records. SignLogger collects and signs these records daily.
Does the staff network also need to be logged?
The staff network produces internet egress, so it falls within logging scope as well. SignLogger records both guest and staff traffic on one platform and signs both with Kamu SM.
Why are logs signed every day?
Daily signing seals each day's record with a timestamp and e-signature the moment it is closed. This makes it legally provable when the record was produced and that it was not altered afterward.
What happens if the Kamu SM credit runs out?
The Kamu SM timestamp works on a credit model. Because SignLogger makes credit usage observable, the balance can be renewed before it is depleted so signing continues without interruption.
Is the data sent to the cloud?
No. SignLogger runs on the institution's own VMware or Hyper-V infrastructure; access records stay on-premises and are not sent to any third party.
Does it work with our existing firewall?
Yes. SignLogger is brand-independent and compatible with any firewall or wireless controller that supports RADIUS, so you do not need to replace your existing hardware.