+998 90 925 41 68 [email protected] On-premise · Tashkent, Uzbekistan
RU ·UZ ·EN
enterprise management

Integrated automated enterprise management system

Document management, archive, CRM, warehouse, and ERP suite in one on-premise platform

Services, database, files, search, and AI deploy inside the customer's perimeter. Data isolation at the database level, classification levels and clearances, an audit log with checksums, and interface and help in three languages.

On-premise RLS in PostgreSQL RU · UZ · EN Modular licensing
kaskad.local/documents
K
Search documents ? RU EN UZ

Registry / Documents

Document register

Inbound, outbound, and internal - filtered by classification and clearance

Export CSV + Document
Type: all Status: all Period: August Group by: department
Number Title Status Created
HR-ord-028/2026 Order appointing the archive officer Signed 12.08.2026
Registry-in-1145/2026 Request for information Registered 12.08.2026
Legal-agr-311/2026 Storage array supply contract In approval 11.08.2026
IS-pol-014/2026 Access control policy, rev. 3 In approval 11.08.2026
Registry-out-0876/2026 Reply to inquiry No. 4412 Signed 10.08.2026
Archive-act-007/2026 Destruction act Draft 10.08.2026
Accounting-ord-091/2026 Inventory count order Registered 09.08.2026
Database-level isolation SHA-256 for every version Three interface languages

6

modules on one platform

3

interface and help languages

1–2 days

to install on the customer's server

0–4

classification levels with employee clearances

~185 MB

of memory for the whole stack

8–12K

pages per hour of OCR

Modules Workspace Routes Security Bank archive Hardware Rollout FAQ

Six modules

One login, one database, one set of permissions - and six working loops on top of them

Pick a module on the left - the panel on the right shows the matching system screen. Licensing is modular: pay only for what you enable.

Registration of inbound, outbound, and internal documents, resolutions and assignments, deadline-driven execution control, records classification scheme, journals and printed forms. Three route types, classification levels 0–4, tracked acknowledgment, digital signing (E-imzo / qualified signatures), full-text search with permission awareness.

EDMS module page →

Long-term storage with a full lifecycle: volumes and case files, links to the file plan, records appraisal, destruction acts. Destruction is possible only against a specific line of an approved act. Three storage layers: cards in the database, files on the file system or in S3-compatible storage, with the long-term archive on top. Batch migration with dry runs and idempotent import.

Records archive page →

Leads, deals, pipelines, counterparties. A commercial proposal travels a route like any document; prices are computed by an exact-arithmetic engine with no rounding errors. Client communication channels including Telegram: messages land in the card, and leads are extracted from conversations. Event-driven rules and triggers, base currency and VAT in the organization profile.

CRM page →

Real-time stock, lots, bins, receiving and shipping, transfers, inventory counts. Cost of goods via valuation layers (FIFO). Warehouse journal: every unit of movement writes a ledger line; history cannot be recalculated after the fact.

Warehouse page →

Request → proposal → route approval → deal → warehouse shipment → report. Shared directories for counterparties, products, and organizations; shared currencies and VAT; shared permissions and audit. One login, one database, no integration with itself.

ERP suite page →

A built-in assistant: two-paragraph document summaries, translation between Russian, Uzbek, and English, answers about document content, lead extraction from conversations. Works with your AI provider, including a fully on-premise model: data never leaves the perimeter, not even for AI.

How CoPilot works →
kaskad.local/workspace
K
Search ? RU EN UZ Log out

Registry / Documents

Document register

Access is determined by document classification and employee clearance

Number Type Status
HR-ord-028/2026OrderSigned
Registry-in-1145/2026InboundRegistered
Legal-agr-311/2026ContractIn approval
Archive-act-007/2026ActDraft
Registry-out-0876/2026OutboundSigned

Archive / File plan

Fonds, sections, inventories, case files, and volumes

Destruction act Storage audit + Node
FondsHead office records01
SectionRegistry01-01
InventoryOrders on core operations01-01/2024
Case fileOrders, 2024Approved01-01/2024-01
Volume 1January - JuneClosed01-01/2024-01-1
Volume 2July - Decemberin archive01-01/2024-01-2

A volume can be destroyed only against its own line in an approved act.

CRM / Deals

Pipeline and commercial proposals

New

18

Proposals in approval

6

In progress

12

Deal Stage Proposal
CRM-deal-0412NegotiationIn approval
CRM-deal-0407Proposal sentSigned
CRM-lead-1188From TelegramNew
CRM-deal-0398ShipmentDone

Proposal prices are computed by an exact-arithmetic engine: no rounding errors.

Warehouse / Stock

Stock Lots Serials Scan a barcode or SKU

Central

12 480

Branch No. 2

3 145

Transit

208

Product Location On hand
Laser cartridge
SKU-04471
CW-A-01-031 240
A4 paper, 80 g
SKU-01102
CW-B-02-118 600
Production scanner
SKU-09330
CW-A-04-0114
NVMe drive 1 TB
SKU-07715
BR2-C-01-0262

Overview / Executive dashboard

Requests

64

Proposals on route

6

Deals

12

Shipments

9

Low warehouse stock

Production scannerSKU-0933014Restock
NVMe drive 1 TBSKU-0771562Restock

Registry / Documents / Card

Access control policy, rev. 3

IS-pol-014/2026

Content

The document defines how permissions are granted and revoked, requirements for classification levels and clearances, and a quarterly permission review procedure.

AI CoPilot

A two-paragraph summary, translation into Uzbek and English, answers about document content. The provider is yours, including an on-premise model.

Summary Translate Ask about the document

Identifier

8f2c41d0-5b9a-4e77-9c3e-1ab6f0d2e845

Workspace

The document card: classification, permissions, lifecycle, and attributes on one screen

Access is determined by document classification and employee clearance, not by folder location. Permissions are granted by name, and "Deny overrides Allow".

kaskad.local/documents/agr-311
K
Search cards and file contents ? RU EN UZ Log out

Storage array supply contract

Legal-agr-311/2026 · type: Contract

In approval Owner: Legal

Lifecycle

Send for signature Return to author File into case

Classification level

2 - Confidential the document is visible to employees whose clearance is at or above its classification

Document access permissions (ACL)

Grant
Subject type User Permission Effect
RolemanagerReadAllow
Usera.karimovEditAllow
LDAP groupcontractorsDownload fileDeny

"Deny" overrides "Allow".

Attributes

Authorm.yusupova Created11.08.2026 Version3 Case file01-03/2026-04 Due14.08.2026

Identifier

c41e7b93-0d2a-4f18-8b6c-7e51a9d3f204

Acknowledgment

The employee's acknowledgment is recorded in the audit log along with time and account.

Classification level

Five levels, 0–4: a document is visible to employees whose clearance is at or above its classification.

ACL table

Named permission grants to roles, users, and directory groups.

Lifecycle

State transitions happen only via routes and role permissions.

Attributes and UUID

Link to the file plan case, version, due date, identifier.

Approval routes

Three route types and deadline-driven execution control

Sequential, parallel, and mixed routes are defined in the system once and applied to a document type. Resolutions and assignments are issued from the card, deadlines are tracked, and acknowledgment is recorded with a mark.

Deadlines on every node; overdue items are visible in the register and the executive dashboard Returning to the author with a comment sends the document back to the original node Digital signing (E-imzo / qualified signature) is a dedicated route node
How routes are configured →
RegistrationDone
Legal reviewDone
InfoSec approvalIn progress
SigningPending
Filing into casePending

Nodes run in order: the next one receives the document only after the previous decision.

Registration
Legal reviewDone
InfoSec approvalIn progress
Financial reviewIn progress
Signing

Branching: all approvers receive the document at once; the node closes on the last decision.

Registration
Legal reviewDone
InfoSec approvalDone
SigningIn progress
Filing into case

A combination: a parallel approval block, then sequential signing and filing.

Security and on-premise

Isolation is enforced by the database, not by a condition in application code

Multi-tenancy at the database level. Row-level security in PostgreSQL: business-unit data is isolated by the database.
Classification levels 0–4 and personal clearances. Document visibility is determined by classification and employee clearance.
Four system roles plus a constructor. owner, admin, manager, viewer - plus custom roles from a role × entity × operation catalog.
Sync with LDAP and Active Directory. A departing employee loses access the moment their domain account is disabled.
Audit log with checksums. Significant actions are recorded; SHA-256 is computed for every file version.
Personal data localization. Data physically resides on your servers in Uzbekistan - the architecture meets the requirement by design.
Backups with standard PostgreSQL tooling. Plus a copy of the file store; the restore procedure is documented.
How security works →
kaskad.local/audit
K
Search RU EN UZ

Administration / Audit log

Audit log

Action: all Object type: document Period: 12.08.2026 Apply Reset
Time Action Who Details
12.08 09:14:22 Version upload m.yusupova dogovor-shd-311.pdf · version 3 · 1 842 016 bytessha256: 9f2b4c7d1e8a05b36c94f7de2a1b8c05d63f4e7a9b2c1d0e5f8a3b6c9d2e4f71
12.08 09:22:07 File download a.karimov dogovor-shd-311.pdf · version 3 · 1 842 016 bytessha256: 9f2b4c7d1e8a05b36c94f7de2a1b8c05d63f4e7a9b2c1d0e5f8a3b6c9d2e4f71
12.08 10:03:51 Classification change s.ibragimov IS-pol-014/2026 · classification 1 → 2object: 8f2c41d0-5b9a-4e77-9c3e-1ab6f0d2e845

The log is immutable; access to it requires a separate security-administrator permission.

The bank archive

From a paper-and-digital legacy to permission-aware search

01

Legacy

Paper case files, scans in network folders, registers in spreadsheets - all of it enters the system as is.

02

Dry run

The batch is validated as a whole: the entire reference graph is checked before a single verdict is written.

03

Discrepancy report

Discrepancies surface before anything is written: the archivist decides what to fix in the source.

04

Idempotent import

Re-uploading the same batch creates no duplicates. Multi-volume case files assemble correctly.

05

Scan OCR

Russian and Uzbek Latin script: 0.2–0.3% error rate, 8–12 thousand pages per hour on four cores.

06

Search and appraisal

Full-text search strictly permission-aware, records appraisal, and destruction acts.

The OCR engine has been benchmarked on a corpus of 160 measurements. A benchmark on your samples is week one of rollout. Storage volume: roughly 0.5 TB per million pages.

More for banks →

ERP suite

One process from request to report

Shared directories for counterparties, products, and organizations; shared currencies and VAT; shared permissions and audit.

01

Request

CRM, a channel, or Telegram

02

Proposal

exact price arithmetic

03

Approval

a route like any document

04

Deal

pipeline and commitments

05

Shipment

warehouse and a ledger line

06

Report

stock, movements, audit

Hardware requirements

The entire stack - five Go services and a web front end - uses about 185 MB of RAM

Runs on an ordinary server. 1 Gbit LAN, Linux OS. No cloud required; internet is needed only for the Telegram and SMS channels, and both can be disabled.

Profile CPU RAM Disk Notes
Pilot, up to 50 users 4 cores 8–16 GB 100 GB SSD One server, everything in one perimeter
Production, up to 300 users 8 cores x86-64 32 GB 500 GB NVMe RAID1 for the system, database, and hot files Archive storage array attaches separately
Archive with scans and OCR + cores for OCR 32 GB and up S3-compatible storage, about 0.5 TB per million pages 0.9–1.8 seconds per A4 page at 300 dpi, single-threaded

Rollout

Four stages with clear timelines

1–2 days

Installation and base configuration

Deploying the stack on the customer's server; tenant, roles, LDAP connection.

2–4 weeks

Pilot

A working group and real procedures: routes, file plan, journals.

from 1 week

Archive migration

Dry runs of batches, discrepancy report, import. Duration depends on volume.

1–3 months from start

Production operation

Training, printed forms, procedures, acceptance.

Platform

Everything deploys inside the customer's perimeter: no external cloud required

Go microservices, PostgreSQL, NATS, and a Next.js web interface. Services run under systemd; an update is a rebuild and restart during business hours, with no weekend maintenance window.

8

cores and 32 GB RAM - the recommended server

40

minutes for a live demonstration

35

sections of built-in EDMS help

Customer server

Web interface Next.js
Application microservices Go NATS
Database with tenant isolation PostgreSQL RLS
Document and scan files FS or S3
Full-text search permission-aware

No external cloud required. Interface and help in Russian, Uzbek, and English.

Developer

CYBER BOOST LLC

An information security integrator based in Tashkent. KASKAD is built in Uzbekistan, deploys inside your perimeter, and is supported by a local team: no foreign-currency subscription, no support from across an ocean, no updates on someone else's schedule.

In the marketsince 2019
Profileintegration of information security solutions
Portfolio70+ vendors
Industry experiencebanks and fintech in Uzbekistan
ProductKASKAD - enterprise management system
Supportlocal, in Russian, Uzbek, and English

FAQ

Six questions asked before a pilot

Yes. Services, database, files, search, and AI run inside your perimeter. Internet is needed only for the Telegram and SMS channels, and both can be disabled.

No. Licensing is modular, with granular capabilities inside each module. Most start with EDMS and the archive; the rest is enabled later without reinstalling.

Russian, Uzbek in Latin script, and English. The interface is fully translated, and so is the built-in EDMS help: 35 sections in each language.

Case files are described in the file plan; scans are uploaded in batches: a dry run verifies the reference graph, a discrepancy report is issued before writing, and the import is idempotent. OCR covers Russian and Uzbek.

Flexible: module licenses plus per-user workstations. One installation serves the head office and branches; we price the exact mix in a commercial proposal for your configuration.

A pilot for up to 50 users - 4 cores, 8–16 GB, 100 GB SSD on one server. Production for up to 300 users - 8 cores, 32 GB, 500 GB NVMe RAID1, plus archive storage. The whole stack uses about 185 MB of memory.

Let's discuss your environment

Tell us about your archive volume, user count, and procedures - we will prepare a commercial proposal and show the system in a live environment. The demo takes 40 minutes.

Direct line: +998 90 925 41 68 · [email protected]

Full form