+998 90 925 41 68 [email protected] On-premise · Tashkent, Uzbekistan
RU ·UZ ·EN
enterprise management
  1. Home
  2. For Banks

Industry solution · banking

Data control stays with the bank: the entire stack runs inside your perimeter

Services, database, files, search, and AI deploy on the bank's servers and never leave the perimeter. The flagship is the records archive: legacy records enter the system in batches, scans become available to full-text search, and destruction happens only under an approved act.

Request a proposal See the system live
on-premise, no caveats isolation: RLS in PostgreSQL SHA-256 for every version LDAP / Active Directory

Typical scenario · bank archive

Legacy records enter the system in batches and become searchable

The bank's paper and digital legacy - case files in boxes, scans in network folders, registers in spreadsheets - follows a single managed route: from batch intake to full-text search and scheduled destruction.

step 1

Legacy

Paper case files, scans in network folders, and registers in spreadsheets are exported in batches: inventories, case files, volumes, files, and links.

step 2

Dry run

The batch is validated in full before any write: the entire reference graph is checked, and a single verdict covers the whole batch.

step 3

Discrepancy report

Discrepancies are visible before anything is written; the archivist decides what to fix at the source. Re-uploading a batch does not create duplicates.

step 4

OCR

OCR: 8–12 thousand pages per hour on four cores; the error rate for Russian and Uzbek Latin script is 0.2–0.3 %. We measure on your samples during the first week of deployment.

step 5

Permission-aware search

Recognized text is indexed the same way as cards and files: an employee finds only what their classification level and clearance allow.

step 6

Appraisal and destruction

When retention periods expire, records appraisal follows; a volume is destroyed only against its own line in an approved destruction act.

The storage lifecycle - the records classification scheme, volumes and case files, acts - is covered in detail on the Records Archive page.

Security and compliance

Compliance gets a mechanism, not a promise

Every item below is a working product mechanism: it can be demonstrated in a live environment and recorded in a security questionnaire.

  • SHA-256 for every file version. The checksum is computed on every change and recorded in an immutable audit log: file substitution shows up on verification, and the action history cannot be rewritten after the fact.
  • Classification levels 0–4 and personal clearances. Five confidentiality levels: a document opens only for an employee whose clearance matches its classification level - a stray link grants nothing.
  • ACL: "Deny overrides Allow." An explicit deny is stronger than any allow - an accidentally granted role does not open a document closed by a direct deny.
  • User directory - LDAP / Active Directory. Accounts, attributes, and lockouts sync from your domain. A departed employee loses access to KASKAD the moment they are disabled in the domain - no manual second registry.
  • Personal data localization. Documents, personal data of employees and clients, and logs physically reside on your servers in Uzbekistan. The on-premise architecture satisfies the localization requirement (Law of the Republic of Uzbekistan "On Personal Data", ZRU-547) by design: there is nowhere for the data to leak.

The full model - roles, backups, updates without a weekend maintenance window - is on the Security page.

Head office and branches

One installation for the entire branch network - the database enforces isolation

A multi-tenant architecture put in banking terms: branches work in a single system, while unit data is separated by the DBMS, not by a condition in code.

One installation

The head organization and branches share a single system: unified reference data, roles, routes, and one audit log instead of a zoo of local copies.

Isolation at the DBMS level

Row-level security in PostgreSQL: the database itself isolates each unit's data. A query without the right permissions returns no foreign rows, by construction.

Flexible licensing

A modular license bound to the customer's server: you enable the circuits you need, and workstations are counted per user. Branches run on a single installation - no separate deployment in each.

The entire stack - five Go services and a web front end - uses about 185 MB of RAM: a branch-network installation requires no cluster. More about licensing

See the bank archive in a live environment

The demo takes 40 minutes and is tailored to your case: legacy migration, OCR, search, retention rules. Tell us about your volumes - we will prepare a commercial proposal.