Russian hosting
Servers located in Russia. On request — specific data centers with confirmation.
On-premise deployment, SSO, base-level roles, change audit, scrypt passwords, protection against XSS, SQL injection and recursive automations.
Russian hosting by default. Closed perimeter — on request. Files in S3-compatible storage.
Servers located in Russia. On request — specific data centers with confirmation.
Full installation in the customer's closed perimeter. Docker Compose or Kubernetes. No calls back to our servers.
Files in S3-compatible storage (AWS, Cloudflare R2, MinIO, Backblaze). Customer's choice.
Scheduled database snapshots, point-in-time restore. Soft-delete with recovery is built in.
Roles, SSO, API keys and audit — the standard set for enterprise use.
owner / moderator / editor / viewer. Column hiding and row filtering by role.
SAML and OIDC on Business and above. Connect to your corporate IdP (Keycloak, Okta, AD).
Scoped: read-only, specific tables, specific operations. One-click rotation.
Create, update, delete events — per record. 90-day retention, longer on request.
What we do in code and infrastructure — concretely, no hand-waving.
scrypt with salt, server-side verification. Timing-safe comparison. Never stored in plaintext.
JWT in httpOnly cookies, sliding renewal. SameSite + CORS whitelist. No tokens stored in the browser.
No unsafe-inline. XSS protection at the browser level.
Server-side rate limiting via Redis. Auth: 20 requests per 15 minutes. API: 1000 per minute.
Parameterized queries. Whitelisted column identifiers. No SQL string concatenation.
10-run-per-minute cap per automation. Guards against accidental loops.
We're open about what's done and what's in progress.
The storage and processing architecture is aligned with the requirements. Certification is in progress.
Internal policies and processes match the standard. Certification is scheduled.
On request we send the architecture, incident response procedure, role model and backup schedule.