Habr•August 5, 2026•🇷🇺Translated from Russian

Developer Builds Decentralized Messenger to Navigate Russian Laws 149-FZ and 152-FZ

A solo developer has released Gram, a lightweight messenger built entirely alone using the $mol framework and HyperBaza technology. The application enables encrypted messaging without logins, passwords, or any personal data collection and is intended only for home or personal use.

The project serves as a practical case study of Russian Federal Law 149-FZ, which defines an instant messaging service organizer as any entity providing systems for exchanging electronic messages where the sender selects the recipient and no public information is hosted. The developer notes that Gram can function offline, does not guarantee instant delivery, and performs all decryption exclusively on user devices.

Key features include direct dialogs by known ID, creation of invite-only conversations, and public registries that users can join voluntarily. All correspondence is end-to-end encrypted via HyperBaza, while push notifications cannot access message content. A built-in proof-of-work mechanism requires CPU effort for each message to deter spam bots.

Under 152-FZ on personal data, the application collects nothing, so no obligations arise. However, 149-FZ obligations fall on whoever operates public HyperBaza nodes because those nodes handle message relay without decryption. The law explicitly exempts citizens acting for personal, family, or household needs, allowing private use but requiring public nodes to be disabled.

The application cannot technically satisfy several legal requirements: identifying users by phone number, providing decryption keys, or storing readable message content for six months. Source code is published on GitHub, and users outside Russian jurisdiction may run their own nodes on gh-pages or local instances.

Metadata such as sender, recipient, and timestamps remains visible on servers. Due to the decentralized architecture, revocation of access to old messages in group chats is impossible. A poll on the original post showed most respondents believe the public node operator would be considered the organizer of information distribution.

Related articles

Habr•Policy & Regulation

Fonts, CDNs, and Hosting: The Cross-Border Data Transfers No One Notices

A Russian developer building a contract-processing service discovered that his website was silently sending visitor data to foreign companies despite keeping all contract data on Russian servers. The site used Vercel for hosting, Google Fonts across 33 pages, and Cloudflare's cdnjs for PDF and Word libraries, exposing IP addresses, browsers, and browsing history. Under Russia's 152-FZ, such transfers require a separate notification to Roskomnadzor, and the United States and EU are not on the list of countries with adequate protection. The developer migrated fonts and libraries to his own Russian server, moved hosting domestically, and updated his privacy policy after a single console command revealed the external domains. The case highlights how common web practices like loading Google Fonts or using CDNs can trigger strict data localization and notification rules, with fines reaching millions of rubles for violations.

Habr•Policy & Regulation

How to Complete the Roskomnadzor Personal Data Notification Form in 2026: Field-by-Field Analysis

The article provides a detailed walkthrough of the current Roskomnadzor notification form for operators processing personal data under Russian law. It explains that the form is an extract from existing internal documents rather than a questionnaire, requiring operators to reference their data processing policy, inventory results, appointment orders, and protection level acts. Key prerequisites include confirming that notification is mandatory after the 2022 amendments removed most exemptions, preparing five core documents, and understanding that the form pulls data directly from those records. The guide covers every section, from operator identification and processing regions to data categories, protection measures, geography, and post-submission obligations. It also addresses common mistakes, the option to save drafts, auto-population features, and liability for non-compliance or inaccurate information. The piece concludes with a checklist mapping each form field to its source document.

Habr•Policy & Regulation

OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches

Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.