AntiMalware•August 25, 2026•🇷🇺Translated from Russian

Bitrix24 Releases Fully On-Premise BI Constructor for Regulated Enterprises

Bitrix24 has launched a new delivery model for its BI Constructor that enables full on-premise deployment without any external dependencies.

The platform for visual analytics can now be installed entirely within a customer's infrastructure. No external servers, cloud APIs, or internet connections are required, keeping all corporate data behind closed doors.

Previously, large enterprises faced difficulties because the BI Constructor was available either in the cloud or as a boxed version that still needed access to external infrastructure for updates and auxiliary services. For companies in regulated industries, such outbound channels often conflicted with internal security policies and regulatory requirements.

In the new variant, all data processing and storage occur exclusively on the customer's servers. Organizations independently manage access rights, backup procedures, updates, and integration with internal security tools.

The solution is fully compatible with the boxed version of Bitrix24 running on PostgreSQL and does not connect to external CDNs or cloud APIs.

1C-Bitrix expects the closed delivery model to appeal to large businesses and organizations that must process restricted-access data inside the corporate perimeter. The product has already been implemented and tested in pilot environments, with broader customer pilots scheduled in the coming months.

Related articles

AntiMalware•Policy & Regulation

Russia Discusses Extra Fees for International Traffic Over 50 GB in 5G Networks

The Russian Ministry of Digital Development is again in talks with mobile operators about introducing charges for international data traffic exceeding 50 GB per month, but only within 5G networks. The measure would potentially apply to VPN services and other foreign resources, adding to users' mobile bills. No final decision has been reached and the exact fee amount remains unspecified. Sources indicate a possible launch in October, though timelines are subject to change. Technical challenges arise because current 5G deployments rely on LTE infrastructure, requiring new traffic separation, network handover tracking, and billing system adjustments. Average monthly mobile data usage stood at 24 GB in 2025, making the 50 GB international 5G threshold a narrow scenario. Headlines claiming VPNs will become paid services overstate the current discussions, which focus solely on international traffic classification.

Habr•Policy & Regulation

Fonts, CDNs, and Hosting: The Cross-Border Data Transfers No One Notices

A Russian developer building a contract-processing service discovered that his website was silently sending visitor data to foreign companies despite keeping all contract data on Russian servers. The site used Vercel for hosting, Google Fonts across 33 pages, and Cloudflare's cdnjs for PDF and Word libraries, exposing IP addresses, browsers, and browsing history. Under Russia's 152-FZ, such transfers require a separate notification to Roskomnadzor, and the United States and EU are not on the list of countries with adequate protection. The developer migrated fonts and libraries to his own Russian server, moved hosting domestically, and updated his privacy policy after a single console command revealed the external domains. The case highlights how common web practices like loading Google Fonts or using CDNs can trigger strict data localization and notification rules, with fines reaching millions of rubles for violations.

Habr•Policy & Regulation

How to Complete the Roskomnadzor Personal Data Notification Form in 2026: Field-by-Field Analysis

The article provides a detailed walkthrough of the current Roskomnadzor notification form for operators processing personal data under Russian law. It explains that the form is an extract from existing internal documents rather than a questionnaire, requiring operators to reference their data processing policy, inventory results, appointment orders, and protection level acts. Key prerequisites include confirming that notification is mandatory after the 2022 amendments removed most exemptions, preparing five core documents, and understanding that the form pulls data directly from those records. The guide covers every section, from operator identification and processing regions to data categories, protection measures, geography, and post-submission obligations. It also addresses common mistakes, the option to save drafts, auto-population features, and liability for non-compliance or inaccurate information. The piece concludes with a checklist mapping each form field to its source document.

Habr•Policy & Regulation

OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches

Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.