Security & Hosting

Your data stays inside Kazakhstan

In all three hosting options, data is stored in Kazakhstan. For sensitive data there's a Hybrid mode: personal data never leaves your company's IT perimeter. The platform complies with the Digital Code of the RK and the Personal Data Law.

What the platform provides

  • Data centers and backups located in Kazakhstan — across every hosting option
  • Compliance with the Digital Code of the RK and the Personal Data Law
  • Encrypted connection; in Hybrid mode — a private server inside the customer's perimeter
  • Role-based access model and an audit log of every user action
  • Regular backups and an SLA on service availability

Architecture and connection security

Three-tier architectureWeb interface, application server and database. Each tier evolves and scales independently — giving flexibility, scalability and easier maintenance.
A web interface with no server loadMatches desktop applications in capability. The visual layer renders entirely in the user's browser, adding no extra load on the application server.
Certificate-based access, TLS 1.2Every user gets access via a client certificate, and the whole connection is protected by TLS 1.2 — the encryption level used in banking and payments.

Three hosting options

In all three, data is stored inside Kazakhstan. What differs is the perimeter that holds personal data.

CloudThe platform, updates and backups are on our side, in data centers within the RK. Fast start, fits most companies.
HybridPersonal and sensitive data never leave your company's IT perimeter. A private TopHR server is deployed inside your network's DMZ zone.
On-premiseA full installation inside your perimeter — for banks and the public sector with strict hosting requirements.

The hybrid storage model

For customers for whom not sending employee personal data to external systems is essential.

Here's how it works: before data ever moves from 1C into TopHR, it goes through depersonalization. The TopHR platform itself never contains or stores employee personal data in the clear — only anonymized data, sufficient for the business logic to run.

This means the customer can be confident that even running in the cloud, their HR data is protected at a level that meets strict information-security and data-protection requirements.

Private server in the DMZ

A private TopHR server is deployed inside the customer's perimeter, in the network's DMZ zone.

Depersonalization

Data from 1C is depersonalized on the private server before it reaches TopHR.

Only anonymized data

Only depersonalized data flows on to the shared TopHR server.

IPSec tunnel

The connection to the private server runs through a secure IPSec tunnel.

Frequently asked

Where is the data physically stored?
In all three hosting options — Cloud, Hybrid, On-premise — data is stored in data centers within the Republic of Kazakhstan. Backups are stored there too.
What is the hybrid storage model?
A private TopHR server is deployed inside your perimeter, in the network's DMZ zone. Data from 1C is depersonalized there before moving to the shared server; the connection runs over an IPSec tunnel. The TopHR platform itself never stores personal data in the clear.
How is the user connection protected?
Every user gets access via a client certificate, and the connection is protected by TLS 1.2 — the encryption level used in banking and payments.
What requirements does the platform meet?
The Digital Code of the RK and the Personal Data Law. A package of security documents is available on request.
How is employee access segregated?
A role-based model: rights are granted by role and org structure. Every action is recorded in the audit log.

Need documents for your security team?

We'll send you a description of the architecture, protection measures and hosting options.

Request