Questions and Answers
Answers to frequently asked questions on information security, biometrics, low-code development, fintech and other areas.
Information Security
314 questionsWhat is a VPN in simple words?
VPN (Virtual Private Network) is a technology that creates an encrypted tunnel between your device and the Internet. All traffic passes through this tunnel, protecting data from interception. It is like a secret corridor through which your data travels safely. VPN is used to protect personal data and access corporate resources. For government systems, a VPN must use certified CIPF. The installation service will help you deploy a VPN in your infrastructure.
How to choose a VPN for business?
For business, a VPN is chosen based on the network scale, the number of employees and regulatory requirements. Key criteria: support for certified CIPF, compliance with 187-FZ and 152-FZ, and the ability to integrate with existing infrastructure. It is recommended to use server VPN solutions (Site-to-Site) to unite branches and Remote Access for remote employees. The "Fintech" company offers installation and configuration of corporate VPN solutions with a guaranteed level of security.
How to set up a VPN for remote access for employees?
To organize remote access for employees to the corporate network via VPN, you need to: 1) deploy a VPN server at the network boundary, 2) configure PKI certificates for client authentication, 3) install VPN clients on work devices. For government systems, the use of certified CIPF is mandatory. The "Fintech" company offers installation and configuration of corporate VPN solutions.
What is the catch of a free VPN?
The catch of free VPN services is that they make money by selling user data to advertisers, limit speed and traffic, and may contain malware. Free VPNs do not guarantee confidentiality and do not use certified CIPF. For government and corporate systems, the use of free VPNs is unacceptable. The "Fintech" company offers reliable corporate VPN solutions with a security guarantee.
What happens if the VPN is on all the time?
An always-on VPN provides continuous protection of all data, but may slow down the Internet speed due to encryption and routing of traffic through remote servers. Problems with access to some local services are also possible. For corporate systems, it is recommended to use a VPN with certified CIPF and split tunneling settings to balance security and performance. The installation service will help you configure the optimal VPN configuration.
How does a VPN protect data on public Wi-Fi networks?
When connecting to public Wi-Fi networks, traffic can be intercepted by attackers. VPN encrypts all traffic, making it unreadable to interceptors. This is especially important for employees working remotely and when using mobile devices to access corporate resources. For organizations whose employees often work outside the office, a VPN is a mandatory element of protection. The installation service will help you configure a corporate VPN solution.
Is there a built-in VPN in my phone?
Android and iOS have built-in VPN clients, but they only support limited protocols (PPTP, L2TP/IPSec, IKEv2). For full functionality and the use of certified CIPF, it is recommended to install specialized VPN applications. For corporate systems, we offer the configuration of VPN clients using PKI certificates. The installation service will help you deploy a corporate VPN solution.
Biometrics and Identification
55 questionsWhat does iris recognition show?
In the biometric context, iris recognition is a method of identifying a person by the unique pattern of the iris of the eye. In the medical context, it is an unconventional method of assessing health by the iris. In our work, iris recognition is used for biometric identification. The Biovizum product includes modules for iris recognition. The design service will help implement the system.
How does iris identification work?
Iris identification takes seconds. The user holds their gaze on the reader, the device scans the iris, compares it with stored templates in the database and finds a match. Scanning does not require physical contact and works at a distance. The Biovizum product includes modules for iris recognition. The design service will help implement the system.
How accurate is iris recognition?
Iris recognition provides one of the highest accuracy levels among all biometric methods. The probability of a false match is estimated at about 1 in 10 million, which is significantly higher than fingerprints or face recognition. The iris pattern is stable throughout a person's life and is practically unaffected by age, which makes it a reliable biometric identifier.
How much does iris recognition cost?
In the biometric context, the cost of iris recognition systems depends on the number of access points, the type of equipment and the complexity of integration. Basic solutions for a small office can cost from 100,000 rubles. For large enterprises and secure facilities, the cost is calculated individually. The Biovizum product offers comprehensive solutions. The design service will help calculate the implementation cost.
What does an iridologist do?
In the medical context, an iridologist studies the iris of the eye to assess health. In our work, iris recognition is used for biometric identification. Specialists in implementing iris recognition systems are engaged in equipment installation, software configuration and integration with existing systems. The Biovizum product provides high-precision recognition.
What is the difference between iris recognition and fingerprint recognition?
Both are biometric methods, but they differ in accuracy and operating conditions. Iris recognition is more accurate (the probability of a false match is about 1 in 10 million versus 1 in 50,000 for fingerprints), works contactlessly at a distance and does not depend on the condition of the skin. Fingerprint recognition requires physical contact and can fail with dirty or damaged fingers.
What are the advantages of iris recognition?
Iris recognition provides high accuracy and speed of identification: the check takes less than a second and does not require physical contact. The iris pattern is unique and stable throughout life, and it is practically impossible to forge it. This makes the method suitable for access control and high-security facilities. The Biovizum product offers iris recognition solutions.
Document Verification and Access Control
42 questionsHow to read the machine-readable zone in a passport?
The machine-readable zone in a passport consists of two lines of fixed length (44 characters each for foreign passports). The lines contain the document type, country code, surname and given name, document number, date of birth, sex, validity period and check digits. Reading is performed by automatic devices with OCR-B. The APM-1 and APM-2 equipment provides fast and accurate MRZ recognition. The design service will help implement reading systems.
What is the machine-readable zone of a passport?
The machine-readable zone (MRZ) is a special area at the bottom of the personal data page containing encoded information about the holder and the document. Russian foreign passports use the TD3 format — two lines of 44 characters. The MRZ contains the document type, country code, surname and given name, passport series and number, date of birth, sex, validity period and check digits. The SPV-7024M equipment provides MRZ reading. The design service will help implement identification systems.
What is a machine-readable passport?
A machine-readable passport (MRP) is a travel document in which the data on the identification page is encoded in optical character recognition format (OCR-B) in a machine-readable zone (MRZ). The MRZ standard is regulated by ICAO Doc 9303. Machine-readable passports allow data to be read automatically at borders and other control points. The APM-1 and APM-2 equipment provides MRZ reading.
Where is the machine-readable zone on a passport?
The machine-readable zone (MRZ) is located at the bottom of the passport page containing personal data and the photo. In Russian foreign passports, this is the page with the photo — at the very bottom there are two lines with an alphanumeric code. Russian internal passports also contain the MRZ on the photo page. The SPV-7024M and APM-1 equipment provides MRZ reading for automatic identification.
How to decode the machine-readable code in a passport?
The machine-readable code in a passport is decoded per the ICAO standard. The first line contains the document type, country code, surname and given name of the holder. The second line contains the passport series and number, nationality, date of birth, sex, validity period and check digits. The check digits allow verifying the correctness of the data. The APM-1 and APM-2 equipment automatically recognizes and verifies the MRZ. The design service will help implement reading systems.
How to read a machine-readable passport?
A machine-readable passport is read by automatic devices using optical character recognition (OCR). MRZ data consists of two lines of 44 characters using the Latin letters A-Z, Arabic digits 0-9 and the filler character "<". MRZ scanners such as the SPV-7024M read the code in a fraction of a second and transfer the data to the system. The APM-1 and APM-2 equipment provides a full identification cycle.
What is the difference between a biometric passport and a machine-readable passport?
A machine-readable passport allows scanners to quickly read the printed information in the MRZ zone. A biometric (electronic) passport does the same, but additionally contains an electronic chip with the holder's biometric data (photo, fingerprints). A biometric passport provides a higher level of forgery protection. The APM-1 and APM-2 equipment supports reading both types of documents.
Low-code and Automation
126 questionsWhat are low-code and no-code platforms?
Low-code and no-code are technologies for creating applications without writing code or with minimal code usage. No-code platforms are aimed at business users and completely exclude programming. Low-code platforms imply that developers can add code where visual tools are not enough. Our SINTEZ-M platform belongs to the low-code class and allows creating enterprise applications with minimal programming. Learn more about approaches in the technologies section.
What is low-code?
Low-code is an approach to software development in which applications are created in a visual constructor using drag-and-drop. The main elements are already programmed by the platform, you just need to configure their parameters. If the standard functionality is not enough, professional developers can write their own code. Our SINTEZ-M platform implements this approach, lowering the entry threshold for creating complex systems. Read more about training in the services section.
What is low-code in simple words?
Low-code is a method of creating applications using visual constructors that reduce the amount of code without eliminating it completely. It is like assembling a constructor from ready-made parts instead of machining every part from scratch. This approach allows creating applications 3-5 times faster than traditional development. The SINTEZ-M platform uses this principle for business process automation. You can familiarize yourself with the basic principles in our glossary.
What low-code platforms are there?
ELMA 365, SimpleOne, Visary and others are popular on the Russian market. Our SINTEZ-M platform occupies a leading position thanks to the combination of BPMS, RPA functionality and web interface creation tools. It is included in the Russian Software Registry and is used in the financial and government sectors. The design service will help choose the optimal architecture for your tasks.
What is low-code no-code for dummies?
For beginners: low-code and no-code are ways to create programs without deep programming knowledge. No-code — without code at all, only dragging blocks. Low-code — with minimal code for complex tasks. Both approaches speed up development and allow business users to create simple solutions. Our SINTEZ-M platform belongs to low-code and is available for learning through our courses. Learn more in the technologies section.
What is a low-code BPM platform?
A low-code BPM platform is a business process management system built on the principles of low-code development. It allows not only modeling processes in BPMN notation, but also creating full-fledged applications with user interfaces with minimal programming. Our SINTEZ-M platform combines BPMS, RPA and low-code in a single environment. Read more about the capabilities in the products section.
What Russian no-code platforms are there?
Craftum, Insales, Flexbe and others are represented on the Russian no-code platform market for creating websites and online stores. For more complex corporate tasks, low-code platforms are used, such as our SINTEZ-M, which allows creating full-fledged business applications. The design service helps determine which class of platforms suits your tasks. Read more about the related approach in the article No-code platform.
Fintech and Public Finance
214 questionsWhat is the point of introducing the digital ruble?
The introduction of the digital ruble is aimed at creating a third, more reliable and technologically advanced form of the national currency. It expands the possibilities for fast, cheap and secure settlements, opens new prospects for the development of the digital economy and increases the transparency of financial flows. It is a tool for digital transformation of the financial system. Read more about financial technologies in the technologies section.
What is the catch of the digital ruble?
The main "catch" of the digital ruble is that it is a tool exclusively for settlements, not for savings. No interest is accrued on the digital ruble balance, so savings will gradually depreciate due to inflation. Also, all transactions become transparent to the state, which limits financial privacy. However, its use is voluntary, and you can always keep savings in traditional deposits.
Will it be possible to refuse the digital ruble?
You can refuse the digital ruble at any time simply by not opening a digital wallet — it is not mandatory to do so, and no refusal statements need to be written. The use of the third form of the national currency is absolutely voluntary. You can continue to receive salary and pensions to a card or in cash, as before. At the same time, for public procurement, the digital ruble can become a convenient tool for controlling targeted use of funds.
How much does 1 digital ruble cost?
One digital ruble equals one ordinary ruble. It is not a separate currency, but the third form of the national currency that will exist in parallel with cash and non-cash rubles. It can be freely exchanged for non-cash or cash money without conversion fees, at a 1:1 ratio.
What will happen to cash after the introduction of the digital ruble?
Cash will not disappear after the introduction of the digital ruble; its abolition is not planned. All three forms of currency (cash, non-cash and digital) will have equal value, circulate in parallel and be freely convertible into each other. The digital ruble is not a replacement for cash, but an addition to it, providing new opportunities for the national payment system.
How is the digital ruble different from money on a card?
The main difference is that non-cash money on a card is stored in an account at a commercial bank, while the digital ruble is stored on the Bank of Russia platform. This means that the digital ruble is protected from the risk of bank bankruptcy. At the same time, it does not accrue interest, unlike deposits, and is intended exclusively for payments and transfers, providing high speed and low fees.
When will the digital ruble be introduced for pensioners?
Payment of pensions in digital rubles is already provided for by law, but a mass transfer of pensioners to this form of currency is not planned. The transition to receiving a pension in digital rubles is exclusively voluntary. Widespread implementation and the ability to open digital wallets on a mass scale start from September 1, 2026. A pensioner has the right to choose how to receive payments: in cash, to a card or in digital rubles. To study related concepts, we also recommend familiarizing yourself with Banking secrecy.
Import Substitution
66 questionsWhat is software import substitution?
Software import substitution is a strategic process of transition of government structures and business from foreign software products to domestic analogues. The goal is to ensure technological sovereignty, protect critical infrastructure from sanctions and prevent data leaks. The transition is strictly regulated by the government and is mandatory for state companies and CII facilities. Our products Sintezm and SKIF-BP are included in the Register of Domestic Software.
Who is required to use Russian software?
All state and significant corporate structures, including owners of critical information infrastructure (CII) facilities, are required to transfer their systems to Russian software. For state customers, the use of domestic software from the Register is a mandatory requirement for procurement under 44-FZ and 223-FZ. Our products Sintezm and SKIF-BP comply with these requirements.
What are 3 examples of import substitution?
Examples of import substitution: the financial sphere — the creation of the Mir national payment card system; information technology — the development of domestic operating systems (Astra Linux) and office suites (MyOffice); agriculture — the construction of agro-industrial complexes to ensure food independence. In the software sphere, our products Sintezm and SKIF-BP are examples of successful import substitution.
What does inclusion in the Russian software register give?
Inclusion in the Russian Software Register gives tax benefits (VAT exemption on sales), advantages in public procurement (priority in purchases for state needs), access to grants and preferential lending, and also increases trust in the product. Our products Sintezm and SKIF-BP are included in the Register. The research service will help you choose suitable solutions.
Why switch to domestic software?
The transition to domestic software ensures technological sovereignty, protection from sanctions risks, data security and compliance with legislative requirements. Only software included in the Register is allowed to participate in tenders under 44-FZ and 223-FZ. Our products Sintezm and SKIF-BP are ready-made solutions for import substitution. The training service will help employees master new systems.
What is the plan for the transition to domestic software?
The transition plan includes an inventory of the foreign software used, selection of analogues from the Register of Russian Software, pilot testing, data migration and employee training. The transition deadlines are set by regulators — for CII facilities until January 1, 2028. Our products Sintezm and SKIF-BP are ready for implementation. The design service will help develop a roadmap.
What are the disadvantages of import substitution?
The disadvantages of import substitution may include rising prices due to reduced competition, the need to improve product quality to meet standards, and increased production costs due to the cost of creating new products. However, for critical information infrastructure, import substitution is an unavoidable necessity. Our products Sintezm and SKIF-BP offer competitive solutions.
Infrastructure
232 questionsWhat is a storage area network in simple words?
A storage area network (SAN) is a powerful digital "safe" for giant volumes of information. Read more about related aspects in the materials: Server virtualization and Containerization (Docker).
What is the difference between a server and a storage system?
Servers process requests, run applications and provide network services, while a storage system (SAN) is a specialized array of disks and controllers designed for centralized, high-performance and fault-tolerant data storage shared between servers. More detailed information is available in the articles about data center (DPC) and Data warehouse.
What is included in a storage system?
A storage system consists of the following elements: power supplies; a controller; a registry of HDD/SSD drives; cache memory. For in-depth study, refer to the sections SMEV (interdepartmental electronic interaction system), Data warehouse and Hypervisor.
What types of storage systems are there?
The main types of storage systems: block, file and object. More detailed information is available in the articles about Hypervisor, Containerization (Docker) and Thin client.
What is a storage system for?
A data storage system is a specialized infrastructure for centralized storage and management of information in computer networks. For in-depth study, refer to the sections Thin client, Server virtualization and Backup system (SRK).
How is NAS different from a storage system?
NAS (Network Attached Storage) is a network storage providing file-level access through standard protocols (NFS, SMB), while a storage system (SAN) provides block-level access at high speed and is better suited for databases and critical systems. More detailed information is available in the articles about data center (DPC) and Workstation.
Can 4 servers be connected to one storage system?
Modern storage systems with a SAS interface allow connecting no more than 8 servers (no more than 4 with path duplication). For in-depth study, refer to the sections Thin client and Containerization (Docker). We also recommend reading Data archiving, Cloud storage and Server rack.
Document Workflow
89 questionsWhat is included in the concept of document flow?
Document flow is the process of movement, processing and storage of documents in an organization from the moment of their creation or receipt to sending, execution or delivery to the archive. For in-depth study, refer to the sections SKIF-BP and the AIS design.
What is document flow in your own words?
Document flow is the movement of documents within a company from the creation of the document to its delivery to the archive. For in-depth study, refer to the sections AIS design, the big data technology and Electronic archive.
What should a document flow specialist know?
A document flow specialist should know: the laws of the Russian Federation, regulations, orders and other normative documents related to the documentation support of the organization; the norms and algorithm of planning and work process; ways and methods of studying, developing and improving the organization's documentation services. For in-depth study, refer to the sections Electronic archive and the big data technology.
What types of document flow are there?
Types of document flow: Internal — document movement within an organization. External — document exchange with external organizations. Manual — paper document transfer. Electronic — automated movement and storage of digital documents. We also recommend familiarizing yourself with the big data technology, Electronic archive and SKIF-BP for a complete understanding of the topic.
What is basic document flow knowledge?
Document flow is the movement of documents in an organization from the moment of their creation or receipt to the completion of execution, sending or transfer to the archive. More detailed information is available in the articles about AIS design, SKIF-BP and the big data technology.
What is included in document flow management?
Document flow management: receipt, creation, registration of documents; processing, approval, signing; sending to the counterparty; delivery for storage. Read more about related aspects in the materials: SKIF-BP and the big data technology.
What documents are included in document flow?
This includes contracts, invoices, acts, waybills and other documents that are sent to each other in the process of cooperation. Read more about related aspects in the materials: AIS design and SKIF-BP. For the study of related concepts, we also recommend familiarizing yourself with Document scan copy, Standard document and Document life cycle.
SKIF-BP
6 questionsError when signing a form in the web client.
Check the CryptoPro plugin version. The plugin version can be checked in the browser here: https://www.cryptopro.ru/sites/default/files/products/cades/demopage/simple.html. If you plan to work with signatures in IE or FireFox, try updating the plugin to version 2; if using Chrome, version 1.5 is currently the maximum.
How do I unfold columns vertically in analytics as in SKIF 3?
The essence of the rotation problem is as follows:
SKIF 3 stored data vertically, i.e. the column number was the same attribute as the header attributes or the row code:
Where A and B are header attributes, Row is the row code, Column is the column, and X is the sum. In other words, each cell was stored in a separate row of the database table.
In SKIF-BP the storage is horizontal. That is, one form row is one row in the database.
You can unfold the data back to vertical in several ways. The simplest of them is the union operator.
Our analytics has two ways to use the union operator:
1. The dedicated "Union of tables" cube.
2. The universal "SQL script" cube.


What do the messages "Indicator XXX with attributes YYY cannot be updated because it has a higher priority owner" mean and what should be done about them?
During the normal flow of the reference data formation process on your server, such messages appear only when users want to refuse the update of some indicator and, for this purpose, set themselves (with a higher priority) as the owner of this row.
To fix this situation you need to:

How do I make an analytics filter for several periods that do not follow each other?
The question of filters on intervals with the ability to obtain NON-CONSECUTIVE intervals is still hotly debated among developers.
There are two ways out at the moment:
1. Use an additional "SQL script" cube to remove the excess.
2. Create two sources for the same form but with two different filters.

Which SQL Server version should I use?
SKIF-BP can be installed on SQL 2005 and higher. SKIF 3 can be installed on 2000 and higher. However, we strongly recommend installing the maximum SQL version available for your OS at the time of deploying the software suite.
Which Postgres version should I use?
SKIF-BP can be installed on PostgreSQL 14.3 and higher.
Recommended system requirements:
Processor: 8 cores, clock speed 2.90 GHz or higher.
Platform: 32-bit or 64-bit.
RAM: 32 GB or higher.
Hard disk: the size depends on the database size, but no less than 1 GB of free disk space
Tax Revenue Monitoring
6 questionsDelivery contents for 2023

When accepting files, no files are visible in the "File selection" window
You have selected the wrong municipality. The selected municipality is indicated in the bottom left corner of the screen. To set the required municipality, select the menu item Service => Settings, tab General, and choose your municipality from the corresponding list.

Purpose of the "Simplified client" program
The «Simplified client» is designed to provide users with access to the central database from remote workstations connected to the main local network via dedicated channels.

When starting the «simplified client», the user enters their OKTMO code as the LOGIN and gets access only to their own municipality reports.
The "Additional summaries and selections" menu item contains no reports
You need to unpack the QueryAdd.zip file from the query\Additional folder into the same folder.

Data for December of last year (as of January 1 of the current year) is not loading.
You need to load the license for the current year into the program for the previous year.
When loading data for December of last year (as of January 1 of the current year), data for January of the current year (as of February 1 of the current year) is loaded.
The Federal Tax Service sent the files not in January but in February, so the files have the month February instead of January in the date. In the program, in the Information resource data loading window, set the required values in the As of and Reporting month fields.
Did not find an answer to your question?
Leave a request — our specialists will contact you and help you solve any task in the field of information security and automation.