Working with contracts
Mobile App
Template Contract
Integrations
QR Contract
Electronic certificates of completed work
International EDI
Electronic employment contracts
Update on the situation regarding the statement from CARCA about the discovered vulnerability in the Documentolog system.
3 min.
08.08.2018
833
Yesterday, August 8, 2018, CARCA - a licensed organization providing pentesting services - published a post on their Facebook page titled «Critical vulnerability found in the Kazakh document management system».
According to CARCA's statement, a critical vulnerability was discovered in the Documentolog document management system, which allowed access to the business correspondence of all organizations using Documentolog, as well as elevated the attacker's privileges to that of a domain controller administrator.
To clarify the situation, Documentolog's CEO, Baizhan Kanafin, shared his comments regarding the aforementioned statement:
«CARCA published a sensational headline on their page claiming that they found a vulnerability in our document management system. They imply that since our clients include large state organizations and we are already working with them, we are vying for the role of a state EDS, this cannot happen without someone’s «paw» or «lobbying». Therefore, they believe they have the right to hack us and fight for the safety of the data we hold.
As we learned yesterday, CARCA was hired by one of our clients to analyze the vulnerability of their electronic document management system «Documentolog», which is located in their domain but operates on a SAAS model, meaning it runs on our resources. They were unable to directly hack the system. By analyzing the requests coming from the system, we found that there were requests from their portal to our internal company portal. This is our internal resource at Documentolog, where the entire company operates.
As a result, they sent an email with embedded executable code from our client’s domain to our technical support service. Naturally, our service opened this email, and the hackers were able to intercept the session. Thus, they gained temporary access to all documents on our portal that the support staff has access to. Consequently, they had access to some internal documents used by our technical specialists. This became the main find for the hackers. After obtaining access to these documents, they began using the information to compromise our clients.
Yesterday, August 7, when our client’s employees informed us about this, we fixed all vulnerabilities within an hour. In particular, we eliminated the possibility of session hijacking, restricted access rights for all employees, and removed documents containing confidential information about our clients from our system.
Undoubtedly, this was very useful information for us, and we were grateful for the identified vulnerabilities; we even considered conducting such tests on a periodic basis. We seem to have agreed to meet with CARCA specialists next week.
As a result, an hour ago, CARCA decided that they should not miss the chance to promote themselves through cheap PR and published a post that I «shared». As the head of Documentolog, I can say the following:
We reiterate that a detailed report regarding yesterday's situation and the measures taken to address the vulnerability will be published at the earliest opportunity.
The interview with Kanafin B. was recorded by reporters from mail.kz
Share the link on social media:
Read more
d8n.ai официально доступен клиентам Documentolog
Сегодня мы запускаем новый этап развития экосистемы Documentolog — d8n.ai стал официально доступен для наших клиентов. И это не просто новая функция — это новый уровень работы с документами, задачами и коммуникациями.
Strengthening Compliance with Labor Legislation in 2026: What Kazakhstan Employers Need to Know
In 2026, Kazakhstan is strengthening control over compliance with labor legislation. One of the key regulatory instruments is the Unified System for Recording Employment Contracts (USREC), operating on the enbek.kz platform. Government authorities are moving toward stricter administration: from March 2026, administrative liability will be introduced for violations of the procedure for entering information on employment contracts into the USREC. This means employers must proactively establish correct processes for registering and maintaining HR documentation to avoid fines and legal risks.
Documentolog and Kontur.Diadoc have launched legally significant cross-border electronic document management between Kazakhstan and Russia
Documentolog is expanding the capabilities of electronic document management and launching an integration with Kontur.Diadoc, one of the largest electronic document management platforms in Russia. The new functionality enables companies from Kazakhstan and Russia to exchange documents and sign them with their countries’ electronic signatures with full legal validity. The integration addresses a key market challenge — the lack of a legal and convenient cross-border electronic document management solution between Kazakhstan and Russia.
17.02.2026 18:59
👋 Здравствуйте! Я Ai.Sulu, ИИ-ассистент Documentolog.
Помогу подключиться к тарифу, разобраться в возможностях платформы или автоматизировать процессы.
Что вас интересует?