Strategy

On-prem CRM for CIS banks: when it is needed and how

When a bank needs an on-prem CRM, how it differs from private cloud and from public cloud, and how deployment inside a bank’s perimeter works in Uzbekistan.

7 min read

ON-PREM · BANK PERIMETER

An on-prem CRM is the system deployed on the bank’s own servers, inside its perimeter: customer data, call recordings and conversations never leave the organisation’s infrastructure. CIS banks need it when the security function and the regulator require the data to stay physically in the country and fully under the bank’s control, rather than in someone else’s cloud.

When a bank needs on-prem and when cloud is enough

On-prem is not for everyone and not always. It is justified when:

  • The regulator requires residency and control — the data must not leave the bank’s perimeter.
  • The security function runs a security review — it needs access to the deployment, the keys and the audit logs.
  • The data contains sensitive categories — call recordings with voice biometrics, payment information, subscriber personal data.
  • Integration with core banking is needed inside the protected perimeter, with nothing going outside.

Without those requirements, cloud deployment is normally enough for small and mid-sized business. We break down the difference between residency, on-prem and cloud in the CRM data security guide.

How an on-prem CRM is built

In an on-prem deployment the whole Zukko.AI platform runs on the bank’s infrastructure:

  1. Servers in the bank’s data centre — the application, the database and the AI model are deployed inside the perimeter.
  2. Data does not go outside — conversations, calls and customer records stay within the organisation’s environment.
  3. Role-based access control (RBAC) — who sees what is defined by roles; a full audit trail captures every action.
  4. Encryption — AES-256 at rest, TLS 1.3 in transit; the keys are held on the bank’s side.
  5. Core banking integration — over protected channels inside the perimeter. More on the Integrations page.

Technical deployment detail and the security review are covered on the Security page.

On-prem vs private cloud vs public cloud — what a bank should choose

CriterionOn-premPrivate cloudPublic cloud
Where the data sitsThe bank’s serversA dedicated environment in our VPCShared cloud infrastructure
Key controlWith the bankSharedWith the provider
Residency in UzbekistanYesYesDepends on the provider
Who it suitsCIS banks, regulated companiesLarge business, fintechSMB
Rollout timeUp to 30 daysFaster than on-premFrom 2 hours

For CIS banks and regulated companies the choice is usually between on-prem and private cloud — both give residency in the country; public cloud remains for SMBs.

The regulatory wedge: why global CRMs do not fit a bank

Classic global CRMs keep data in EU, US or Russian data centres and offer neither residency in Uzbekistan nor on-prem for a bank — a structural limitation of that class of system, not a setting. Meanwhile the ZRU-547 law “On Personal Data” (as amended by ZRU-1125 of 26 March 2026) requires localisation for biometric data, genetic data and telecom subscriber data. Because voice biometrics may be present in call recordings, “servers in the country” stops being an option for a bank — it becomes a requirement. What exactly the law obliges a business to do is covered in a separate article.

What the bank gets

  • Data fully under control — all customer information stays inside the bank’s perimeter.
  • Passing the security review — access to the deployment, the keys and the audit trail for the security function.
  • Residency compliance — support for ZRU-547 compliance, not a legal guarantee.
  • An AI platform inside the perimeter — sales, support and call analysis with no data leaving the environment.

How the AI-CRM itself works and what is inside the platform is on the product page. Where the data physically sits in a cloud scenario is covered in “Where your CRM data is stored”.

An honest word on certifications

On certifications we are blunt: we claim none. What we show a bank are the controls already in force: encryption, role-based access, a full audit trail, regular penetration testing and deployment inside its own perimeter. We apply GDPR practices and help with ZRU-547 compliance — for a bank, transparency beats overstatement.

Frequently asked questions

What does on-prem CRM mean?

It means deploying the CRM on the bank’s own servers, inside its perimeter; the data never leaves the organisation’s infrastructure.

How does on-prem differ from private cloud?

On-prem is the bank’s hardware in its own data centre; private cloud is a dedicated environment in our VPC. Both give residency in the country, but with on-prem the keys are entirely under the bank’s control.

Is on-prem mandatory for a bank?

Not always — it depends on the requirements of the regulator and the security function. For sensitive data and call recordings, on-prem or private cloud is usually necessary.

How long does an on-prem rollout take?

A turnkey enterprise rollout takes up to 30 days, including the security review and audit-trail configuration.

Does on-prem help with ZRU-547 compliance?

Yes — residency, access control and the audit trail support compliance; this is help with meeting the law, not a legal guarantee.

DEMO

Launch an AI employee on your own channels

We will assemble a demo on your real chats from Instagram, Telegram and telephony — you will see the result on your own numbers. SMB launch from 2 hours.

Uzbek, Russian and English. Connects to your channels and systems.