Skip to content

Project Governance & Digital Asset Control Platform

Dedicated Data Infrastructure for the 42 MW Mistri Khola Hydroelectric Project

Prepared forMountain Energy Nepal Limited (MENL)
Prepared byAashik Baruwal
DateSeptember 20, 2026

1. Executive Summary

As a publicly listed entity on the NEPSE, Mountain Energy Nepal Limited (MENL) requires absolute data integrity across its corporate disclosures, regulatory reporting, O&M procurement, and operational risk management for the 42 MW Mistri Khola Project.

I have built a working platform that brings these together in a project portal plus a controlled admin system: structured publishing, maker-checker-approver controls, procurement workflows, document integrity checks, bilingual disclosures, risk tracking, and auditable records. It runs as a single Cloudflare Worker with low overhead.

This proposal defines a proven digital architecture framework. Deployment scope, timeline, and operational constraints are finalized during discovery to align precisely with Mountain Energy Nepal Limited's corporate requirements.

Prototype and Deployment Scope

What you see here is a working prototype from a comparable hydropower context. A Mountain Energy Nepal Limited deployment would be configured around its project structure, roles, procedures, and approved disclosures.

Proposed Next Step

A short walkthrough to check fit against project requirements. Scope, timeline, support, and commercial terms follow only if there is fit. The concept covers:

  • Project disclosure: Public technical repository with approval before publication.
  • Procurement: Browser-encrypted bidding with client-side AES-256-GCM.
  • Records: Maker-checker-approver transitions with verifiable WORM audit history. See Technical Appendix for the state machine and enforcement.
  • Generation & Risk Tracking: An air-gapped dashboard for administrative tracking of metrics and risks, completely isolated from operational technology (OT/SCADA) networks to eliminate any external attack surface.

2. Why a Dedicated Project Platform

When disclosures, procurement files, and governance records sit across websites, email, and spreadsheets, control and auditability get harder.

One controlled system fixes that:

  • Reporting support: Drawdown histories, environmental records, and disclosure registers for lender, shareholder, and management review.
  • Generation tracking: Logs paired with applicable seasonal PPA baselines.
  • Operational Records & Logs: A highly secure, governed ledger for logging daily generation output, transmission performance, and environmental compliance data. Crucially, this system operates completely air-gapped from the plant automation network, using audited manual batch uploads rather than live connections to completely isolate critical systems from cyber threat vectors.
  • Listed-Market Disclosures: Cryptographically secured, append-only records of mandatory public and regulatory notices to guarantee absolute compliance with the Electricity Regulatory Commission (ERC) and SEBON guidelines.

3. What Is Proposed

One codebase, two layers:

A. Public Portal and Technical Repository

  • Salient features: Geomorphic specs, catchment hydrology, structures from the headworks (downstream of the Nilgiri/Ghalemdi confluence) to the powerhouse at Besigaun, Narchyang.
  • Bilingual archive: Linked English and Nepali notices, EIA updates, and Annapurna Rural Municipality-4 community notices. Next.js SSR.
  • Generation Dashboard: An air-gapped presentation surface showing historic and daily generation batch logs mapped cleanly against seasonal PPA baselines (Dry vs. Wet season tariffs) for executive review without risking system exposure.
Public PortalProject Landing & Disclosure Surface
Public Project Landing Page
Figure 3.1: Public surface: parameters, air-gapped metrics, approved regulatory disclosures. Prototype illustration.

B. Protected Administrative Enclave

Restricted workspace behind a deployment-specific secret slug (ADMIN_SECRET_SLUG), not a guessable /admin path.

  • Authentication: MFA with server-enforced 15-minute inactivity timeout.
  • Separation of duties: Server and database enforced. No self review or self approval.
Admin EnclaveExecutive Management Workspace & Operational Queues
Executive Workspace Dashboard
Figure 3.2: Enclave: reviews, risk posture, procurement pipeline. Prototype illustration.

Screenshots are from the working prototype. They show function and layout. Production would use Mistri Khola operational parameters, MENL corporate roles, and localized bilingual content.


4. Governance and Operational Capabilities

Controlled Procurement Workflows

Sealed Two-Envelope Bidding for Operational & Maintenance (O&M) packages, replacement components (such as turbine runners or valves), and future expansion contracts (e.g., the 12 MW Mistri Khola 2 project). Financial envelopes are encrypted in the bidder browser with AES-256-GCM. The server stores ciphertext only and holds no decryption keys. Opening-date rules are enforced server side. Result: controlled, verifiable bidding with an audit trail and reduced early-access exposure.

ProcurementSealed Bid Envelopes
Sealed Bids Inbox
Figure 4.1: Sealed envelopes: ciphertext only, no server keys, opening-date locks. Prototype illustration.

5x5 Risk Register

Live 5x5 register. Examples below are illustrative only. Final catalogue is set during discovery:

  1. Hydrological & Siltation (Operational): Monitoring turbine erosion risks and abrasive sediment management during high-velocity monsoon flows on the Mistri Khola tributary axis.
  2. Grid & Transmission (Evacuation): Logistical tracking of line trips, capacity limitations, and variance logging along the transmission alignment to the Dana Substation.
  3. Community & Regulatory (Compliance): Management of local resource shares, public notices within Annapurna Rural Municipality-4, and project timelines for the Mistri Khola 2 expansion.

Nightly Cron escalates overdue mitigations. Scoring anchors, control checks, KRI thresholds, and three-person rules: see Technical Appendix.

Risk Engine5x5 Enterprise Risk Posture
Enterprise Risk Posture and 5x5 Heat Map
Figure 4.2: 5x5 heat map, control health, escalation. Prototype illustration.

Verifiable Audit History (WORM Ledger)

Governance events go into an append-only WORM chain. Each entry links to the prior one with SHA-256 and is checked against an external checkpoint. Alteration is detectable, not claimed impossible.

Audit LedgerCryptographic WORM Execution Ledger
WORM Audit Ledger
Figure 4.3: Hash-chained ledger with external checkpoints. Prototype illustration.

5. Platform Architecture and Capability Comparison

Architecture Diagram
flowchart LR B[Bidder / Local Community] --> CF[Cloudflare Edge T7 WAF] CF --> Worker[Next.js Serverless Worker] Worker --> Redis[Upstash Redis: Session / Rate Limit] Worker --> Postgres[Supabase DB: RLS & Workflow Triggers] Worker --> R2[Cloudflare R2: Secure PDF / Encrypted Bids] Postgres --> WORM[HMAC-Signed WORM Audit Chain]
Capability areaCommon approachWhat the platform demonstrates
Audit recordsEmail and spreadsheets, hard to verify.WORM ledger with verifiable history and tamper detection.
Project identityBuried in a corporate site.Dedicated 42 MW operational portal with air-gapped asset registries.
BiddingGeneral channels.Two-envelope bidding, AES-256-GCM, opening-date enforcement.
Risk trackingFiles, no escalation.5x5 register, 3-person separation at database layer.
InfrastructureVaries by provider.Serverless Cloudflare Worker architecture. The public surface has zero data-exchange pipelines or connections routing back to the physical powerhouse SCADA network, providing permanent cryptographic isolation.

Engineering detail (five-layer enforcement, RLS, trigger-level Maker-Checker, sealed-bid crypto, fail-closed): see Technical Architecture Appendix.


6. Myagdi Regional Coordination

Being based locally in Myagdi enables direct, rapid coordination with both your regional corporate offices and the site operation teams at Narchyang and Tatopani Bazaar.

  • Local coordination: Direct access to regional offices and stakeholders.
  • Direct developer access: Built by me. No intermediaries for technical changes.
  • Handover: Source config, migrations, and R2 setup transfer subject to agreed scope and terms.

7. Indicative Implementation

Prototype exists. Configuration follows discovery and scope agreement. Indicative plan:

PhaseDeliveredDuration
DiscoveryReporting needs, PPA baselines, roles10 days
Configuration5x5 risk templates, AES bidding gateway22 days
Validation and cutoverTamper tests, walkthroughs, DNS cutover prep28 days

8. Closing and Walkthrough Request

A working prototype is already operational and demonstrates WORM audit chains, sealed bidder key handling, and automated 5x5 heatmap calculations. You can see it and test it.

A brief 15-minute walkthrough, online or in Beni, allows us to verify operational fit. A fixed implementation plan, timeline, and commercial terms will be structured immediately following that scoping discussion.

Working prototype (not MENL production):

Video DemoWorking Prototype in Action
Video walkthrough: Comparable hydro deployment. Prototype only.

Submitted by

Aashik Baruwal

Beni Bazaar, Myagdi

Email: workwithaa.sik@gmail.com

LinkedIn: https://www.linkedin.com/in/aashikbaruwal/

Confidential Client Proposal