Project Governance & Digital Asset Control Platform
Dedicated Data Infrastructure for the 42 MW Mistri Khola Hydroelectric Project
1. Executive Summary
As a publicly listed entity on the NEPSE, Mountain Energy Nepal Limited (MENL) requires absolute data integrity across its corporate disclosures, regulatory reporting, O&M procurement, and operational risk management for the 42 MW Mistri Khola Project.
I have built a working platform that brings these together in a project portal plus a controlled admin system: structured publishing, maker-checker-approver controls, procurement workflows, document integrity checks, bilingual disclosures, risk tracking, and auditable records. It runs as a single Cloudflare Worker with low overhead.
This proposal defines a proven digital architecture framework. Deployment scope, timeline, and operational constraints are finalized during discovery to align precisely with Mountain Energy Nepal Limited's corporate requirements.
Prototype and Deployment Scope
What you see here is a working prototype from a comparable hydropower context. A Mountain Energy Nepal Limited deployment would be configured around its project structure, roles, procedures, and approved disclosures.
Proposed Next Step
A short walkthrough to check fit against project requirements. Scope, timeline, support, and commercial terms follow only if there is fit. The concept covers:
- Project disclosure: Public technical repository with approval before publication.
- Procurement: Browser-encrypted bidding with client-side AES-256-GCM.
- Records: Maker-checker-approver transitions with verifiable WORM audit history. See Technical Appendix for the state machine and enforcement.
- Generation & Risk Tracking: An air-gapped dashboard for administrative tracking of metrics and risks, completely isolated from operational technology (OT/SCADA) networks to eliminate any external attack surface.
2. Why a Dedicated Project Platform
When disclosures, procurement files, and governance records sit across websites, email, and spreadsheets, control and auditability get harder.
One controlled system fixes that:
- Reporting support: Drawdown histories, environmental records, and disclosure registers for lender, shareholder, and management review.
- Generation tracking: Logs paired with applicable seasonal PPA baselines.
- Operational Records & Logs: A highly secure, governed ledger for logging daily generation output, transmission performance, and environmental compliance data. Crucially, this system operates completely air-gapped from the plant automation network, using audited manual batch uploads rather than live connections to completely isolate critical systems from cyber threat vectors.
- Listed-Market Disclosures: Cryptographically secured, append-only records of mandatory public and regulatory notices to guarantee absolute compliance with the Electricity Regulatory Commission (ERC) and SEBON guidelines.
3. What Is Proposed
One codebase, two layers:
A. Public Portal and Technical Repository
- Salient features: Geomorphic specs, catchment hydrology, structures from the headworks (downstream of the Nilgiri/Ghalemdi confluence) to the powerhouse at Besigaun, Narchyang.
- Bilingual archive: Linked English and Nepali notices, EIA updates, and Annapurna Rural Municipality-4 community notices. Next.js SSR.
- Generation Dashboard: An air-gapped presentation surface showing historic and daily generation batch logs mapped cleanly against seasonal PPA baselines (Dry vs. Wet season tariffs) for executive review without risking system exposure.
Public PortalProject Landing & Disclosure Surface

Figure 3.1: Public surface: parameters, air-gapped metrics, approved regulatory disclosures. Prototype illustration.
B. Protected Administrative Enclave
Restricted workspace behind a deployment-specific secret slug (ADMIN_SECRET_SLUG), not a guessable /admin path.
- Authentication: MFA with server-enforced 15-minute inactivity timeout.
- Separation of duties: Server and database enforced. No self review or self approval.
Admin EnclaveExecutive Management Workspace & Operational Queues

Figure 3.2: Enclave: reviews, risk posture, procurement pipeline. Prototype illustration.
Screenshots are from the working prototype. They show function and layout. Production would use Mistri Khola operational parameters, MENL corporate roles, and localized bilingual content.
4. Governance and Operational Capabilities
Controlled Procurement Workflows
Sealed Two-Envelope Bidding for Operational & Maintenance (O&M) packages, replacement components (such as turbine runners or valves), and future expansion contracts (e.g., the 12 MW Mistri Khola 2 project). Financial envelopes are encrypted in the bidder browser with AES-256-GCM. The server stores ciphertext only and holds no decryption keys. Opening-date rules are enforced server side. Result: controlled, verifiable bidding with an audit trail and reduced early-access exposure.
ProcurementSealed Bid Envelopes

Figure 4.1: Sealed envelopes: ciphertext only, no server keys, opening-date locks. Prototype illustration.
5x5 Risk Register
Live 5x5 register. Examples below are illustrative only. Final catalogue is set during discovery:
- Hydrological & Siltation (Operational): Monitoring turbine erosion risks and abrasive sediment management during high-velocity monsoon flows on the Mistri Khola tributary axis.
- Grid & Transmission (Evacuation): Logistical tracking of line trips, capacity limitations, and variance logging along the transmission alignment to the Dana Substation.
- Community & Regulatory (Compliance): Management of local resource shares, public notices within Annapurna Rural Municipality-4, and project timelines for the Mistri Khola 2 expansion.
Nightly Cron escalates overdue mitigations. Scoring anchors, control checks, KRI thresholds, and three-person rules: see Technical Appendix.
Risk Engine5x5 Enterprise Risk Posture

Figure 4.2: 5x5 heat map, control health, escalation. Prototype illustration.
Verifiable Audit History (WORM Ledger)
Governance events go into an append-only WORM chain. Each entry links to the prior one with SHA-256 and is checked against an external checkpoint. Alteration is detectable, not claimed impossible.
Audit LedgerCryptographic WORM Execution Ledger

Figure 4.3: Hash-chained ledger with external checkpoints. Prototype illustration.
5. Platform Architecture and Capability Comparison
Architecture Diagram
| Capability area | Common approach | What the platform demonstrates |
|---|---|---|
| Audit records | Email and spreadsheets, hard to verify. | WORM ledger with verifiable history and tamper detection. |
| Project identity | Buried in a corporate site. | Dedicated 42 MW operational portal with air-gapped asset registries. |
| Bidding | General channels. | Two-envelope bidding, AES-256-GCM, opening-date enforcement. |
| Risk tracking | Files, no escalation. | 5x5 register, 3-person separation at database layer. |
| Infrastructure | Varies by provider. | Serverless Cloudflare Worker architecture. The public surface has zero data-exchange pipelines or connections routing back to the physical powerhouse SCADA network, providing permanent cryptographic isolation. |
Engineering detail (five-layer enforcement, RLS, trigger-level Maker-Checker, sealed-bid crypto, fail-closed): see Technical Architecture Appendix.
6. Myagdi Regional Coordination
Being based locally in Myagdi enables direct, rapid coordination with both your regional corporate offices and the site operation teams at Narchyang and Tatopani Bazaar.
- Local coordination: Direct access to regional offices and stakeholders.
- Direct developer access: Built by me. No intermediaries for technical changes.
- Handover: Source config, migrations, and R2 setup transfer subject to agreed scope and terms.
7. Indicative Implementation
Prototype exists. Configuration follows discovery and scope agreement. Indicative plan:
| Phase | Delivered | Duration |
|---|---|---|
| Discovery | Reporting needs, PPA baselines, roles | 10 days |
| Configuration | 5x5 risk templates, AES bidding gateway | 22 days |
| Validation and cutover | Tamper tests, walkthroughs, DNS cutover prep | 28 days |
8. Closing and Walkthrough Request
A working prototype is already operational and demonstrates WORM audit chains, sealed bidder key handling, and automated 5x5 heatmap calculations. You can see it and test it.
A brief 15-minute walkthrough, online or in Beni, allows us to verify operational fit. A fixed implementation plan, timeline, and commercial terms will be structured immediately following that scoping discussion.
Working prototype (not MENL production):
- Governance portal: https://durbang.aashikbaruwal.com.np/
- More work: https://www.aashikbaruwal.com.np/arc-and-civ
Video DemoWorking Prototype in Action
Video walkthrough: Comparable hydro deployment. Prototype only.
Submitted by
Aashik Baruwal
Beni Bazaar, Myagdi
Email: workwithaa.sik@gmail.com