Project Governance & Digital Asset Control Platform
Dedicated Data Infrastructure for the 109 MW Nilgiri Khola Hydropower Complex - Nilgiri Khola-1 (38 MW) & Nilgiri Khola-2 Cascade (71 MW)
1. Executive Summary
Nilgiri Khola Hydropower Company Pvt. Ltd. requires structured data governance across its corporate disclosures, regulatory reporting, O&M procurement, and operational risk management for the 109 MW Nilgiri Khola Hydropower Complex.
I have built a working platform that brings these together in a project portal plus a controlled admin system: structured publishing, maker-checker-approver controls, procurement workflows, document integrity checks, bilingual disclosures, risk tracking, and auditable records. It runs as a single Cloudflare Worker with low overhead.
This proposal defines a proven digital architecture framework. Deployment scope, timeline, and operational constraints are finalized during discovery to align precisely with Nilgiri Khola Hydropower Company Pvt. Ltd.'s corporate requirements.
Prototype and Deployment Scope
What you see here is a working prototype from a comparable hydropower context. A Nilgiri Khola Hydropower Company Pvt. Ltd. deployment would be configured around its dual-plant structure (Nilgiri-1 and Nilgiri-2 Cascade), roles, procedures, and approved disclosures.
Proposed Next Step
A short walkthrough to check fit against project requirements. Scope, timeline, support, and commercial terms follow only if there is fit. The concept covers:
- Project disclosure: Public technical repository with approval before publication.
- Procurement: Browser-encrypted bidding with client-side AES-256-GCM.
- Records: Maker-checker-approver transitions with verifiable WORM audit history. See Technical Appendix for the state machine and enforcement.
- Generation & Risk Tracking: An air-gapped dashboard for administrative tracking of metrics and risks, completely isolated from operational technology (OT/SCADA) networks to eliminate any external attack surface.
2. Why a Dedicated Project Platform
When disclosures, procurement files, and governance records sit across websites, email, and spreadsheets, control and auditability get harder.
One controlled system fixes that:
- Reporting support: Drawdown histories, environmental records, and disclosure registers for lender, shareholder, and management review.
- Generation tracking: Logs paired with applicable seasonal PPA baselines.
- Operational Records & Logs: A highly secure, governed ledger for logging daily generation output, transmission performance, and environmental compliance data. Crucially, this system operates completely air-gapped from the plant automation network, using audited manual batch uploads rather than live connections to completely isolate critical systems from cyber threat vectors.
- Corporate, Lender & Regulatory Disclosures: Cryptographically secured, append-only records of mandatory public and regulatory notices, lender oversight documentation, and environmental mitigation compliance audits to guarantee validation required by funding commercial banks and the Electricity Regulatory Commission (ERC).
3. What Is Proposed
One codebase, two layers:
A. Public Portal and Technical Repository
- Salient features: Comprehensive asset profiles mapping geomorphic specifications and catchment hydrology from the primary headworks at Humkhola down to the Chotepa powerhouse (Nilgiri-1) and the interconnected Dobilna cascade powerhouse (Nilgiri-2).
- Bilingual archive: Unified English and Nepali compliance logs, public notices, and environmental monitoring alerts serving Annapurna Rural Municipality-4, Myagdi. Next.js SSR.
- Generation Dashboard: An air-gapped presentation surface showing historic and daily generation batch logs mapped cleanly against seasonal PPA baselines (Dry vs. Wet season tariffs) for executive review without risking system exposure.
Public PortalProject Landing & Disclosure Surface

Figure 3.1: Public surface: parameters, air-gapped metrics, approved regulatory disclosures. Prototype illustration.
B. Protected Administrative Enclave
Restricted workspace behind a deployment-specific secret slug (ADMIN_SECRET_SLUG), not a guessable /admin path.
- Authentication: MFA with server-enforced 15-minute inactivity timeout.
- Separation of duties: Server and database enforced. No self review or self approval.
Admin EnclaveExecutive Management Workspace & Operational Queues

Figure 3.2: Enclave: reviews, risk posture, procurement pipeline. Prototype illustration.
Screenshots are from the working prototype. They show function and layout. Production would use Nilgiri Complex operational parameters (Humkhola to Chotepa axis, Chotepa and Dobilna powerhouses, 7.4 km 220 KV Chotepa-Dana evacuation corridor), Nilgiri Khola Hydropower Company corporate roles, and localized bilingual content.
4. Governance and Operational Capabilities
Controlled Procurement Workflows
Sealed Two-Envelope Bidding built to manage specialized Operations & Maintenance (O&M) contracts; shared across both Nilgiri-1 and Nilgiri-2 sites. Financial envelopes are encrypted in the bidder browser with AES-256-GCM.
The server stores ciphertext only and holds no decryption keys. Opening-date rules are enforced server side. Result: controlled, verifiable bidding with an audit trail and reduced early-access exposure.
ProcurementSealed Bid Envelopes

Figure 4.1: Sealed envelopes: ciphertext only, no server keys, opening-date locks. Prototype illustration.
5x5 Risk Register
Live 5x5 register for the dual-plant cascade. Examples below reflect Nilgiri operational reality. Final catalogue is set during discovery:
- Hydrological Cascade Interdependency (Operational): Monitoring tailrace discharge alignment and flow volume control between the Nilgiri-1 outfall at Chotepa and the Nilgiri-2 intake down to Dobilna to mitigate hydraulic head drops.
- Geotechnical & Sector Logistics (Logistical): High-altitude access corridor tracking, managing severe landslide vulnerabilities along the steep Humkhola supply tracks to ensure physical asset security during monsoon transitions.
- Corporate Compliance & Finance (Governance): Append-only tracking of lender oversight documentation, environmental mitigation compliance audits, and regulatory notice validation required by funding commercial banks.
Nightly Cron escalates overdue mitigations. Scoring anchors, control checks, KRI thresholds, and three-person rules: see Technical Appendix.
Risk Engine5x5 Enterprise Risk Posture

Figure 4.2: 5x5 heat map, control health, escalation. Prototype illustration.
Verifiable Audit History (WORM Ledger)
Governance events go into an append-only WORM chain. Each entry links to the prior one with SHA-256 and is checked against an external checkpoint. Alteration is detectable, not claimed impossible.
Audit LedgerCryptographic WORM Execution Ledger

Figure 4.3: Hash-chained ledger with external checkpoints. Prototype illustration.
5. Platform Architecture and Capability Comparison
Architecture Diagram
| Capability area | Common approach | What the platform demonstrates |
|---|---|---|
| Audit records | Email and spreadsheets, hard to verify. | WORM ledger with verifiable history and tamper detection. |
| Project identity | Buried in a corporate site. | Dedicated 109 MW dual-plant portal (Nilgiri-1 38 MW + Nilgiri-2 Cascade 71 MW) with air-gapped asset registries. |
| Bidding | General channels. | Two-envelope bidding for shared O&M, Pelton/injector spares, and 7.4 km 220 KV line maintenance, AES-256-GCM, opening-date enforcement. |
| Risk tracking | Files, no escalation. | Cascade-aware 5x5 register, 3-person separation at database layer. |
| Infrastructure | Varies by provider. | Serverless Cloudflare Worker architecture. The public surface has zero data-exchange pipelines or connections routing back to the physical powerhouse SCADA network, providing permanent cryptographic isolation. |
Engineering detail (five-layer enforcement, RLS, trigger-level Maker-Checker, sealed-bid crypto, fail-closed): see Technical Architecture Appendix.
6. Myagdi Regional Coordination
Being based locally in Beni Bazzar enables direct, rapid coordination with both your regional corporate offices and the site operation teams at Chotepa (Nilgiri-1) and Dobilna (Nilgiri-2 Cascade) along the Humkhola axis.
- Local coordination: Direct access to regional offices and stakeholders.
- Direct developer access: Built by me. No intermediaries for technical changes.
- Handover: Source config, migrations, and R2 setup transfer subject to agreed scope and terms.
7. Indicative Implementation
Prototype exists. Configuration follows discovery and scope agreement. Indicative plan:
| Phase | Delivered | Duration |
|---|---|---|
| Discovery | Reporting needs, PPA baselines, roles | 10 days |
| Configuration | 5x5 risk templates, AES bidding gateway | 22 days |
| Validation and cutover | Tamper tests, walkthroughs, DNS cutover prep | 28 days |
8. Closing and Walkthrough Request
A working prototype is already operational and demonstrates WORM audit chains, sealed bidder key handling, and automated 5x5 heatmap calculations. You can see it and test it.
A brief 15-minute walkthrough, online or in Beni, allows us to verify operational fit. A fixed implementation plan, timeline, and commercial terms will be structured immediately following that scoping discussion.
Working prototype (not Nilgiri Khola Hydropower Company production):
- Governance portal: https://durbang.aashikbaruwal.com.np/
- More work: https://www.aashikbaruwal.com.np/arc-and-civ
Video DemoWorking Prototype in Action
Video walkthrough: Comparable hydro deployment. Prototype only.
Submitted by
Aashik Baruwal
Beni Bazaar, Myagdi
Email: workwithaa.sik@gmail.com