Centralized budget operations — 2026

Built for real-time, secure budget operations.

One centralized system for disbursement, access control, security, and performance.

/dashboard/disbursements

Disbursement ledger

Live · This fiscal quarter

Released to dateLive

₱7,590,000

Dept. of Engineering

₱2,450,000Released

Health Services

₱1,180,000Released

Public Works

₱3,020,000Pending

Education Office

₱940,000Released
/dashboard/roles

Role-based access

ASP.NET auth + Next.js proxy

Admin
Finance Officer
Auditor
Dept. Head
Approver
Viewer
zap-scan./report

ZAP DAST scan

Automated · OWASP Top 10

Injection
Broken Authentication
Sensitive Data Exposure
Broken Access Control
Security Misconfiguration
Cross-Site Scripting
0 vulnerabilities found
/dashboard

Load time

Tag-based cache · SWR

Uncached840ms
Cached · SWR120ms
stale-while-revalidate
Built withNext.jsASP.NET CorePostgreSQLTypeScript

One system. Four guarantees.

Disbursement

Tracked in real time

Access roles

6 roles, double-enforced

Security

0 vulnerabilities

Performance

840ms → 120ms cached

Try it yourself

Click around — it's live
/dashboard/disbursements

Disbursement ledger

Click to release the next fund

Released

₱3,630,000

Dept. of Engineering

₱2,450,000Released

Health Services

₱1,180,000Released

Public Works

₱3,020,000Pending

Education Office

₱940,000Pending
/dashboard/roles

Role access simulator

Click a role to see its permissions

Finance Officer can

View all budgets
Approve disbursements
Manage roles
Export reports
zap-scan./report

ZAP DAST scan

Click run to scan the live app

Injection
Broken Authentication
Sensitive Data Exposure
Broken Access Control
Security Misconfiguration
Cross-Site Scripting
0 vulnerabilities found

What's included

5 core systems

Real-time disbursement tracking

Budget releases, tracked live

Every fund release moves through a visible pipeline — from approval to disbursement — so finance officers and department heads see status the moment it changes, not at end-of-day reconciliation.

Role-based access, six roles deep

Enforced twice, not once

Every request is checked by ASP.NET authorization on the API and again by a Next.js proxy layer in front of it — a role's permissions can't be bypassed from the client, only from the server that owns them.

Zero known vulnerabilities

OWASP Top 10 · ZAP DAST

Automated OWASP ZAP dynamic scans run against the live app and validate against all ten OWASP Top 10 categories — the current build clears every one.

Export to Excel & PDF

One click, audit-ready

Budget ledgers, disbursement logs, and role activity all export straight to Excel or PDF, formatted for the auditors and department heads who need them offline.

Sub-second load times

Tag-based cache · SWR

Tag-based cache invalidation on the backend and stale-while-revalidate fetching on the frontend keep pages fast without ever serving stale budget data.

Run every disbursement from one portal.

Real-time, role-secured, and validated against the OWASP Top 10 — built to hold up to an audit as well as it holds up to a scroll.