DEVELOPMENT MODE Finance is Supabase-authoritative. Browser storage is retained as an exact safety cache.

Finance operating picture

Plan, price, track, and reconcile the Ball

One source for projected revenue, vendor obligations, subsidies, and actual spending.

More
Finance administration

Protected payment destination

Official payment configuration

Checking
Official account label
QR asset
Configuration mode Read-only in local build

GUIDON does not provide a general QR-image upload control. In production, payment-destination changes require privileged authentication and reauthentication.

Integrity verification

QR fingerprint

The public portal verifies the payment QR asset against the approved SHA-256 fingerprint before displaying it when the site is served over HTTP/HTTPS.

Approved fingerprint

Observed fingerprint

Not checked yet.

Production security model

Production security controls

Privileged payment role

Only authorized users can modify payment destinations.

Authentication required
Reauthentication and MFA

Sensitive changes require a fresh credential check and second factor.

Planned
Immutable audit trail

Old value, new value, user, time, and security context are retained.

Planned
Public portal is read-only

Guest-facing code can display payment information but cannot modify it.

Architecture rule