Icodeio
Source Code

SACCO Core Banking Platform (Kenya, SASRA-aligned)

A complete core banking system for Kenyan deposit-taking SACCOs: members and KYC, FOSA and BOSA, a double-entry ledger, the full loan lifecycle, mobile money, SASRA reporting, a staff portal, a branded website and a member mobile app.

SACCO Core Banking Platform (Kenya, SASRA-aligned)
SACCO Core Banking Platform (Kenya, SASRA-aligned) screenshot
SACCO Core Banking Platform (Kenya, SASRA-aligned) screenshot
SACCO Core Banking Platform (Kenya, SASRA-aligned) screenshot
SACCO Core Banking Platform (Kenya, SASRA-aligned) screenshot
SACCO Core Banking Platform (Kenya, SASRA-aligned) screenshot
SACCO Core Banking Platform (Kenya, SASRA-aligned) screenshot
$300.00

Editions

1.0.0 — First release.$300.00

Nine backend modules, staff portal, public website and Android member app. Branch dimension, hash-chained audit trail and demo mode added ahead of release.

Enterprise30-day support180-day updates

Description

Everything a deposit-taking SACCO runs on, as source code you own: member onboarding and KYC, FOSA and BOSA savings, share capital and dividends, the full loan lifecycle from application to write-off, a real double-entry general ledger, M-Pesa and bank integrations, SASRA-aligned reporting, and an append-only audit trail. Four applications ship together. A .NET 10 API with 201 REST operations across nine business modules. A 37-page staff portal in Next.js where every page is gated by permission. A tenant-branded public website with an online membership application. A Flutter member app for phone-and-PIN self-service with biometric unlock. It is built for the way a SACCO is actually regulated. FOSA and BOSA are one ledger with a segment tag on every account and journal line, so each trial balance stands on its own and nets to zero consolidated — not two systems reconciled by hand. Every money-moving approval is maker-checker, enforced in code. Authorization is 58 granular permissions resolved server-side, so revoking access takes effect immediately. The audit trail is hash-chained and the database itself refuses to let anyone edit or delete it. One deployment can serve several SACCOs. Tenant isolation is enforced by PostgreSQL row-level security, forced at the database level, so a connection with no tenant bound reads nothing at all. The whole system runs on your laptop with no production credentials. A seed tool builds a complete demo society — three branches, twenty members across every KYC state, twelve months of balanced postings, six loans across every aging bucket, a provisioning run and a statutory return awaiting approval — and five mock gateways stand in for M-Pesa, Airtel Money, Equity, NCBA and SMS. Swapping sandbox credentials for production ones is a configuration change, never a code change. Included: full source for all four applications, 29 database migrations, 269 backend tests, a k6 load test for concurrent debits, Docker Compose, GitHub Actions pipelines, Terraform for three AWS environments, 18 architecture decision records explaining why each structural decision was made, a SASRA requirement mapping and a production cutover runbook.

Features

  • Double-entry general ledger with FOSA/BOSA segment tagging on every account and journal line Concurrency-safe posting engine — atomic conditional updates
  • no distributed lock
  • load-tested Member onboarding
  • KYC verification with document capture
  • suspension
  • and a controlled exit workflow Savings
  • share capital
  • fixed deposits and dividends
  • with idempotent deposits and notice-period withdrawals Fee matrix — flat
  • percentage or tiered pricing by channel
  • product and amount band Full loan lifecycle: application
  • appraisal
  • guarantors
  • N-of-M approval
  • disbursement
  • repayment and accrual Guarantees enforced as ledger holds against the guarantor's deposits
  • with ratio and count caps NPL aging and loan-loss provisioning
  • computed by one officer and posted by another Per-SACCO credit scorecard with a stored factor-by-factor breakdown on every application Loan write-off
  • restructuring and settlement from deposits on member exit M-Pesa
  • Airtel Money
  • Equity (Jenga) and NCBA integrations behind one provider interface Idempotent payment webhooks — the provider reference is claimed before any ledger posting SASRA-aligned statutory returns with eight reconciliation checks that must pass before submission Nightly branded PDF digest emailed to board members without a portal login Append-only
  • hash-chained audit trail the database itself refuses to edit or delete Permission-based authorization — 58 permissions
  • resolved server-side
  • revocation is immediate Maker-checker on every money-moving approval
  • enforced in code and covered by tests Multi-tenant by design
  • isolated with forced PostgreSQL row-level security Branches as a reporting dimension on one set of books
  • not separate books Staff onboarding by invitation with mandatory authenticator-app two-step verification Real-time in-app notifications over SignalR
  • plus an SMS and email outbox with retry Tenant-branded public website with a Turnstile-protected membership application Flutter member app: phone and PIN sign-in
  • SMS OTP on a new device
  • biometric unlock Complete demo data and five mock gateways — run every workflow with zero production credentials

Requirements

  • .NET 10 SDK and PostgreSQL 16 Node.js 20+ for the staff portal and public website Flutter 3.8+ to build the member app (Android verified; iOS project included but unbuilt) Docker and Docker Compose to run the stack locally A Safaricom Daraja and/or Airtel Money account for live mobile money A bank API account (Equity Jenga or NCBA) for live bank transfers An SMTP provider for email and an SMS gateway account for messaging Cloudflare Turnstile keys for the public membership form A developer comfortable with ASP.NET Core and Next.js to deploy and maintain it

What's included

  • Full source for all four applications — API
  • staff portal
  • public website and Flutter member app Nine backend modules
  • 201 REST operations
  • and a committed OpenAPI document 29 EF Core database migrations Seed tool that builds a complete demo SACCO
  • idempotent and re-runnable Five mock gateways (M-Pesa
  • Airtel Money
  • Equity
  • NCBA
  • SMS) with an end-to-end script 269 backend tests (174 unit
  • 95 integration) and a k6 load test for concurrent debits Docker Compose for the whole stack and Dockerfiles for every service GitHub Actions pipelines for backend
  • frontend and infrastructure Terraform modules for three AWS environments
  • with backups and Multi-AZ in production 18 architecture decision records explaining the reasoning behind each structural decision SASRA requirement-to-implementation mapping and an open-items confirmation register Production cutover runbook and per-area developer guides Generated TypeScript API client
  • kept in sync with the backend by CI

What's not included

  • Production payment credentials — the live M-Pesa
  • Airtel
  • Equity and NCBA code is written and driven against mock gateways
  • but has not been certified against a real provider account Credit reference bureau integration — the interface exists; connecting TransUnion
  • Metropol or Creditinfo is still to be done SASRA electronic submission format — returns are produced as structured JSON and CSV; mapping onto the regulator's portal format is not done Confirmed prudential figures — provisioning rates
  • aging buckets
  • capital and liquidity minima ship as configurable defaults flagged as open items SDGF contribution computation — the basis is unset
  • so it is not calculated A verified iOS build or app store submission — Android is verified
  • the iOS project is untested Automated front-end test suite — the two Next.js apps are covered by lint and build only Hosting
  • domains
  • SSL certificates and managed database costs Data migration from your existing core banking system Regulatory sign-off
  • licensing or SASRA approval on your behalf

Release history

v1.0.0Initial releaseCurrent

Reviews

No reviews yet.

Frequently asked questions

OpenID ConnectDockerEntity Framework CoreNext jsWolverinePostgreSQL.NET 10FlutterASP.NET CoreSignalR#featured#saas#microfinance#sacco#fintech#core-banking#double-entry-ledger#sasra#loan-management#mpesa