Enterprise Online Secured Payroll Web Application
Automated BIR TRAIN Law & 2025 statutory math engine
Field-level encryption for SSS, PhilHealth, TIN & Bank IDs
Modern decoupled App Router & Pydantic v2 API backend
1-Payslip-per-page print layout & executive summary reports
About the Project
Enterprise Online Secured Payroll Web Application is a full-stack, enterprise-grade payroll system engineered for modern Philippine corporate payroll management. Built using Next.js 14 (App Router, React 18, TypeScript) and FastAPI (Python 3.10+, Pydantic v2), it automates statutory contributions and tax calculations while delivering bank-grade security and print-ready reporting. Key Core System Architecture & Features: 1. Philippine Statutory & BIR Tax Compliance Engine: - BIR TRAIN Law Tax Engine (2023 Revised Schedules): Automatically evaluates semi-monthly (₱10,417), weekly (₱4,808), and daily (₱685) tax-exemption thresholds. - 2025 SSS Contribution Schedule: Supports up to ₱35,000 Monthly Salary Credit (MSC) with exact EE/ER shares. - PhilHealth 5.0% Premium Rate: 50/50 split between employee and employer (₱10,000 floor to ₱100,000 ceiling). - Pag-IBIG Mandatory Contribution: Circular No. 460 standards (₱200/₱200 share). 2. Printable Reports & Payslips: - 1-Payslip-Per-Page Printing: Clean @media print layout featuring company headers, rate basis, itemized earnings/deductions, net pay banner, and employee signature lines. - Location Breakdown Summary: Executive summary metrics and location-level payroll breakdown tables. 3. Bank-Grade Security & Governance: - AES-256 Fernet Encryption: Sensitive employee identification (SSS, PhilHealth, Pag-IBIG, TIN, Bank account numbers) encrypted at rest in the database. - JWT & Role-Based Access Control (RBAC): Protected API endpoints with Admin and Manager permission checks. - Audit Logging: Every sensitive action (logins, payroll locks, profile updates) recorded in an immutable audit trail. 4. Flexible Workflows: - Configurable Weekly Cycles: Custom start and cutoff day configurations (e.g. Wed-Tue) with dynamic live UI updates. - Location Management: Dynamic site assignment with safety guards preventing deletion of active branch locations.
Challenges
Engineered precise floating-point rounding for multi-tiered Philippine statutory compliance (BIR tax schedules, SSS 2025 MSC brackets, PhilHealth 5% ceilings, and Pag-IBIG Circular 460) while maintaining AES-256 field-level encryption for sensitive employee Identifiers without degrading database query performance or report generation speed.
Learnings
Mastered full-stack architecture combining Next.js 14 App Router with FastAPI and Pydantic v2. Gained deep expertise in cryptography (Fernet AES-256 field encryption at rest), statutory payroll math engine design, role-based JWT security, and CSS @media print optimization for single-page corporate payslips.
What I'd Do Differently
Encrypting the SSS, PhilHealth, TIN and bank fields at rest made them unsearchable, so any lookup by those identifiers has to decrypt row by row in application code. I would keep the encryption but add a deterministic blind index — an HMAC of the normalised value — per searchable field so the database can still match on equality. I would also move the statutory tables out of code and into versioned, effective-dated configuration rows; with the 2025 SSS brackets hardcoded, a rate change ships as a code deploy instead of a data update, which is the wrong cost for something that changes on a government schedule.
Development Journey
BIR TRAIN & Statutory Math Calculation Core
Engineered FastAPI tax calculators for BIR TRAIN Law, SSS 2025 MSC brackets, PhilHealth 5% rates, and Pag-IBIG Circular 460.
AES-256 Fernet Encryption & JWT RBAC Auth
Implemented AES-256 field-level encryption for sensitive PII data and JWT authentication with Admin/Manager RBAC scope checks.
App Router Web Client & Glassmorphism System
Constructed responsive dashboards, employee list management, location branch safety controls, and audit trail visualizers.
@media Print Layouts & Railway/Vercel Pipelines
Designed clean 1-payslip-per-page print layouts and deployed backend services to Railway PostgreSQL and web frontend to Vercel.
