How is it engineered?
Measured from the source repository, not estimated. As of Oct 2026.
Architecture
I built it as an Electron app with a sandboxed, context-isolated React renderer talking to the main process over about 775 named IPC channels, local SQLite as the source of truth, and a Capacitor build for Android and iOS.
Data and isolation
SQLite with 119 versioned migrations applied transactionally on launch, every money column stored as integer cents (never floating point), rows scoped per company, and optional per-company sync that pushes from a trigger-fed outbox with last-write-wins merge.
Security and privacy
- Cloud sync is end-to-end encrypted with AES-256-GCM under a scrypt-derived workspace key, so the cloud only ever holds ciphertext
- Licence keys are Ed25519-signed and verified offline; the app ships only the public key
- Passwords hashed with scrypt, stored API tokens encrypted with the OS keychain, database file locked to owner-only permissions, auditor role blocked from every write at the SQLite layer
- macOS release pipeline signs with a hardened runtime and notarises and staples both the app and the disk image
Regulatory rules in code
The code builds and submits LHDN MyInvois e-invoices (UBL 2.1 JSON, OAuth2, sandbox and production), prepares SST-02, and computes Malaysian personal income tax with year-specific bands, reliefs, section 6A rebates and zakat.
Quality evidence
| Schema migrations | 119 | Distinct versions in the migration registry |
|---|---|---|
| Automated check scripts | 90 check scripts, 982 assertion call sites | Count of check scripts and assert/ok/check calls inside them |
| CI smoke | 48 of 48 checks pass | Pure-Node smoke covering trial balance, balance sheet, cash-flow reconciliation, e-invoice builder and licence verify, run on 2026-10-08 |
| CI workflows | 4 | GitHub Actions: CI smoke, Windows build, Linux build, progress publish |
| Commits | 909 (8 Jun 2026 to 8 Oct 2026) | Git history |
Operations
Releases ship as a universal macOS disk image, Windows installers for x64 and arm64, Linux packages and an Android build across 38 tagged releases, with an in-app update check against the public release feed and built-in backup, validated restore and full CSV export.
The problem
Malaysian SME owners often run their books in a spreadsheet full of macros. One broken formula and the trial balance stops adding up, and nobody can tell where. Cloud accounting tools solve that, but many owners want their financial data on their own machine.
My role
I own Orbit Finance end to end: product decisions, interface design, architecture and the build itself. It is the data hub of Orbit Suite, my own line of local-first software for Malaysian businesses.
Approach
- A ledger that cannot drift. A full double-entry engine where the trial balance and balance sheet balance by construction, not by reconciliation.
- Local-first by default. Data lives in SQLite on the owner’s device, with end-to-end encrypted sync between Macs when they turn it on.
- Built for Malaysia. Ringgit in integer sen, BM by default with English, LHDN e-invoice settings, SST and SSM fields on printable A4 documents.
- One app, many jobs. Invoices, expenses, multi-company, multi-currency, inventory, time tracking, project costing and a built-in POS module.
- Same code on more screens. The desktop app ships for macOS and Windows, and the same React code runs on Android tablets through Capacitor.
Outcome
Orbit Finance is on sale through its own zone at orbitsuite.io/finance. It replaced the original Excel workbook and now anchors the rest of the suite: Orbit HR posts payroll journals into it and Orbit POS syncs sales into it.


