ASL Municipal Utilities — Source library
Public documentation snapshot: 2026-09-08
Run the whole town office from one screen.
Water, sewer and trash billing plus the whole town office, run by one clerk on one system.
Run the whole town office from one screen.
Built for: The town clerk or treasurer who bills water, sewer and trash and also answers the phone · Small towns and rural water, sewer and sanitation districts with a few hundred to a few thousand accounts · Public works crews reading meters, running routes and closing work orders · A mayor and board who need meeting minutes, a resident lookup and a public website that stays current
ASL Municipal Utilities exists because of this.
A town of a few hundred households does not have a billing department. It has a clerk. That clerk bills the water, takes a payment at the counter, orders the dumpster, types the minutes, dispatches the crew when a line breaks, and locks the door at four. Everything that keeps the water running goes through one desk and, usually, one person's memory. The tools almost never fit. Billing sits in one program, payments in another, meter readings in a notebook or a spreadsheet, work orders on a clipboard, the roster on a whiteboard, the ordinance book in a filing cabinet, and the town website with a company that answers email in three days. None of it talks to anything else. Closing the month means opening five things and typing the same numbers into each one. When a resident calls to argue about a bill, the answer is somewhere in that pile, and finding it costs the afternoon. And the stakes are not small ones. A rate the board changed in March has to be provable next year. An account in dispute needs the note somebody wrote at the counter eight months ago. The auditor asks what a service cost last spring and somebody has to be able to say. Meanwhile the state expects the public pages to work for residents with disabilities, half the town may read Spanish first, and the crew's hours have to be right on payday. The clerk carries all of it. When the clerk retires, most of it walks out the door with them.
ASL Municipal Utilities exists because of this.
Nothing ships with a price in it. Every rate, deposit and rental charge is blank until the town sets it, an unpriced service cannot be billed at all, and there are no late fees, penalties or reconnect charges anywhere in the software.
ASL Municipal Utilities exists because of this.
A rate in use is superseded, never overwritten, so what a service cost last March is always answerable and the invoices that used it never change.
ASL Municipal Utilities exists because of this.
The audit record is sealed entry to entry under a key the database does not hold, carries a per-entry position, and is anchored to an append-only record outside the database, so an edit, a deletion from the middle and a cut tail are all detectable - and the check names which it found.
ASL Municipal Utilities exists because of this.
Location is refused at the server when somebody is off the clock, instead of being collected and filtered afterwards, and the people with oversight roles cannot see the crew map at all.
ASL Municipal Utilities exists because of this.
Every permission is a switch the town controls - 34 of them across 8 roles - stored only where it differs from the default, marked on screen wherever the town has changed one, and the town cannot accidentally switch off its own ability to change them.
ASL Municipal Utilities exists because of this.
The exit is built in: a full export to ordinary spreadsheet files with a written guide to the columns, generated from the live table definitions rather than a hand-written list, plus sealed copies under a passphrase or a key only the town holds.
ASL Municipal Utilities exists because of this.
Bilingual all the way down and gated by a build check that also reads the software's own vocabularies, so a half-translated screen cannot ship and a resident never meets a raw English token.
How ASL Municipal Utilities works, start to finish.
ASL Municipal Utilities is one workspace that covers the billing, the crew, the office and the public face of a small utility. A clerk signs in once and gets the whole job: customers and their service addresses, meters and readings, the rates the town has set, billing runs, invoices, payments, deposits, account credit, payment arrangements, delinquency and aging. A resident signs in to the same system and gets their own bill and nothing else. A council member gets meeting minutes, town news and a resident lookup. A field worker gets their routes, their work orders and a clock. Nobody is reconciling five vendors, because there are not five vendors. The billing is built to stop rather than guess. A run reads the meters, applies your rates and produces a draft, and nothing is collectable until a person approves it. If a service somehow ends up with two current rates the run refuses instead of choosing one, because two neighbours billed differently is the complaint that turns up at a board meeting. Money is held and calculated in whole cents, so a statement adds up to the penny. Nothing ships with a price inside it: your water, sewer and trash rates, the deposit a new account pays, what a dumpster rental costs and what a kept trash cart costs each month are all blank until the town sets them, and a service with no rate simply cannot be billed. There are no late fees, penalties or reconnect charges anywhere in the software, because none were ever written in for a town to inherit. When the board passes a new rate you set it yourself, and a rate already in use is superseded rather than overwritten, so last March's price is still readable and the bills that used it never change. The operations side is the same handful of people, so it lives in the same place. Work orders, ordered route stops assigned to a vehicle and a person, fleet records, maintenance, fuel logging, a time clock, a two-week roster drawn from approved time off, and dispatch. Field workers report their location for dispatch only while their time-clock entry is open, and an off-duty report is refused outright rather than collected and filtered later. Council members and residents cannot see the crew map at all. Trash carts and rented dumpsters are tracked by the number already painted on them, a container cannot be booked into two driveways at once, and a rental's real charge is worked out from when it actually came back, itemized so the resident can see the arithmetic. The public half is a real town website, not a brochure. Ordinances are hosted in full text and searchable without signing in, and writing one down and publishing it are two separate acts, so a half-finished draft cannot land on the town's front page. Meeting minutes and town news are kept as two separate lists, because an announcement and the record of what the board decided are different things and merging them makes the minutes impossible to search. Every staff screen, every resident page and every letter and text message exists in English and Spanish, held in step by a check that fails the build if a phrase exists in one language and not the other. Accessibility is treated as a legal gate rather than a finishing touch, because for a Colorado municipality it is one: an automated sweep runs all sixteen pages against WCAG 2.1 AA on every release and stops the release on any finding, and the result has also been walked by hand with a screen reader. Underneath all of it is a record you can check instead of trust. Every action is stored with who did it and when, each entry sealed to the one before it so that altering the record can be detected rather than merely discouraged, and a button on the audit screen runs that check and names which kind of problem it found. Staff read their own history from their own profile, the same record an administrator sees about them. Every permission is a switch your administrator controls per role, and the routes that carry consequence read that switch on the request itself. Your data is yours on the way out too: the whole database exports as ordinary spreadsheet files with a plain guide to the columns, and sealed encrypted copies can be produced either with a passphrase only the town knows or, on a schedule, to a public key the town generates and keeps the private half of, which means we can write those copies and cannot open one.
Everything in the current release.
Each of these is built and working today. Nothing on this list is a roadmap item.
Billing that stops instead of guessing
A billing run reads the meters, applies the town's rates and produces a draft. Nothing is collectable until somebody approves it, so a whole cycle gets reviewed before a single invoice goes out. Where the software does not know something, it stops and says so: a missing or impossible reading becomes an exception rather than an invented number, and a service that somehow has two current rates halts the run instead of the software picking one. Money is held and calculated in whole cents throughout, never in decimals that drift.
Your prices, never ours
Water, sewer and trash rates, the deposit a new account pays, what a dumpster rental costs, what a kept trash cart costs each month. Nothing ships with a price in it and no form opens with a suggested figure, because a number we invented sitting in a box is how a made-up price ends up on a resident's bill and then gets defended as what the system said. A service with no rate cannot be billed and a container size with no price cannot be booked. Late fees, penalties and reconnect charges do not exist in the software at all. Charging something other than the standard deposit is allowed, because hardship waivers are real, but it is refused without a written reason, and the standard figure, the figure actually charged and the reason are all kept together.
Rates you change yourself, with last year still readable
When the board passes a new rate you set it from the admin screen instead of calling us, tiers included. A rate plan that has never priced anything is simply corrected in place. A rate already in use is superseded: a new version takes effect on your date, the accounts move to it, and the old version is kept and retired, so an auditor asking what water cost last March still gets an answer. The dialog tells you which of the two will happen, and names how many accounts are affected, before anything is saved. Past invoices keep the price they were billed at, so no rate change can rewrite history.
Meters that outlive the people at the address
A meter is plant attached to a property, not a possession of whoever lives there. When a house changes hands the meter is released with a final reading and stays with the premises, its reading history intact, and the new occupant is never billed for the previous occupant's usage. Readings keep their source, their time, who took them and an anomaly flag, with a filter that shows just the flagged ones, so a bad read gets caught before it becomes a bad bill.
A customer file with a memory
A resident's file holds their services, meters, invoice history and balance, plus two things that usually live in somebody's head. Contact notes carry the kind of contact - phone call, counter visit, complaint, field visit - who wrote them and when, and an over-long note is refused with an explanation rather than quietly truncating somebody's account of a call. Beside it sits who worked on this account: every recorded action against the resident and against the things that belong to them, their invoices and their service accounts, without an administrator having to read the whole town's log and eyeball it.
Find a resident with whatever you have
Whoever is at the counter has half a name, a phone number read out over the line, a street, or the account number off the bill. One box searches all of it. A phone number matches however it is punctuated, a partial name works in either order, an address matches whether it is where the water goes or where the bill goes, and the number painted on somebody's cart or container finds them too, including a cart that has already been collected, because the movement log remembers. Account numbers stay the town's own, free-form, exactly as they were before the software arrived.
Work orders, routes, and dispatch that respects the clock
Build an ordered stop list, assign it to a vehicle and a person, and let the crew mark stops complete from their phone. Route distances are real road distances rather than straight lines, and the response says which of the two it is showing you, so a saving can never be presented as something it is not. Field workers report their position only while their time-clock entry is open; clock out and it stops, and a report from somebody off the clock is refused at the server rather than stored and filtered later. There is no opt-out toggle while clocked in, which is worth saying out loud to a crew before rollout. Council members and residents cannot see the crew map at all, because knowing where a crew is, is a dispatch job and not an oversight one.
Carts and dumpsters tracked by the number painted on them
Every cart and container already has a number on its side and the crew reads that number off the bin, so that number is its identity here. Nothing assigns its own, because that means somebody maintaining a translation table that goes wrong the first time a bin is replaced. A cart still at a house whose service ended is flagged and charged the town's cart rate monthly until it comes back, once per household however many carts they kept, and a size the town has not priced is reported as a billing exception rather than billed at a figure we invented. A dumpster cannot be promised to two driveways at once, including when an earlier rental has not come back yet, its final charge comes from when it actually returned rather than from the plan, and the bill shows the arithmetic instead of a bare total.
The roster, time off, and one rule about wages
Two weeks at a glance: who is working and who is away, drawn from approved time off so nobody cross-references two screens to find out why Thursday looks thin. A time-off request is asked for, decided, and final, with refusals carrying a reason because the person who asked will read it, and an approved request cannot be quietly refused later. Nobody can be rostered on a day they were granted off. Appointments still live on the same screen, lower down. And only the mayor can set or change what an employee is paid: an administrator can see a wage, because payroll runs from it, and by default has no way to change one.
Permissions the town switches, not us
Billing clerk means a different job in a town of 250 than in one of 25,000, so every permission is a switch your administrator turns on or off per role: 34 of them across 8 roles, grouped into customers, meters, billing, payments, work, schedule, people and oversight. The routes that carry consequence - the audit log and its integrity check, rate, deposit and cart-rate setting, backups, container imports, employee pay and the staff list - read the switch when the request arrives, not just when a screen loads, and a refusal names the missing permission so a support call is short. Only the differences from the defaults are stored, and the screen marks every cell the town has changed. A town cannot switch off its own ability to switch permissions.
A record you can check, not just trust
Every action is recorded with who did it and when, and each entry is sealed to the one before it under a key the database itself does not hold, so somebody who can edit the table still cannot re-seal it. Each entry carries its own position, so a deletion from the middle leaves a gap even if the chain is relinked perfectly, and the head of the chain is also written to an append-only system record outside the database so a cut tail shows up too. A button on the audit screen runs the check and names how it broke rather than only that it did. When that outside witness is missing, verification says so instead of giving a clean bill of health it cannot give. An administrator or auditor reads the whole town's record; everybody else reads their own from their own profile, and it is the same record an administrator sees about them rather than a friendlier version.
Your records leave whenever you want, and your accountant gets a clean handoff
The whole database exports as ordinary spreadsheet files in one archive - customers, locations, service accounts, meters, readings, rate plans including retired versions, invoices, payments and the audit log - with a plain guide to the columns and how the records join up, and the audit export carries its own seal so anyone can check it for gaps. The export reads the live table definitions rather than a hand-written column list, so a future change cannot turn it into an error page, and values that a spreadsheet would treat as formulas are neutralized. No format that needs our software to read it, and no asking us first. Sealed encrypted copies come two ways: on demand under a passphrase only the town knows, which we never store and cannot recover, or on a schedule to a public key the town generates, where we hold only the public half. Separately, billing can post into the town's QuickBooks as balanced journal entries - the ledger movement rather than every resident's name copied into a second system - and it stays off until somebody deliberately turns it on.
A town website, ordinances and minutes residents can actually use
The public site is part of the same system: services, government, contact, news, meeting minutes and a resident sign-in. Ordinances are published in full text and searchable without an account, because the point of hosting the code is that a resident can read it without asking anyone. Ordinance numbers are kept exactly as adopted, because that is what appears in the minutes and on the signed copy. Writing an ordinance down and publishing it are two separate acts, each publication recorded on its own, so a draft cannot reach the front page by accident, and repealed or superseded ordinances are kept and marked rather than deleted. Minutes and news are separate lists with their own search, because merging them made the minutes impossible to hunt through.
English and Spanish everywhere, and accessibility gated on every release
Not a translated front page with an English system behind it. Every staff screen, every resident page, every letter, notice and text message, in both languages, held in step by a check that fails the build if a phrase exists in one language and not the other. The same check reads the software's own vocabularies and fails if a status, payment method or service type can be displayed without a label in both languages, because the fallback is printing the raw English token to a resident and that looks like working software. Accessibility is swept automatically across all sixteen pages against WCAG 2.1 AA on every release, the sweep stops the release on any finding, and the current result is zero. That is our own testing, confirmed by hand with a screen reader; it is not a third-party conformance audit and we do not describe it as one.
Numbers we can stand behind.
Every figure below comes from the product's own release record or test suite, not from a marketing estimate.
Numbers we can stand behind.
Imports are previewed line by line and committed all or nothing, because a half-loaded customer list or ordinance book is worse than an empty one.
Numbers we can stand behind.
Billing, the crew, the roster, the council and the public website are one system, so the clerk's month-end happens in one place instead of five.
Numbers we can stand behind.
Every optional connection is off until you turn it on, and the QuickBooks posting switch can always be turned off with no preconditions at all, because a stop control that can be blocked is not a stop control.
Surfaces and status.
Status as of 2026-09-02. Deployed and answering when checked on 2026-09-02: the town-facing site returned 200 and the staff workspace returned its sign-in gate. But the repository is explicit that this is an evaluation deployment and not production. The maintained status document, dated 2026-08-02, records the decision as controlled evaluation, not approved for public production or live municipal billing, and states that the town is not represented as a customer and the app is not an official government app. The README and the town document both state that every page carries a banner saying so and that no resident has been billed. Written authorization from a municipality is still listed as the first go-live gate and has not been obtained. The running release the repository records is 20260820T054900Z at, deployed 2026-08-20, which passed 305 automated tests and a zero-issue accessibility sweep of all 16 pages on the machine that runs it, with the release archive and its checksum recorded; work continued through 2026-08-24 (last). The Android companion is on internal distribution only and the iPhone app has never been built. That evidence supports In development, not an availability claim.
Worth more together.
Products on this platform share one sign-in, one support queue, and one engineering standard. These pair naturally with ASL Municipal Utilities.
ASL Files
Encrypted storage for the documents a town has to keep and sometimes send out: signed ordinance copies, easements, contracts. Every file is checked for tampering on download, and a link on its own is not enough to open one.
ASL Messaging
Colleague chat for the office and the crew without another vendor account. Staff who leave are deactivated rather than deleted, so the conversation about a job survives the person.
Viavitna
A grounded question-answering assistant that runs entirely on hardware you own - self-hosted is the product, not an option - so the questions people ask and the documents behind them never leave your own network.
ASL Tickets
Somewhere for requests that are not yet work orders to land and be tracked, so nothing lives only in a voicemail.
ASL Scan
Security review of the apps and sites you publish, for the board member who asks what happens if somebody attacks the website.
Recent progress.
This product ships often. The most recent verified changes, newest first.
Recent progress.
2026-08-17 appointments with reminders, and postal Intelligent Mail integration whose encoder is validated against all four official reference examples from the postal specification.
Recent progress.
2026-08-18 statements rendered with the postal barcode; an account credit ledger so an overpayment becomes credit instead of vanishing; payment arrangements with a switch the town controls; ordinances published and searchable without signing in; full English and Spanish coverage of the resident portal and of outbound bills, notices and texts; three accessibility passes ending in a real screen-reader session; a set of money-correctness fixes, each proven by removing the fix and watching the test fail; and the evaluation banner cut to a single word with every occurrence of the old wording removed from the shipped product on the operator's instruction.
Recent progress.
2026-08-19 rates the town edits itself, with an in-use rate superseded rather than overwritten; a deposit schedule the town owns, with no default figure anywhere and a written reason required to depart from it; customer and meter import from a spreadsheet, previewed line by line and committed all or nothing; cart and container imports on the town's own tag numbers; dumpster rentals end to end from booking to invoice; the permission matrix across 8 roles; the audit screen with its integrity check; a staff directory, contact notes, and employee pay restricted to the mayor; the scheduling screen reworked from customer appointments into the staff roster with time-off requests, appointments kept alongside it; scheduled sealed copies plus offsite copies proven by an actual restore rather than a log line; maps and geocoding moved to a licensed provider with the key never reaching the browser and road distances instead of straight lines; and QuickBooks journal entries with an off switch that cannot be blocked.
Recent progress.
2026-08-20 a line-by-line review of every screen closed 42 defects, the clerk and auditor workspaces were translated (248 phrases in both languages), four new build checks were added, and release 20260820T054900Z was deployed with 305 tests green and zero accessibility issues across all 16 pages.
Recent progress.
2026-08-22 the Android companion was rebuilt natively.
Recent progress.
2026-08-24 inbound text opt-out handling with the provider signature verified against their published reference rather than our reading of it and against every origin the deployment answers on, test coverage for the resident audit page, a check that stops untranslated markup shipping, and the last three deferred defects closed.
Recent progress.
Pricing for ASL Municipal Utilities is quoted after a short conversation about your situation, because the right scope differs from one team to the next. There is no charge for that conversation.
We already have a billing program. Why would we change?
Most towns this size do not have a billing problem, they have a five-vendors problem: billing here, payments there, meters in a spreadsheet, work orders on a clipboard, the website with somebody else. This is one system for all of it, so the month closes in one place and the clerk stops retyping the same numbers. If your billing program is genuinely fine and everything around it is too, there is no reason to move, and we would rather say that than sell you a migration.
Is it finished? Can we start next month?
No, and it is worth being blunt. It is deployed and running, and a release has to pass 305 automated tests and a zero-issue accessibility sweep of all sixteen pages on the actual machine before it ships. But the deployment that exists is an evaluation one, it says so on every page, no town has authorized live billing on it and no resident has been billed. Bringing a utility on is deliberate work: your rates, taxes and opening balances validated, a cycle run in parallel with what you have now, and written authorization before anything reaches a resident. If you need to be billing in thirty days, this is not that.
What does it cost?
There is no published price. Towns differ enough in size, services and what has to be migrated that a list price would be wrong for most of them, so pricing is quoted after a conversation about your accounts, your services and your data. Ask and you get a figure, not a range that moves later.
How do our existing customers get in? Ours are in a spreadsheet from the old system.
You upload the file and it is previewed line by line before anything is written: created, updated, or the specific reason a row cannot be imported, with the Import button disabled while any row has a problem. Committing is a separate deliberate act and it is all or nothing, because a half-imported customer list produces duplicate accounts and bills nobody can explain. Meters come in on the same row and attach to the right service, re-running the same file does not create anybody twice or add a second address to an existing account, and headers are matched loosely because your export will not use our column names.
What happens to our data if we stop paying, or if you disappear?
You export everything as ordinary spreadsheet files in one archive, with a written guide to the columns and how the records join together: customers, locations, services, meters, readings, rate plans including retired versions, invoices, payments and the audit log. It opens in any spreadsheet program and needs neither this software nor us. You can take that copy today, before you sign anything, and keep taking it. There is no export you have to ask us for.
We are a town of a few hundred. Is this too much software for us?
It was built for exactly that size, which is why it assumes there is no billing department, only a clerk who also answers the phone. That shows in small ways: one search box that takes half a name or the number on a cart, a page that tells each staff member in plain language what they are allowed to do so they stop asking the administrator, permissions you can narrow to fit a job that is really three jobs. Bigger utilities can use it, but the design decisions went the other way.
Who can see what? Our board is going to ask.
Roles set the starting point and your administrator adjusts each of the 34 permissions per role from a screen, with any change from the default marked. Residents see only their own account. Council members get minutes, news and a resident lookup, and deliberately cannot see the crew map, because tracking crews is dispatch work and not oversight work. Only the mayor can change what somebody is paid. And a town cannot remove its own ability to manage permissions, so nobody can lock the town out of its own settings.
Can residents pay online, and does that touch our bank details?
Residents can see their bill and their payment history from their own account page today. Paying online is built but switched off: the button stays disabled with an explanation until your utility connects its own processor account, because settlement has to land with the town and not with us. When it is on, card details are collected on the processor's own hosted page rather than typed into anything we store, so raw card numbers never enter the town's records. Turning it on includes running a small live payment and refund first.
How would we prove to an auditor that a record was not changed?
Every action is stored with who did it and when, and each entry is sealed to the one before it using a key the database itself does not contain, so somebody who can edit the table still cannot re-seal it. Each entry also carries a position, so removing one from the middle leaves a gap even if the chain is relinked, and the head of the chain is written to an append-only record outside the database so a cut tail is caught too. A button on the audit screen runs the check and names how it broke, and the audit export carries its seal so an auditor can check it outside our software.
What should I know before I rely on it?
We would rather you hear this from us than discover it later. As of 2026-09-02:
What should I know before I rely on it?
The deployment running today is an evaluation deployment, not a production one. Every page of it carries a banner saying so, no municipality has given the written authorization the project lists as its first go-live gate, and no resident has been billed.
What should I know before I rely on it?
There is no customer town yet, and no town is presented as one. The deployment that exists is a demonstration and evaluation, and the repository says so in as many words.
What should I know before I rely on it?
Online card payment is built against a hosted checkout page, so raw card numbers never reach the software, and it is tested. It is not switched on anywhere: the resident's pay button stays disabled with an explanation until a utility connects its own processor account and a live payment and refund have been run.
What should I know before I rely on it?
Posting to QuickBooks as journal entries is built, balanced-or-refuse, off by default, with an off switch that takes no preconditions. The one-time QuickBooks connection has never been completed on any deployment.
What should I know before I rely on it?
Postal barcodes and address standardization stay dormant and fail closed until the utility installs its own postal account credentials. A statement without them still prints, just without the barcode.
What should I know before I rely on it?
Text messaging, including the reply-STOP handling, is built and signature-verified but dormant until the utility supplies its own messaging account.
What should I know before I rely on it?
The Android companion goes to approved staff devices on an internal track rather than a public store download, its store audience and data-safety declarations are unfinished, and it is currently built for the hosts of the deployment it serves. The iPhone app is written but has never been compiled, signed or submitted.
What should I know before I rely on it?
Payroll figures are for reporting and for handing to an accountant. They are not a substitute for approved payroll and tax filing software and must not be used for real payroll until separately reviewed.
What should I know before I rely on it?
The software charges no late fees, penalties or reconnect fees at all. If your ordinance requires them, that is work to be scoped, not a setting to switch on.
What should I know before I rely on it?
There is no automatic meter-reading device integration. Readings are entered or arrive with an import, and there is no offline queue for a crew out of signal.
Run the whole town office from one screen.
Prefer email? contact@autosecurelogin.com