Expolio Group Logo
CMS SaaS

By Expolio Group

Home Features Security & Isolation Pricing FAQ
Data Privacy Guarantee

One Clinic = One Firebase Project

Our architectural commitment to healthcare compliance, tenant isolation, and patient privacy.

1

Dedicated Isolated Firebase Instance

Unlike common SaaS systems that store all healthcare providers in one shared database table, every clinic on the Expolio Platform gets its own dedicated Google Cloud / Firebase project. Firestore documents, Auth users, and Storage buckets are physically and logically segregated.

2

Platform Administration ≠ Clinic Data Access

The Master Admin console has visibility solely into platform metadata: clinic ID, owner contact, billing subscription, and infrastructure provisioning status. Master administrators have zero browsing interfaces for patients, medical records, or prescriptions.

3

AES-256 Encryption at Rest

All Firebase API keys, service credentials, and sensitive tenant configuration payloads are encrypted at rest using Laravel's AES-256-GCM authenticated cipher before storage in MySQL.

4

Data Preservation Policy

When a 14-day trial concludes or a subscription changes, clinical records and patient histories are never deleted casually. Data remains securely retained in the clinic's private Firebase environment until explicitly requested by the clinic owner.

Architectural Blueprint

Visual breakdown of how Laravel SaaS orchestrates subscriptions while clinical data remains strictly inside isolated Firebase projects.

[ Public Web & Master Admin ]

└─ Laravel / MySQL: Plans, Pricing, Subscriptions, Audit Logs, Provisioning Queue

[ Clinic Tenant Layer ]

├─ Clinic 1 ➔ Firebase Project A [ Auth A · Firestore A · Storage A ]

├─ Clinic 2 ➔ Firebase Project B [ Auth B · Firestore B · Storage B ]

└─ Clinic N ➔ Firebase Project N [ Auth N · Firestore N · Storage N ]