One Clinic = One Firebase Project
Our architectural commitment to healthcare compliance, tenant isolation, and patient privacy.
Dedicated Isolated Firebase Instance
Unlike common SaaS systems that store all healthcare providers in one shared database table, every clinic on the Expolio Platform gets its own dedicated Google Cloud / Firebase project. Firestore documents, Auth users, and Storage buckets are physically and logically segregated.
Platform Administration ≠ Clinic Data Access
The Master Admin console has visibility solely into platform metadata: clinic ID, owner contact, billing subscription, and infrastructure provisioning status. Master administrators have zero browsing interfaces for patients, medical records, or prescriptions.
AES-256 Encryption at Rest
All Firebase API keys, service credentials, and sensitive tenant configuration payloads are encrypted at rest using Laravel's AES-256-GCM authenticated cipher before storage in MySQL.
Data Preservation Policy
When a 14-day trial concludes or a subscription changes, clinical records and patient histories are never deleted casually. Data remains securely retained in the clinic's private Firebase environment until explicitly requested by the clinic owner.
Architectural Blueprint
Visual breakdown of how Laravel SaaS orchestrates subscriptions while clinical data remains strictly inside isolated Firebase projects.
[ Public Web & Master Admin ]
└─ Laravel / MySQL: Plans, Pricing, Subscriptions, Audit Logs, Provisioning Queue
[ Clinic Tenant Layer ]
├─ Clinic 1 ➔ Firebase Project A [ Auth A · Firestore A · Storage A ]
├─ Clinic 2 ➔ Firebase Project B [ Auth B · Firestore B · Storage B ]
└─ Clinic N ➔ Firebase Project N [ Auth N · Firestore N · Storage N ]