Moanv
Elixty case study
Elixty

Architecture

Elixty

A solution-architecture summary — how the system is designed, and why. Verified from the source code.

Type of system
Multi-tenant SaaS (AI social scheduling)
Users
Founders, small teams and agencies
Hosting
United Kingdom
Main stack
Laravel + React (Inertia), SQLite
Status
Live (payments launching soon)
Built for
Moanv's own product (a fork of the open-source Shoutrrr scheduler)

The problem

Staying visible online eats an evening a week small teams don't have, and the tools that exist are one more dashboard to babysit. The hard part isn't scheduling — it's writing posts that sound like you, consistently, across every channel your customers use.

How it fits together

Users

Founders · teams · agencies

Front end

React 19 + Inertia

Tenant boundary

Backend / API

Laravel 13 on Octane/FrankenPHP (one container: web + queue + scheduler)

Database

SQLite (file, on a volume)

One shared database; every row is scoped to a workspace_id by a global query filter.

External services

  • Anthropic Claude — drafting
  • Stripe — billing
  • X, Bluesky, LinkedIn, Facebook, Instagram, Threads, Discord
  • Telegram — draft approval
  • SMTP — email
Founders, teams and agencies use a React front end joined to a Laravel backend by Inertia, running on Octane with a queue and scheduler in one container, backed by SQLite. Every row is scoped to a workspace. Claude drafts posts, Stripe handles billing, and the app publishes to seven social networks; drafts can be approved from Telegram.

Tech stack

Front end

  • React 19, Inertia, Tailwind 4, TypeScript, Vite
  • TipTap (editor), Recharts (charts)

Backend

  • PHP 8.5, Laravel 13 on Octane + FrankenPHP
  • One Docker container: web server + queue worker + scheduler

Database

  • SQLite on a Docker volume (a Postgres path is available, not enabled)

Hosting

  • United Kingdom
  • Single Linux host, Docker Compose, nginx, Let's Encrypt; Azure DevOps SSH deploy

Third-party

  • Anthropic Claude (Sonnet 5 / Haiku 4.5)
  • Stripe via Cashier
  • X, Bluesky, LinkedIn, Facebook, Instagram, Threads, Discord
  • Telegram (approvals)
  • SMTP (email)

Key design decisions

Fork the open-source Shoutrrr scheduler

Why: The scheduling and publishing plumbing already existed and was battle-tested; we added the AI drafting and brand-voice layer on top.

Trade-off: We inherit the fork's structure and keep it in sync with upstream.

Human approval on by default

Why: AI posts to a brand's real audience, so a draft waits for approval — in-app or via Telegram — before it publishes.

Trade-off: Fully-automatic posting is opt-in, not the default.

Workspace-scoped multi-tenancy (shared DB + workspace_id)

Why: The simplest reliable isolation for many small tenants; a global filter scopes every query to the current workspace.

Trade-off: Isolation depends on the filter being applied everywhere, so it's enforced centrally.

Encrypt the secrets that matter, in the app

Why: Social tokens and API keys are AES-256 encrypted at the field level, so the database file alone doesn't yield credentials.

Trade-off: Encryption is keyed from the app secret, which must itself be protected.

Stripe-hosted checkout

Why: Card details never touch Elixty's servers; Stripe handles PCI, tax and invoices.

Trade-off: Less control over the exact checkout screens.

Security & data protection

  • Hosted in the United Kingdom.
  • TLS with HSTS, a strict per-request Content-Security-Policy, X-Frame-Options DENY, nosniff and Referrer-Policy.
  • Email + password (Laravel Fortify, bcrypt), with optional TOTP two-factor and passkeys (WebAuthn).
  • Role-based access (owner / admin / member) enforced by policies and request checks.
  • Sensitive fields — social tokens and API keys — encrypted at rest with AES-256.
  • Rate limits on login, two-factor, the API, account connections, AI and uploads; CSRF protection on.
  • Retention jobs prune usage events after 180 days and abandoned uploads after 6 hours; users can delete their own account.

Built to hold up

Performance
Laravel Octane keeps the app warm (no per-request boot); background work runs on a queue.
Availability
A single UK host with a health check at /up.
Scalability
Workspace-scoped tenancy; SQLite suits the current scale, with a Postgres path ready when it's needed.

Results

  • PageSpeed (mobile): 90 / 100, largest content painted in 3.0s.

What we'd do next

  • Add an activity audit log for security-relevant actions.
  • Turn on the wired-up error monitoring and automated database backups.
  • Publish the privacy and cookie policy before payments go live.