Architecture
Elixty
A solution-architecture summary — how the system is designed, and why. Verified from the source code.
- Type of system
- Multi-tenant SaaS (AI social scheduling)
- Users
- Founders, small teams and agencies
- Hosting
- United Kingdom
- Main stack
- Laravel + React (Inertia), SQLite
- Status
- Live (payments launching soon)
- Built for
- Moanv's own product (a fork of the open-source Shoutrrr scheduler)
The problem
Staying visible online eats an evening a week small teams don't have, and the tools that exist are one more dashboard to babysit. The hard part isn't scheduling — it's writing posts that sound like you, consistently, across every channel your customers use.
How it fits together
Users
Founders · teams · agencies
Front end
React 19 + Inertia
Tenant boundary
Backend / API
Laravel 13 on Octane/FrankenPHP (one container: web + queue + scheduler)
Database
SQLite (file, on a volume)
One shared database; every row is scoped to a workspace_id by a global query filter.
External services
- Anthropic Claude — drafting
- Stripe — billing
- X, Bluesky, LinkedIn, Facebook, Instagram, Threads, Discord
- Telegram — draft approval
- SMTP — email
Tech stack
Front end
- React 19, Inertia, Tailwind 4, TypeScript, Vite
- TipTap (editor), Recharts (charts)
Backend
- PHP 8.5, Laravel 13 on Octane + FrankenPHP
- One Docker container: web server + queue worker + scheduler
Database
- SQLite on a Docker volume (a Postgres path is available, not enabled)
Hosting
- United Kingdom
- Single Linux host, Docker Compose, nginx, Let's Encrypt; Azure DevOps SSH deploy
Third-party
- Anthropic Claude (Sonnet 5 / Haiku 4.5)
- Stripe via Cashier
- X, Bluesky, LinkedIn, Facebook, Instagram, Threads, Discord
- Telegram (approvals)
- SMTP (email)
Key design decisions
Fork the open-source Shoutrrr scheduler
Why: The scheduling and publishing plumbing already existed and was battle-tested; we added the AI drafting and brand-voice layer on top.
Trade-off: We inherit the fork's structure and keep it in sync with upstream.
Human approval on by default
Why: AI posts to a brand's real audience, so a draft waits for approval — in-app or via Telegram — before it publishes.
Trade-off: Fully-automatic posting is opt-in, not the default.
Workspace-scoped multi-tenancy (shared DB + workspace_id)
Why: The simplest reliable isolation for many small tenants; a global filter scopes every query to the current workspace.
Trade-off: Isolation depends on the filter being applied everywhere, so it's enforced centrally.
Encrypt the secrets that matter, in the app
Why: Social tokens and API keys are AES-256 encrypted at the field level, so the database file alone doesn't yield credentials.
Trade-off: Encryption is keyed from the app secret, which must itself be protected.
Stripe-hosted checkout
Why: Card details never touch Elixty's servers; Stripe handles PCI, tax and invoices.
Trade-off: Less control over the exact checkout screens.
Security & data protection
- Hosted in the United Kingdom.
- TLS with HSTS, a strict per-request Content-Security-Policy, X-Frame-Options DENY, nosniff and Referrer-Policy.
- Email + password (Laravel Fortify, bcrypt), with optional TOTP two-factor and passkeys (WebAuthn).
- Role-based access (owner / admin / member) enforced by policies and request checks.
- Sensitive fields — social tokens and API keys — encrypted at rest with AES-256.
- Rate limits on login, two-factor, the API, account connections, AI and uploads; CSRF protection on.
- Retention jobs prune usage events after 180 days and abandoned uploads after 6 hours; users can delete their own account.
Built to hold up
- Performance
- Laravel Octane keeps the app warm (no per-request boot); background work runs on a queue.
- Availability
- A single UK host with a health check at /up.
- Scalability
- Workspace-scoped tenancy; SQLite suits the current scale, with a Postgres path ready when it's needed.
Results
- PageSpeed (mobile): 90 / 100, largest content painted in 3.0s.
What we'd do next
- Add an activity audit log for security-relevant actions.
- Turn on the wired-up error monitoring and automated database backups.
- Publish the privacy and cookie policy before payments go live.