S — Secure
Your records, locked by default.
- Encrypted by default
- NDPA 2023 compliant
- Hosted in Africa
Most healthcare software re-implements auth, audit, and records in every product. Fastclinic puts them under every product — so each new app inherits identity, a hash-chained audit trail, and a patient-controlled record system by default, not by integration.
Patient signs in
FastLogin· identity
passkey ✓ · provider verified
Doorcta· telehealth
ready
FastCredits· ledger
350.00 cr
OneHealth· records
no active session
Every Fastclinic product is built on a shared foundation — one identity, one currency, one record system. You don’t stitch them together. We did.
What is shipped
AES-256
per-record envelope encryption
Every record has its own DEK · GCM mode
7 yr
tamper-evident audit retention
Hash-chained · WORM export daily
FHIR R4
standard record export
Patient · Observation · Consent · Provenance
Ed25519
signed on every DSAR
Detached manifest · verifiable with a public key
48 h
erasure cool-off window
NDPA-aligned reversibility window
18 ctry
ID database validation
NIN · BVN · CURP · DNI — powered by Didit
Every line on this grid maps to a merged subsystem. Ask for the commit hash.
Every product you see — and every product we ship next — rides on the same three foundation layers. That is the bet.
— Layer 04
Products
— Layer 03
OneHealth
— Layer 02
FastCredits
— Layer 01
FastLogin
bottom → foundation · top → product surfaces
Doorcta today. EMR, lab, pharmacy tomorrow. Every new surface plugs into the same three layers below.
Records layer. Per-record AES-256-GCM envelope encryption. Patient-granted, time-boxed access. Hash-chained audit of every read.
Currency layer. Auto-created with your FastLogin account. Hold / capture / release semantics power every metered action.
Identity foundation. Ory Kratos + Hydra. Passkey, TOTP, backup codes. KYC-verified provider credentials. OAuth2 into everything above.
Getting onto Fastclinic is straightforward. Here is how we partner with healthcare organisations.
Step 01
We analyse your workflows, regulatory profile, and infrastructure to identify the right combination of Fastclinic products.
Step 02
Start with the surfaces you need — Doorcta, OneHealth, FastCredits — connected through a single FastLogin identity.
Step 03
Our team handles deployment, data migration, integration, and staff training with a proven five-phase rollout.
Step 04
Add facilities, onboard more providers, and expand regions — on one platform, one identity, one ledger.
Illustrative mockups of the experiences we are designing. Same identity, same ledger, same audit chain — different audiences.
Your health, on your terms. Book, pay with credits, and decide who sees what.
Good morning
FastCredits
340.00
Dr. A. Adebayo — Cardiology
Tomorrow · 09:30 · Video consultation
72bpm
118/76
Stable
Recent records
Consultation — Dr. A. Adebayo
14 Apr 2026
Lab panel — Full metabolic
02 Apr 2026
Prescription — Lisinopril 10mg
01 Apr 2026
Dr. Adebayo shared a pre-consultation note. Open before your appointment.
Sign users in with FastLogin. Get an access token. Use it everywhere — to check their FastCredits balance, to open a metered OneHealth session, to export a FHIR R4 bundle. No per-product auth theatre.
1# 1. Redirect the user2GET https://login.fastclinic.xyz/oauth2/auth3?client_id=your_app4&scope=openid%20profile%20credits.read%20phi.read5&response_type=code6&code_challenge_method=S2568# 2. Exchange code for tokens9POST /oauth2/token10grant_type=authorization_code11code_verifier=<pkce_verifier>13-> 200 { access_token, id_token, refresh_token }14access_token: 15 min · refresh rotates every use
FastCredits
FastCredits is the universal currency of the Fastclinic ecosystem. Linked to your FastLogin identity, your credit balance travels with you across every product — simplified billing, complete flexibility.
A single credit balance powers every Fastclinic product — Doorcta, OneHealth, and more.
Your FastCredits account is created automatically with your FastLogin account. One identity, one balance.
The more credits you purchase, the lower your effective cost per unit.
Your investment is protected — use credits on your own timeline.
Fastclinic is designed so patients, providers, and developers all get the same underlying guarantees — just through different surfaces.
Patient
Grant access
Chiamaka allows Dr. Adebayo to view her records for 30 days.
Stay informed
Every view is logged. She can inspect the audit trail at any time.
Auto-expire
30 days later, access revokes — no action required.
Provider
Open a session
Dr. Adebayo starts a consent-gated session; FastCredits holds 10 credits.
Read what is needed
Each record opened is scoped, timestamped, and hash-chained.
Close the session
Actual usage is captured; the rest is released back to the balance.
Developer
Sign in users
Register an OAuth2 client; redirect to FastLogin; receive tokens.
Use one token
Same access token reads balances, starts sessions, and exports records.
Ship faster
No bespoke auth, no per-vendor billing plumbing, no audit glue.
File a Data Subject Access Request and receive a signed, encrypted, standards-compliant archive — not a dump, not a screenshot, not a 90-day wait.
Signature · verified
Manifest signed with the OneHealth DSAR service key.
Per-document encryption
Every attached document carries its own AES-256-GCM key. Losing one key does not compromise the rest.
FHIR R4 · not a proprietary dump
Records ship as HL7 FHIR R4 resources. Any FHIR-aware system can read them — including yours.
Fastclinic isn't just another vendor. We're a platform company purpose-built for the complexities of modern healthcare delivery.
Every product shares one identity (FastLogin), one currency (FastCredits), and one health record system (OneHealth). No fragmentation, no vendor sprawl.
Designed for the realities of African healthcare — intermittent connectivity, local regulations, and diverse facility types from rural clinics to teaching hospitals.
Encryption at rest and in transit, role-based access controls, audit logging, and full compliance with Nigeria's Data Protection Act.
AI that augments clinicians, never replaces them. Built with bias testing, transparency, human oversight, and patient safety guardrails.
Four promises. Plain English. No fine print.
Your records, locked by default.
Every action leaves a receipt.
Credits make pricing transparent. No hidden fees.
Your records, your call.
Fastclinic is built on named, battle-tested infrastructure. Not a proprietary black box.
Ory Kratos
Identity
Ory Hydra
OAuth2 / OIDC
Paystack
Payments
Didit
KYC / AML
HashiCorp Vault
KMS
PostgreSQL
Datastore
Redis
Cache
AWS S3
WORM audit
FHIR R4
HL7 standard
Resend
Transactional email
WebAuthn
Passkey MFA
Ed25519
DSAR signing
Ory Kratos
Identity
Ory Hydra
OAuth2 / OIDC
Paystack
Payments
Didit
KYC / AML
HashiCorp Vault
KMS
PostgreSQL
Datastore
Redis
Cache
AWS S3
WORM audit
FHIR R4
HL7 standard
Resend
Transactional email
WebAuthn
Passkey MFA
Ed25519
DSAR signing
Most healthcare organisations buy five or six point solutions and spend the next two years gluing them together. Fastclinic is what you get when identity, billing, and records were designed together on day one.
Every claim on this page maps to a shipped subsystem with a real interface, a real schema, and a real audit line. Here are the six that matter most.
Every record has its own AES-256-GCM data encryption key. The DEK is sealed with a KMS-held master key. Compromising one record does not cascade.
Every audit event includes the hash of the previous event. Append-only at the trigger level. Break the chain and it is cryptographically detectable.
WebAuthn / passkey, TOTP, and one-time backup codes. Mandatory for every account. No SMS fallback to social-engineer around.
Every archive ships with an Ed25519 signature over its manifest. Patients verify integrity with a public key — no trust in us required.
Daily audit-root exports land in a write-once, read-many S3 bucket in a separate AWS account. 7-year retention. Independently auditable.
Access grants are time-boxed, purpose-scoped, and revocable mid-session. Access attempts beyond consent return 403 — not a softer signal.
security.txt · architecture notes · threat model
Read the trust page →Built in Nigeria
Fastclinic Limited (RC 1919428) is incorporated in Nigeria and operates in compliance with the Nigeria Data Protection Act 2023. Compliance is not a localisation layer — it is the architecture. NDPA 2023 consent semantics, NDPR retention rules, and the National Health Act sit alongside the schema, not on top of it.
We do not pre-announce. These lanes reflect what is merged, what is actively being built, and what is committed to next.
No marketing fog. If the answer changes, we update this section.
See how Fastclinic's integrated platform can modernize your operations, improve patient outcomes, and drive growth.