Built on Lovable?
Now make it compliant.

Keep the screens, data model, and logic you already built. Our migration agent moves your health app onto a HIPAA ready foundation and rewrites what isn't safe for patient data, typically in about three days.
Lovable
Replit
Base44
Bolt
v0
Anything you can put in a GitHub repo works.
CarePortal v0.9 (beta)
! No BAA on file, PHI stored unencrypted
Next visit: Video consult, 2:30 PM
Click here to join the call
Messages (2)
Your results are ready…
Search patient…
SubmitRefresh
CAN'T LAUNCH
NOT HIPAA COMPLIANT
Compliant. Live.
CarePortal
NEXT VISIT
Video consult, 2:30 PM
BAA SIGNED PHI ENCRYPTED
Hi! Your results are ready to review.
Great, can we talk today?
72
HEART RATE
98%
SPO2
What launching actually takes

It takes secure code and secure infrastructure.
Vibe-coding gives you neither.

Your product decisions and designs come with you. Anything tied to your old platform, including the backend, gets rebuilt on Specode

Code
Identifiers leak into URLs, PHI lands in logs, database access sits wide open. The migration and HIPAA agents find these and fix them.
Infra
Auth, hosting, secrets, and a BAA that actually permits patient data. The move rebuilds this layer on a HIPAA-ready foundation.
Lovable
BLOCKS PHI
Its terms bar protected health information unless you have a signed BAA, and the standard product doesn't include one.
Replit
SILENT ON HIPAA
Its terms don't mention HIPAA, protected health information, or a business associate agreement at all. An absence is harder to hand a reviewer than a rule.
A SOC 2 report ≠ a signed BAA
Both publish security attestations. Neither publishes a HIPAA offering. Only a signed BAA decides whether patient data is allowed in.
Migration, not rewrite

What moves with you, and what we rebuild

Patient data needs application code that handles it safely and a foundation that's contractually allowed to hold it. Miss either and you can't launch. Migrating rebuilds the foundation while the agents rewrite what the code gets wrong, so both are covered before you go live.

Comes across

Your product

The parts that took real decisions.
Screens, layouts, and flows
Your data model and its relationships
Business rules and validation
Copy, content, and assets
Integrations you hold the keys to
Gets rebuilt

The plumbing

The parts welded to your old platform.
Authentication and sessions
Hosting, deploys, and environments
Secrets and environment configuration
Logging, monitoring, and error handling
Anything wired to the old platform's runtime
How the move works

Four steps, and nothing starts without your sign off.

STEP 1
Connect your repo, read only
STEP 2
Scan builds your project map
STEP 3
You approve the plan
STEP 4
Live on HIPAA ready infra
1
Grant read only access
Connect the GitHub repo your app lives in, whether Lovable, Bolt, v0, Base44, or exported code. Access is read only: we read only the repositories you pick, we can't change or push anything, and you remove it yourself anytime.
2
Get your project map
The scan reads your code and sorts every part into three buckets: what transfers directly, what needs adjustment to meet compliance, and what won't work in a HIPAA environment, flagged so you can decide before, not during.
3
Approve the plan
We walk you through what the scan found and how the move would go, including what we propose for anything that can't come across as is. If an answer is wrong for your product, this is the cheap moment to say so.
4
Go live on HIPAA ready infrastructure
Your app lands on a foundation built from prebuilt healthcare components. You keep building with the AI coder the way you did before. The foundation underneath is just different.
Pricing

One price to get compliant

Start migrating today. No rebuild, no setup fee.

MIGRATION
$
250/month
Everything you need to move your app onto a compliant foundation
The migration agent
HIPAA compliance agents and HIPAA-related fixes
300 monthly credits to run the agents, and you can put them toward building too
Upgrade to Pro for product iteration, new features at anytime.
Two agents do the work

One moves your app. One keeps it compliant.

Migration agent
Moves your app onto Specode
It brings your existing build across and rewrites the parts that aren't safe for patient data, then hands off to the HIPAA agent for a hardening plan. The failures are boringly consistent, and it goes looking for them.
Identifiers in URLs
PHI in logs
Wide open database access
Clinical detail in emails
HIPAA agent
Hardens what's left
It scans from the Compliance Center and reports findings across eleven categories, split into must fix and recommended. Send any finding to the AI coder, it changes the code, and you rerun the scan to confirm, each run saved with a score so you can see you're moving the right way.
Scored, rerunnable
Eleven categories
Human review before launch
What you're agreeing to

Fast, reviewed, and still yours

3 days
To a HIPAA-ready foundation
100%
Your code, still
Human review before launch
SOC 2
Type II hosting

Questions people ask first

Can I make my Lovable app compliant instead of moving it?

Only if Lovable has signed a Business Associate Agreement (BAA) with you. Its standard terms don't include one. Without a BAA, security fixes alone won't make the app compliant, because Lovable still isn't allowed to handle your patient data. That's why the usual fix is to move the app off Lovable.

Does my Supabase database have to move too?

Yes. Specode apps run on Convex, so Supabase is no longer part of your stack. Your data moves into a Convex database, and because Convex structures data differently, your backend gets rewritten as part of the migration.

Will I lose the features I already built?

Your screens and business rules come with you, and so does your data model. The parts tied to your old platform get rebuilt, including the backend, authentication, and hosting. Before any work starts, the migration plan lists anything that won't carry over.

Do I need a Business Associate Agreement (BAA) with every vendor in my stack?

Only with the ones that handle patient data for you, such as your database or email provider. Those vendors, in turn, need BAAs with any of their own subcontractors that touch that data. We'll tell you which ones apply to your setup.

Is it safe to bring my prototype's data with me?

If your prototype only ever held test data, yes. If real patient data ever went into it, you likely already have a real HIPAA problem on your hands, and we can't move that data into Specode. Email us at support@specode.ai right away, and we'll help you figure out how to resolve it.

Can I use real patient data while I build in Specode?

No, and that holds on every plan, Pro included. The Specode build environment, including your app preview, is for development only. Our team and Specode AI have direct access to your code and settings there, and no BAA covers it, so it should only ever hold test data. Real patient data belongs only in your production app, after a HIPAA-compliant deployment.

What do I get for $250/month, and when do I need Pro?

The $250/month plan covers migration and compliance: the migration agent, the HIPAA compliance agents, HIPAA-related fixes, and 300 credits to use on that work. Pro adds HIPAA-compliant app deployment, which needs hands-on work from our team, plus product iteration, so you can keep building new features.

How do I keep my third-party integrations working after the migration?

Add the credentials for each integration in your project settings. Specode AI tells you the exact key names it needs and where to find the value for each one.

Start here

Built it already? Bring it across.

Migrations start as a conversation, not a signup form. We'll go through your stack, tell you which bucket each part falls into, and say plainly whether a move makes sense for you.