Built for the clinical standard.
PHI is not a feature. It's the foundation. Here's exactly what we protect, how — and what we do not claim.
BAA in place
HIPAA-compliant. BAA in place. Built on SOC 2 Type II and ISO 27001-certified infrastructure.
Role isolation
Each partner’s data is isolated at the API layer. Partners cannot see each other’s records or your clinical notes.
AI transparency
AI drafts are labeled, attributed, and deny-by-default without clinician attestation.
Clinician-in-the-loop
AI drafts are never auto-filed. Safety alerts never auto-dispatch. Every clinical action requires your explicit sign-off.
Encrypted storage
Data encrypted in transit and at rest.
Audit trail
Every AI output, note signing, consent action, and safety record is timestamped and attributed.
HIPAA compliance
LoveCode is HIPAA-compliant. A Business Associate Agreement is in place. The platform is built on Google Cloud infrastructure certified to SOC 2 Type II and ISO 27001. PHI is encrypted in transit and at rest. Role isolation is enforced at the API layer — each partner's records are separated from the other's, and clients never see clinical notes.
What LoveCode is and is not
- LoveCode is a clinical documentation platform — a support tool for licensed clinicians.
- It is not a licensed mental health provider and does not provide therapy or clinical advice.
- We do not publish uptime SLAs without a real measurement.
- LoveCode makes no claims of clinical outcomes, recovery rates, or FDA clearance. It is not a medical device.