HotDoc
Appointment flow where booking instructions and intake copy can change often.
- Google Play installs
- 2.1M
- Store rating
- 4.6
When a fix only touches the web layer of your Capacitor app, ship it as an encrypted live update. Test it on a staging channel, roll it out in steps, and keep a record of every release for your compliance team.
14-day unlimited free trial. No credit card required
Enterprise needs? Talk to our team
A clinician reports a wrong label on a medication or intake screen. The fix is a few lines of JavaScript.
With a store-only process, you build a new binary, submit it, and wait. Store review is often 24–48 hours, sometimes much longer.
Even after approval, patients and staff still have to install the update before they see the fix.
Booking, intake, and reminder screens change often. Each web-layer fix waits for a new binary, store review, and user updates.
Reviewers want to know what the updater sends, where it goes, and whether you can keep it in your own infrastructure.
When a clinician reports an issue, your team has to tell which bundle and native version that device runs.
Compliance teams ask who shipped a change, when, and to which channel.
Encrypted bundles, staged exposure, and updater settings your compliance owner can review.
Upload the fixed JavaScript, HTML, and CSS with the Capgo CLI. By default, devices download the bundle and apply it when the app moves to the background. Native code changes still go through the stores.
Capgo signs a BAA with healthcare customers. The updater does not send names, emails, or medical record numbers, and you can limit or move what it does send.
BAA and HIPAA optionsCreate a key pair with the CLI. Bundles are encrypted before upload and checked by the app before install. Capgo, storage providers, and CDNs only see ciphertext.
Encryption docsSend a bundle to a small share of devices, check install and failure data, then increase. Auto-pause can stop a rollout when failures rise, and a bundle that never calls notifyAppReady() is rolled back on the device.
How it works
Set up the updater once to match your review, then send each web-layer fix through staging and a staged production rollout. Every command below is from the Capgo docs.
Point all three plugin endpoints to the EU host, or set statsUrl to an empty string if hosted statistics are not allowed. Do not set a custom ID that maps to a patient. Ship this config in a store build.
// capacitor.config.ts
plugins: {
CapacitorUpdater: {
updateUrl: 'https://plugin.eu.capgo.app/updates',
// use statsUrl: '' to disable hosted statistics
statsUrl: 'https://plugin.eu.capgo.app/stats',
channelUrl: 'https://plugin.eu.capgo.app/channel_self',
},
}
BAA and HIPAA options
Create a key pair, save the public key in your Capacitor config, and sync. Keep the private key in your CI secrets, never in the repo.
npx @capgo/cli@latest key create
npx @capgo/cli@latest key save --key ./.capgo_key_v2.pub
npx cap sync
Encryption docs
Upload the encrypted bundle to the staging channel and check it on QA devices before it reaches patients.
npx @capgo/cli@latest bundle upload --channel staging --key-v2
Channels docs
Start with 5% of production devices. When install and failure data look right, promote the bundle to everyone. If not, roll the cohort back.
npx @capgo/cli@latest bundle upload --channel production --key-v2 --rollout 5
npx @capgo/cli@latest channel set production --rollout-promote
# or, if something looks wrong
npx @capgo/cli@latest channel set production --rollout-rollback
Progressive rollouts docs
Link each bundle to its commit, keep an audit log of who shipped it, and show the running version inside the app.
Add a comment and a link to each bundle at upload time with --comment and --link, so you can trace a deployed bundle back to its source.
# Attach the commit to each bundle
npx @capgo/cli bundle upload \
--comment "Fix dosage rounding ($(git rev-parse --short HEAD))" \
--link "https://github.com/your-org/your-app/commit/$(git rev-parse HEAD)"
Read the current bundle and native version with CapacitorUpdater.current() and show them on a settings or support screen, so staff can tell support what they run.
// Show version info to clinical staff
const info = await CapacitorUpdater.current()
// Display in app settings
console.log(info.bundle.version) // "2.4.1"
console.log(info.native) // Native app version
What you can share with your compliance owner and vendor review
Use EU endpoints, disable or self-host updater statistics, or move to licensed self-hosting. Your compliance owner decides which setup fits.
Capgo and HIPAASOC 2 Type II, ISO 27001, and SSO are included on the Enterprise plan. The DPA and sub-processor list are public for your vendor review.
The updater plugin and the Capgo backend are open source on GitHub. Your team can read the code that runs on patient devices.
Apps built with Capacitor
Appointment, health-record, and benefits apps can update intake screens, booking instructions, provider messaging, and patient education without destabilizing the native shell.
Appointment flow where booking instructions and intake copy can change often.
Health-record app with public guidance and document flows that must stay current.
Benefits app where provider, eligibility, and support journeys need careful patching.
Customer proof
Lead Developer, drivolino GmbH
“The Capgo Capacitor Updater plugin completely transformed how we ship updates. What used to take days now takes just minutes.”
Founder, NuTriQ
“Being able to push production OTA updates instantly without waiting for full App Store review cycles has been a massive operational advantage.”
Developer, Webincode
“Being able to add Device ID's to certain groups and push the changes to only certain groups is a life saver.”
FAQ
Short answers for engineering teams preparing a security or HIPAA review.
Capgo signs a Business Associate Agreement (BAA) with healthcare customers, and U.S. organizations already run Capgo in HIPAA-compliant programs. The updater data is minimal and device-scoped. If your review needs more control, you can also use EU endpoints, disable statistics, self-host the statistics endpoint, or move to licensed self-hosting.
BAA and HIPAA optionsOperational data: app ID, a random app-scoped device ID, platform, bundle and native versions, OS version, plugin version, and update events. The IP address is used at transport level. It does not send names, emails, account IDs, or medical record numbers. Do not set a custom ID that maps to a patient or user.
Privacy and data collectionYes. Point the update, stats, and channel endpoints to plugin.eu.capgo.app to keep the plugin data path in Europe. You can also send statistics to your own endpoint. The Enterprise plan adds dedicated, hybrid, and licensed self-hosted options.
EU data locationOnly the web layer: JavaScript, HTML, CSS, and assets. Changes to native code, plugins, or permissions still need a new build through the App Store and Google Play.
What can ship as a live updateAudit logs record bundle uploads, channel changes, and member changes. Channel history lists every bundle that was live, and each bundle can carry a comment and a commit link. Roles limit who can upload bundles or change channels.
Audit logsSet up a staging channel, encrypted bundles, and the updater config your review needs on your own app during the trial.
human support from Martin
14-day unlimited free trial. No credit card required
Enterprise needs? Talk to our team
14-day free trial, no credit card. A BAA, SOC 2 Type II, ISO 27001, SSO, and self-hosting options come with the Enterprise plan.