Skip to main content
Q-Code

Personal vibe-coding platform

Build sites that AI can find, understand, and use.

Q-Code builds websites, platforms and apps from a conversation, and ships them ready for AI to find, understand and use.

You describe what you want in plain English, watch it build, check it on a live preview, and publish in about twenty seconds. What comes out is answer-ready for the engines that now do the finding, scored on how machines see it, and able to serve an AI assistant as tools rather than pages. Every site ships hardened by default, and the hosting account, the repository, the domain and the database are all in your name.

build · bike-shop

A site for my bike shop. Opening hours, a repair booking form, and it has to look calm rather than shouty.

Building a four-page site: home, repairs, opening hours and contact. Adding the bookings module for the repair slots, and taking a deposit is one switch if you want it later.

warm neutral base · one amber accent

Build 14

  • Read the brief
  • Wrote 4 pages
  • Installed @ccd/bookings
  • Generated opening hours markup
  • Auditing built HTML
previewbike-shop.preview.q-code.ai98 · ready
A build in progress: the request, the plan it produced, and the steps completing.

AI-readiness

Found, understood, used.

A growing share of visits starts with an AI doing the looking, and some of them are not people at all. Every site built here is prepared for that in three layers, and all three ship by default.

  1. 01 · Found by AI

    Readable by a machine, not only by a browser

    The parts an answer engine looks for are written on every build rather than added later, because a site that leaves them out is one an AI has to guess about.

    • An /llms.txt saying what the site is for and which page covers what
    • A robots policy that allows answer engines and citation crawlers; training crawlers are the only real choice, and the default allows them too
    • Content Signals, so the file and the zone say the same thing
    • JSON-LD on every page: Organisation, WebSite and WebPage, plus Article, FAQPage, HowTo and BreadcrumbList where a page earns them
    • Answer-ready content: the first paragraph after the h1 answers the page’s question outright
  2. 02 · Measured and fixed

    Scored on how machines see it, then repaired

    The visibility engine reads the HTML a crawler actually receives, plus, for security, the live response headers and the database, and returns one report, with each finding written as a sentence and a button rather than as homework. Measuring agent readiness at all is an unusual thing for a site builder to do.

    • Machine visibility, covering SEO, AEO and LLMO
    • Conversion, which asks whether the page has a next step at all
    • Security, reading transport, headers, exposure, leaked-secret counts and the database
    • Agent readiness, fetched from a public agent-readiness scan of the published site
    • Findings become fixes in one click, routed by consequence: safe ones apply, ones that change what the site does wait for a nod
    • Anything that would expose the site to agents is withheld unless agent access is switched on

    How the audit works

  3. 03 · Usable by AI

    The site as tools an assistant can call

    One module turns the site into an MCP server at /mcp, so an assistant working for a visitor can ask it questions instead of scraping it. Its tools are derived from the modules the site has installed.

    • A catalogue gives search and item tools; booking gives availability and booking; blog, FAQ, testimonials and the contact form each give their own
    • Thirteen tools on a site with everything installed, and none on a site with nothing
    • Reads return only what a visitor already sees: approved rows, published items, no drafts
    • The two write tools need the person’s consent, are rate-limited per address, and mark what they create as made through an agent
    • Off by default, and switched on with one flag

    What an AI-ready site is

The loop

Chat, build, preview, publish.

Four steps, and the third one is the reason the other three are safe: nothing reaches your domain until you have looked at it.

  1. 01

    Describe it

    Say what you want in the words you would use to a person. No brief, no wireframe, no ticket.

  2. 02

    Watch it build

    The build narrates itself as it goes, in plain English, so you can tell whether it understood you before it finishes.

  3. 03

    Check the preview

    Every build lands on a real preview URL first. You see it before anybody else can.

  4. 04

    Publish it

    One click puts it on your own domain, with a certificate, in about twenty seconds.

The loop, in full detail

Security by default

Every site ships hardened.

Security is not a module you remember to install or a checklist handed back to you at the end. Every site built here comes with the controls below already set, and the platform’s own security lens scores a default site 99 out of 100.

  • Secure response headers, so a browser is told what not to do with the page
  • HTTPS with HSTS, so a browser refuses an insecure connection
  • An enforced content-security-policy, so only the code the site uses runs
  • Row-level security on the data, so a private row refuses an anonymous read
  • A managed web application firewall in front of the sensitive endpoints
  • Dependencies and code scanned for known vulnerabilities and leaked secrets

And a trust page anyone can read

Every site can publish a public trust page saying, in plain English, how it is secured, where it runs and how it handles what you send it. It is maintained from the site’s own configuration rather than written by hand, so it cannot quietly describe a site that no longer exists.

Read this site’s trust page

Ownership

The difference is what you are left holding.

Most builders of this kind hand you a website and keep the ground it stands on. Q-Code puts the ground in your name first and builds on top of it.

The hosting
A Cloudflare account in your name. Not a seat on ours.
The code
A real Git repository you can clone, read and take elsewhere.
The domain
Held in your own account, with the DNS zone yours to move.
The data
Your database. Every table exportable, including the ones you did not ask for.
The bill
You pay Cloudflare and Stripe directly. Nothing is resold to you with a margin.
The exit
Everything above means leaving is a decision, not a negotiation.

How that compares with Lovable, Wix and Webflow

Visibility

A site nobody can find is not finished.

Every build is audited against six pillars: SEO, AEO, LLMO, conversion, security and agent readiness. Most are read from the HTML a crawler actually receives rather than the source it was written from; security also reads the live response headers and the database directly. The score is one number, each finding is a sentence you can act on, and the fix is a button rather than a homework assignment.

Answer engines are included on purpose. A growing share of visits begin with an AI reading the page and answering on your behalf, so the audit checks whether your answer is near the top of the page where it can be quoted, and whether the site publishes a machine-readable description of itself.

How the audit works

visibility · report

Visibility score

90/100

+11 since last build

  • SEO94
  • AEO88
  • LLMO91
  • Conversion76
  • Security92
  • Agent readiness100

Conversion

The repairs page asks for a booking twice and never says what it costs.

Fix this

AEO

Two pages open with background instead of the answer.

Fix this

A visibility report: an overall score of 90, six pillar scores, and two findings each offering a one-click fix.

Running it

What it is like once you own a few of them.

Four small things that decide whether a platform is pleasant to live with: you can see the sites, hand it files, see what it costs, and trust a long job to finish.

Real screenshots

Every project is a card carrying a real screenshot of the site as it looks now, captured at the edge. Not an icon, not a stock thumbnail, so a board of eight projects reads at a glance.

Attachments in the chat

Attach a logo and say rebrand, or drop in photographs and say add these to the gallery. The files are used directly, rather than uploaded somewhere else first and referred to later.

Cost you can see

Spend is shown per build and per month, with a budget warning before a budget is crossed. Cost is a number in front of you rather than a statement you go and open.

Tasks that never dead-end

A long change checkpoints its progress and continues, rather than stopping at an error you cannot get past. If it is about to spend past a ceiling, it warns you and asks first.

More on the cockpit and the chat

Coming from Lovable

Move a project in, gate by gate.

A guided wizard brings a Lovable project across into a Q-Code project you own, in five visible steps. Your domain is the last thing to move, because it is the thing a visitor notices going wrong.

  1. 01A member signs inA real person signs in successfully on the imported site.
  2. 02A payment event arrivesA real payment event arrives from the provider, so the money path is proven.
  3. 03Secrets are rotatedKeys and tokens are rotated, so the old project cannot act on the new one.

The admin comes with it

An imported React site gets the same owner admin console a site built here from scratch gets, with an overview, analytics, brand voice and access, drawn in the imported site’s own palette rather than the platform’s.

Nothing dangerous is automated away. The wizard does the tedious part and holds the consequential part until you have checked it.

How importing works

Module library

20 modules, built once and reused.

A module is a feature that has already been written, argued about and hardened on somebody else’s project. Installing one is a switch, not a build.

    • Visibility engine
    • Analytics
    • Security baseline
    • Legal pages
    • Cookie consent
    • Self-improving blog
    • FAQ
    • Testimonials
    • Gallery
    • Footer
    • Listings
    • Booking
    • Contact form and inbox
    • Newsletter
    • Social profiles
    • AI chat
    • Admin dashboard
    • Sign-in and members
    • Google connections
    • Agent access
  • Every module carries its own admin panel, structured data and audit rules, so installing one does not quietly cost you a point of visibility.

    See the whole library

Built on it

Two sites you can go and look at.

The shortest answer to what this produces is a site it produced.

v-code.ai

A live reference site about vibe coding, built on this platform from a single brief. Worth a look if you want to see what one description turns into.

Code Craft Digital

The web agency that runs on Q-Code and builds every client site on it. The platform is not a side project it sells; it is the one it uses.

Q&A

Questions people ask about Q-Code

What is vibe coding?

Vibe coding is building software by describing what you want in natural language and letting an AI write the code. You review the result rather than the syntax. Q-Code adds the parts that decide whether the result is usable: a live preview, a real domain, an audit, and ownership of everything it produces.

How is Q-Code different from Lovable?

Mostly in where the result lives. Q-Code builds onto infrastructure held in your name, meaning your Cloudflare account, your repository, your domain and your database, and bills you directly for it. There are also no message limits, and a shared library of modules that have already been built and hardened on other projects.

Do I need to be able to code?

No. Every build narrates what it is doing in plain English, and the things you change most often, such as copy, photographs, prices, opening hours and testimonials, are rows you edit in a panel without a build at all.

What can I build with it?

Marketing sites, catalogues, booking systems, member areas, internal tools and small apps. There are 20 installable modules across five groups, so most projects are assembled from things that already work rather than written from nothing.

Is the site any good technically?

Every page is static HTML on a global edge network, ships no JavaScript unless a feature needs it, and is checked on every build for one h1, heading order, alt text, meta description, valid structured data and anything that would overflow a phone.

Is a Q-Code site secure by default?

Yes, and nothing is asked of you to make it so. Every site ships with HTTPS and HSTS, secure response headers, an enforced content-security-policy and row-level security on the data. A managed firewall sits in front of the endpoints that take public input, and dependencies and code are scanned for known vulnerabilities and leaked secrets on every change.

Can I move a project over from Lovable?

Yes, through a guided import wizard that runs in five steps: source, pre-flight, import, gates and result. Three verification gates have to clear before your domain moves: a real member signs in on the imported site, a real payment event arrives from the provider, and the secrets are rotated.

Can I see what a build costs?

Yes. Spend is shown per build and per month, with a budget warning before a budget is crossed, so cost is a number in front of you rather than a surprise at the end of the month. A build about to spend past a ceiling stops and asks you first.

What happens if I stop paying?

You keep the site. The hosting, domain, repository and database are on accounts in your name, so what stops is the building, not the running.

Start with a sentence.

Describe the thing you want to exist. The first preview is usually up before you have finished explaining it.