← Jobb

Senior Node.js / DevOps Contractor — Replit Production Migration for Health SaaS

Budget: $4000.0 FIXED / ⭐ 0.00 (0) United States

node.js, postgresql, devops, git, cicd, amazon-web-services

HealthStory is an early-stage women's health SaaS platform. It is currently developed and hosted in Replit. I need an experienced individual contractor to move the existing production infrastructure off Replit into HealthStory-owned accounts and a production environment appropriate for handling protected health information. This is an infrastructure migration only. It is not a feature-development project, UI redesign, app rewrite, or full HIPAA compliance audit. CURRENT STACK -- Node.js / Express backend -- React frontend -- Drizzle ORM -- PostgreSQL currently on Replit-managed Neon infrastructure -- OpenAI API currently routed through a Replit-managed proxy -- Sentry error monitoring -- Existing in-memory lab PDF upload/parsing code using pdf-parse and tesseract.js -- Replit will remain the development environment for synthetic or de-identified test data only There are no active customer-account migration concerns. PRODUCTION ARCHITECTURE Preferred baseline: -- Fly.io for production hosting -- HealthStory-owned Neon account for PostgreSQL -- HealthStory-owned Git repository and repeatable Git-based deployment process -- Direct OpenAI API routing from production -- Replit removed from production hosting, database access, AI routing, and production secrets AWS may be recommended if it offers a clear cost, operational, or future document-storage advantage. HealthStory has an existing signed AWS BAA, so contractors may propose an AWS-based alternative with a clear explanation and first-year cost estimate. SCOPE The selected contractor will: -- Review the codebase, Replit dependencies, database access, environment variables, and production data paths. -- Set up client-owned production accounts, production secrets, access controls, and deployment workflow. -- Establish a Git-based release process so HealthStory can continue developing in Replit and deploy approved code outside Replit. -- Migrate the existing app and PostgreSQL database from Replit-managed infrastructure. -- Configure HTTPS, domain routing, health checks, backups, and complete a restore test. -- Remove the Replit-managed OpenAI proxy and configure direct OpenAI API routing. -- Audit Sentry and other connected services so PHI, AI prompts/outputs, request bodies, and secrets are not unintentionally captured. -- Test existing core workflows before cutover. -- Regression-test the existing lab PDF upload/parsing functionality using synthetic test PDFs only. -- Provide a rollback plan, production cutover, documentation, and a recorded handoff. -- Provide 14 calendar days of post-cutover support for migration-caused issues. NOT INCLUDED -- New product features -- New lab-upload, document-storage, OCR, or AI-extraction functionality -- UI/UX redesign -- Major refactoring unrelated to migration -- Formal HIPAA certification, legal advice, or penetration testing -- Ongoing support after the included 14-day stabilization period -- Vendor subscription and usage costs TIMELINE -- Technical review and migration plan: within 3 business days -- Working synthetic-data deployment: target by Day 7 -- Production cutover: target within 10-15 business days -- Final stabilization and handoff: 14 days after cutover Total engagement may span up to approximately four calendar weeks. BUDGET Fixed-price proposals up to $4,000. Milestone payments will be based on accepted deliverables: -- 25% - verified production foundation and working synthetic-data deployment -- 45% - completed migration and production cutover -- 30% - completed 14-day stabilization period, documentation, and handoff No hourly overages or change orders without written approval. REQUIRED EXPERIENCE Please apply only if you have direct, hands-on experience with production infrastructure for healthcare, PHI/ePHI, BAA-backed vendors, or similarly sensitive regulated data. General website deployment experience or "healthcare-adjacent" work alone is not sufficient. You should be able to demonstrate experience with: -- Mapping where ePHI may be created, received, stored, transmitted, backed up, or logged across an application and its vendors. -- Working with BAA-backed vendors and identifying when hosting, database, logging, email, AI, storage, or authentication providers may be part of the ePHI data path. -- Configuring production safeguards such as secrets management, encryption in transit and at rest, MFA, least-privilege access, backups, restore testing, and rollback procedures. -- Preventing PHI exposure through logs, Sentry/error monitoring, request bodies, query strings, analytics, email notifications, and AI requests. -- Production Node.js / Express deployments. -- PostgreSQL migrations, backup configuration, and restore testing. -- Git-based deployment workflows / CI/CD. -- Fly.io and Neon, or AWS ECS/EC2 and RDS. This is not a request for legal advice, HIPAA certification, or a formal compliance audit. However, the selected contractor must be able to identify where PHI/ePHI can be created, received, stored, transmitted, logged, backed up, or exposed across the application and its vendors. PLEASE INCLUDE IN YOUR PROPOSAL -- Your fixed price and estimated hours. -- Relevant Node/Postgres production migration experience. -- Experience with Fly.io + Neon and/or AWS. -- Your recommended architecture and why. -- A brief explanation of how you would move production away from Replit while allowing continued development in Replit. -- Your approach to backups, restore testing, cutover, and rollback. -- Assumptions, exclusions, and likely blockers. -- Whether you use subcontractors or perform work outside the United States. -- Describe one production system you personally deployed or maintained that handled PHI/ePHI or operated in a BAA-backed healthcare-data environment. Briefly explain the cloud stack, how you handled backups and access controls, and how you prevented sensitive data from entering logs or error-monitoring tools. Detailed scope, milestones, acceptance criteria, and HIPAA-aligned technical requirements will be shared with shortlisted candidates.
Öppna på Upwork