Security & Patch Management
CVE patching, dependency updates and a monthly security review.
Digital Experience
Website maintenance that goes beyond uptime monitoring — security patches, dependency updates, content edits, performance reviews and a small backlog of improvements shipped every month, with a named engineer on call.
Security & Patch Management
Uptime & Performance
Content & Copy Edits
Backup & Disaster Recovery
Accessibility Audits
Monthly Improvement Backlog
Overview
Most websites fail slowly. A plugin stops getting updated, a Node version goes out of support, a content edit takes a week to ship because the only person who knows the admin left. By the time the site is visibly broken, the cost of recovery is several times the cost of maintenance.
We run website maintenance as a monthly retainer with a named engineer, a written scope and a small backlog of improvements shipped every month. The work is the unsexy part of running software: dependency updates, security patches, performance reviews, content edits, accessibility audits and the small changes that keep the site earning its traffic.
This is the wrong engagement if you only have one site and the team that built it is still on retainer. We are happy to take over, but the conversation to have first is what the maintenance really costs when nobody is on it.
What we deliver
CVE patching, dependency updates and a monthly security review.
Uptime monitoring, Core Web Vitals review and the fixes that follow.
Small content and copy changes shipped on a weekly turnaround.
Daily backups with a tested restore path, not just a folder of files.
Quarterly WCAG checks and the fixes that follow from them.
A small set of UX, performance or SEO improvements shipped each month.
Our process
01
Discover
We audit the site, the stack and the current maintenance posture.
02
Plan & Design
We write the monthly scope, the SLAs and the improvement backlog.
03
Develop
We harden the stack, set up monitoring and close the critical gaps.
04
Deploy
We hand over the runbook, the contacts and the dashboards.
05
Optimize & Grow
We ship the monthly backlog and report on what changed.
Technology
What you can expect
Industries we serve
A written scope agreed during onboarding — usually a fixed number of hours for content edits, dependency updates, security patches, performance reviews and the monthly improvement backlog. SLAs are explicit: critical security patches within 24 hours, content edits within 48 hours, performance fixes within the week. Anything outside the scope is quoted separately.
Yes, after a short audit. The audit takes a week and produces a written report of the current posture, the critical fixes and the monthly scope. Once that is agreed, the retainer starts. Sites with no source control, no documentation and a long history of changes take longer to bring under maintenance, and we will say so before quoting.
The retainer includes uptime monitoring, a named on-call rotation and a 24-hour response SLA on critical incidents. The runbook we hand over lists the recovery steps and the contacts, so the on-call engineer is not the only person who knows how to restore the site. Backups are daily and tested monthly.
Yes, with 30 days notice. The handover at the end of the engagement is complete: repositories, cloud accounts, runbook, contacts and the post-mortem history. We are happy to keep going as long as the work is useful, and equally happy to hand back when the in-house team is ready to take over.
Related services
Business software
Tell us the outcome you need. We’ll come back with an approach, a timeline and a written estimate.