E-commerce
A broken checkout on a Saturday, discovered on Monday, with two days of orders lost.
Synthetic checkout monitoring every few minutes and an alert before customers notice.
Software does not sit still. Dependencies get security advisories, browsers change, payment gateways deprecate endpoints, and certificates expire on a Sunday. A site nobody maintains is not stable — it is slowly becoming someone else's problem.
Maintenance covers security patching, dependency upgrades, uptime and error monitoring, tested backups, content and small feature changes, and a defined response time for incidents. Retainers are priced on what the system does and the response time you need, both written into the contract.
Business-hours response for a site-down or checkout-broken incident on our standard retainer.
Uptime, errors, backups restored, dependencies, certificates, performance, forms, tracking and more — run as a checklist, not from memory.
An actual restore from backup. A backup nobody has restored is an assumption.
Every project we ship comes with a month of support before any retainer conversation happens.
Access inventory and risk register
A stable baseline
Alerting in place
Monthly maintenance report
A site that improves quietly
Nothing changed, and yet the contact form stopped emailing four months ago, the SSL certificate is due next week, six dependencies have security advisories, and the last backup that anyone can find is from a hosting panel nobody has the login for.
The risk of neglect is different depending on what the system does. So is the appropriate response time.
A broken checkout on a Saturday, discovered on Monday, with two days of orders lost.
Synthetic checkout monitoring every few minutes and an alert before customers notice.
A form that silently stops posting, costing weeks of enquiries that nobody knows are missing.
Automated form submission tests and an alert on unusual silence in lead volume.
Unpatched vulnerabilities and no audit trail, discovered during an assessment.
Scheduled patching, access reviews and a documented change log.
Publishing blocked because the only person who could deploy has left.
A CMS your team runs plus a retainer for anything structural.
Nobody knows how it was built, so nobody dares change anything.
A documentation and access audit first, then incremental modernisation under retainer.
An OS update breaks the app and the store rating collapses before anyone notices.
OS beta testing, crash alerting and a scheduled compatibility release each cycle.
Emergency work is the most expensive way to buy engineering: no context, no preparation, and it always coincides with something else important.
A dependency upgrade taken monthly is routine. The same upgrade deferred for two years is a project, because six other things now depend on the old version.
Someone who works on your system monthly fixes an incident in an hour. Someone meeting it for the first time spends that hour reading. You pay for the reading either way.
The difference between 'the site was down for six hours on Sunday' and 'the site was down for eleven minutes' is entirely whether something was watching.
A retainer makes minor improvements possible continuously, which is how a site stays current instead of needing a redesign every three years.
Access, hosting, domains, certificates, backups, dependencies and documentation — and a list of what is missing, which on inherited systems is usually a lot.
Uptime, error rate, form submission, checkout and certificate expiry, with alerts routed to a channel someone reads.
Security patches applied promptly, dependency upgrades on a monthly cadence, tested in staging before production.
Automated, off-site, with a restore actually performed each quarter and the result recorded.
An agreed monthly allowance of hours for copy, page and minor feature changes.
Fixed within the agreed response time, with a note on what caused it, not just what changed.
Core Web Vitals reviewed monthly, because sites get slower quietly rather than suddenly.
Uptime, incidents, changes made, upgrades applied and what we recommend next — in plain language.
Software does not sit still. Dependencies get security advisories, browsers change, payment gateways deprecate endpoints, and certificates expire on a Sunday. A site nobody maintains is not stable — it is slowly becoming somebody's emergency.
Security patching, dependency upgrades, uptime and error monitoring, tested backups, content and small feature changes, and a response time written into the contract rather than described as responsiveness.
Emergency work is the most expensive way to buy engineering: no context, no preparation, and it always coincides with something else important. Someone who works on your system monthly fixes an incident in an hour; someone meeting it for the first time spends that hour reading. You pay for the reading either way.
There is a compounding version of the same point. A dependency upgrade taken monthly is routine. Deferred for two years it becomes a project, because six other things now depend on the old version.
Uptime, error logs, form and checkout submission, backups, dependency and security updates, certificate expiry, Core Web Vitals, Search Console coverage, analytics integrity, broken links and an access review. Several you can do yourself this afternoon — the full list with what each one catches is in the website maintenance checklist.
A large share of what we maintain, we did not build. The engagement starts with an access and risk audit, then stabilising the urgent items — backups, certificates, critical vulnerabilities, broken forms — before any routine begins. Occasionally that audit concludes the honest recommendation is a rebuild, and we will say so with reasons rather than billing indefinitely against a ceiling.
A number, not an adjective. Which issues count as critical, how quickly someone responds, who escalates to whom, and what happens outside business hours. If a supplier will not put those in writing, the practical answer to how fast they respond is: unknown.
Every stage ends in something you can hold — a document, a build, a live account. If a stage cannot name its output, it is a meeting, not a stage.
Get access to everything, document it, and produce a risk list.
Fix the urgent items — backups, certificates, critical vulnerabilities, broken forms.
Monitoring and alerting on the things that cost money when they break.
Monthly patching, upgrades, performance checks and the agreed change allowance.
Use the remaining allowance on the highest-value small improvements rather than letting it lapse.
Everything here is part of the engagement at no extra cost. We do not itemise them on an invoice and we do not withhold them if you leave.
Access, hosting, domains, certificates, backups, dependencies and documentation, with a written risk list. Even for sites we did not build.
And complete a test purchase if you sell online. Silent form failures are among the most expensive faults on a business site and almost nobody checks.
Performed, not assumed. A backup nobody has restored is not a backup.
Unused change allowance goes on the highest-value small improvements rather than lapsing quietly.
What changed and when, so the first question in any incident — what happened before this broke — has an answer.
Longer answers to the questions people ask before they hire anyone for maintenance & support.
Built by us, free, no signup, nothing uploaded to a server. Take them whether or not you ever become a client.
It is set by the response time you need and how much the system does. A brochure site that needs to stay secure and online is a different commitment from a store where an hour of downtime costs money, which is different again from a system needing on-call cover and a contractual SLA. Per-incident work without a retainer costs more per hour and takes longer.
Tell us what you have now and what you are trying to reach. We will audit it and tell you what we would do, what it would cost and whether you need us at all. The audit is free and yours to keep.