The part that decides whether the investment holds its value
Software does not stay working by itself. Dependencies age, certificates expire, traffic patterns change, and one unpatched component eventually becomes somebody's way in.
Most organisations treat maintenance as an optional extra and discover its value at the worst possible moment. The pattern is familiar: a site or system is built well, runs happily for a year, and then decays. A plugin update is skipped because nobody is sure it is safe. A certificate lapses on a holiday. A dependency with a published vulnerability sits in production for eight months. A backup exists but has never been restored, and when it is finally needed it turns out to be incomplete.
None of these are dramatic in isolation and together they represent the single largest source of avoidable business disruption we see. The cost of prevention is a fraction of the cost of the incident, and unlike most insurance, maintenance also actively improves things — sites get faster, dependencies get cleaner, and small annoyances get fixed rather than accumulating.
We provide maintenance across everything we build and, frequently, across systems built by others. Taking over somebody else's work is normal for us; we start with an assessment so both sides know what is being inherited, then stabilise and improve from there.
What distinguishes our plans is that the commitments are specific and measurable. Response times are defined and reported against. Backups are restored quarterly and the result recorded. The monthly report contains actual numbers rather than a summary of activity.
What a maintenance plan actually covers
Security patching is the core. Framework, library, plugin and operating system updates applied on a defined cadence — security patches promptly, feature updates tested on staging first. We track your dependency tree against published vulnerability databases so a newly disclosed issue in something you use surfaces the same day.
Backups with verification. Automated daily off-site backups of database and files, retained to an agreed schedule, and — the part that distinguishes a real plan from a checkbox — a restore performed to a scratch environment every quarter with the result and duration recorded. About one in six estates we take over has a backup that does not restore correctly, and the owners had no idea.
Monitoring and response. Uptime checks on critical journeys from multiple locations, performance monitoring with alerts on degradation, error tracking, and certificate and domain expiry monitoring. When something breaks we usually know before you do, which changes the conversation from a complaint to a notification.
Small changes. Every plan includes a monthly allowance of development time for content updates, small design changes, new pages, form adjustments and minor features. This is the part clients use most, and it removes the friction that otherwise causes sites to go stale.
Service levels, defined properly
A support commitment that says "we will respond promptly" is not a commitment. Ours are specific by severity and reported against every month.
A critical incident — site or system down, data at risk, payments failing — gets a fifteen-minute first response on 24×7 plans and one business hour on standard plans, with continuous work until resolution. High severity, meaning a significant function is broken but the system is usable, gets four business hours. Standard requests get one business day, and planned work is scheduled.
Importantly, response time is measured from alert rather than from your report, because our monitoring generally detects critical issues first. Our current median first response across all severities is eleven minutes.
| Severity | Definition | 24×7 plan | Business-hours plan |
|---|---|---|---|
| Critical | Down, data at risk, payments failing | 15 min response, continuous work | 1 business hour |
| High | Major function broken, system usable | 1 hour | 4 business hours |
| Medium | Minor function affected, workaround exists | 4 hours | 1 business day |
| Low | Cosmetic, content, enhancement | 1 business day | 2 business days |
| Planned | Scheduled changes and releases | Agreed window | Agreed window |
The monthly report
Every client receives a monthly report, and we write it to be read by a business owner rather than an engineer. It contains uptime with any incidents explained, performance trend with Core Web Vitals from real users, security actions taken including specific patches applied, backup and restore verification results, tickets raised and resolved with response times measured against the SLA, and the work done from the monthly change allowance.
It also contains a recommendation section — what we think should be addressed next, with an honest indication of urgency. Some months that section says nothing needs attention, which is a legitimate finding rather than a failure to sell something.
Quarterly we run a review call covering the trend rather than the month: where the system is heading, what will need investment in the next year, and whether the plan level is still right. We have recommended clients move to a smaller plan when their usage did not justify the one they were on.
What we do not do
We do not bill for time spent fixing bugs in work we built. We do not treat every request as a change order. And we do not hold your access hostage — you have full credentials to everything at all times, and leaving us requires no cooperation from us beyond a handover call.
Taking over somebody else's system
A large share of our maintenance clients arrive with a system built by an agency or developer who is no longer available. The system works, more or less, and nobody knows how.
We start with a takeover assessment: code review, dependency and vulnerability scan, infrastructure inventory, backup verification, security posture and performance profile. That produces a written report with a prioritised list of what needs attention, separated into "fix now", "fix within a quarter" and "acceptable as is". Clients frequently find this document valuable on its own.
Then we stabilise — usually a two to four week effort addressing the urgent items, establishing backups and monitoring, and getting the code into version control if it is not already. From there ongoing maintenance is straightforward. We have taken over systems in every state including a production application whose only copy of the source code was on a laptop.
In practice
Every engagement starts with a conversation, not a proposal template.
Thirty minutes with a senior engineer. You leave with an architecture sketch and an honest cost range, whether or not you hire us.
Beyond keeping the lights on
A maintenance relationship that only prevents decay is a missed opportunity. The teams who get the most value use their monthly allowance deliberately — a quarterly performance improvement, a new landing page for a campaign, an accessibility fix, a small automation.
We also proactively suggest improvements from what monitoring shows us. A page that is slower than the rest, a form with an abnormal abandonment rate, a search query users repeat that returns nothing, an error appearing a hundred times a day that nobody has reported. These come from data we are already collecting and they are frequently the highest-return work in a given month.
“Our previous arrangement was that we called when something broke and waited. Now we get a report every month, things get fixed before we notice, and the site is measurably faster than when it launched.”
Plans and what they suit
Our Essential plan suits marketing sites and small applications: monthly patching, daily backups with quarterly restore verification, uptime monitoring, business-hours support and two hours of changes a month.
Business adds performance monitoring with real-user data, weekly patch cadence, four-hour response on high severity, six hours of changes and a quarterly review call. This is where most of our clients sit.
Enterprise covers revenue-critical systems: 24×7 monitoring and response, fifteen-minute critical response, dedicated engineer familiarity, monthly restore drills, security scanning, twenty hours of changes and a named account contact.
All plans are month to month after an initial three-month term. We do not use long lock-ins, because a plan people cannot leave is a plan that does not have to stay good.
Every engagement starts with a conversation, not a proposal template.
Thirty minutes with a senior engineer. You leave with an architecture sketch and an honest cost range, whether or not you hire us.
What is actually included in maintenance & managed support
Each of these is something we have shipped and still support in production — not a list of things we could do if asked.
Security patching
Framework, library, plugin and OS updates tracked against vulnerability databases and applied on cadence.
Verified backups
Daily off-site backups with quarterly restore drills to a scratch environment and recorded results.
Uptime and journey monitoring
Critical user journeys checked from multiple locations, not just a homepage ping.
Performance monitoring
Real-user Core Web Vitals with alerting on regression and quarterly optimisation.
Incident response
Defined severity levels, measured response times and a written post-incident review.
Change allowance
Monthly development hours for content, design and small feature work.
Takeover assessment
Fixed-price evaluation of an inherited system with a prioritised remediation plan.
Reporting and review
Monthly report with real numbers and a quarterly strategic review call.
The stack we actually use for this
Chosen for what your team can maintain in three years, not for what looks impressive in a proposal.
Monitoring
- UptimeRobot
- Grafana
- Sentry
- Lighthouse CI
- CrUX data
Backup
- Automated snapshots
- Off-site object storage
- Restore verification harness
Security
- Dependabot
- Snyk
- Wordfence
- OWASP checks
- SSL monitoring
Support
- Ticketing with SLA tracking
- WhatsApp escalation
- Status page
From first conversation to something in production
Two-week slices, a demo you can share every alternate Friday, and no phase where you are waiting without seeing progress.
Onboarding audit
Full inventory of code, infrastructure, access, backups and current risk.
Stabilise
Urgent items addressed, monitoring and backups established, access secured.
Baseline
Performance, uptime and security posture recorded so improvement is measurable.
Operate
Patching cadence, monitoring, incident response and monthly change work.
Report
Monthly written report with numbers and honest recommendations.
Review
Quarterly call on trend, upcoming investment and whether the plan still fits.
Everything hands over. No lock-in, ever.
Source code in your Git organisation, infrastructure in your cloud account, domains in your name and documentation written for the next team rather than for us. If you part ways with us in year three, a competent engineer should be able to take over in a fortnight.
Deliverables checklist
- Onboarding audit report with prioritised risks
- Monitoring dashboards and alert configuration
- Verified backup schedule with restore evidence
- Access and credential register
- Monthly report with uptime, performance, security and ticket metrics
- Post-incident reviews for any critical event
- Quarterly review with roadmap recommendations
What this typically costs
Real ranges from real projects. The variable is almost always scope and integration count — the calculator will get you closer in two minutes.
Essential
₹9,500 / month
Marketing sites and small applications.
- Monthly patching
- Daily backups + quarterly restore
- Uptime monitoring
- Business-hours support
- 2 hours changes
Business
₹24,000 / month
Business-critical sites and applications.
- Everything in Essential
- Weekly patching
- Real-user performance monitoring
- 4-hour high-severity response
- 6 hours changes
- Quarterly review
Enterprise
₹65,000 / month upwards
Revenue-critical platforms and plant systems.
- 24×7 monitoring and response
- 15-minute critical response
- Monthly restore drills
- Security scanning
- 20 hours changes
- Named account contact
All figures exclude GST. Fixed-price options available on defined scope. Build your own estimate →
The questions clients actually ask
Including the ones where the honest answer is that you may not need us. If your question is not here, call +91 70033 91355 — you will speak to an engineer, not a call handler.
That is a legitimate model and some clients use it — we charge hourly with best-effort response and no SLA. What you give up is prevention: no patching, no monitoring, no verified backups, and no priority when something does break. In our experience break-fix costs more over two years than a maintenance plan, because problems compound and because emergency work is always more expensive than scheduled work. We will quote both honestly.
Yes, and it is a large part of our work. We start with a fixed-price takeover assessment covering code quality, security, dependencies, infrastructure and backups, and give you a prioritised report. If the system is in reasonable shape we take it on directly; if it needs stabilisation we quote that separately. We have declined to maintain systems that were genuinely beyond safe repair and recommended rebuilds instead, which is a better outcome than pretending.
Content updates, small design changes, new pages built from existing components, form and configuration changes, minor features and performance work. What does not count is bug fixing in anything we built — that is our responsibility regardless of hours — or incident response. Unused hours roll over for one month. Larger pieces of work are quoted separately, and we will always tell you before something exceeds the allowance rather than after.
Enterprise plans have a 24×7 escalation number with fifteen-minute response. Business and Essential plans have business-hours response, but our monitoring runs continuously regardless of plan — if your site goes down at 2 AM we will typically know, and for genuine outages we respond rather than waiting for the clock. The SLA defines what we commit to, not the limit of what we do.
You give a month's notice and we hand over. You already hold all credentials and own all code and infrastructure, so there is nothing for us to release. We do a handover call with whoever takes over, provide current documentation, and answer questions for a reasonable period afterwards. We have never made an exit difficult and we would rather be chosen than retained by friction.
Yes, where they are cloud or virtual infrastructure we can access. That includes operating system patching, resource monitoring, capacity planning, certificate management and cost review. For physical on-premise servers we cover the software layer and coordinate with your local IT for hardware, which is usually the sensible division.
Why being local to you matters here
A recurring situation in Kolkata: a business had a site or system built by a freelancer who has since moved to a full-time role and answers messages sporadically. The system works until it does not, and then there is nobody. A maintenance relationship with a firm rather than an individual removes that single point of failure, and being local means we can be in your office the same day when it genuinely matters.
For website and software maintenance in Kolkata, call +91 70033 91355 or WhatsApp us. The takeover assessment is fixed price and gives you a useful document regardless of what you decide.
Services that pair with this
View everythingTell us what is slowing your business down.
A 30-minute call with a senior engineer — not a salesperson. You leave with an architecture sketch and an honest cost range, whether or not you hire us.
Direct line
+91 70033 91355Mon–Sat · 9:30 AM – 7:30 PM IST · Sealdah, Kolkata