Maintenance and support retainer

Your application kept patched, current and watched, by a named engineer who knows the code.

Price
Monthly fee, set after the onboarding review
Timeline
Monthly, after a one-off onboarding review
Engagement
retainer

A monthly retainer for web applications in production: security patches, dependency and framework upgrades, uptime and error monitoring, backups that are tested, and hours for fixes and small features. It suits Laravel, Node.js, Python and Next.js applications, including ones I didn't build: those start with a short onboarding review.

  1. 01

    Security and dependency updates, deployed and verified

  2. 02

    Uptime, error and performance monitoring with alerts

  3. 03

    A tested backup restore every quarter

  4. 04

    A monthly report: what changed, what to watch and what's next

  5. 05

    Hours for fixes and small features, tracked in the same report

Who this is for

  • Products whose original developer or agency has moved on
  • Teams without an engineer for upgrades and incidents
  • Owners who want proof the backups work before they need them

Who this is not for

  • Round-the-clock on-call with a contractual response time in minutes
  • Hosting plans with no access to the server or the code

What this service is

The maintenance and support retainer keeps a web application in production patched, current and watched, by a named engineer who knows the code. Each month covers security patches, dependency and framework upgrades, uptime and error monitoring, a backup restore that proves the backups work, and hours for fixes and small features. It suits Laravel, Node.js, Python and Next.js applications, including ones I didn't build, and it is for products whose original developer or agency has moved on, or teams without an engineer for upgrades and incidents.

Scope

A retainer starts with a one-off onboarding review: access, a read of the code, the servers, the backups and the dependencies, and a written list of risks. Nothing is my responsibility until that review is done and we've agreed the list. Then the urgent items come first, patches, working backups and monitoring, before the monthly rhythm begins.

What is maintained and reported

Every month: security and dependency updates, deployed and verified; monitoring and alerts for uptime, errors and performance; fixes and small features from an agreed list; and a short report of what changed, what to watch and what's next, with hours tracked in the same report.

Upgrades are planned ahead of each version's end of support rather than after it. The projects publish their windows: Laravel gives each major release bug fixes for 18 months and security fixes for two years, each PHP branch is fully supported for two years before a security-only period, and Node.js versions move from Current to long-term support to end of life on a published schedule. The report shows where your app sits on each.

Each quarter, a backup is restored into a separate environment and checked, because a backup nobody has restored is a hope, not a plan.

What it is not

It is not round-the-clock on-call with a contractual response time in minutes; if you need that, I'll say so plainly and help you arrange it. It is not a hosting plan either: I need access to the server and the code, and I work in your accounts.

How the engagement runs

  1. Onboarding review

    Access, a read of the code, servers, backups and dependencies, and a written list of risks.

  2. Stabilize

    The urgent items first: patches, working backups and monitoring.

  3. Monthly rhythm

    Updates, fixes and small features, with a short report each month.

  4. Plan ahead

    Framework and runtime upgrades scheduled before their end of support.

Technologies I use for this

  • Laravel
  • Node.js
  • Python
  • Next.js
  • MySQL
  • PostgreSQL
  • Redis
  • Sentry
  • GitHub Actions

How this works in your market

How this works in the United States

For US teams, monitoring alerts reach me whenever they fire, and urgent issues come first in my working day, which overlaps the East Coast morning. Planned updates are deployed in a window we agree, and the monthly report lands at the start of your month.

How this works in the United Kingdom

For UK teams, your morning falls in my afternoon, so most issues raised in your working day are handled the same day. Where maintenance gives me access to personal data, the retainer includes a data processing agreement under UK GDPR, and access is limited to what the work needs.

Questions about Maintenance and support retainer

Can you maintain an app you didn't build?

Yes. It starts with an onboarding review: I read the code, check the servers, backups and dependencies, and write down the risks before taking responsibility for anything.

What if something breaks outside my hours?

Monitoring alerts me, and urgent issues come first in my working day, which overlaps with US, European and Gulf business hours. If you need round-the-clock cover, I'll say so plainly and help you arrange it.

Do you handle framework upgrades?

Yes, planned ahead of each version's end of support, one major version at a time, with tests.

What happens to unused hours?

The monthly report shows them. How they're handled, carried over or not, is agreed when the retainer starts, so there's no ambiguity later.

Do you need production access?

Enough to deploy, monitor and restore: usually access to the repository, the CI/CD system, the cloud account and the monitoring tools, with credentials scoped to the job and revoked when the retainer ends.

Can we end the retainer?

Yes. On exit you get the runbook, the risk list and a handover session, so whoever comes next starts with everything I know.

Related writing

Where this work happens