Support
Application Maintenance and Support Services
- Sev-1 response target
- 30 minSev-1 response target
- Coverage available
- 24/7Coverage available
About Application Maintenance & Support
Software does not stay still when you stop touching it. Dependencies accumulate vulnerabilities, certificates expire, cloud providers deprecate services, browsers change behaviour, data volumes grow past the point the original queries were designed for, and the one person who understood the deployment process leaves. An application that received no attention for two years is not in the same condition it was in — it is measurably worse, and the cost of catching up grows non-linearly.
Our maintenance engagements cover four things that are genuinely different from each other. Corrective: incident response and defect resolution under agreed severity levels and response times. Preventive: dependency and framework upgrades, security patching, certificate rotation, backup restore verification, and capacity headroom review before it becomes an incident. Adaptive: keeping pace with browser, OS, cloud provider and third-party API changes that arrive whether you planned for them or not. And perfective: a proportion of hours reserved each month for improvement — performance work, technical debt reduction, or small enhancements the business asks for.
That last category is what separates maintenance from life support. Contracts that only cover break-fix produce software that degrades slowly and predictably; we deliberately allocate capacity to improvement so the application is in better condition after a year of support than it was at the start. What that capacity is spent on is your decision, reviewed monthly.
We support applications we built and applications we inherited. For inherited systems we start with a transition period — knowledge capture, documentation of what is missing, environment access verification, monitoring installation and a risk register — before any SLA commences, because committing to response times on a system nobody has mapped is not a commitment worth having.
Why it matters
What you get
Response times you can hold us to
Severity-based SLA with defined response and resolution targets, 24/7 coverage available, and monthly reporting against actual performance.
Preventive work, not just break-fix
Dependency upgrades, security patching, certificate rotation, restore verification and capacity review before any of them become incidents.
Improvement capacity every month
A reserved share of hours for performance, technical debt and small enhancements — so the application improves rather than merely survives.
Inherited systems taken on properly
A structured transition covering knowledge capture, documentation, monitoring and a risk register before the SLA starts.
Transparent monthly reporting
Availability, incident volume and causes, hours by category, security posture and the improvement backlog — reviewed with you.
How we deliver
Our process for this work
Adapted to this service specifically — not a generic five-box diagram.
- 01
Transition & assessment
2–4 weeksKnowledge transfer, architecture and dependency documentation, access verification, monitoring installation, and a documented risk register.
- 02
Stabilisation
4–8 weeksCritical vulnerabilities patched, monitoring and alerting tuned, backups verified by restore, and runbooks written for the known failure modes.
- 03
Steady-state support
OngoingIncident response to SLA, scheduled preventive maintenance, and the monthly improvement allocation spent against your priorities.
- 04
Monthly review
MonthlyAvailability against target, incident causes and follow-up actions, hours by category, security posture and the next improvement priorities.
- 05
Quarterly roadmap
QuarterlyTechnical health assessment, upgrade and modernisation planning, and capacity forecasting against expected business growth.
Answers
Application Maintenance & Support — common questions
Related
Services that usually go with this
Infrastructure as Code & Managed Cloud
Reproducible environments and a cloud estate someone actually runs.
Learn moreSite Reliability Engineering (SRE)
SLOs, observability and incident practice that make uptime predictable.
Learn moreThinking about application maintenance & support?
Tell us the problem rather than the solution. A 30-minute call is usually enough for both of us to know whether this is the right service and whether we are the right team.