Managed maintenance

The part nobody quotes for

From $250/mo, nine things every month: hosting, monitoring, spec-revision migrations, upstream-drift fixes, auth upkeep, CVE patching, up to two tool changes, a usage report, and a named escalation path. Everything not included is published beside it. This is where 94% of the value lives, because the 2026-07-28 revision proved that a server nobody maintains breaks silently.

Included, and excluded

Managed maintenance: what is included every month versus what is not
Included every monthNot included
Hosting with TLS, monitoring, alertingA brand-new system
Spec-revision migrationsPenetration testing
Upstream-API-drift fixesA full compliance audit
Auth and token-rotation upkeepWriting your upstream API
CVE patchingFeature work beyond two changes
Up to two tool changes, a monthly report24/7 pager cover

What actually breaks

  • Spec revisions. Loud, dated, and the reason this business exists.
  • Upstream API drift. A field renames and a tool starts returning nulls.
  • Auth and token expiry. Silent until a customer cannot connect.
  • Dependency CVEs. A patch you did not know you needed.

Pricing by tier

Maintenance scales with what it is keeping alive. An internal server is $250 per month, a product server is $700, and a multi-system or compliance build starts at $1,000. The pricing page carries the full context and the adders.

Cancellation

Thirty days notice, no lock-in, your code and data are yours.

Maintenance questions

What exactly is included each month?
Nine things: hosting with TLS, uptime monitoring and alerting, spec-revision migrations, upstream-API-drift fixes, auth and token-rotation upkeep, dependency CVE patching, up to two tool additions or changes, a monthly usage report, and a named escalation path. The excluded column is published next to it, because a definition of "managed" that hides its edges is not a definition.
Why does a running server need maintaining at all?
Because it breaks in ways you do not see. The 2026-07-28 revision is the loud example, but the quiet ones are worse: an upstream API changes a field, a token expires, a dependency ships a CVE. Three of the four common failure classes are silent, which is exactly why a server nobody maintains is worse than no server.
What are the response-time commitments?
We work 09:00 to 20:00 IST (UTC+5:30), with a stated overlap for US Eastern and UK mornings. Acknowledgement of a production issue is within that window, and the monthly report tells you what happened and what we changed. We publish the commitment we can actually keep rather than a number we cannot.
Can we cancel?
Yes, on 30 days notice, with no lock-in. Your code and your data are yours, and we hand over the repository and the deployment on the way out. A retainer that traps you is a retainer you should not sign.
Do you maintain servers you did not build?
Yes, after an audit. We need to see what we are taking on before we commit to keeping it alive, so a takeover starts with the fixed-fee audit against the 2026-07-28 revision, then moves onto the retainer if you want it.
What is not included?
A brand-new system, penetration testing, a full compliance audit, and writing or fixing your own upstream API. Those are real pieces of work with their own prices, and folding them silently into a $250 retainer would mean either doing them badly or raising everyone else's price to cover them.
See what this costs