Managed maintenance
The part nobody quotes for
From $250/mo, nine things every month: hosting, monitoring, spec-revision migrations, upstream-drift fixes, auth upkeep, CVE patching, up to two tool changes, a usage report, and a named escalation path. Everything not included is published beside it. This is where 94% of the value lives, because the 2026-07-28 revision proved that a server nobody maintains breaks silently.
Included, and excluded
| Included every month | Not included |
|---|---|
| Hosting with TLS, monitoring, alerting | A brand-new system |
| Spec-revision migrations | Penetration testing |
| Upstream-API-drift fixes | A full compliance audit |
| Auth and token-rotation upkeep | Writing your upstream API |
| CVE patching | Feature work beyond two changes |
| Up to two tool changes, a monthly report | 24/7 pager cover |
What actually breaks
- Spec revisions. Loud, dated, and the reason this business exists.
- Upstream API drift. A field renames and a tool starts returning nulls.
- Auth and token expiry. Silent until a customer cannot connect.
- Dependency CVEs. A patch you did not know you needed.
Pricing by tier
Maintenance scales with what it is keeping alive. An internal server is $250 per month, a product server is $700, and a multi-system or compliance build starts at $1,000. The pricing page carries the full context and the adders.
Cancellation
Thirty days notice, no lock-in, your code and data are yours.
Maintenance questions
- What exactly is included each month?
- Nine things: hosting with TLS, uptime monitoring and alerting, spec-revision migrations, upstream-API-drift fixes, auth and token-rotation upkeep, dependency CVE patching, up to two tool additions or changes, a monthly usage report, and a named escalation path. The excluded column is published next to it, because a definition of "managed" that hides its edges is not a definition.
- Why does a running server need maintaining at all?
- Because it breaks in ways you do not see. The 2026-07-28 revision is the loud example, but the quiet ones are worse: an upstream API changes a field, a token expires, a dependency ships a CVE. Three of the four common failure classes are silent, which is exactly why a server nobody maintains is worse than no server.
- What are the response-time commitments?
- We work 09:00 to 20:00 IST (UTC+5:30), with a stated overlap for US Eastern and UK mornings. Acknowledgement of a production issue is within that window, and the monthly report tells you what happened and what we changed. We publish the commitment we can actually keep rather than a number we cannot.
- Can we cancel?
- Yes, on 30 days notice, with no lock-in. Your code and your data are yours, and we hand over the repository and the deployment on the way out. A retainer that traps you is a retainer you should not sign.
- Do you maintain servers you did not build?
- Yes, after an audit. We need to see what we are taking on before we commit to keeping it alive, so a takeover starts with the fixed-fee audit against the 2026-07-28 revision, then moves onto the retainer if you want it.
- What is not included?
- A brand-new system, penetration testing, a full compliance audit, and writing or fixing your own upstream API. Those are real pieces of work with their own prices, and folding them silently into a $250 retainer would mean either doing them badly or raising everyone else's price to cover them.
