Skip to content
Netronsoft
Services

Maintenance & Support

If the developer who built your system has stopped replying and nobody on your side knows what happens when it breaks, that risk is already on your books.

The person who built it has moved on — a new job, another country, or simply stopped answering messages. The last update was a long time ago. Nobody on your side is quite certain where the code lives, who pays for the hosting, or which mailbox the domain renewal notice arrives in.

Then something small happens on a Friday. A certificate expires and every browser starts warning your customers away. A disk fills up. A payment integration stops because the provider retired an old version months ago and the notice went to an address nobody reads. None of it is beyond repair. Nobody has simply been looking after it.

Software does not stand still. Dependencies age, providers change their rules, and security problems turn up in libraries you never chose directly. Maintenance is not an upsell bolted onto a finished project — it is the difference between a system that lasts and one that quietly becomes a liability.

What we actually do

Taking over a system somebody else wrote

We start with an audit: what it is built on, which versions are past support, where code, data, domains and hosting live, who holds access, and whether backups exist and have ever been restored. Most takeovers begin as an access inventory, because the commonest finding is that nobody is sure who holds the keys. If the audit shows the system is beyond sensible repair, we say so rather than bill you monthly to keep it upright.

Keeping it healthy

Then routine care: security patches and dependency updates applied on a schedule, tested in staging with a way back rather than pushed straight to production on a hopeful afternoon. Backups automated and — the part usually skipped — actually restored as a test, so you know the recovery time before you need it. Monitoring for what takes a system down quietly: certificate expiry, disk space, failed background jobs, rising error rates.

Small changes without drama

Most requests are not incidents. A new report, an updated tax rate, an extra field, a wording fix before a campaign. Those go into a short queue handled by a named engineer who knows your system, so they take days rather than waiting for the next project.

What you get

  • A written takeover audit with prioritised findings, including anything not worth keeping
  • An access and credentials inventory, held in accounts under your name
  • Scheduled updates and security patching, tested in staging before production
  • Automated backups plus a restore procedure documented and tested
  • Monitoring and alerting for expiry, capacity, errors and failed jobs
  • An agreed support channel and response-time tiers written into your contract
  • A short monthly note of what was done and what we recommend next
  • Documentation kept current, so another team could take over without a rescue

Why Netronsoft

We do not print a headline response time on a web page. The only number that means anything is the one written into your contract, and it should be set by what actually goes wrong when your system is down for an hour. Tell us that and we size the arrangement around it, including being clear about our working hours and what falls outside them.

We will tell you when you do not need a retainer. A small, stable system is often better served by an hourly arrangement with a documented escalation route than by a monthly invoice for watching something that rarely moves.

We keep documentation current on purpose, so you are never stuck with us for want of anyone else who could take over.

And we would rather keep a system healthy than be called in to rescue it.

Questions people ask before they call

What response time do you guarantee? Whatever is written into your contract. Tiers are agreed per client — critical outages, degraded service, routine requests — and priced against the cover you need. A number quoted before anyone has seen your system is marketing.

Can you support software you did not build? Usually yes, after an audit. If it is in a stack we support well we will say so, and if it is not we will tell you rather than learn on your budget.

We have lost access to everything. Can that be recovered? Often, through registrar, hosting and platform recovery processes, though it takes documents proving ownership. Some things genuinely cannot be, and we will tell you early which case you are in.

Do we need a monthly plan? Not always. If your system is small and rarely changes, an hourly arrangement with agreed escalation may cost far less. Retainers earn their keep when downtime is expensive or changes are frequent.

What counts as maintenance rather than a new project? Fixes, updates, security work and small changes are maintenance. A new module or significant feature is a project, quoted separately. We say which before doing the work, not after.

How do you handle security? Scheduled patching, dependencies watched for known vulnerabilities, least-privilege access and credentials in a secrets manager. A deep review or penetration test is separate specialist work.

Will you say if the system should be replaced? Yes. Sometimes keeping an old system alive costs more than replacing part of it, and saying so is worth more to us than a quiet retainer.

What happens if we stop? You keep everything: code, accounts, documentation, credentials. We hand over to whoever comes next and answer their questions.

Let's talk it through

Tell us what you are running, who built it, and what worries you most — the thing you would not want to happen on a Friday afternoon. We will tell you what we would check first, whether a takeover audit is the right starting point, and what level of cover actually fits.

Message us on WhatsApp, call +962 7 9087 9419, or email [email protected]. Knowing the platform it was built on and where it is hosted is enough for a concrete answer.

What's included

Benefits

Someone to call who answers

A named engineer who knows your system and an agreed channel, instead of hunting for a developer who stopped replying two years ago.

Problems caught before Friday

Monitoring for certificate expiry, capacity, failed jobs and error rates, so the quiet failures are found by a system rather than by a customer.

Backups that have been restored

Automated backups plus a restore we have actually performed and documented, so recovery time is a known figure rather than a hope.

Updates on a schedule, not after an incident

Security patches and dependency updates applied regularly and tested in staging, rather than left until something forces the issue.

Knowledge written down, not held by one person

Documentation and an access inventory kept current, so your system does not depend on one memory — ours included.

A cost you can plan around

An agreed monthly or hourly arrangement sized to what you actually run, so support stops being an unpredictable emergency expense.

Our process

How we work

1

Takeover audit

What the system is built on, which versions are out of support, where code and data live, and what would happen today if it failed — written down and ranked.

2

Access and credentials

An inventory of every account, domain, hosting and third-party service, consolidated into accounts under your name with credentials stored properly.

3

Stabilise

The urgent findings first — expired or expiring items, missing backups, unpatched components — tested in staging and applied with a way back.

4

Monitoring and backups

Alerting configured to reach a real person, backups automated, and a restore performed once as a test so the recovery time is a measured number.

5

Ongoing support

An agreed channel and response tiers, a named engineer for requests and small changes, and a short monthly note of what was done and what we advise next.

Frequently asked questions

Whatever we agree and write into your contract, which is the only number that means anything. Tiers are set per client — a critical outage, a degraded but working system, and routine requests are different situations with different response windows — and they are priced against the cover you actually need. We will be explicit about our working hours and what falls outside them rather than implying round-the-clock cover that your plan does not include. Treat a published guarantee with no reference to your system as marketing.

Usually, and it is a large part of what we do. It starts with a takeover audit so we know what we are agreeing to support rather than discovering it during an incident. If the system is built on a stack we support well, we will say so and quote. If it is in something we cannot maintain properly, we will tell you that instead of learning on your budget. And if the audit shows the system is genuinely past sensible repair, we would rather tell you than bill monthly to keep it standing.

Frequently yes, but it takes patience and paperwork. Domain registrars, hosting companies and platform providers all have recovery processes, and they generally require documents proving the organisation owns the asset — company registration, the original payment method, or an email domain that matches. Some things genuinely cannot be recovered, particularly where an account was registered personally by someone unreachable. We will tell you early which category you are in rather than billing hours against a dead end.

Not always, and we will say so. If your system is small, stable and rarely changes, an hourly arrangement with an agreed escalation route and monitoring in place can cost you considerably less than a monthly plan. Retainers earn their keep when downtime is expensive, when changes are frequent, or when you need a defined response window rather than joining a queue. We would rather set up the cheaper arrangement that fits than sell you cover you will not use.

Fixes, security patches, updates, monitoring and small changes are maintenance — a corrected tax rate, an extra column in a report, a new field on a form, a wording change. A new module, a redesigned workflow or an integration with another system is a project and gets quoted separately. Where a request sits near the line, we tell you which side it falls on and what it would cost before doing the work, not on the following invoice.

Security patches applied on a schedule, dependencies watched for known vulnerabilities, access kept to least privilege, credentials in a secrets manager, and backups verified so ransomware is a bad day rather than the end. That is routine hygiene and it prevents the majority of ordinary incidents. A deep security review or a penetration test is separate specialist work with its own scope, and we will tell you when your situation genuinely calls for one instead of implying that routine patching covers it.

Yes, and we would rather say it early. Sometimes an old system costs more to keep alive than to replace a part of it, particularly when it depends on a framework or runtime that no longer receives security updates. When that is the case we will show you the reasoning and the options, including phased replacement that keeps the parts still doing their job. A quiet monthly retainer propping up something unsustainable is worth less to us than your trust.

You keep everything, because it was yours throughout. Source code, hosting, domains, third-party accounts, credentials and documentation are all in accounts under your name, and the documentation is deliberately kept current so another team can take over without a rescue operation. We will hand over to whoever comes next and answer their questions. Making an exit difficult is a way of keeping clients who would rather leave, and we would rather keep the ones who want to stay.