Engineering/Maintenance & Support

Maintenance should make software better.

Agile Labs keeps software running, fixes what needs attention and improves the system between incidents.

Support should show what is improving

Response times say how quickly a support team reacts. They do not say whether the software is becoming more reliable, secure or easier to maintain. Agile Labs measures and reports both.

ecoSPIRITS

A platform we inherited, and still run.

CircularOne had been a year in development with another vendor and was not usable. Agile Labs took it over, put it into service worldwide, and has extended it since.

  • Improvement
  • Patch clocks
  • End-of-life
  • Monthly report
  • Clean handover
Read the ecoSPIRITS story
CircularOne performance dashboard

What the retainer commits to

Improvement spends visibly

Enhancements draw from a monthly hours allocation; unused hours roll one month, then lapse. Anything above the agreed threshold leaves the retainer for a fixed quote, priced by the ticket — a rebuild cannot arrive in pieces.

The report renews the contract

Each month closes with the hours split across the four categories, uptime per endpoint, incidents against the promised response times, and the patch record with dates. It is written as audit evidence, because sooner or later an auditor reads it.

Patches run on a named clock

Known-exploited vulnerabilities take a fast lane measured in days, critical severities in weeks, routine updates a monthly batch. Each clock is named in the contract, and the update trail is the evidence an auditor accepts.

End-of-life is never absorbed silently

Every runtime and framework is tracked against its published end-of-life date. A declined upgrade is accepted in writing, with the date on it — a retainer should not quietly underwrite an unpatchable stack.

Access runs to the audited standard

Named individual accounts in the client’s own tenancy, least privilege, quarterly review, a break-glass procedure for production. Agile Labs is certified against ISO/IEC 27001:2022 and CSA Cyber Trust — Performer; the controls behind those certificates are the controls each engagement runs on.

Built to be left

Monitoring and tooling live inside the client’s infrastructure, and offboarding hands over every credential, revokes our access in writing and leaves a final backup verified restorable. A retainer that ends changes who answers the phone, not whether the system runs.

Taking a system into support

WEEKS ONE AND TWO

Understand before changing

We spend the first one to two weeks understanding the codebase, infrastructure and known issues. The result is a written record of what we found, what is missing and what needs attention.

FIRST MONTH

Stabilise the system

We prove that backups can be restored, remove old access, rotate credentials, verify deployment and put monitoring around the parts of the system that matter.

EVERY DAY

One place for support

Every request comes through one channel and is given a severity based on agreed definitions. Day-to-day support runs during business hours, with an out-of-hours route for critical incidents.

EVERY WEEK

Keep the small problems small

A regular slot clears smaller issues, reviews dependency updates and deals with preventive work such as flaky behaviour, slow queries and missing tests.

EVERY MONTH

Review and plan

We review what happened, reprioritise the queue with the system owner and agree what needs attention.

When organisations call us

Call us when

Software the business runs on daily, with nobody clearly on the hook when it breaks.A build leaving its warranty — ours or another firm’s.A takeover from a vendor who left, went quiet, or only ever fixed.A security review asking for patch evidence the current arrangement cannot produce.

Not us when

A system the business could lose for a week without noticing.Feature work the size of a rebuild — that is scoped and quoted as a project, not fed through a retainer.

If the software matters,
talk to us.

Keep your software reliable, secure and running.