Engineering/Maintenance & Support
Agile Labs keeps software running, fixes what needs attention and improves the system between incidents.
Response times say how quickly a support team reacts. They do not say whether the software is becoming more reliable, secure or easier to maintain. Agile Labs measures and reports both.
ecoSPIRITS
CircularOne had been a year in development with another vendor and was not usable. Agile Labs took it over, put it into service worldwide, and has extended it since.
Read the ecoSPIRITS story →
Enhancements draw from a monthly hours allocation; unused hours roll one month, then lapse. Anything above the agreed threshold leaves the retainer for a fixed quote, priced by the ticket — a rebuild cannot arrive in pieces.
Each month closes with the hours split across the four categories, uptime per endpoint, incidents against the promised response times, and the patch record with dates. It is written as audit evidence, because sooner or later an auditor reads it.
Known-exploited vulnerabilities take a fast lane measured in days, critical severities in weeks, routine updates a monthly batch. Each clock is named in the contract, and the update trail is the evidence an auditor accepts.
Every runtime and framework is tracked against its published end-of-life date. A declined upgrade is accepted in writing, with the date on it — a retainer should not quietly underwrite an unpatchable stack.
Named individual accounts in the client’s own tenancy, least privilege, quarterly review, a break-glass procedure for production. Agile Labs is certified against ISO/IEC 27001:2022 and CSA Cyber Trust — Performer; the controls behind those certificates are the controls each engagement runs on.
Monitoring and tooling live inside the client’s infrastructure, and offboarding hands over every credential, revokes our access in writing and leaves a final backup verified restorable. A retainer that ends changes who answers the phone, not whether the system runs.
We spend the first one to two weeks understanding the codebase, infrastructure and known issues. The result is a written record of what we found, what is missing and what needs attention.
We prove that backups can be restored, remove old access, rotate credentials, verify deployment and put monitoring around the parts of the system that matter.
Every request comes through one channel and is given a severity based on agreed definitions. Day-to-day support runs during business hours, with an out-of-hours route for critical incidents.
A regular slot clears smaller issues, reviews dependency updates and deals with preventive work such as flaky behaviour, slow queries and missing tests.
We review what happened, reprioritise the queue with the system owner and agree what needs attention.