Application Maintenance and Support

Application Maintenance and Support Services | RaftLabs

See our work
  • We maintain applications we built and applications we didn't

  • Monthly retainer or ad-hoc - no minimum commitment

  • Incident response SLA from 2 hours for critical production issues

Recent outcomes

Application support · Healthcare platform

23 critical bugs resolved in 6 weeks

Took over an unmaintained HIPAA-compliant patient portal from a dissolved agency, resolved 23 critical bugs, and stabilized uptime to 99.9%.

Dependency upgrade · SaaS product

0% order errors post-migration

Migrated a Node 12 food-order management platform (Gula) through two major runtime versions without downtime, cutting deployment risk and eliminating 0% order errors post-upgrade.

Incident response · Booking platform

3x booking volume supported

Provided ongoing maintenance for a direct booking platform after relaunch, keeping the system stable as bookings grew 3x.

4.9 / 5 on ClutchSee our work

The problem

Sound familiar?

  • Your developer left six months ago and no one knows why a critical bug appears every third Tuesday?

  • Your app runs on Node 14 and you know you need to upgrade but no one has time to do it without breaking something?

  • Your old agency is unresponsive and the only person who understood the codebase is no longer there?

The short answer

RaftLabs provides application maintenance and support for live software across the US, UK, Europe, Canada, GCC, South Africa, and Southeast Asia. Services cover bug fixes, security patches, dependency updates, and on-call incident response with 2-hour SLA. Retainers from 10 to 40 hours per month.

Key Takeaways

  • RaftLabs provides application maintenance and support for live software in the US, UK, and Australia.
  • Critical incident response SLA starts at 2 hours, with same-day resolution target for production-down issues.
  • Retainers run from 10 to 40 hours per month with no minimum commitment; ad-hoc scoping is also available.
  • We maintain applications we built and applications we did not build, including codebases taken over from agencies or departed developers.
  • A healthcare platform onboarding audit resolved 23 critical bugs in 6 weeks and stabilized uptime to 99.9%.
  • A Node 12 to current migration was completed with 0% order errors post-upgrade.

Trusted by

Vodafone
Nike
Microsoft
Cisco
T-Mobile
Aldi
Heineken
GE

Software delivery, by the numbers

software products shipped
100+
average time to first production release
12 weeks
rated by clients on Clutch
4.9/5
years delivering software for established businesses
9+

Most production applications were built by someone who is no longer there. The original developer moved on. The agency relationship ended. The team downsized. The code still runs, until it doesn't, and there is no one who knows it well enough to fix it without risk.

According to IEEE research cited in Gartner's software cost analysis, 60% of total software cost occurs during the maintenance phase — not during initial development. For most businesses, the question is not whether to invest in maintenance, but whether to do it proactively or reactively after something breaks.

We take over live applications in any state. Bug fixes, security patches, dependency upgrades, performance monitoring, and on-call incident response. On retainer or ad-hoc. For applications we built and for applications we didn't.

Maintenance services

What the retainer covers

  • 01

    Bug investigation and fixes

    Bug reports triaged by severity on receipt. Critical bugs affecting core functionality or data integrity are treated as incidents, with a 2-hour response SLA and same-day resolution target. We investigate the root cause before patching. A fix that hides a symptom without addressing the underlying cause creates more bugs down the line. All fixes are deployed to a staging environment and validated before going to production. We document every fix in a change log so you have a record of what changed, when, and why.

  • 02

    Security patching and dependency updates

    Dependency audits run monthly against your package manifests. Known CVEs (Common Vulnerabilities and Exposures) in your dependencies are triaged by severity: critical and high severity vulnerabilities are patched as a priority; medium and low severity are bundled into the monthly maintenance cycle. Major version upgrades, the kind where a library changes its API and the patch is not a simple version bump, are scoped separately so you know what the upgrade involves before we start. Operating system and runtime updates (Node, Python, PHP, Ruby) handled as part of the retainer where they fall within the agreed scope.

  • 03

    Performance monitoring and alerting

    Monitoring configured for your application's critical paths: API response times, database query duration, error rates, and uptime. Alerts route to Slack or PagerDuty (your choice) when response times cross defined thresholds or error rates spike. We review performance metrics monthly and flag degradation trends before they become user-visible problems. Database performance reviews include slow query identification, index analysis, and query plan optimization. We don't wait for users to report performance problems.

  • 04

    Database maintenance

    Monthly database health checks covering index fragmentation, table bloat, slow query log analysis, and backup verification. We confirm that backups are actually running and that a restore test succeeds, not just that a backup job is scheduled. Query optimization for the slow queries that appear in your logs. Storage growth monitoring so you're not surprised by a disk-full event at 2am. For PostgreSQL, MySQL, and MongoDB, we handle routine administration within the retainer scope.

  • 05

    Minor feature additions

    Small feature requests (additions or changes up to 2-4 hours of work) are handled within the retainer without separate scoping. Changes to form fields, report outputs, user permissions, notification logic, and configuration options typically fall in this category. Anything larger is scoped as a project and priced separately before work begins. We don't start work on ambiguous requests. Every change is written up in a short spec that both sides agree on before a line of code is changed.

  • 06

    Incident response

    When production goes down or a critical workflow breaks, the retainer includes on-call response. We triage the incident, identify the cause, apply a fix or a safe rollback, and communicate status throughout. Post-incident, we write a short incident report covering what happened, how it was resolved, and what we're doing to prevent recurrence. For applications with business-critical uptime requirements, we discuss SLA terms at retainer start and agree on escalation paths before an incident happens, not during one.

  • 07

    Third-party application onboarding

    If your application was built by another agency or developer, we start with an onboarding audit before taking over support. The audit covers: codebase review to understand the architecture and identify the highest-risk areas, infrastructure documentation (what's running where, what depends on what), test coverage assessment, dependency audit, and a prioritized list of known issues. You receive a written report at the end of the audit. After that, we take over the maintenance retainer with full context. No black-box support where we're fixing bugs we don't understand.

Why us

Why teams choose RaftLabs

  • 01
    Senior engineers build what they scope

    The engineers who assess your application also handle the maintenance. No bait-and-switch, no offshore handoff after the retainer is signed. The team you meet in week 1 is the team on call in week 12.

  • 02
    Fixed price before work starts

    We scope the retainer, calculate the cost, and lock it in writing before any work begins. A scope change is a change request: priced, agreed, or dropped. It never absorbs into the monthly fee and appears on the invoice without warning.

  • 03
    9 years and 100+ products shipped

    Clients include Vodafone, T-Mobile, Aldi, Nike, Cisco, and Lockheed Martin. We maintain applications across healthcare, fintech, logistics, and hospitality, both applications we built and those we inherited from other teams.

  • 04
    Compliance built in from the start

    GDPR, HIPAA, SOC 2 - compliance requirements are confirmed at retainer start, not retrofitted when an audit appears. We have maintained HIPAA-compliant systems for US healthcare clients and GDPR-compliant products for European markets.

Onboarding process

How we take over a live application

  1. Weeks 1-2
    01

    Onboarding audit

    For applications we didn't build, we spend 1-2 weeks reviewing the codebase, infrastructure, and documentation. We map every external dependency, document what runs where, identify the critical paths and known failure modes, and run a dependency audit. You receive a written report covering the application's current state, the risks we've identified, and our recommendations. We don't take over support for an application we haven't read.

  2. Week 2
    02

    Monitoring and alerting setup

    Before the retainer goes live, we configure monitoring for the application's critical paths. Uptime monitoring, API response time tracking, error rate alerting, and database performance baselines are set up and validated. Alerts are tested and routed to the agreed channels. We don't start a maintenance retainer without monitoring in place.

  3. Week 2
    03

    SLA agreement and escalation paths

    We agree the SLA response times for each severity tier before the retainer starts: what constitutes a critical incident, what the response commitment is, and who gets notified at each escalation level. Clear enough that when a critical issue happens at 11pm, everyone knows what to do and who is responsible.

  4. Ongoing
    04

    Monthly maintenance cycle

    Each month: dependency audit and patching, slow query review, backup verification, performance metric review, and a written summary of what was done, what was found, and what is being monitored. Minor feature requests and bug fixes are handled within the retainer hours. You receive the monthly report before the next billing cycle.

  5. Every 3 months
    05

    Quarterly review and roadmap

    Every quarter we review the application's overall health: dependency age, technical debt accumulation, infrastructure costs, and anything approaching end-of-life. If a dependency upgrade or refactor is worth doing, we scope it and give you a fixed cost before any work starts.

Is your application running on dependencies that are years out of date?

Tell us what you're running, who maintains it now (or doesn't), and what's giving you problems. We'll scope the retainer.

What clients say

What clients say about working with us

Three-year average engagement. Founders and operators describing the work in their own words. No marketing varnish.

Amer Abu Khajil
Amer Abu Khajil
Canada flagCanada
Founder, Peak Studios & Perceptional

I found RaftLabs to be the perfect partner for Perceptional, with their expertise in helping startup founders build MVPs, a free consultation, a prototype that matched my vision, and their unwavering support.

01 / 06

Application Maintenance and Support Services | RaftLabs, scoped in one call.

Tell us what's broken. Within one business day you get a straight take on cost, timeline, and the right first step. No deck, no pressure.

Stay on topic

More on custom software

Frequently asked questions

A basic maintenance retainer - bug fixes, minor updates, dependency management, and monthly review - runs £1,500-£4,000 per month for most applications. Applications with higher complexity, larger codebases, or SLA requirements for incident response run higher. Ad-hoc project work (a specific upgrade or refactor) is scoped and priced separately.

Yes. We conduct an onboarding audit (1-2 weeks, £2,000-£5,000) to understand the codebase, document what's running where, identify the critical paths and known issues, and establish a baseline for support. After the audit, we take over maintenance on a retainer. We have picked up applications from agencies that closed, developers who left, and codebases that went unmaintained for years.

Retainers cover: bug investigation and fixes, security vulnerability patching, dependency and package updates, performance monitoring and alerting, database maintenance (index optimization, backup verification), minor feature changes (up to 2-4 hours each), and monthly status reports. Larger feature work is scoped separately as a project.

We offer three response tiers: Critical (production down, data at risk) - 2-hour response, same-day resolution target. High (significant feature broken) - 4-hour response, 48-hour resolution target. Normal (minor bugs, non-blocking issues) - 1 business day response, 5-day resolution target. SLA terms are agreed at retainer start.

Yes. Applications running on end-of-life stacks (Node 12, Python 2, PHP 7, Ruby 2.x) need an upgrade path, not just patches. We scope the migration as a separate project alongside the maintenance retainer, typically upgrading in incremental steps to avoid a big-bang rewrite. See our software modernization service for larger replatforming work.

Yes. We sign NDAs before the onboarding audit begins. Application maintenance gives us access to your codebase, infrastructure credentials, and production data - confidentiality is non-negotiable. We have signed NDAs with clients in the US, UK, Australia, and Canada, including in regulated industries such as healthcare and fintech where data handling requirements are strict.

Work with us

Tell us what you need. We'll tell you what it would take.

We scope Application Maintenance and Support Services | RaftLabs in 30 minutes. You walk away with a clear cost, timeline, and approach. No commitment required.

  • Scope and cost agreed before work starts. No surprises. No obligation.
  • Working prototype within 3 weeks of kickoff.
  • Pay by milestone. You see progress before each invoice.
  • 60-day post-launch warranty. Bug fixes, UI tweaks, and deployment support. No retainer.
  • All conversations are NDA-protected.