Software delivery, by the numbers
01
- software products shipped
- 100+
02
- average time to first production release
- 12 weeks
03
- rated by clients on Clutch
- 4.9/5
04
- years delivering software for established businesses
- 9+
Most production applications were built by someone who is no longer there. The original developer moved on. The agency relationship ended. The team downsized. The code still runs, until it doesn't, and there is no one who knows it well enough to fix it without risk.
According to IEEE research cited in Gartner's software cost analysis, 60% of total software cost occurs during the maintenance phase — not during initial development. For most businesses, the question is not whether to invest in maintenance, but whether to do it proactively or reactively after something breaks.
We take over live applications in any state. Bug fixes, security patches, dependency upgrades, performance monitoring, and on-call incident response. On retainer or ad-hoc. For applications we built and for applications we didn't.
Maintenance services
What the retainer covers
- 01
Bug investigation and fixes
Bug reports triaged by severity on receipt. Critical bugs affecting core functionality or data integrity are treated as incidents, with a 2-hour response SLA and same-day resolution target. We investigate the root cause before patching. A fix that hides a symptom without addressing the underlying cause creates more bugs down the line. All fixes are deployed to a staging environment and validated before going to production. We document every fix in a change log so you have a record of what changed, when, and why.
- 02
Security patching and dependency updates
Dependency audits run monthly against your package manifests. Known CVEs (Common Vulnerabilities and Exposures) in your dependencies are triaged by severity: critical and high severity vulnerabilities are patched as a priority; medium and low severity are bundled into the monthly maintenance cycle. Major version upgrades, the kind where a library changes its API and the patch is not a simple version bump, are scoped separately so you know what the upgrade involves before we start. Operating system and runtime updates (Node, Python, PHP, Ruby) handled as part of the retainer where they fall within the agreed scope.
- 03
Performance monitoring and alerting
Monitoring configured for your application's critical paths: API response times, database query duration, error rates, and uptime. Alerts route to Slack or PagerDuty (your choice) when response times cross defined thresholds or error rates spike. We review performance metrics monthly and flag degradation trends before they become user-visible problems. Database performance reviews include slow query identification, index analysis, and query plan optimization. We don't wait for users to report performance problems.
- 04
Database maintenance
Monthly database health checks covering index fragmentation, table bloat, slow query log analysis, and backup verification. We confirm that backups are actually running and that a restore test succeeds, not just that a backup job is scheduled. Query optimization for the slow queries that appear in your logs. Storage growth monitoring so you're not surprised by a disk-full event at 2am. For PostgreSQL, MySQL, and MongoDB, we handle routine administration within the retainer scope.
- 05
Minor feature additions
Small feature requests (additions or changes up to 2-4 hours of work) are handled within the retainer without separate scoping. Changes to form fields, report outputs, user permissions, notification logic, and configuration options typically fall in this category. Anything larger is scoped as a project and priced separately before work begins. We don't start work on ambiguous requests. Every change is written up in a short spec that both sides agree on before a line of code is changed.
- 06
Incident response
When production goes down or a critical workflow breaks, the retainer includes on-call response. We triage the incident, identify the cause, apply a fix or a safe rollback, and communicate status throughout. Post-incident, we write a short incident report covering what happened, how it was resolved, and what we're doing to prevent recurrence. For applications with business-critical uptime requirements, we discuss SLA terms at retainer start and agree on escalation paths before an incident happens, not during one.
- 07
Third-party application onboarding
If your application was built by another agency or developer, we start with an onboarding audit before taking over support. The audit covers: codebase review to understand the architecture and identify the highest-risk areas, infrastructure documentation (what's running where, what depends on what), test coverage assessment, dependency audit, and a prioritized list of known issues. You receive a written report at the end of the audit. After that, we take over the maintenance retainer with full context. No black-box support where we're fixing bugs we don't understand.
Why us
Why teams choose RaftLabs
01Senior engineers build what they scope
The engineers who assess your application also handle the maintenance. No bait-and-switch, no offshore handoff after the retainer is signed. The team you meet in week 1 is the team on call in week 12.
02Fixed price before work starts
We scope the retainer, calculate the cost, and lock it in writing before any work begins. A scope change is a change request: priced, agreed, or dropped. It never absorbs into the monthly fee and appears on the invoice without warning.
039 years and 100+ products shipped
Clients include Vodafone, T-Mobile, Aldi, Nike, Cisco, and Lockheed Martin. We maintain applications across healthcare, fintech, logistics, and hospitality, both applications we built and those we inherited from other teams.
04Compliance built in from the start
GDPR, HIPAA, SOC 2 - compliance requirements are confirmed at retainer start, not retrofitted when an audit appears. We have maintained HIPAA-compliant systems for US healthcare clients and GDPR-compliant products for European markets.
Onboarding process
How we take over a live application
- Weeks 1-2
01Onboarding audit
For applications we didn't build, we spend 1-2 weeks reviewing the codebase, infrastructure, and documentation. We map every external dependency, document what runs where, identify the critical paths and known failure modes, and run a dependency audit. You receive a written report covering the application's current state, the risks we've identified, and our recommendations. We don't take over support for an application we haven't read.
- Week 2
02Monitoring and alerting setup
Before the retainer goes live, we configure monitoring for the application's critical paths. Uptime monitoring, API response time tracking, error rate alerting, and database performance baselines are set up and validated. Alerts are tested and routed to the agreed channels. We don't start a maintenance retainer without monitoring in place.
- Week 2
03SLA agreement and escalation paths
We agree the SLA response times for each severity tier before the retainer starts: what constitutes a critical incident, what the response commitment is, and who gets notified at each escalation level. Clear enough that when a critical issue happens at 11pm, everyone knows what to do and who is responsible.
- Ongoing
04Monthly maintenance cycle
Each month: dependency audit and patching, slow query review, backup verification, performance metric review, and a written summary of what was done, what was found, and what is being monitored. Minor feature requests and bug fixes are handled within the retainer hours. You receive the monthly report before the next billing cycle.
- Every 3 months
05Quarterly review and roadmap
Every quarter we review the application's overall health: dependency age, technical debt accumulation, infrastructure costs, and anything approaching end-of-life. If a dependency upgrade or refactor is worth doing, we scope it and give you a fixed cost before any work starts.
Is your application running on dependencies that are years out of date?
Tell us what you're running, who maintains it now (or doesn't), and what's giving you problems. We'll scope the retainer.