● Every plan ships a written SLA · Restore tested quarterly, not assumed
Home/Services/Web & apps/Web maintenance
● Patching · monitoring · backups · change hours
Website maintenance that gets measured, not promised
A monthly care plan for the site or application you already depend on: security patches applied on a cadence, uptime watched, backups restore-tested, performance held to a budget. Written SLA, monthly report you can forward to your board, and a block of change hours that never expires unused in the same month.
Service levels · every plan
in the contract
Uptime commitmentMeasured externally · monthly
99.9%
SLA
Critical security patchFrom vendor disclosure
< 24h
SLA
Backup frequencyOffsite · 30-day retention
Nightly
SLA
Restore testFull recovery to staging
Quarterly
verified
Mobile LCP held atp75 field data · alerted on drift
< 2.5s
budget
Miss the SLA · you get a credit
Reported monthly
61 sites under care · 99.98% median uptime
WordPressOdooNext.jsAstroPostgresAWS
EN · FR · AR
What maintenance covers
Six things that quietly break when nobody owns them.
Most sites do not fail dramatically. They drift — an unpatched plugin, a certificate nobody renewed, a backup that was never restored, a page that got slow one release at a time. A care plan makes each of those someone’s job on a schedule.
M.01 · Security
Patching & dependency updates
CMS core, plugins, packages and server OS updated on a fixed cadence — staged first, smoke-tested, then promoted. Critical CVEs are out of band, inside 24 hours.
CadenceWeekly · CVEs in 24h
M.02 · Availability
Uptime & certificate monitoring
Synthetic checks every minute from three regions, plus TLS expiry, DNS and domain renewal watches. Alerts route to a human on call, not an unread inbox.
Checks60s · 3 regions
M.03 · Recovery
Backups with a tested restore
Nightly offsite backups of database and files, 30-day retention, and a full restore into staging every quarter. An untested backup is a hope, not a control.
Recovery point≤ 24h · RTO 4h
M.04 · Performance
Core Web Vitals watch
Field data tracked per template with a budget attached. Drift raises a ticket with the regression identified — usually a new script, an unoptimized image or a plugin.
BudgetLCP · INP · CLS
M.05 · Integrity
Forms, links & tracking checks
Contact and quote forms tested weekly end-to-end, broken links and 404s swept monthly, analytics and conversion tags verified so reporting does not silently go dark.
SweepWeekly + monthly
M.06 · Change
Change hours you direct
Content edits, new sections, small features, accessibility fixes. Requested by email or ticket, prioritized by you, delivered in the same month or rolled once.
Included4–40 h / month
When something breaks
Four severities. Each with a clock we publish.
Severity is assigned by business impact, not by how upset the ticket sounds. The response target starts when you report it or when our monitoring catches it, whichever comes first — usually ours.
SEV 1 · 30-minute acknowledgement
Severity
Definition
Acknowledge
Update cycle
Target resolution
SEV 1
Down or revenue-blockingSite unreachable, checkout or login broken, data exposure suspected.
30 min24/7 · critical plan
HourlyUntil restored
4 hOr workaround
SEV 2
DegradedA key template or form failing, severe slowdown, one locale broken.
4 bus. hBusiness hours
DailyUntil closed
2 bus. days
SEV 3
Defect with a workaroundCosmetic breakage, minor content or layout fault, single-browser issue.
1 bus. day
Weekly
Next release
SEV 4
Request or improvementContent change, new section, enhancement — drawn from change hours.
2 bus. days
Sprint
Same month
Escalation path named at onboarding · engineer → lead → partner
Post-incident note within 5 business days for every SEV 1
The maintenance month
A repeating cycle, so nothing waits for someone to notice.
The same rhythm every month, plus a deeper review each quarter. You get one report at the end of it: what was patched, what broke, what changed, what we recommend next.
01
Weekly
Patch & verify
Updates staged, smoke-tested against key journeys, then promoted. Forms tested end-to-end and monitoring reviewed.
- Staged updates
- Form tests
- Alert triage
02
Monthly
Change hours
Your queue, your priority order. Content, fixes and small features shipped through the same review and deploy pipeline as a project.
- You set priority
- Reviewed & deployed
- One-month rollover
03
Monthly
Report
Uptime against SLA, patches applied, incidents and their causes, Core Web Vitals trend, hours used, and the next recommended action.
- SLA scorecard
- Vitals trend
- Hours ledger
04
Quarterly
Deep review
Restore test from backup, dependency and end-of-life audit, accessibility spot check, and a roadmap call on what the site needs next.
- Restore rehearsal
- EOL audit
- Roadmap call
Care plans
Monthly, month-to-month after ninety days.
Priced on what has to be watched and how fast we have to answer, not on page count. Sites we did not build start with a paid takeover audit so the SLA is based on the real state of the code.
Marketing site
Essential care
For a brochure or marketing site where downtime is embarrassing rather than expensive. Business-hours response, everything patched and monitored.
- Weekly staged patching
- Uptime, TLS and DNS monitoring
- Nightly offsite backups
- Monthly report
- 4 change hours · rollover 1 month
- Business-hours response
Most common
Managed care
For sites that generate pipeline and portals people log into daily. Faster clocks, deeper monitoring, and enough hours to keep improving rather than only holding the line.
- Everything in Essential
- SEV 1 acknowledged in 1 business hour
- Core Web Vitals budgets & alerting
- Quarterly restore test & EOL audit
- Accessibility spot checks
- 12 change hours · rollover 1 month
- Named lead · quarterly roadmap call
Portal or application
Business-critical care
For applications where an outage stops work or revenue. 24/7 on-call, a named engineer who knows the codebase, and incident practice before you need it.
- Everything in Managed
- 24/7 on-call · 30-minute SEV 1
- 99.95% uptime SLA with credits
- Named engineer + backup engineer
- Annual DR exercise & load test
- Security review & patch attestation
- 40 change hours · dedicated sprint slot
Under care
Across 61 sites, last twelve months.
Taken from the same monthly reports clients receive. Where we missed an SLA target we issued the credit and said so in the report — that is what the number below is net of.
Median monthly uptime
Median critical patch time
Quarterly restore tests passed
Median SEV 1 acknowledgement
Client · Verrand Logistics
MD
Marie Delorme · Director of Operations, Verrand · Montréal
Web maintenance FAQ
Before you hand over keys.
If your current site cannot be responsibly maintained, we will say so during the audit and tell you what it would take to get there — including when the honest answer is a rebuild.
What is included in website maintenance?
+
Security patching of the CMS, plugins and server packages; uptime and certificate monitoring; nightly offsite backups with a quarterly restore test; Core Web Vitals and error monitoring; broken-link and form checks; a monthly written report; and a block of change hours you can spend on content, fixes or small features.
How much do website maintenance services cost?
+
Essential care is CAD $850 per month for a marketing site with 4 change hours. Managed care is $2,400 per month with 12 hours, business-hours SLA and staged updates. Business-critical care starts at $6,500 per month for portals and applications with 24/7 response, on-call escalation and a named engineer. There is no setup fee, and plans are month-to-month after the first 90 days.
Do you maintain websites you did not build?
+
Yes, after a paid takeover audit. We review the codebase, dependencies, hosting, backups and known vulnerabilities, then give you a written remediation list with a fixed price. Some sites need work before they can responsibly go under an SLA — we tell you that before you sign anything, not after.
What is your response time if the site goes down?
+
Severity 1 — the site or a revenue path is down — is acknowledged within 30 minutes on business-critical plans and one business hour on managed plans, with work continuing until service is restored. Severity 2 degradation is four business hours. Every plan includes a written SLA with the target, the escalation path and the credit if we miss it.
Do unused change hours roll over?
+
They roll over for one month, so a quiet January can fund a busy February. They do not bank indefinitely, because a maintenance plan is capacity we reserve for you rather than a prepaid balance. If you consistently need more, we move you up a plan rather than billing overage.
Which platforms do you maintain?
+
WordPress, Odoo Website and eCommerce, Next.js and Astro sites with headless CMS backends, and custom Node or Python applications. We do not maintain unsupported PHP versions, abandoned page builders, or sites we cannot deploy from source control — those need a replatform first.
Is hosting included?
+
Hosting runs in your own cloud account and is billed by your provider, not marked up by us. We manage the infrastructure as code, so you keep ownership of the accounts and the DNS. If you would rather we held the hosting relationship, we can — at cost plus a management fee stated on the invoice.
Can we cancel?
+
With 30 days notice after the initial 90-day term. On exit you get current documentation, credentials, infrastructure code and a final backup — the same handover package we would give a new developer. Nothing in the plan is a lock-in mechanism.
Related services & reading
Related services
Maintenance by platform
By city
● Start with the audit
Send us the URL. We will send back the risks.
A takeover audit covers dependencies, hosting, backups, known vulnerabilities and performance, and comes back as a written list with a fixed remediation price. It is yours to keep whether or not you take a plan.
© Noordev Technologies Inc. · 2012–2026
Montréal · Toronto · Miami · Rabat