System Care is a single monthly subscription. We run and host the servers your systems live on, and bundle in the engineering work that keeps them healthy, patched, and defended — not a menu of line items you have to opt into one by one.
On-call rota & incident response
Named engineer on rotation, not an inbox. Urgent production issues are acknowledged inside the SLA window, day or night, with a real human taking ownership through to resolution.
SLAs that mean something
Written response and resolution targets by severity. Tracked on every ticket. Reported monthly. If we miss one, you see it before you ask.
Managed hosting
We run the servers your systems depend on — DigitalOcean, AWS, Vercel, Supabase. Provisioning, scaling, cost monitoring, backup verification, disaster-recovery drills.
Patching & dependency management
Weekly CVE scans. Runtime upgrades (Node, Python, Postgres). Framework migrations. Dependency bumps with tests. Emergency zero-day response when a critical advisory drops.
Security hardening
Firewall rules, IP allow-listing, WAF configuration, rate limiting, bot protection. Regular security group and IAM audits. Secrets rotation on a schedule — not when someone remembers.
Access control & auditing
SSO enforcement, access reviews when staff change roles or leave, credential rotation, signed audit logs for who did what when. Evidence for your customers’ security questionnaires is already in the drawer.
Monitoring, alerting & observability
Uptime probes, error-rate dashboards, log retention, anomaly alerts routed to the right humans. You find out before your customers do — often before the symptom reaches the user.
Backups & disaster recovery
Scheduled, encrypted backups with restore drills. RPO and RTO targets agreed in writing. Tested quarterly against a fresh environment, not “probably works”.
TLS & domain hygiene
Certificate renewal, DNSSEC, email authentication (SPF, DKIM, DMARC), registrar security. The quiet stuff that only makes news when it breaks.
AI agent guardrails
If AI coding tools or agent frameworks touch your production data, we scope them with MCPlexer — directory-scoped routing, deny-first access control, full audit trail. Agent blast radius contained by design.
Compliance evidence
Audit-ready records for your customers’ security questionnaires: access logs, change logs, backup records, patch history, incident timelines. Pre-assembled, not reconstructed under pressure.
Minor feature iteration
Small changes, copy edits, config tweaks, and tuning as the system evolves — the work that’s too small for a project engagement but still needs doing. In scope without a change-order dance.
Customer portal
A single pane for invoices, tickets, maintenance reports, audit history, and open RFQs. Rolling out now — direct link goes here when live.
Exact scope — coverage hours, SLA tiers, included environments — is agreed in writing during onboarding.