Offices in Noida · Ranchi, India admin@twaratechnologies.comCareers

Service

Support & Maintenance

We keep your websites, apps and systems secure, up to date and running through patching, monitoring, backups and small improvements under an agreed plan.

What's included

What this service covers

Security patching

Applying security fixes to your application, its libraries, the operating system and hosted services, prioritised by how exposed and how serious each issue is.

Dependency and platform updates

Keeping frameworks, libraries, runtimes and app-store requirements current, so you avoid being stuck on unsupported versions that are risky and expensive to upgrade later.

Monitoring and alerting

Uptime checks, error tracking, log review and alerts on resource usage, routed to the people who need to act.

Backups and restore testing

Scheduled backups of databases and files, stored separately from the live system, with restores tested so you know they actually work.

Bug fixes and incident handling

Investigating and fixing faults, restoring service when something breaks, and recording what happened and how to prevent a repeat.

Small enhancements

Content changes, minor features, performance tuning and usability fixes handled within the plan, with larger work scoped separately.

Documentation upkeep

Keeping runbooks, architecture notes and access records current, so knowledge stays with your organisation rather than in someone's head.

Who this is for

Software does not stay finished. Libraries publish security fixes, operating systems and browsers change, app stores raise their requirements and certificates expire. This service is for organisations that want those changes handled steadily rather than in a rush when something breaks. It suits:

  • Businesses whose website, web application or mobile app was built by a supplier who is no longer involved.
  • Teams with a working system but no one with the time or skills to keep it patched and monitored.
  • Organisations that have just launched something and want ongoing care from the start.
  • Owners of older systems that still work but are running on unsupported versions and getting harder to change.

What maintenance covers

A maintenance plan is a written agreement about what we look after and how. Typically it covers:

  • Security patches. We track security advisories for the components your system uses and apply fixes based on severity and exposure. Outdated and unsupported components are a well-known source of risk; the OWASP Top 10:2025 lists Software Supply Chain Failures as A03, a category that includes software that is vulnerable, unsupported or out of date.
  • Dependency updates. Beyond urgent security fixes, we keep libraries and frameworks reasonably current in small, tested steps. Small regular updates are far less disruptive than one large upgrade after years of neglect.
  • Monitoring. Uptime, errors, performance and resource usage are watched, with alerts going to the right people. Logs are kept long enough to investigate problems.
  • Backups. Data is backed up on a schedule, stored separately from the live system, and restores are tested. A backup that has never been restored is an assumption, not a safeguard.
  • Small enhancements. Minor changes, content updates and small improvements are handled within the plan, so the system keeps up with how your organisation works.
  • Health reporting. We report periodically on what was done, what risks remain and what we recommend next, so you can plan budgets for larger work.

How we take over an existing system

Handing over a system you did not build yourself can feel risky. We make it structured:

  1. Gather access and information. Code repositories, hosting accounts, domains, third-party services, any existing documentation and contact with the previous supplier if possible.
  2. Assess the current state. We review the code, dependencies, hosting configuration, backups, security settings and known issues. You receive a written summary of findings, ranked by risk.
  3. Secure the basics. Before anything else, we confirm backups work, rotate shared or former-supplier credentials, and set up monitoring.
  4. Reproduce the build. We make sure the system can be built and deployed from source in a repeatable way. If it cannot, that becomes a priority.
  5. Agree the plan. Based on the assessment, we agree what ongoing maintenance covers and which one-off fixes are needed first.
  6. Document as we go. Each thing we learn about the system is written into a runbook that stays with you.

Decisions we help you make

  • Upgrade or replace. When a system is far behind on versions, we help you compare the cost and risk of upgrading in place against rebuilding parts of it.
  • What level of coverage you need. Not every system needs the same attention. We help you match monitoring and response arrangements to how critical each system is.
  • When to retire something. Old features, unused integrations and forgotten admin pages still need patching and still widen the attack surface. We help you identify what can be switched off safely, archive its data where needed and remove it, which often makes the rest of the system cheaper and simpler to maintain.
  • Hosting and cost. Maintenance often reveals unused resources or hosting that no longer fits. We point these out with the trade-offs.
  • What to log and keep. Logs help investigate incidents but can contain personal data. We help you balance the two and be aware of legal requirements. For example, the CERT-In directions of 28 April 2022 require covered entities in India to keep logs of their ICT systems for a rolling period of 180 days within Indian jurisdiction, to report specified incidents within six hours of noticing them, and to synchronise system clocks with the NTP servers of NIC or NPL, or with servers traceable to them.

Security and quality built in

  • Changes are tested before release. Updates go to a test or staging environment first where one exists, and we recommend setting one up where it does not.
  • Every change is recorded. Version control, a change log and the ability to roll back are standard practice in how we work.
  • Least privilege. Access is limited to what each person or service needs, and reviewed when people or suppliers change.
  • Secrets are handled properly. Passwords and keys live in a secrets store or the platform’s secure configuration, not in code or shared documents.
  • Incidents are learnt from. After a significant problem we write up what happened, the cause and what has been changed to prevent a repeat.

What we need from you to start

  • A list of the systems you want covered and what each is used for.
  • Access to code repositories, hosting, domains and connected services, or a plan for obtaining it.
  • Any existing documentation, however incomplete, and contact details for the previous supplier if available.
  • Known problems, upcoming deadlines and any changes you already know you will need.
  • Your expectations for coverage hours and how critical each system is to your operations.
  • A named contact on your side who can approve changes and be reached when something urgent comes up.

With that in hand, we begin with the onboarding assessment and share what we find before agreeing the ongoing plan.

FAQ

Common questions

Can you maintain a system someone else built?

Yes. We begin with an onboarding assessment to understand the code, hosting and current risks. If parts are undocumented or source code is missing, we tell you what that means for maintenance and what it would take to fix.

How quickly do you respond to problems?

Response arrangements are agreed in the maintenance plan and depend on how critical the system is, the hours it must be covered and the level of support you choose. We do not publish a standard figure because a small internal tool and a customer-facing payment flow need very different arrangements.

What does maintenance cost?

Cost depends on the size and age of the system, the number of components and integrations, how often things change, the monitoring and coverage hours you need, and how much enhancement work you expect. An older system with outdated dependencies usually needs more effort at first to bring it to a maintainable state.

What is not included in a maintenance plan?

Larger new features, redesigns, platform migrations and major version upgrades that need significant rework are usually scoped as separate pieces of work. The plan states this boundary clearly so there are no surprises.

What access do you need?

Typically the code repository, hosting or cloud console, domain and DNS settings, monitoring tools and any third-party services the system relies on. We recommend accounts stay in your organisation's name, with individual access for us that you can review and revoke.

What happens if there is a security incident?

We help contain the problem, preserve logs, restore service and work out the cause. Organisations in India should also be aware of their own reporting obligations; CERT-In directions require covered entities to report specified cyber incidents within six hours of noticing them. We help you gather the technical information needed for that.

Can we move maintenance elsewhere later?

Yes. Because we keep documentation current and accounts in your name, handing over to your own team or another supplier is a matter of transferring knowledge, not recovering it.

Have something you want to build or fix?

Tell us what you are trying to achieve. We will reply with questions, options and an honest view of what it would take, whether or not we are the right fit.