
Launching a SaaS product or web app is the beginning of the work, not the end. Libraries get security patches, integrations change their APIs, certificates expire, databases grow, and customers find paths nobody tested. Someone has to watch the system and look after it.
Many founders hire a maintenance provider without a clear picture of what they are buying. The result is a plan that sounds reassuring and turns out to cover very little. This guide explains what a sensible plan includes, how to compare providers on things that matter, and the questions to ask before you sign.
What software maintenance actually covers
Maintenance is more than bug fixing. Engineers usually describe several kinds of work: corrective (fixing defects), adaptive (keeping up with changing environments), perfective (improving performance and usability), preventive (finding problems early) and security work. Our overview of the types of software maintenance explains each one.
A good plan turns those categories into specific, repeatable activities with a clear owner and a monthly report.
What a good plan should include
- Uptime and error monitoring. Automated checks and error tracking, with alerts that reach a named person and a rule for what counts as an incident.
- Backup checks and restore tests. Confirmation that backups run, plus a scheduled test that they can actually be restored.
- Security patches and dependency updates. Selected updates applied and tested in a staging environment before release, instead of updated blindly.
- Bug investigation and fixes within an agreed monthly allowance of engineering time.
- Checks on the things that fail quietly: payment webhooks, scheduled jobs, email delivery and third-party API connections.
- Controlled releases. Accepted changes deployed through a repeatable process with release notes.
- A monthly report covering work done, incidents, time used, outstanding risks and recommended next steps.
The six things to define before you subscribe
- Coverage. Which applications and environments (production, staging) are included, and who your named contacts are on both sides.
- Support hours and time zone. "24/7" and "business hours in your time zone" are very different products with very different prices.
- Severity levels and response targets. What counts as critical, and how fast the provider acknowledges each level.
- The monthly engineering allowance. How many hours are included, whether unused hours expire or carry over, and what happens when you exceed them.
- Responsibilities for backups and approvals. Who is accountable for backups and restore tests, and which changes need your sign-off.
- Commercial terms. Monthly fee, billing date, minimum term if any, and how to cancel.
Response time is not resolution time
This is the most commonly misunderstood line in any plan. A response target usually means the provider acknowledges your report and starts investigating within a set time. It does not mean the problem is fixed by then. Some problems take minutes and some take days, depending on the cause.
Ask what the provider does after the first response: how often they update you, who escalates, and what happens if the fix needs work beyond your allowance. Be wary of any provider that promises guaranteed resolution times without knowing your system.
Common pricing models compared
| Model | How it works | Good for | Watch out for |
|---|---|---|---|
| Monthly retainer with an hour allowance | Fixed fee for a set number of engineering hours plus monitoring and reporting | Most early and growing products | Unclear rules for unused hours and overages |
| Pay per incident or per task | You raise a request and pay for the work done | Stable apps with few changes | Slow starts, no proactive monitoring, surprise bills |
| Managed service with a formal SLA | Defined hours, response targets and escalation paths, often with on-call cover | Revenue-critical or regulated products | Cost, and promises that exceed what the team can staff |
None of these is universally best. Choose the one that matches how much downtime would actually cost you.
Red flags when comparing providers
- A price with no written scope, or a scope that says only "maintenance and support".
- No mention of staging, testing or release notes.
- Promises of instant fixes or "zero downtime" with no detail.
- Providers who want exclusive control of your accounts, hosting or code.
- No handover terms if you cancel.
- Hosting, software subscriptions and AI usage fees bundled in without being itemised.
Ten questions to ask before signing
- What exactly is monitored, and who receives the alerts?
- How do you test updates before they reach production?
- When did you last test restoring a backup, and how long did it take?
- What counts as an incident, and what are your response targets by severity?
- What is included in the monthly hours, and what is not?
- What happens to unused hours?
- Who owns the code, the hosting and the third-party accounts?
- What access do you need, and how is it limited and removed?
- What will the monthly report contain? Can I see an example?
- What happens to documentation and access when we end the agreement?
Ownership and continuity
You should keep ownership and administrative control of your code, accounts and infrastructure. The provider should receive access by role, with the minimum permissions required. If the relationship ends, the handover should include current documentation, the status of open work and removal of the provider's access. If a provider resists any of this, treat it as a warning.
When to start, and when to fix first
Maintenance works best on an application that has been reviewed. A good provider begins with an onboarding review of the architecture, deployment process, access and known technical debt, so the plan reflects reality. If that review finds serious existing problems, such as exposed data or broken billing, they are usually best handled first as a separate engagement. Our AI app technical audit and AI app repair and production launch are designed for that stage, and our launch checklist shows what to verify.
Once the application is stable, SaaS monthly maintenance keeps it that way, with a defined scope, a monthly engineering allowance and a report you can read in five minutes.
Frequently asked questions
What is included in a SaaS maintenance plan?
Typically monitoring and alerting, backup checks and restore tests, security patches and dependency updates tested before release, bug fixes within a monthly allowance, checks on webhooks, scheduled jobs and integrations, controlled releases and a monthly report.
What is the difference between response time and resolution time?
Response time is how quickly the provider acknowledges an issue and starts triage. Resolution time is when it is actually fixed, which depends on the cause and cannot be guaranteed without knowing the system.
Do I still need maintenance if I use managed hosting like Vercel or Supabase?
Yes. Managed platforms look after their own infrastructure, but not your application code, dependencies, integrations, data issues or release process.
Who should own the code and accounts during maintenance?
You should. The provider receives role-based access with minimum permissions, and the agreement should state what documentation and handover you receive when it ends.
How we can help
- SaaS Monthly MaintenanceMonthly care for SaaS and web apps — monitoring, backups, security patches, bug fixes, integration checks, controlled releases and a monthly report.
- AI App Technical AuditFixed-scope review of apps built with Lovable, Cursor, Bolt, Replit or v0 — auth, Supabase RLS, Stripe, secrets and deployment — with a prioritized fix plan.
- AWS, Cloud & DevOps ServicesAWS, Azure, and GCP architecture, migration, Kubernetes, Terraform, FinOps cost optimization, and 24/7 SRE — typical 25-40% cloud bill reduction.
Talk to an engineer about your project
Tell us what you are building. We reply within one business day with a candid view on scope, approach and effort.
Book a free strategy callWritten by the UnlockLive IT engineering team. UnlockLive IT Limited works with clients through its Toronto headquarters and delivers engineering from its Dhaka delivery centre. About us