Quality assurance, maintenance & support

Software does not decay because the code changes. It decays because the world around it does — dependencies, platforms, certificates, third-party APIs. This practice is about keeping a system trustworthy after the launch party.

Practice 06 · Testing · Audits · Maintenance · Incidents

01 — Position

Testing is part of the estimate, never a line you can decline

When testing is quoted separately it becomes the first thing cut, and the saving is borrowed from the next twelve months at a punitive rate. So we do not quote it separately. The number we give you already includes the suite and the pipeline that runs it.

We are not dogmatic about coverage percentages. We are dogmatic about the critical paths: the flows where a failure costs money, loses data, or has to be explained to a regulator.

We also take on systems we did not build. That starts with an audit, not a promise.

What an audit covers

  • Architecture, and where it will resist the next change
  • Test coverage on the paths that actually matter
  • Dependency age, known vulnerabilities, upgrade path
  • Secrets handling and access control
  • Build and deployment reproducibility
  • Backup and restore, verified rather than assumed
  • A prioritised remediation list with effort estimates

02 — What we do

Scope of the practice

Automated testing

Unit tests for logic, integration tests for boundaries, end-to-end tests for the journeys a customer would notice breaking.

Code & architecture audit

A written assessment of an existing codebase: what is sound, what is fragile, what it would cost to fix, in priority order.

Dependency & security review

Scheduled scanning, a real upgrade plan for what is out of date, and hardening of the obvious exposures before someone else finds them.

Maintenance agreements

An agreed response window, a named escalation path, and a scheduled slot each month for updates so they never queue up into a project.

Incident response

When something breaks: triage, mitigation, root cause, and a written post-incident note describing what changed so it does not recur.

Documentation rescue

Reconstructing the runbook for a system whose original authors are gone, so operating it stops depending on institutional memory.

03 — Support levels

What a maintenance agreement covers

Response windows are contractual. The exact hours and severities are agreed per client — the shape below is our standard starting point.

Severity 1 — production down
The system is unavailable or losing data. Work starts within the agreed window on business days, and continues until service is restored or a mitigation is in place.
Severity 2 — major function broken
A critical process fails but the system is usable. Triaged the same business day, with a fix or a workaround agreed before we close the ticket.
Severity 3 — defect with a workaround
Scheduled into the next maintenance slot, with the workaround documented for your team in the meantime.
Scheduled maintenance
Dependency updates, security patching, certificate renewal and backup verification, performed on a regular cadence rather than when something breaks.
Reporting
A monthly written summary: what was done, what was deferred and why, and anything we think will need attention in the next quarter.

04 — Questions

About maintenance

Will you maintain software you did not write?

Yes, after an audit. We need to know what we are agreeing to support before we agree to support it — that protects you as much as us. If the audit shows the system is in worse shape than expected, you get the report and the option to walk away.

Do you offer 24/7 on-call?

We are a small senior team, and we do not pretend otherwise. Standard agreements cover business days in our time zone, which overlaps working hours across Europe and the Gulf. Extended cover can be arranged where the system genuinely warrants it, and we will tell you honestly if another arrangement would serve you better.

What if we only need a one-off review?

That is a common and useful engagement. A fixed-scope audit, a written report with a prioritised list, and no obligation to continue. Several clients have taken that report and executed it with their own team, which is a perfectly good outcome.

Ask for the audit first

Fixed scope, written report, prioritised list. Yours to keep whether or not we do the work.

HALDIR LTD · HE 459882 · Nicosia, Cyprus