Skip to content
Computese home

02

Hosting & maintenance

Your website or application hosted, patched, backed up and watched from the outside, with restore drills that prove the backups work and engineers you can reach when something looks wrong.

  • Updates applied
  • Backups verified
  • Uptime monitored

Example status strip, 30 days

Start with
Hosting health check
Ways to engage
Fixed price, time and materials
Works to
3-2-1 backup rule, CIS Benchmarks, RPO and RTO
Reply time
Within 24 hours

Who it is for.

If you run a business

You want the site to stay up and stay patched without thinking about it, and one address to email when it doesn't.

Sound familiar?

  • Nobody is sure when the site was last updated.
  • The last outage was reported by a customer.
  • Backups exist, in theory.
  • The previous developer still holds the passwords.

If you lead a technology team

You want managed hosting with clear lines of responsibility: who patches what, how backups are proven, what is monitored and what happens in the first hour of an incident.

Sound familiar?

  • Runtimes or CMS versions are past end of life.
  • Backups have never been restored end to end.
  • Certificates and domains renew from someone's memory.
  • There is no change log, so every incident starts with archaeology.

What changes.

What you can hold the work to, in plain terms.

  1. 01

    Patched on a schedule, not after a scare.

    Operating system, runtime, CMS and plugin updates applied on a published cadence, staged first, always with a way back.

  2. 02

    Backups that are proven.

    Three copies on two kinds of storage, one off-site and immutable, and restore drills that measure how long recovery really takes.

  3. 03

    Problems found before customers find them.

    Synthetic checks from several regions, certificate and DNS expiry alerts, and error and latency monitoring with context attached.

  4. 04

    A record of every change.

    What changed, when, why and by whom, so audits and incident reviews start from facts rather than recollection.

A managed stack, watched from outside.

Traffic, recovery and monitoring are designed together, so the people who run the stack are the people who answer the alert.

Traffic lane: DNS, an edge network with CDN, WAF, DDoS absorption and TLS 1.3, the application with blue-green releases and rolling updates, and a primary and replica database with point-in-time recovery. Recover lane: 3-2-1 backups (a snapshot for fast local restore, an off-site copy in a separate region and account, and an immutable copy under object lock), proven by restore drills timed against the recovery time objective. Watch lane: synthetic checks from several regions, certificate and DNS monitoring, logs and metrics, routed to an engineer who fixes the issue and records it in the change log.

Fig. 1 Reference architecture for managed hosting. Components scale with the site; the recovery and monitoring lanes stay the same.
The rear of a rack server with two redundant power supplies and neatly bundled cables, one status light glowing orange.

What we bring.

The disciplines inside this service, and the detail we work to in each.

  • 01

    Platform and migration

    A move from your current host, planned like a cutover: inventoried, rehearsed, and reversible until you sign off.

    • Inventory of sites, domains, mail and secrets
    • Rehearsed migration on a staging address
    • DNS cutover with lowered TTLs
    • Previous host kept warm as the rollback
  • 02

    Patch and lifecycle management

    Updates staged, tested and applied on a cadence, with end-of-life dates tracked long before they bite.

    • OS, runtime, CMS and plugin updates
    • Staging first, then production
    • End-of-life calendar for every component
    • Out-of-cycle patching for critical CVEs
  • 03

    Backup and recovery

    The 3-2-1 rule with an immutable copy, and drills that measure recovery against agreed objectives.

    • Snapshots, off-site and immutable copies
    • Point-in-time recovery for databases
    • Scheduled restore drills, with evidence
    • RPO and RTO written down per site
  • 04

    Edge and hardening

    The front door configured with the same care as the application behind it.

    • CDN caching and HTTP/3
    • WAF rules and rate limiting
    • TLS 1.3, HSTS and a strict CSP
    • Least-privilege access, MFA for every admin
  • 05

    Monitoring and incidents

    Checks from outside the platform, alerts with context, and a written record of every incident.

    • Uptime and key-journey synthetic checks
    • Certificate, domain and DNS expiry alerts
    • Error, latency and saturation metrics
    • Post-incident notes: cause, fix, prevention
  • 06

    Performance and cost care

    Hosting that stays fast and right-sized as traffic and content grow, reviewed with numbers rather than impressions.

    • Cache hit ratio and time to first byte tracked
    • Image and asset optimisation
    • Database housekeeping and indexing
    • Right-sizing reviews of plans and instances
    • Regular service report: uptime, changes, incidents
    • A public or private status page on request

Where it runs, and why.

The platform follows the application, the team and the budget. Recovery targets are agreed for each system before anything moves.

PlatformFits whenHow it recoversTrade-off
Managed WordPress platformFits whenA content site on WordPress with well-known plugins.How it recoversPlatform snapshots, plus an off-site copy where agreed.Trade-offLess control of the server; the platform's limits apply.
Containers on AWS or AzureFits whenCustom applications, several environments, frequent releases.How it recoversInfrastructure rebuilt from code, and point-in-time database recovery.Trade-offMore moving parts, worth it when releases are frequent.
Virtual private serverFits whenOne application, a steady load and a tight budget.How it recoversImage snapshots plus off-site file and database backups.Trade-offOperating system patching is part of the job.
Your own serversFits whenData must stay on premises, or the hardware is already paid for.How it recoversAgent backups to an off-site, immutable target.Trade-offThe hardware lifecycle stays with you; we monitor and patch.

Whichever platform it is, the domain, DNS and hosting accounts stay in your name.

How it runs.

Every stage ends with a document you keep and a gate you can check.

  1. 01

    Review

    How the site runs today, what it depends on and what could break.

    Exit gate: Every account, dependency and renewal date on record.

    • Access audit
    • End-of-life check
    • Test restore

    You receiveCurrent set-up and risk notes

  2. 02

    Move

    Migration rehearsed on staging, then cut over with the rollback kept ready.

    Exit gate: Smoke tests pass on the new host, with the old one still ready to take traffic back.

    • Rehearsal
    • DNS cutover
    • Smoke tests

    You receiveSite on managed hosting

  3. 03

    Run

    Updates, backups and monitoring on a published schedule.

    Exit gate: Every report shows what was patched, the state of the backups and any restore tested.

    • Patch windows
    • Restore drills
    • Monitoring

    You receiveChange log and service reports

  4. 04

    Improve

    Findings from incidents and reports turned into fixes.

    Exit gate: Each incident closed with a cause and a fix on the backlog.

    • Incident review
    • Right-sizing
    • Hardening

    You receiveImprovement backlog

What is in scope.

Written down before work starts, so nothing is assumed.

Included

  • Set-up, or migration from your current host
  • Operating system, runtime, CMS and plugin updates
  • 3-2-1 backups with scheduled restore drills
  • Uptime, key-journey and certificate monitoring
  • CDN, WAF, TLS and security header configuration
  • A change log and a regular service report
  • Cover outside business hours, arranged in the agreement

Not included

  • New features or redesigns (see Web design & development)
  • Security assessment beyond routine hardening (see Security testing)

Standards and stack.

The public frameworks we measure the work against, and the platforms we run it on.

Standards we work to

3-2-1 backup rule
Three copies, on two kinds of storage, one off-site; one of them immutable.
CIS Benchmarks
Hardening baselines for operating systems and web servers.
RPO and RTO
Recovery objectives agreed per site, then proven in drills.
OWASP Secure Headers
HSTS, CSP, frame and referrer policies set and verified.
Mozilla TLS guidance
Modern TLS configuration, re-checked after every change.

How we choose tools

Certified engineers
AWS Solutions Architect, Azure Solutions Architect Expert, Google Cloud and security certifications, held by the engineers who do the work.
Licensed tools only
Every tool comes from an approved list: commercial software under its licence, or open source under a standard licence. Nothing cracked, nothing unlicensed.
Your platform first
Where you already run something that works, we build on it.
Not on the list?
Ask. Engineers who know the fundamentals pick up a new tool quickly, and we will tell you plainly if we have not used it before.

Platforms and tools we work with

Cloud and VPS

  • AWS
  • Microsoft Azure
  • Google Cloud
  • DigitalOcean
  • Akamai Cloud (Linode)
  • Vultr
  • Hetzner
  • OVHcloud

Managed platforms and panels

  • WP Engine
  • Kinsta
  • Pantheon
  • Cloudways
  • Vercel
  • Netlify
  • Render
  • Fly.io
  • Heroku
  • Coolify
  • cPanel
  • Plesk

Operating systems

  • Ubuntu
  • Debian
  • Red Hat Enterprise Linux
  • Rocky Linux
  • AlmaLinux
  • Amazon Linux
  • Windows Server

Web servers and proxies

  • NGINX
  • Apache HTTP Server
  • Caddy
  • HAProxy
  • Traefik
  • Varnish
  • IIS
  • PHP-FPM

Containers

  • Docker
  • Docker Compose
  • Podman
  • Kubernetes
  • k3s
  • Amazon ECS
  • Azure Container Apps
  • Google Cloud Run

Edge, DNS and TLS

  • Cloudflare
  • Amazon CloudFront
  • Azure Front Door
  • Fastly
  • Amazon Route 53
  • Azure DNS
  • Let's Encrypt
  • Cloudflare WAF
  • AWS WAF

Applications

  • WordPress
  • WooCommerce
  • Next.js
  • Node.js
  • PHP
  • Laravel
  • Drupal
  • Adobe Commerce (Magento)
  • Python
  • .NET

Databases

  • PostgreSQL
  • MySQL
  • MariaDB
  • Microsoft SQL Server
  • MongoDB
  • Redis
  • Amazon RDS
  • Azure SQL Database
  • Azure Database for PostgreSQL

Backup and storage

  • Restic
  • BorgBackup
  • Veeam
  • AWS Backup
  • Azure Backup
  • Amazon S3
  • Backblaze B2
  • Cloudflare R2
  • Wasabi

Monitoring

  • Prometheus
  • Grafana
  • Loki
  • Uptime Kuma
  • Better Stack
  • UptimeRobot
  • Checkly
  • Datadog
  • New Relic
  • Sentry
  • Zabbix
  • Amazon CloudWatch
  • Azure Monitor

Automation

  • Terraform
  • Ansible
  • GitHub Actions
  • GitLab CI

Mail delivery

  • Amazon SES
  • SendGrid
  • Postmark
  • Mailgun

Where we have done it.

Client cases name the industry and the stack, never the client.

How to start.

A fixed, small first engagement, then the model that fits the rest.

A first engagement

Hosting health check

A read-only review of where and how the site runs today, before anything moves.

You receive

  • Who owns the domain, DNS, certificates and accounts
  • End-of-life and patch status of every component
  • A test restore of the current backup
  • Risks ranked, with a migration plan

What we need from you

  • Read-only access to hosting and DNS accounts
  • A list of your sites, applications and domains
  • Who to contact when something breaks
  • Any past incidents you remember

Then, the model that fits

  • Fixed price

    Defined projects: a website, an assessment, a migration stage

    One price for that scope

  • Time and materials

    Ongoing improvement, support and discovery work

    Billed for the time used

Common questions.

Can you take over a site another company built?

Yes. It starts with the health check, so you know the risks before anything moves, and the migration is rehearsed on a staging address first.

What happens when the site goes down?

An external check raises the alert, an engineer confirms it and works the incident, and you receive a written note of the cause and the fix. Engineers work Monday to Friday, 9:00 to 17:00 ET, and cover outside those hours is arranged in the agreement.

How do you know the backups work?

By restoring them. A drill restores a recent backup into an isolated environment, checks it and records how long recovery took against the agreed objective.

Do we keep ownership of our domain and accounts?

Yes. Domains, DNS and hosting accounts stay in your name, and access goes to named engineers with multi-factor authentication.

What if an update breaks the site?

Updates are tested before production, on staging where one exists, and key pages are checked before and after. If something still breaks, the update is rolled back and held until the cause is fixed.

When is managed hosting not the right fit?

When a site is a brochure that changes twice a year, plain shared hosting and a yearly check-up may be enough. If that is you, we will say so.

What happens if we leave?

The domain and accounts are already in your name. You receive a final backup, the runbook and the change log, and every credential we held is rotated and handed over.

Guides from the blog.

Plain-language articles on hosting & maintenance, with their sources.

Hosting16 min read

How to create a data backup strategy for a small business

Plan backups in six steps: list where data lives, set RPO and RTO, choose backup types, follow the 3-2-1 rule, set retention and test restores.

Updated

Hosting19 min read

Website backups: why they matter, what to copy and how to restore

Back up a website's database, files, configuration and DNS to a copy outside your host, as often as you can afford to lose changes, and prove it by restoring.

Updated

Hosting17 min read

How to create a secure backup strategy that survives ransomware

Protect backups from ransomware: immutable and offline copies, encryption with separate keys, isolated admin accounts, deletion alerts and clean restore tests.

Updated

Hosting11 min read

How to renew an SSL certificate in 2026: manual steps and automation

Renew an SSL/TLS certificate step by step: check the expiry, create a new key and CSR, pass domain validation, install the full chain and automate renewals.

Updated

Security18 min read

What is a DDoS attack and how does it work? Types, signs and protection

A DDoS attack floods a service from many machines at once. How botnets, floods and amplification work, how to spot one, and how DDoS protection stops it.

Updated

All Hosting articles →

Start with a conversation.

Tell us what you run and what is getting in the way. You get a reply within 24 hours.

Hours
Mon–Fri, 9:00–17:00 ET
Closed on statutory holidays
Office
110 Place d'Orléans Dr
Ottawa, ON K1C 2L9