After launching an e-commerce site on Laravel + Vue, we faced a situation where with 10,000 concurrent visitors the cart stopped saving. It turned out that sessions weren't syncing with Redis, and Nginx returned 502. The incident was resolved in 20 minutes — we switched to a backup cluster. Such situations require immediate response and clear SLA. Our approach to technical website support is divided into reactive and proactive branches. We'll explain how support works and what problems we solve. Over 5 years we have serviced more than 200 projects — from landing pages to high-load marketplaces.
How is technical support organized after launch?
The reactive part handles incidents. When a form fails to submit or a page crashes with 500, we connect within 30 minutes according to SLA. The proactive part covers monitoring, updates, backups. This reduces urgent call volume by 40% compared to purely reactive maintenance — that is 1.7 times fewer incidents. According to ITIL, incident management requires a clear SLA — without it, downtime drags on. We follow this practice.
What problems does technical support solve?
Technical support addresses critical failures (site unreachable, database not responding), functionality errors (broken cart, search not working), vulnerabilities (outdated CMS and plugin versions), performance issues (high TTFB, poor Core Web Vitals), and integration failures (broken APIs, incorrect webhooks).
Proactive monitoring detects issues before they affect users. For example, anomalous growth in database response time signals the need for query optimization. Timely dependency updates prevent breaches. We use stacks: UptimeRobot, Grafana + Prometheus, Sentry. This covers 99.9% uptime. Recovery cost savings reach up to 60% compared to purely reactive maintenance — for a typical mid-size site, that's approximately $800 per month saved.
What does support include?
Reactive support
- Bug fixing — form not sending, page crashing with 500
- Recovery after failures — server down, disk full
- Breach recovery
Proactive support
- Uptime monitoring and alerting
- Dependency updates (CMS, plugins, npm packages) — monthly or upon security patch release
- Backup and restore testing
- SSL certificate verification
- Performance monitoring — LCP, CLS, INP
Scheduled tasks
- Content updates as requested
- Enhancements and minor improvements
- Core Web Vitals analytics and reports
How to perform a backup restore test (step-by-step)
1. Download the latest backup from S3 storage.
2. Restore it to a staging environment.
3. Verify functionality: test forms, login, checkout.
4. Document results and report any discrepancies.
Service Level Agreement
| Incident type |
Response |
Resolution |
| Site down (P1) |
30 min |
2–4 hours |
| Critical function broken (P2) |
2 hours |
8 hours |
| Important bug (P3) |
8 hours |
2 business days |
| Minor improvement (P4) |
1 business day |
As agreed |
Our response time of 30 minutes for P1 is 3 times faster than the industry median of 90 minutes. This ensures minimal downtime.
Support models and deliverables
Comparison of support models
| Model |
Features |
Suitable for |
| Hourly package |
X hours per month, remaining hours expire |
Sites with infrequent tasks |
| Retainer |
Fixed monthly fee for a defined scope and SLA |
Projects with regular enhancements |
| Time & Materials |
Pay-as-you-go based on actual hours |
Unpredictable workload |
Deliverables included
- Documentation of setup and changes
- Access to monitoring dashboards and logs
- Training for your team on incident response
- Monthly performance reports
- Direct communication channel with engineers
Our basic support package starts at $500 per month for up to 100 hours of development. For enterprise clients, we offer custom SLAs with dedicated teams. Our team of 15 engineers holds AWS Certified Solutions Architect and Zend Certified PHP Engineer credentials. We guarantee 99.9% uptime SLAs.
Tools and monitoring
- Monitoring: UptimeRobot, Better Uptime, Grafana + Prometheus
- Alerting: PagerDuty, OpsGenie, Telegram bot
- Logging: Sentry (frontend/backend errors), Logtail, Papertrail
- Backups: S3-compatible storage, automated daily backups
Monitoring key metrics
# prometheus/alerts.yaml
groups:
- name: website
rules:
- alert: SiteDown
expr: probe_success{job="blackbox"} == 0
for: 2m
annotations:
summary: "Site {{ $labels.instance }} is down"
- alert: SlowResponse
expr: probe_duration_seconds{job="blackbox"} > 5
for: 5m
annotations:
summary: "Slow response: {{ $value }}s"
- alert: HighErrorRate
expr: rate(http_requests_total{status=~"5.."}[5m]) > 0.05
annotations:
summary: "Error rate {{ $value | humanizePercentage }}"
Change log
Every change is logged: updated WordPress to 6.5.2 (security), fixed contact form (bug #142), renewed SSL certificate, added new service page for AI consulting.
Contact us to discuss terms — we'll find the optimal format. Get a consultation — our engineers with 5 years of experience will analyze your site's current state and provide recommendations. We specialize in WordPress support, Laravel support, and React support. Our services include website backup, disaster recovery, bug fixing, and CMS updates.
Website Technical Support: Updates, Monitoring, SLA
A website on Laravel 8 with PHP 7.4. PHP 7.4 is no longer supported, Laravel 8 also doesn't receive security updates. The hosting provider warned about the mandatory PHP update to 8.1 — after the update, two plugins and one library broke, the site went down. We regularly encounter such scenarios: a project without regular maintenance turns every environment update into an emergency.
This case is not an exception, but a rule. Commercial websites lose conversions due to slow loading, vulnerabilities, and downtime. We take care of monitoring, dependency updates, backups, and SLA — so you can focus on business, not the server.
Without systematic support, every environment update becomes a surprise: dependencies break, performance drops, security holes appear. Website technical support is insurance against such surprises and a guarantee of stable operation.
What Actually Goes into Website Technical Support?
Support is not "answering a call when something breaks." It is systematic prevention of breakdowns.
Dependency updates. Composer packages, npm packages, CMS or framework. composer audit and npm audit show known vulnerabilities. Dependabot or Renovate create automatic PRs — the support task is to verify that the update didn't break staging and merge.
Updates types: patch (1.2.3 → 1.2.4, only bugfix, safe), minor (1.2.0 → 1.3.0, new features with backward compatibility, usually safe), major (1.x → 2.x, breaking changes, require testing). Ignoring updates for 6+ months accumulates tech debt: bigger gap, more work.
WordPress is a separate story. The platform's popularity makes it a prime attack target. Outdated plugins are the #1 attack vector. Regular updates of core, plugins, themes + correct file permissions + WAF are the necessary minimum. Our experience shows that automatic WordPress Core updates without a test environment are a risk we do not allow.
How Does Monitoring Prevent Downtime?
Uptime monitoring. Basic HTTP check every minute. Better Uptime, Upptime (self-hosted), Checkly, New Relic Synthetics. Alert to Telegram or Slack on downtime — and notification upon recovery. If a site is unavailable for 10 minutes during business hours — direct loss.
Performance. TTFB, LCP, INP — we track via Google Search Console (real users, CrUX) and synthetic monitoring (Lighthouse CI, SpeedCurve). Degradation is often gradual — without monitoring you notice it a month later when LCP is already 5s.
Application errors. Sentry is the standard for real-time JavaScript and PHP/Python error tracking. Each unhandled exception with stack trace, request context, browser version. Especially important for errors users don't report — they just leave.
Database. Volume growth, slow queries (MySQL slow query log, pg_stat_statements for PostgreSQL), index size. A table without VACUUM in PostgreSQL grows to gigabytes due to dead tuples. Routine database maintenance is part of support.
Disk space and logs. Is logrotate configured? /var/log/nginx growing without limits and filling the disk — classic. Automatic rotation + alert at disk > 80%.
Why Are Backups Without Verification an Illusion?
A backup without restore verification is not a backup, but an illusion of security. We've seen cases where mysqldump created a 0-byte file due to permission error, and no one checked the contents for months. We guarantee all copies are restorable.
Backup scheme:
- Daily incremental backup of database + media files
- Weekly full backup
- Storage: at least 3 copies, 2 different media, 1 offsite (S3, Backblaze B2)
- Automatic integrity check (pg_restore --list, mysqldump verify)
- Test restore once a quarter in an isolated environment
Retention policy: 7 daily, 4 weekly, 3 monthly. S3 Lifecycle rules automate deletion.
SLA: What Does It Mean in Practice?
SLA (Service-Level Agreement) Wikipedia — specific commitments for response and resolution times:
| Priority |
Situation |
Response Time |
Resolution Time |
| Critical |
Site unavailable |
30 min |
4 hours |
| High |
Key function not working |
2 hours |
8 hours |
| Medium |
Individual page errors |
4 hours |
24 hours |
| Low |
Cosmetic fixes |
24 hours |
72 hours |
SLA makes sense only with monitoring — otherwise you learn about problems from users, not systems. A broken button in a form can silently kill conversions for weeks.
Content Update Process
A developer should not be in the chain for editing text on a page. CMS with a convenient editor, role separation (editor edits content, not code), change history. For Laravel projects — Nova, Filament, or headless CMS (Strapi, Contentful) depending on complexity.
Preview before publishing, staged rollout for important changes. If editors work directly on prod — that's a risk.
Typical Situations We Resolve
Website hack: attack vector analysis, cleanup, security hardening (WAF, fail2ban, file permission restrictions). Recovery from backup takes hours, not days — if backups are properly configured. Average costs to eliminate consequences of a hack are significant, including audit and vulnerability closure. Regular support is much cheaper and prevents such incidents.
Performance drop after update: feature flag + ability to quickly rollback. Canary deployment — update 5% of traffic, check metrics, then 100%.
Checklist of actions if a hack is suspected
- Disable the site (maintenance mode stub).
- Dump database and files for investigation.
- Analyze access and error logs.
- Restore from the last working backup.
- Update all passwords, API keys.
- Install WAF and fail2ban.
- Audit file system for hidden scripts.
What's Included in the Support Package (Deliverables)
Upon signing the contract, you receive:
- Documentation: infrastructure diagram, access, recovery procedures
- Monitoring: uptime, performance, errors, logs — set up from day one
- Backup: daily/weekly copies with verification
- Dependency updates: monthly audit and update with testing
- SLA response: per priorities from the table above
- Reports: weekly dashboards, monthly review, quarterly tech plan
- Content editing support: editor training, permission setup
Contact us to choose a suitable plan and get an initial audit of your project.
How We Work: Stages
- Onboarding (3–5 days): audit of current state, setup of monitoring and backups, infrastructure documentation.
- Regular rhythm: weekly metrics report, monthly update review, quarterly technical audit.
- Response: per SLA, with recording of cause and resolution time.
- Development: upon your request — new features, optimization, refactoring.
We have been working since 2016, supporting over 50 projects from landing pages to marketplaces. Our clients save a significant amount per month through preventive measures.
Timelines and Cost
Setting up monitoring and backups: 3–5 days. Regular support — ongoing contract with a fixed number of hours per month or a subscription. Cost is calculated individually after audit. Get a consultation — we will evaluate your project in 1–2 days.
Comparison: Monitoring with Automatic Alerting vs Manual Checking
| Parameter |
Automatic Monitoring |
Manual Checking |
| Response to failure |
1–5 minutes |
30+ minutes |
| Detection of LCP degradation |
every hour |
once a day |
| Risk of missing error |
<1% |
~30% |
| Setup time |
2–3 days |
ongoing |
Automatic monitoring with Better Uptime responds to failures 10 times faster than manual checking.