-
Services
Manage & Build Your Website
-
MaintenanceKeep the site fast, secure, and current without hiring for it.
-
AuditsFind out what is actually wrong before you spend money fixing it.
-
AccessibilityServe every customer and reduce your legal exposure.
-
Integrations & APIsMake your tools talk to each other so your team stops copying data by hand.
-
Page BuildingNew pages that match your brand and load fast.
-
Application BuildingCustom software when off-the-shelf will not do the job.
Define your business
View all ServicesOptimize for Growth
-
Landing PagesFocused pages built to convert a specific audience.
-
Google AnalyticsKnow what your site is actually doing, in numbers you trust.
-
Google Tag ManagerTrack what matters without a developer for every change.
-
SEO/AIOGet found in search and in AI-generated answers.
-
Lead RoutingGet every enquiry to the right person quickly.
-
User ResearchDecisions grounded in what your customers actually do.
-
User Journey MappingSee where people get stuck on the way to buying.
-
Feasibility TestingFind out whether an idea is worth building before you build it.
-
-
Use Cases
View all Use CasesSmall TeamsTechnology handled so your few people can do their real jobs.Small & Medium-size BusinessesA partner who knows your setup and picks up the phone.StartupsShip, measure, and change direction without rebuilding.NonprofitsCareful spending, clear reporting, no in-house tech team needed. -
Toolset
Most breaches start with something boring
An outdated plugin. A login that belonged to someone who left in 2023. A backup nobody ever tried to restore. We handle the unglamorous work that stops most of what actually happens to businesses your size.
Security for a business without a security team
Small and mid-size businesses rarely get attacked by someone who chose them. They get swept up by automated scanning that finds a known vulnerability in a component that has been out of date for eleven months.
That is good news, because the defense is unexciting and affordable. Keep software current, keep the list of people with access short, keep backups you have actually tested, and know within hours rather than weeks when something changes.
We do that work as part of ongoing maintenance rather than as a separate security product, because a security posture that depends on a quarterly project does not survive a busy quarter.
What we handle
On a retainer, most of this happens on a schedule you never have to think about.
Dependency and platform updates
Plugins, gems, packages, themes, and the language runtime underneath them. We watch published advisories for the specific versions you run, and we patch on staging first so an update never takes your site down at 4pm on a Friday.
Access review and offboarding
Named accounts, least-privilege roles, multi-factor authentication on anything that matters, and a real removal step when someone leaves. Old accounts are the most common thing we find during onboarding.
Secrets kept out of the code
API keys, database passwords, and payment credentials belong in a secrets store, not in a repository or a shared document. When we inherit a codebase, we check the history for keys that were committed and rotate what we find.
Backups we have restored
A backup nobody has tested is a hope, not a plan. We run a restore periodically so we know how long recovery takes and what it costs you in lost data.
Transport and browser hardening
HTTPS enforced, certificates renewed automatically, sensible security headers, and a content policy that limits what third-party scripts can do on your pages.
Monitoring and error tracking
Uptime checks, error reporting, and alerts that go to a person. Most incidents are survivable if somebody notices the same day.
What happens when something looks wrong
Agreed in advance, so nobody is inventing a process while a site is down.
Stop it from getting worse
Take the affected path offline, rotate credentials, and block the route in. Containment comes before diagnosis, because the investigation takes longer than the damage does.
You hear it from us, early and plainly
What we know, what we do not know yet, and what we are doing about it. Including when the cause turns out to be something we did. If regulated data may be involved, your compliance and legal contacts are in the conversation from the start.
Get you back up on clean ground
Restore from a known-good backup rather than trying to clean a compromised system in place. Cleaning a defaced or injected site by hand misses things almost every time.
Fix the way in, not just the symptom
Patch the vulnerability, remove the access that was abused, and check whether the same weakness exists anywhere else in your stack.
A short account you can hand to anyone
Timeline, cause, impact, and the changes made. Useful for your insurer, your board, and your own team the next time somebody asks whether this could happen again.
Where we stop and bring in a specialist
We are a development team that takes security seriously. We are not a penetration testing firm, a managed security operations center, or a SOC 2 auditor.
If you need a formal penetration test, a compliance certification, or forensics after a confirmed breach, you need a specialist, and we will help you find and brief one. We stay involved as the people who know your systems, which usually makes their engagement shorter and cheaper.
We would rather tell you that than sell you an assessment we are not the right people to run.
Security work inside a live engagement
At Spectrum Medical Care we run the development team for a clinic where the data is sensitive and the site changes every week. Security review is part of the sprint, not a project.
Running the development team for a Phoenix healthcare clinic
Questions we get about this
- Our site got hacked. Can you clean it up?
-
Usually yes. We contain first by taking the affected path offline and rotating credentials, then restore from a known-good backup rather than cleaning a compromised system in place, because hand-cleaning misses things.
After that we find and close the way in, check whether the same weakness exists elsewhere, and write up a short account you can give your insurer or your board. If the incident involves regulated data or needs forensic evidence preserved, we will tell you to bring in a specialist and help you brief them.
- Who is responsible for security updates if we are on a retainer?
-
We are. Plugin, package, theme, and runtime updates run on a schedule, patched on staging first so an update never takes your site down unannounced. We watch published advisories for the versions you actually run rather than waiting for something to break.
What stays with you is the human side: who gets an account, and telling us when someone leaves.
- Do you do penetration testing?
-
Not as a formal service. We review code, dependencies, configuration, and access as part of ongoing work, and that catches most of what realistically threatens a business your size.
If you need a formal penetration test for a compliance requirement or a customer contract, you want a specialist firm. We will help you pick one, brief them on your systems, and fix what they find.
- How fast do you respond to emergencies?
-
Response SLAs are tier-dependent and written into your contract. The Steady tier is within two business days for non-urgent work and within twenty-four hours for site-down emergencies. Active and In motion tiers tighten that further.
- Will you maintain a site you didn't build?
-
Yes, often. Our retainer practice started largely with sites built by other teams. We'll do a short technical and accessibility audit before the retainer starts so we both know what we're working with.
Not sure when your site was last updated?
That question alone is usually enough to start with. In a free consultation we will look at what you are running, who still has access, and whether your backups would actually come back.
No fear pitch. Just the two or three things worth doing first.