Websites do not break loudly
They break in ways nobody sees. A form that quietly stops sending looks exactly like a slow month.
Is your website actually being looked after?
Eight questions. It names the one thing most likely to hurt you, and what to do about it today.
Has anyone filled in your own contact form and checked the email arrived, in the last month?
Would you get an alert if the site went down, or would a customer tell you?
Is the domain in your company name, with renewal notices going to an address someone reads?
Has a backup been restored, anywhere, in the last year?
Is the software behind the site patched on a schedule?
Is anyone watching whether the certificate renews?
If whoever built it vanished tomorrow, do you hold the logins?
Has anyone used the site on a phone in the last three months?
The answer
Answer the eight
Unattended, out of eight
—
Do this today
Show everything unattended
A second pair of eyes
Want someone to check the ones you are not sure about?
Send your answers over with the address of the site and you get back what we can see from the outside: whether the form delivers, when the certificate expires, who the domain says it belongs to, and what the site is running.
Goes to one inbox.
In short
Almost nothing that goes wrong with a website announces itself. The page still loads, so nobody looks. The expensive failures are the silent ones: a contact form that stopped delivering, a certificate that lapsed, software left unpatched for a year, a domain renewal notice sent to somebody who left. Maintenance is not updating software on a schedule. It is checking the handful of things that fail without telling you, and proving the backup restores before the day you need it to.
What we take on
The things that fail silently
Your own form filled in and sent every month, by us, checking the email actually arrives. A form that stops delivering produces no error and no complaint. It produces a quiet month, which is the most expensive thing a website can do to you.
Certificates and domains, watched
Since 15 March 2026 a TLS certificate can last at most 200 days, dropping to 100 in 2027 and 47 in 2029. Renewal is now a routine rather than a yearly reminder. Domain and DNS in your company name, with the notices going somewhere a person still reads.
Updates, on a copy first
Patched on a schedule, tested on a copy, with a way back. Sites that get compromised are usually running something that had a published fix available for months.
A backup you have actually restored
An untested backup is a hope. We restore one to a spare location on a schedule and check the site comes up, so the first restore anyone attempts is not the one that matters.
Why nobody notices
Because the home page still loads. Every check a business owner naturally makes is a check that the site is up, and up is the one thing that rarely goes wrong. What goes wrong is one step inside: the form posts and returns a thank you and sends nothing, the payment page throws on one card type, the booking calendar stops syncing. All of it looks perfectly healthy from the outside, which is exactly why it can run for months.
The certificate question changed recently and most people have not noticed. A TLS certificate used to last well over a year, so renewal was an annual event somebody remembered. Since March this year the maximum is 200 days, and it becomes 100 days in 2027 and 47 days in 2029. Anything renewed by hand is now a recurring job, and a lapsed certificate does not degrade politely. Browsers put a full page warning in front of your site.
Then there is the domain, which is the only failure on this page that can end a business rather than dent it. It is worth knowing, today, whose name the domain is registered in and which inbox the renewal notice lands in. A surprising number of companies find out that both answers are a developer they stopped working with in 2021, and they find out in the week the domain expires.
None of this is difficult work. It is unglamorous work with no deadline attached, which is a different problem: it never gets done because nothing is ever late. Putting it on a schedule somebody owns is most of the value, and the rest is knowing which handful of things are worth checking at all.
Questions we get
Our site is fine. Do we need this?
Possibly not. Worth spending two minutes on the checker above before deciding, because the question is not whether the site is up.
The question is whether anyone would know if the contact form stopped delivering tomorrow. If the honest answer is that you would work it out from a quiet fortnight, that is the gap, and it is the same gap on a beautiful site as on an ugly one.
Can you maintain a site somebody else built?
Yes, and it is most of this work. We start by finding out what it is actually built on, which is occasionally a surprise to everyone.
The first pass is an inventory: platform, plugins, hosting, domain, DNS, certificates, and who holds each login. That inventory is worth having even if nothing else happens, and you keep it either way.
What if we do not have the logins?
Common, and recoverable more often than people expect. Domain ownership is provable, hosting accounts have recovery paths, and registrars have a process for exactly this.
It is much cheaper to sort out on a calm Tuesday than during an outage, which is when almost everybody discovers the problem.
How often does anything actually need doing?
Monthly for the checks that matter, and immediately for a security fix that is being actively exploited.
Certificates used to be annual and are now roughly twice a year, heading toward every seven weeks by 2029. That change alone has moved a lot of sites from something you could ignore into something that needs a routine.
Do you host the site as well?
We can, and we do not insist on it. Plenty of clients stay where they are and that is usually the right call.
Moving hosting to whoever maintains the site makes the invoice simpler and makes leaving harder. Worth being aware of when anyone suggests it, including us.
What do we get that we could not do ourselves?
Honestly, all of it is doable in house. The checks are on the page and the tool scores them for nothing.
What is hard to do yourself is the boring part on a schedule, forever, when nothing is ever urgent. That is the whole product. If you have somebody who will genuinely own it, take the list and go.
More in the guides and every answer in one place.
Shaheer Shaikh, operations lead at LARVOL, a San Francisco AI company working with global pharma on clinical trial data and model benchmarking. Six Sigma on the process side, Anthropic certified on the Model Context Protocol, ten years across eight industries. More about the firm