Managed Services

A server is not finished when it boots. These plans cover the part that never ends: watching it, patching it, hardening it, and picking up the phone at three in the morning when something breaks.

What we actually do

Every plan below is engineer time, not a licence you pay for and never use.

We watch it

Uptime, disk, memory, certificate expiry and backup completion, checked around the clock. You hear from us before your customers do.

We patch it

Operating system and package updates applied on a schedule, tested on a staging copy first where the plan includes one.

We harden it

Firewall rules, SSH policy, fail2ban, sane TLS, and the small unglamorous settings that stop most intrusions.

We prove the backups

A backup nobody has restored is a rumour. We test restores and tell you the result in writing.

We tune it

Nginx, PHP-FPM and MySQL settings matched to your traffic instead of the defaults that shipped with the distro.

We answer

On the Pro plan, a named on-call engineer, an incident response process, and a written post-mortem afterwards.

What we take off your hands

Six areas of work, from the firewall to the phone call. What each plan includes is set out below; anything beyond that list is scoped and quoted after the audit.

Protection

  • A firewall that is closed by default: only the ports your services need are open.
  • Automatic bans for repeated failed logins and for scanning, before an attacker gets lucky.
  • Web application firewall rules that drop injection and file-probing requests before your code sees them.
  • Key-only SSH, no root logins and a separate user for each site.
  • Strong TLS settings, with certificates issued and renewed for you.
  • On our servers, DDoS and DNS-flood filtering at the data-centre edge sits in front of all of it.
Server security in detail

Servers

  • Operating system and package updates applied on a schedule.
  • Urgent security fixes applied the day they are published.
  • Disk, memory and load alerts that fire before a limit is reached, not after.
  • Web server and PHP-FPM settings matched to your traffic instead of the distribution defaults.
  • Certificate expiry watched, so the padlock never disappears.
Tuning in detail

Cloud and VPS

  • The same hardening, patching and monitoring on Cloud, Cloud Lite, Arm, EPYC and VPS plans alike.
  • Firewall rules written for what the instance actually runs, not copied from a template.
  • Daily backups on our plans, each kept for seven days, with a check that they finished.
  • Full root access stays with you on the servers you rent from us.
  • A server at another provider is taken on as it is, or moved to us for free.
Cloud, VPS and dedicated servers

Databases and the PHP stack

  • MySQL, MariaDB, PostgreSQL, Redis and the other engines installed, tuned and monitored.
  • The slow query log read, the worst queries explained, indexes added with the reason recorded.
  • A second copy set up where one is worth having, with replication lag watched.
  • PHP-FPM pools sized from the memory the server really has, with OPcache and Redis object caching where they help.
  • Every change measured against a reading taken before it, so we can show you what it did.
Databases in detail

Backups and recovery

  • Copies kept off the server, so losing the server does not lose the copy.
  • Restores rehearsed on a separate machine, with every result written down.
  • Point-in-time recovery for databases from the change log, to the second before a mistake.
  • The way back written down before any upgrade begins.
  • You decide whether lost rows are copied back or the restored copy takes over, with the difference in front of you.
  • A hacked server cleaned, the way in closed and the site brought back.

Monitoring and incident response

  • Uptime, disk, memory, certificate expiry and backup completion checked around the clock.
  • Routine blocks stay in the log; you are told only when something needs a decision.
  • A written health report every month.
  • Where a plan lists it: a named on-call engineer, an incident response process and a written post-mortem.
  • Where a plan lists priority response, your alert goes to the front of the queue.
The uptime guarantee

Which machines we manage

Managed plans go on Linux servers: ours, or one you run somewhere else.

Cloud and VPS servers

Cloud, Cloud Lite, Arm, Performance EPYC and VPS instances in our data centres.

See the servers

Dedicated servers

Bare-metal machines with full root access and an unmetered 1 Gbit/s uplink.

Where they run

A server somewhere else

At another provider, in a cloud, or in your own office: taken on as it is, or moved to our infrastructure for free.

Free migration

Web hosting accounts

The servers under our hosting plans are ours, and they already carry monitoring, backups and free SSL as part of the plan, under a 99.9% uptime guarantee.

Web hosting plans
Managed plans are written for Linux servers. Windows VPS is sold separately, so ask us before you assume it is covered.

How a month looks

Nothing here is a surprise: these are the rhythms your servers run on, from the minute to the quarter.

  1. Around the clock

    Watching

    Uptime, disk, memory, certificate expiry and backup completion are checked day and night. Routine blocks go to the log; a real problem goes to an engineer.

  2. Every day

    Backups

    Backups run daily on our cloud and dedicated plans and are kept for up to ten days. Finishing is on the watch list, so a failed one does not go unnoticed.

  3. On a schedule

    Patching

    Operating system and package updates go on at set times. A security fix that cannot wait is applied the day it is published.

  4. Regularly

    Restore tests

    A backup is restored on a separate machine and the result is written down and sent to you.

  5. Each month

    Report and hours

    A written health report, and the engineer hours your plan includes spent on hands-on work. Unused hours do not roll over.

  6. Each quarter

    Architecture review

    On the plan that includes it, we go through how your system is laid out and tell you what we would change.

  7. Whenever it breaks

    On call

    On the plan that includes it, a named engineer takes the alert, follows the incident process and writes the post-mortem afterwards.

In every plan, and what a plan adds

Each plan builds on the one before it. The prices are in the plan cards just below.

In every plan

  • 24/7 uptime monitoring
  • OS and package updates
  • Backup verification
  • Monthly health report

Managed Plus adds

  • Security hardening
  • Performance tuning
  • 4 engineer-hours a month
  • Priority response

Managed Pro adds

  • 24/7 on-call engineer
  • 12 engineer-hours a month
  • Incident response and post-mortems
  • Quarterly architecture review

Maintenance Plans

Add to any EGPHP server, or to a server you already run somewhere else

Managed Basic
47.73 $
/ month

We watch it so you do not have to

  • 24/7 uptime monitoring
  • OS and package updates
  • Backup verification
  • Monthly health report

Auto-renews monthly. Cancel anytime.

Start this plan
Managed Pro
267.31 $
/ month

An on-call team for production systems

  • Everything in Plus
  • 24/7 on-call engineer
  • 12 engineer-hours a month
  • Incident response and post-mortems
  • Quarterly architecture review

Auto-renews monthly. Cancel anytime.

Start this plan

All prices include 14% VAT. Prices are shown in your local currency at the day's rate.

How these are priced. Unlike our hosting and server plans, maintenance is not resold hardware — it is our engineers' time, so it carries no supplier cost to mark up. The hours quoted on each plan are the hours you get; unused hours do not roll over, and work beyond them is quoted before it starts.

What we need from you, and what stays yours

A managed server works when the line between the two is clear, so here it is.

What we need from you

  • Access to the server, by key, so we can look before we change anything.
  • A short description of what runs on it: how many sites and applications, which databases, and what would hurt most if it stopped.
  • One person who can approve a change and be reached when we need a decision.
  • A word before a launch or a large campaign, so the server is ready for the traffic.

What stays yours

  • Your application code and its bugs. Our SLA does not cover downtime caused by customer code, configurations or third-party software.
  • Your data, and the decision to restore it.
  • Your domain registration and any external DNS provider.
  • The server itself: a plan is engineer time added to it, not a replacement for it.
  • Any work beyond the hours of your plan, which is quoted before it starts.

How we start

Every engagement begins the same way, whatever the plan.

  1. Audit

    We look at the server as it is and give you a written list of what is open, old or weak, before changing anything.

  2. Hardening

    Firewall, SSH policy, automatic bans, TLS and a user for each site, set up for your server and written down.

  3. Monitoring live

    Checks and alerts switched on, backups confirmed by a test restore, and a first reading taken so later changes can be compared with it.

  4. Monthly report

    From the first month you receive the health report, and the hours of your plan go to the list the audit produced.

Questions we get asked

Can you manage a server that is hosted somewhere else?

Yes. We take it on as it is, or move it to our infrastructure for free. Managed plans are written for Linux servers, and the audit tells us what is there before we change anything.

Is the monitoring really around the clock?

Yes, on every plan: uptime, disk, memory, certificate expiry and backup completion are checked day and night. What happens after an alert depends on the plan. A named on-call engineer and an incident process belong to the plan whose list includes them.

What happens when something breaks?

The alert reaches an engineer, the cause is found and fixed, and where your plan includes it you get a written post-mortem afterwards. If your own application code is the cause, we tell you what the logs show; the fix in that code is yours.

What if the hours of my plan run out?

Unused hours do not roll over, and work beyond the hours of your plan is quoted before it starts. Nothing is billed that you have not agreed to.

Does this come with an uptime guarantee?

Our hosting infrastructure carries a 99.9% monthly uptime guarantee with service credits, written down in the SLA. It does not cover downtime caused by customer code, configurations or third-party software, and a managed plan does not change that: it adds the people who keep the machine healthy.

Do you restore backups, or only make them?

We restore them: on a separate machine, on a set schedule, with the result written down. A database can be brought back from its change log to the second before a mistake.

My server was already hacked. Can you help?

Yes. We find how they got in, remove what they left, close the door and bring the site back. After that the server goes through the same audit and hardening as any other. See server security.

Do you change my application code?

No. Your application code stays with you and your developers. We work on the layers around it: the operating system, the web server, PHP-FPM, the database and the backups.

Already have a server elsewhere?

We will take it on as it is, or move it to our infrastructure for free

Free migration Talk to an engineer
An operations desk at night with the city behind it, the mark on a card
The operations desk, watching
MickeyAnswers in seconds