The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
Assemblysoft provides SLA-backed managed support for live applications, whether they were built by us, by a previous supplier, by an in-house team, or with AI tools. We take operational ownership of established C# / .NET and Microsoft Azure estates, keep them secure and monitored, and improve them over time, as a long-term technology partner rather than a pool of development resource.
Each has its own page, its own process, and its own set of answers. All of them end in the same place: a supported, documented system with a named team behind it.
Support is not a ticket queue. It is monitoring, patching, fixing, improving, and reporting, run to an agreed SLA by a team that knows your system.
Business hours through to round-the-clock monitoring, with severity definitions, response and resolution targets, and escalation paths agreed in writing and recalibrated quarterly.
Application Insights and Azure Monitor dashboards tracking response times, failure rates, dependency health, and business KPIs, with alerting on anomalies before users notice.
Defects and vulnerabilities fixed at the root and released through tested CI/CD pipelines. No manual deployments, ever: every release carries an audit trail, test gates, and sign-off.
Continuous analysis of application performance, slow queries, memory, and cloud resource utilisation, with rightsizing recommendations that actively reduce your Azure bill.
Incremental enhancements delivered alongside maintenance, so the application keeps pace with the business instead of merely surviving. Same team, same pipelines, weekly staging releases.
Full estate oversight: scaling, cost governance, security posture, backup verification, and disaster recovery testing. Infrastructure as Code so nothing lives only in someone's head or the portal.
Organisations looking for a long-term technology partner usually need all of the following in one place, with clear separation between development and operational control. This is the full scope we take on.
Defect fixes, enhancements, and new features across ASP.NET Core, Blazor, and .NET Framework codebases.
Subscription governance, landing zones, App Service, Container Apps, SQL, Key Vault, and cost control on Microsoft Azure.
Stabilise first, then modernise release by release: legacy .NET upgrades and cloud migration without a big-bang rewrite.
Automated build, test, and deployment pipelines with quality gates, environment parity, and blue/green or canary releases. See Azure DevOps services.
REST, GraphQL, SignalR, webhooks, and third-party platforms such as Xero, QuickBooks, Stripe, and Dynamics kept healthy and extended. See our integration case study.
SQL Server, Azure SQL, Cosmos DB, and PostgreSQL: query tuning, index health, backup and point-in-time restore verification, and schema change management.
OWASP-aligned reviews, dependency scanning, penetration testing, and a documented disaster recovery plan with tested restores and agreed RTO/RPO. See our Trust Centre.
Incident management restores service. Problem management finds the cause so it stops recurring. We run both and report on them separately.
A named architect owns the target architecture and a living roadmap, reviewed quarterly with your stakeholders. Written for CTOs and technical leaders.
Continuous improvement delivered in sprints by the same team that supports the platform, so knowledge compounds instead of leaking away.
We work collaboratively with internal product owners, IT, and leadership, with daily visibility of progress and a monthly service review. See how a partner transition runs →
Three phases. The first is short and produces a written proposal you can act on with us or without us.
A deep dive into systems, architecture, infrastructure, and codebase to surface risks and quick wins. AI-augmented analysis helps us understand unfamiliar code fast, then senior engineers verify what it finds.
Knowledge transfer workshops, tool and environment access, runbooks, monitoring and alerting, and CI/CD validation. Escalation paths are rehearsed before they are needed.
Monthly reports on support volumes, SLA adherence, system health, security events, and cost. Quarterly reviews recalibrate coverage and plan improvements. Your application gets better, not just maintained.
Coverage hours and maintenance windows are written into the SLA, so there is no ambiguity at 2am.
Monday to Friday, UK working hours. Right for internal systems where an outage is an inconvenience rather than an emergency.
Shaped to your operational day: early starts, late finishes, or weekend trading peaks. Coverage follows your customers, not the calendar.
Continuous cover with one planned weekly release window. For platforms that run around the clock but can schedule a quiet period.
Round-the-clock automated monitoring and alerting with agreed out-of-hours escalation, for revenue-critical or safety-critical systems.
An SLA should describe your business, not a generic template. These six sections are agreed during onboarding and reviewed every quarter.
Driven by business impact: what stops trading, what degrades service, what can wait. Written with you, in your language.
Separate targets per severity, honest about whether a fix needs a release, and measured against the pipeline rather than a promise.
Hours of cover and planned work windows documented, communicated, and agreed in advance so patching never surprises anyone.
Who is contacted, in what order, and what triggers escalation. Rehearsed during onboarding, not discovered during an outage.
Incidents restore service. Problems remove the cause. We run both processes and report on them separately so recurring issues are visible and shrinking.
Monthly reporting on incidents, health, security, and cost. Quarterly reviews recalibrate the SLA and support allowance against real demand.
Taking over vendor-built, contractor-built, and abandoned applications is core to what we do, not an exception. The discovery phase exists precisely so we can own a system responsibly. Our LV= case study is a good example: support and migration of business-critical legacy applications for a major UK insurer.
Code, infrastructure, pipelines, and documentation stay in your accounts. Bespoke deliverables are assigned to you on payment, and everything we do is documented so you can bring support in-house or move on. It is written into our Client Playbook.
We use AI tooling to map unfamiliar codebases, trace dependencies, and draft documentation in hours rather than weeks. Every finding is verified by a senior engineer before it reaches a report or a release. See our AI development services.
No offshoring and no rotating cast. The engineers who onboard your system are the engineers who support it, so context is never lost between tickets. Based in Bournemouth, working with clients across the UK. About Assemblysoft.
Managed support is Phase 12 of our Client Playbook, which sets out the whole engagement journey and the commercial framework, alongside our published rate card.
Most organisations looking for a long-term partner for an existing C# / .NET and SQL Server system ask the same things. Here are the straight answers, before the introductory call.
Assemblysoft has built and supported Windows and .NET business applications for over 25 years and has traded as a company for 15+. Our day-to-day covers C# on .NET Framework 2.0 through 4.8.1 and modern .NET, Visual Studio solutions of every vintage, WinForms and WPF desktop systems installed on customer servers and PCs, ASP.NET web applications, and Microsoft SQL Server from 2008 onwards, including T-SQL stored procedures, indexing, and query tuning. We are a Microsoft Partner.
Established bespoke systems, usually built by someone else, are the majority of our support work: business-critical legacy .NET applications for LV=, a scaffolding management and ERP system, a warehouse management and ordering system, print hub management software, and ferry booking integrations. Browse all case studies.
We are a UK company headquartered in Bournemouth, Dorset, operating UK business hours with a compact, senior engineering team and no offshoring. Small enough that the engineers who onboard your system are the ones who answer the phone; established enough to hold Cyber Essentials Plus, professional indemnity and cyber insurance, and a published Trust Centre. More about the team.
Our day rates are published on the rate card: mid-level developer £425 to £575, senior developer £550 to £725, database developer £450 to £600, all-inclusive and billed weekly. Ongoing support is normally a monthly plan sized to the SLA tier and a bank of engineering hours drawn at those rates, with unused time reviewed quarterly. Discovery is a short, fixed-scope engagement at the same rates, and the terms are set out in our Client Playbook. Hourly equivalents are available on request.
Every plan uses a written severity matrix agreed with you during onboarding. The targets below are indicative of a typical business-hours plan and a 24/7 monitoring plan; your SLA states the exact figures.
| Severity | Typical example | Response, business hours plan | Response, 24/7 plan | Resolution target |
|---|---|---|---|---|
| P1 Critical | System down or trading stopped for all users | Within 1 business hour | Within 1 hour, any time | Service restored or workaround in place within 4 hours; root cause fixed in the next release |
| P2 High | A major function is unusable and there is no workaround | Within 4 business hours | Within 2 hours | Fix or workaround within 1 business day |
| P3 Medium | Degraded function with a workaround, or a data correction | Next business day | Next business day | Scheduled into the next planned release |
| P4 Low | Cosmetic issue, question, or enhancement request | Within 2 business days | Within 2 business days | Prioritised with you in the monthly review |
Requests arrive by email, phone, or a shared ticket board; every ticket has a named engineer and you see its status. Fixes go through the same tested pipeline as feature work. Monthly reports show volumes, response times against target, and system health. See the six SLA components we put in writing and the coverage models.
Every managed support engagement is staffed with these roles. Larger estates add a technical architect and additional engineers.
Your primary contact. Coordinates the team, owns SLA reporting, and manages escalations.
Defect fixes, patches, enhancements, and performance work across the application and its data layer.
Pipelines, Azure infrastructure, monitoring, deployments, backups, and disaster recovery.
Regression coverage that validates every fix and stops new issues slipping into production.
Proven on booking platforms, insurance systems, and member portals: see Condor Ferries, LV=, and Fitness First.
Most clients run managed support while they plan modernisation, then phase it in with the same team. Support stabilises the estate and produces the evidence needed to decide what to migrate, what to rebuild, and what to leave alone. When the time comes, our legacy .NET upgrade and migration and Azure cloud migration services pick up without a second discovery, a second vendor, or a second knowledge transfer.
A maintainability review gives you an independent, written answer, with risk ratings and costed options, before you commit to either path.
Every engagement starts from the same foundation: understand the estate, take operational ownership, then improve it. These pages cover the situations we are asked about most.
The overview: SLA-backed support, monitoring, patching, and improvement for live .NET and Azure applications.
Handing a live system to a new partner means trusting them with source code, credentials, and data. We make that easy to verify: our policies, certifications, and evidence are published openly in our Trust Centre, and the commercial terms we work to are set out in our Client Playbook.
Our complete policy set, certifications including Cyber Essentials, insurance, and company information in one place.
Visit the Trust CentreHow we protect your code, credentials, and data during an engagement: secrets in Key Vault, encrypted transfers, least privilege.
Read the policyHow a security incident would be handled: containment, investigation, and prompt notification of affected customers.
See how we respondWhere your data lives while we support the system, and how UK residency is maintained when your obligations require it.
Check data residencyEngagements are governed by our Master Services Agreement, with a UK GDPR Article 28 Data Processing Agreement wherever personal data is involved. We are happy to sign a mutual NDA before any access is granted. Common due-diligence questions, answered →
It scales with scope, SLA tier, and the size of the estate, so we do not quote a figure before discovery. The discovery phase is short, billed at our published day rates, and produces a written proposal with the support tier, allowances, and monthly cost. Where we also manage your Azure environment, the infrastructure management fee set out in our Client Playbook applies. No retainers you cannot see the value of, and no surprises.
Yes. Taking over vendor-built, contractor-built, and in-house applications is the majority of our managed support work. The structured discovery phase exists so we can assess, document, and monitor a system before we accept SLA responsibility for it. See development partner transition and internal systems handover.
Flexible tiers from business hours with next-business-day response through to 24/7 monitoring with agreed out-of-hours escalation. Severity definitions, response and resolution targets, escalation paths, and maintenance windows are agreed in writing and reviewed every quarter.
Incident management restores service as fast as possible. Problem management identifies the underlying cause so the same incident stops recurring. We run both processes and report on them separately, so you can see recurring issues being eliminated rather than repeatedly patched.
Yes. As a Microsoft Partner we manage the application and the Azure estate as one team, so there are no hand-off gaps during an incident. Where you already have an IT provider or infrastructure security partner, we coordinate directly with them and keep development and security administration strictly separate.
Yes. Legacy application support covers .NET Framework, classic ASP.NET, WCF, SQL Server, and on-premise systems with SLA-backed patching, monitoring, incident response, and compliance evidence. Modernisation is optional and can be planned in parallel.
Yes. Whether a vendor has disappeared, a project has stalled, or an AI-generated prototype needs hardening for production, we start with an assessment and a stabilisation plan. See vibe coding rescue and the maintainability review.
Always. Source control, Azure subscriptions, DNS, certificates, and app store accounts stay in your name. We document everything we do so you can bring support in-house or change partner without a knowledge cliff. Our Client Playbook sets this out contractually.
That is normal for partner transitions and acquisitions. We begin with an initial discussion on capability and fit, sign a mutual NDA (yours or ours), and only then receive the detail needed to scope discovery. Our policies and evidence are already published in the Trust Centre to speed up your due diligence.
Ideally the source code, any documentation, the software licences in use, and access to a copy of the database and the environment the system runs in, whether that is a server in your office or a cloud subscription. If the original developers are still reachable, an hour with them is worth a great deal. If some of that is missing, discovery works from what exists. Our legacy application support page lists the typical starting pack.
Yes. Accounting integrations are one of the most common things that quietly break in an established system: OAuth 2.0 tokens expire, API versions are retired, SDK packages fall out of support, and reconciliation drifts. We keep the connection healthy, monitor for failures, and update the integration ahead of provider deprecations. See integration maintenance.
Because the cost of an unplanned outage, a missed security patch, or a departed developer is always higher than the cost of cover. We wrote about this in why you should have a support plan in place.
Whether your development partner is winding down, your lead developer has moved on, or an AI-built app has outgrown its origins, it starts with an initial discussion on capability and fit. Confidentiality arrangements are welcome from the very first conversation.
Book an Initial Discussion All Managed Support ServicesCyber Essentials certified · UK-based team · Microsoft Partner · Policies and evidence at our Trust Centre