1. Home
  2. Services
  3. Managed Support
  4. Legacy Application Support
Legacy Application Support

Keep legacy systems stable, secure, and supported, without a rebuild.

SLA-backed managed support for legacy .NET Framework, classic ASP.NET, SQL Server, and on-premise applications. We patch, monitor, fix, and document the systems your business still depends on, and we produce the compliance evidence your auditors and insurers now ask for. Modernisation is optional and can be planned in parallel with the same team.

Patching & CVE response Monitoring & alerting Runbooks & knowledge capture Audit evidence
The legacy reality

Why legacy applications need dedicated support

The system still works. That is exactly why it is hard to justify replacing it, and exactly why the risk keeps quietly compounding.

Framework end-of-life & CVE backlog

Runtimes, frameworks, and unmaintained packages accumulate known vulnerabilities faster than a stretched team can review them.

The original developers have moved on

Institutional knowledge left with them. The current team is understandably reluctant to touch code nobody fully understands.

Too critical to break, too old to rebuild now

Revenue-critical workflows depend on it, and a full modernisation programme takes years and budget you do not have this financial year.

Compliance evidence falling behind

Cyber Essentials, ISO 27001, insurers, and customer audits want proof of patch cadence and vulnerability response. Legacy systems rarely produce it.

What we support

Legacy Microsoft stacks are our home ground

Assemblysoft has built and supported Windows and .NET applications for over 25 years. We take over systems inherited from previous vendors, in-house teams, and departed contractors, and we hold Cyber Essentials certification for the work.

.NET Framework 2.0 – 4.8.1 Classic ASP.NET & Web Forms WCF & ASMX services VB.NET & VB6 SQL Server (on-prem or Azure) WinForms & WPF desktop Windows Services & scheduled jobs Ageing Angular, jQuery, Knockout Xamarin & older mobile IIS on Windows Server Xero, QuickBooks & Sage integrations Visual Studio solutions & T-SQL

  Is the server itself out of support?

If the application runs on Windows Server 2012 or SQL Server 2014, support alone cannot make it patchable. Our legacy .NET upgrade and migration service moves it to a supported platform in weeks, with no rewrite, and then managed support takes over. See our Windows application development expertise.

Established bespoke systems

The support brief we hear most often

A well-established C# / .NET Framework business system with a SQL Server database, installed on your own server or PCs, with source code and documentation available, that needs a long-term partner rather than a rebuild. This is the shape of most legacy support engagements we take on, and here is how each requirement is met.

Ongoing application support

A named team, an agreed SLA, and a ticket board you can see. Questions, how-tos, and incidents handled in UK business hours, or around the clock where the plan needs it. Response times.

Bug fixing and issue resolution

Reproduced on a staging copy of your system, fixed at the root in the Visual Studio solution, regression-tested, and released through a repeatable deployment route rather than by hand.

New feature development

Enhancements planned with you in the monthly review, estimated at published rates, and delivered in the existing codebase's style so the system stays coherent for whoever maintains it next.

Database support and optimisation

SQL Server health checks, T-SQL stored procedure and query tuning, index and statistics maintenance, backup and restore verification, and upgrade paths from older SQL Server versions.

Maintenance of integrations

Xero, QuickBooks, Sage, payment gateways, and other third-party APIs kept working through token expiry, API deprecations, and package updates. How we maintain integrations.

Documentation review and updating

Existing documentation reviewed against the code as it actually is, gaps filled, and an operations runbook produced, so the knowledge lives with the system rather than with a person.

Advice on upgrades and modernisation

Quarterly, in writing: which .NET Framework, SQL Server, and Windows versions you are on, what is reaching end of support, and the costed options. See legacy .NET migration and support or modernise.

  What we need to get started

  • Source code, ideally in a repository; a zip is fine to begin with
  • Any documentation, however dated
  • Software licences and third-party components in use
  • A copy of the database and the install location or environment
  • Credentials for integrations, handled via Key Vault, never email
  • An hour with anyone who knows the system, if available
Integration maintenance

Integrations are where established systems break first

The core of a mature business system rarely changes. The services it talks to change constantly. Accounting platforms retire API versions, rotate authentication schemes, and deprecate SDK packages; payment providers tighten authentication; suppliers change file formats. Under support we treat every integration as a monitored dependency with its own runbook, so an invoice sync that stops overnight is a ticket we raise, not one you do.

We have integrated with the leading platforms for over 15 years, and maintaining someone else's integration is the same discipline applied to code we did not write.

Xero, QuickBooks and Sage integrations

  • OAuth 2.0 connection and refresh-token lifecycle managed and monitored, with alerts before a connection lapses
  • Xero API version and Xero .NET SDK package updates applied ahead of provider deprecation dates
  • Rate-limit handling, retry, and idempotency so re-runs never create duplicate invoices or contacts
  • Reconciliation checks between your system and the ledger, with exceptions reported monthly
  • Credentials moved out of config files into a secrets store
  • Documented mapping of your entities to Xero contacts, invoices, payments, and tracking categories
What's included

Six things every legacy system needs

Security patching & dependency updates

We monitor the stack for vulnerabilities, apply patches through tested pipelines, and where a framework is end-of-life we add compensating controls and targeted upgrades.

Bug fixes & incident response

SLA-backed response and resolution targets. Root cause analysis and permanent fixes rather than the workaround that becomes tomorrow's incident.

Performance monitoring & optimisation

Application Insights and Azure Monitor visibility even for on-premise systems, with slow queries, memory leaks, and scaling bottlenecks identified and tuned.

Knowledge capture & runbooks

When the original developers are gone, we reverse-engineer from code and production behaviour and write down what we learn, so your organisation is never locked out of its own technology again.

SLA tiers to match business risk

Business hours through to 24/7 monitoring with agreed response and resolution targets, reviewed quarterly. See the coverage models.

Compliance & audit evidence

Monthly reports on patch status, vulnerability remediation, access reviews, and SLA adherence, in a form your Cyber Essentials assessor, ISO auditor, or insurer will accept.

Support or modernise?

An honest decision framework

We offer both, so we have no reason to push you either way. These are the signals we look for.

Support now, modernise later

  • The application is stable and does a bounded, well-understood job.
  • Business logic is unlikely to change significantly in the next two years.
  • The technology still has a security patch pathway, or can be given one with compensating controls.
  • A full rebuild would outlast the system's remaining useful life.
  • The modernisation budget is not available this financial year.
  • You need time to plan modernisation properly instead of under pressure.

Modernisation is overdue

  • The platform cannot scale to current or forecast demand.
  • Vendors no longer issue security patches for core components at all.
  • Business rules are changing faster than the codebase can safely absorb.
  • Cost per feature is rising every quarter.
  • Cloud, AI, or mobile integration is needed and the stack blocks it.
  • The skills required are unavailable at a reasonable cost.
Comparison of legacy application support and legacy application modernisation
ServiceTypical outcomeTime to valueBusiness disruptionBest when
Legacy application support The existing system keeps running: stable, patched, monitored, documented. Weeks from onboarding. Low. No architectural change. Budget and timing are not ready for a rebuild, but the risk cannot wait.
Legacy .NET migration Same application on a supported Windows Server, SQL Server, and .NET runtime. No rewrite. Three to five weeks per application. Minutes of cutover downtime with instant rollback. The platform is out of support but the application is sound.
Modernisation & cloud migration Migrated, re-architected, or rebuilt as cloud-native .NET on Azure. Months, delivered in phases. Planned, release by release. Scale, security, or cost of change forces the issue.
How it works

From black box to documented, supported system

1
1 to 3 weeks

Discovery & knowledge capture

We assess the application, infrastructure, and operational context. If the original team is available we run knowledge transfer sessions. If not, we reverse-engineer from the codebase and production behaviour.

Deliverable: written report on architecture, stack, known issues, security posture and CVE backlog, recommended SLA tier, and a proposal
2
2 to 4 weeks

Onboarding & runbooks

Monitoring, alerting, and access set up in your environment. Runbooks written for common operational tasks. Escalation paths agreed. The deployment route validated so patching is safe and repeatable.

Outcome: a documented, supported system replacing black-box operations
3
Ongoing

Support & quarterly review

Fixes, patches, monitoring, and compliance evidence against the agreed SLA. Monthly reports on activity, health, patch status, and adherence. Quarterly reviews recalibrate the tier and flag modernisation triggers early.

Team: a named UK-based team that knows your system
Proven in production

Supporting business-critical legacy applications for a major UK insurer

For Liverpool Victoria we supported and migrated critical legacy .NET applications and services, built Azure DevOps pipelines around them, and kept adviser-facing tooling running throughout. Read the LV= case study, or browse all case studies.

  Inheriting from someone else?

If the system is arriving from a departing supplier or an in-house developer, the transition itself needs structure. See development partner transition and internal systems handover.

Trust & Compliance

Due diligence, already answered

Handing a live system to a new partner means trusting them with source code, credentials, and data. We make that easy to verify: our policies, certifications, and evidence are published openly in our Trust Centre, and the commercial terms we work to are set out in our Client Playbook.

Trust Centre

Our complete policy set, certifications including Cyber Essentials, insurance, and company information in one place.

Visit the Trust Centre

Information Security

How we protect your code, credentials, and data during an engagement: secrets in Key Vault, encrypted transfers, least privilege.

Read the policy

Incident Response

How a security incident would be handled: containment, investigation, and prompt notification of affected customers.

See how we respond

Hosting & Data Residency

Where your data lives while we support the system, and how UK residency is maintained when your obligations require it.

Check data residency

Engagements are governed by our Master Services Agreement, with a UK GDPR Article 28 Data Processing Agreement wherever personal data is involved. We are happy to sign a mutual NDA before any access is granted. Common due-diligence questions, answered →

Frequently asked questions

Legacy application support, answered

What counts as a legacy application?

There is no fixed definition, but it typically means systems on .NET Framework 4.x or earlier, classic ASP.NET and Web Forms, WCF, VB6 or VB.NET, on-premise SQL Server, ageing Angular, jQuery, or Knockout front ends, and Xamarin or Cordova mobile apps. If the original team has moved on, the framework is out of mainstream support, or the cost of change grows every quarter, it qualifies.

Do you support software you did not build?

Yes. A large share of our legacy work is systems built by previous vendors, in-house teams, or departed contractors. A structured discovery phase comes first, then we accept SLA-backed ownership.

How is this different from legacy modernisation?

Support keeps the existing system reliable without architectural change. Modernisation is the migration or rebuild programme that replaces the underlying platform. Many clients run support while planning modernisation, then phase it in with the same team. Our modernisation and cloud migration page covers the second path.

What SLAs do you offer?

Tiered options from business hours with next-business-day response to 24/7 monitoring with rapid response on priority incidents. Targets are agreed in writing and reviewed quarterly. See the SLA components we put in writing.

Can you support end-of-life .NET Framework applications?

Yes. .NET Framework 4.8.1 remains supported as a component of current Windows Server versions, so most 4.x applications have a long supported future without recompilation. Earlier versions get compensating controls and a targeted upgrade path. Where the operating system itself is out of support, our legacy .NET migration service moves it first.

Do you support legacy web front ends and mobile apps?

Yes. Coverage includes ageing Angular, jQuery, Knockout, and early React web apps, plus Xamarin and older cross-platform mobile apps: store submissions, SDK updates, OS compatibility testing, security patching, and bug fixes.

Can support bridge into future modernisation?

It is the most common path. Support stabilises the system while we assess options together. The same UK team handles both, so there is no second discovery, second vendor, or second knowledge transfer.

Our system runs on a server in our office, not in the cloud. Is that a problem?

No. Many of the bespoke systems we support are installed on a customer's own Windows server or PCs, often under Program Files with a local SQL Server. We connect through a secure remote access route you control, keep a staging copy for safe testing, and add monitoring even to on-premise systems. Moving to the cloud is an option for later, not a condition of support.

Can you maintain our Xero integration?

Yes. We manage the OAuth 2.0 connection and token refresh, keep the Xero .NET SDK and API version current ahead of deprecation dates, add monitoring so a failed sync is caught immediately, and reconcile your records against the ledger. The same applies to QuickBooks, Sage, and payment gateways. See integration maintenance.

What does legacy application support cost?

It depends on the stack, complexity, and SLA tier. Discovery is short and billed at our published day rates; it ends with a written proposal that sets out the monthly support cost. See our Client Playbook for how we work commercially.

Keep your legacy systems running while you plan the next step

Tell us about the system, what is worrying you, and the cover you need. We will come back with a written assessment, a recommended SLA tier, and a proposal you can take to the board.

Discuss Legacy Support All Managed Support Services

Cyber Essentials certified  ·  UK-based team  ·  Microsoft Partner  ·  Policies and evidence at our Trust Centre

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor