Ongoing support - A daily check on your app

Every night I check that your app is up, that its security settings hold, and that nothing it is built on has a publicly known flaw. Each month you get a written report that proves it ran — the document a customer security review or an insurer asks you for. $49/month, and the first one months are free.

A daily check on your app · ongoing support

A Daily Check on Your App

Will Pickeral, William Belle LLC · support@williambelle.co

Your app works today. When that stops being true, you should hear it from me and not from a customer.

Most owners learn their app is down from a customer. They learn a security setting lapsed from an insurer. And they never learn that a flaw was published in something their app is built on, because nobody is looking. This is the cheapest way to fix all three.

** a month for one app. The first one months are free.**


What Happens Every Day

Every night, eleven checks run against your app. Five need nothing but your web address. The other six need the reporter — a small piece of software that sits inside your app and tells me what it is actually running.

What every night's check catches Needs the reporter
Your app has stopped answering
The security settings in front of it have lapsed
Your certificate is about to expire, or already has
Your domain registration is running out
Anyone can send email that looks like it came from you
Something your app is built on has a publicly known flaw
That flaw is one attackers are using right now
Or one they are most likely to start using this month
The platform underneath your app is behind on security fixes
That platform stops getting security fixes on a known date
Your app is running in development mode in production

A publicly known flaw is not a theory. Your app is assembled from parts other people wrote. When a serious flaw is found in one, it is published where anyone can look it up, including whoever is deciding whether to trust you. I check every part your app is actually running against that public record.

Being used is a different thing from being serious. Almost every tool sorts flaws by how bad they would be, so you get a list of forty and forty decisions handed back to you. I also check whether anyone is using them. The United States government publishes a list of flaws attackers are confirmed to be using, and a separate score estimates how likely each of the rest is to be used in the next month.

Those two disagree with severity often enough to matter. In a real example from this work, a flaw scoring 7.5 was far less likely to be used than one scoring 6.1. That is what lets a report say this one needs attention this week and the others can wait.

A platform's end date is the one problem you get months of warning about. Moving to a supported version is ordinary planned work if you know in October and an emergency if you find out in February.

About the reporter

It reads what your app is running and sends me that list. It accepts nothing back, changes nothing, sees none of your data, and cannot slow your app down.

It needs a server of your own to live on. If your app is a front end with no server behind it, the five address checks still run and the rest does not apply. I will tell you which you have before you pay for anything.

One honest limit: the domain check reads its date from the registry that holds your name, and not every registry publishes one. Where yours does not, I will say so rather than let a silent check look like a passing one.

What Arrives Every Month

A written report, in plain language, that tells you:

  • What was checked, and what it found
  • Anything worth doing, why it matters, and what it would cost to fix
  • Nothing, when there was nothing — see below

Keep the reports. They are your evidence that the checks ran. When a customer security review reaches you, when an insurer asks what you have in place, or when a regulator asks how you know your app is sound, this is the document that answers them. You cannot reconstruct it afterward; the value is that it was written down each month as it happened. Every report stays available to you, so losing the email loses nothing.

"We watch for vulnerabilities" is what everyone says. "Every part my app is built on was checked against the public record of known flaws, on this date, and here is the report" is a different kind of answer, and it is the one that ends the conversation.

A quiet month is the service working

Most months will find nothing. That is the point. A service that only feels valuable when something is wrong is a service people cancel in a good year.

The report still arrives, it still says the checks ran, and it is still the evidence you keep. You are not paying for problems to be found. You are paying to know, and to be able to prove it.


What This Is Not

Nothing is fixed under this agreement. If I find something, I tell you what it is, what it means for you, and what it would cost. You decide whether it is worth doing. Nothing is done, and nothing is charged, until you say so.

That is deliberate. A service that promised repairs at this price would have to say no when the repair was real, or stop existing. Keeping the watching separate from the fixing is what lets the watching stay cheap enough to have on every app you own.

If you want the version where the fixing is included, that is Keep your app running — an agreed number of hours each month for hands-on work, with the daily check included at no extra charge. It is quoted per app, because the hours are.

What It Costs

Apps covered A month
1 app $49
up to 3 apps $89
up to 6 apps $149

More than six apps is quoted rather than priced from this list.

The first one months are free, from the day the first app is added. You will get at least one full monthly report before anything is charged, so you can see what you are buying before you buy it.

You can stop at the end of any month. There is no term and no notice period.

What I Need From You

One thing: your written confirmation that you own the app and that you authorize me to check it.

This is not a formality. Checking an application without its owner's permission is the line between security work and something else entirely, and I do not cross it for anyone. Nothing runs against your app until that confirmation is on record, with the date and who gave it.

Everything else I need is public — the address your customers already use.

Getting Started

Reply to the email that brought you here, or tell me which app you want watched. I will confirm the address, record your authorization, and the first check runs that night.

Twenty minutes, and no pitch.

I'll tell you what I'd fix first in what you've built, and why. No pitch.