Managed vulnerability patching · for self-hosted & on-prem infrastructure
The software you self-host now gets critical, remotely-exploitable fixes almost every week. The gap between a fix shipping and someone applying it is where companies get breached — and that gap is now measured in days. StayPatched watches that clock and closes it, continuously.
Why now
AI-assisted discovery broke the old patch cycle. The same self-hosted software you've run for years now gets critical, remotely-exploitable fixes almost every week — and the time attackers need to weaponise them has collapsed to hours. Miss one, on a service that faces the internet, and that's how the breach starts.
Sources: FIRST 2026 CVE forecast, CISA BOD 22-01 & BOD 26-04 (remediation deadlines), Bitsight "A Global View of the CISA KEV Catalog" (median time-to-remediate), Cloud Security Alliance 2026 (AI exploit generation). A small team without someone watching this continuously can't keep up — that's the gap we close.
What it costs when it's missed
Unpatched, internet-facing software is now one of the top ways companies get breached. The gap between "a fix exists" and "we applied it" is exactly where it happens — and it's getting wider, not narrower.
Sources: Verizon 2025 Data Breach Investigations Report (exploitation share, +34% YoY, edge-device remediation); IBM "Cost of a Data Breach 2025" (average & ransomware cost); Bitsight "A Global View of the CISA KEV Catalog" (median time-to-remediate). These are industry-wide figures — the point is the pattern every small company faces.
What we do
Not "apply every update and pray." Someone watching the vulnerabilities that actually affect the software you run, deciding what genuinely matters, and closing it fast — before a known flaw becomes your incident.
We map the self-hosted and on-prem services you run and which of them face the internet — the attack surface that actually matters.
Continuous monitoring of vendor advisories and vulnerability feeds for the exact software in your stack — not a monthly glance.
Reachable from outside? Actively exploited? Known ransomware vector? That's what jumps the queue — the modern, risk-based approach, not "patch everything."
Planned, tested updates applied outside your business hours — backups verified first, rollback ready — with a plain-language report of what changed and why. Zero interruption to your operations.
Everything runs in your maintenance window — evenings, weekends, whenever the business is quiet. An update pushed during the working day can cost more in lost productivity than the fix itself; that's never how it's done here.
Continuity is built in: monitoring and alerting run around the clock, every system is documented in runbooks, and there's a named escalation path — so coverage doesn't depend on any one person being awake. Need a system rebuilt or moved off dead-end software before it can be kept current? We handle that too.
Who it's for
Legacy and industry-specific software, on-prem systems kept for compliance or data-residency reasons, internal tools, OT — the stuff that can't be made someone else's problem with a subscription. If it runs on your infrastructure, it needs patching, and that's the gap we fill.
Don't see yours? If you self-host it, it almost certainly fits. Ask →
How it works commercially
It's a subscription, not a project: one predictable monthly fee for continuous monitoring, prioritisation and patching across the services we agree on — cancel month to month, no lock-in. Typically far less than carrying the specialist headcount it would otherwise take.
Straight answers
No. It reads information your services already publish to anyone — certificate-transparency logs, DNS, and the version a service returns to a normal visitor — and matches that to published CVEs. No exploitation, no credential guessing, no attacks. It's a starting point for a conversation, not an assessment of your defences.
That's exactly why a person reviews findings, not just a scanner. A public version string can lag reality — distro backports, mitigations. The check flags what looks exposed; confirming whether it truly is, is part of the work. Flagging a patched system as critical is the fastest way to lose a competent admin's trust, and we don't do it.
For some flaws, a WAF rule can temporarily blunt a known exploit — but it's a bypassable stop-gap, and for whole classes (authentication bypass, access-control and logic flaws) it does nothing, because the malicious request looks legitimate. The only reliable fixes are patching the software or taking it off the internet. You can't WAF your way out of this.
No. Updates are planned and applied outside your business hours — evenings or weekends — on tested, backed-up systems with a rollback ready. An update pushed during the working day can cost more in lost productivity than the fix itself, so that's never how it's done.
Where you can, often you should — and we'll tell you so. But most companies run things that can't move: legacy and industry-specific software, on-prem systems kept for compliance, internal tools, OT. For those, patching is a need, not a choice — and that's the work.
Coverage doesn't hinge on any one person: monitoring and alerting run continuously, every environment is documented in runbooks, and there's a named escalation path. For larger projects, we bring in additional vetted engineers.
No. The core service is patching what you already run. If a system needs rebuilding or moving off dead-end software before it can realistically be kept current, we can do that too — but it's optional, not a precondition.
Get in touch
Tell us your domain and what you run. We'll come back with a short, honest read of where you stand and what it would take to keep it patched. No obligation.