Managed vulnerability patching · for self-hosted & on-prem infrastructure

Most breaches start with a patch nobody applied.

The software you self-host now gets critical, remotely-exploitable fixes almost every week. The gap between a fix shipping and someone applying it is where companies get breached — and that gap is now measured in days. StayPatched watches that clock and closes it, continuously.

Free exposure check — see what your services reveal to the internet

Reads only public data — certificate-transparency logs, DNS, and the version banners your services return to any visitor. Nothing is stored. Not a penetration test. How it works →

Reads only public data Nothing stored No trackers, no cookies

Why now

Patching used to be a monthly chore. Now it's a weekly race you lose by default.

AI-assisted discovery broke the old patch cycle. The same self-hosted software you've run for years now gets critical, remotely-exploitable fixes almost every week — and the time attackers need to weaponise them has collapsed to hours. Miss one, on a service that faces the internet, and that's how the breach starts.

~20%
more vulnerabilities published than a year ago — and rising
~66,000+
CVEs forecast for 2026 — a record year (FIRST)
3 days
to patch the worst actively-exploited flaws — the new CISA clock (BOD 26-04)
~10 min
for AI to produce working exploit code from a fresh disclosure (CSA, 2026)
The CVE firehose keeps growing
Published vulnerabilities per year — 2026 is on track for a record.
record
More software, found faster — much of it in the self-hosted stacks small companies run. A trend, not a spike.
The deadline vs the reality
Days to fix an actively-exploited flaw.
The deadline you're given14 days
The standard CISA clock — and as little as 3 days for the worst flaws since 2026 (BOD 26-04).
What organisations actually take~174 days
Median time to remediate — and only ~40% are fixed by the deadline at all (Bitsight).
~10 min AI can turn a fresh disclosure into working exploit code in ~10 minutes (CSA, 2026). The deadline is weeks, reality is months — the exploit is minutes.

Sources: FIRST 2026 CVE forecast, CISA BOD 22-01 & BOD 26-04 (remediation deadlines), Bitsight "A Global View of the CISA KEV Catalog" (median time-to-remediate), Cloud Security Alliance 2026 (AI exploit generation). A small team without someone watching this continuously can't keep up — that's the gap we close.

What it costs when it's missed

This isn't hypothetical — it's what the public data already shows.

Unpatched, internet-facing software is now one of the top ways companies get breached. The gap between "a fix exists" and "we applied it" is exactly where it happens — and it's getting wider, not narrower.

1 in 5
breaches now start with a known vulnerability being exploited — up 34% in a single year
$4.44M
average cost of a data breach — around $5.08M when ransomware is involved
~174 days
median time to fix a known-exploited flaw — only ~40% are fixed by the deadline at all
54%
of exploited edge & VPN device flaws ever get fully remediated — the exposed stuff rarely does

Sources: Verizon 2025 Data Breach Investigations Report (exploitation share, +34% YoY, edge-device remediation); IBM "Cost of a Data Breach 2025" (average & ransomware cost); Bitsight "A Global View of the CISA KEV Catalog" (median time-to-remediate). These are industry-wide figures — the point is the pattern every small company faces.

What we do

Continuous patching — prioritised by real risk, not patched blindly.

Not "apply every update and pray." Someone watching the vulnerabilities that actually affect the software you run, deciding what genuinely matters, and closing it fast — before a known flaw becomes your incident.

1

Inventory what you expose

We map the self-hosted and on-prem services you run and which of them face the internet — the attack surface that actually matters.

2

Watch every relevant CVE

Continuous monitoring of vendor advisories and vulnerability feeds for the exact software in your stack — not a monthly glance.

3

Prioritise by real exposure

Reachable from outside? Actively exploited? Known ransomware vector? That's what jumps the queue — the modern, risk-based approach, not "patch everything."

4

Patch, test, report

Planned, tested updates applied outside your business hours — backups verified first, rollback ready — with a plain-language report of what changed and why. Zero interruption to your operations.

Everything runs in your maintenance window — evenings, weekends, whenever the business is quiet. An update pushed during the working day can cost more in lost productivity than the fix itself; that's never how it's done here.

Continuity is built in: monitoring and alerting run around the clock, every system is documented in runbooks, and there's a named escalation path — so coverage doesn't depend on any one person being awake. Need a system rebuilt or moved off dead-end software before it can be kept current? We handle that too.

Who it's for

For companies that already self-host things they can't just move to SaaS.

Legacy and industry-specific software, on-prem systems kept for compliance or data-residency reasons, internal tools, OT — the stuff that can't be made someone else's problem with a subscription. If it runs on your infrastructure, it needs patching, and that's the gap we fill.

GitLabJira & ConfluenceBitbucket NextcloudZabbixGrafana KeycloakMattermostPostgreSQL / MySQL ProxmoxLinux serversFirewalls & VPN Reverse proxiesDocker / Kubernetes…and the rest of your stack

Don't see yours? If you self-host it, it almost certainly fits. Ask →

How it works commercially

A fixed monthly subscription, scoped to your estate.

It's a subscription, not a project: one predictable monthly fee for continuous monitoring, prioritisation and patching across the services we agree on — cancel month to month, no lock-in. Typically far less than carrying the specialist headcount it would otherwise take.

  1. Free exposure read. Start with the check above, or send your domain — we come back with an honest picture of what's exposed and current.
  2. Scope & fixed quote. We agree which services are covered; you get a fixed monthly price for them.
  3. We keep it patched. Continuous, from then on. Cancel monthly — no lock-in.
Get a free exposure read →

Straight answers

Questions a careful buyer asks.

Is the exposure check a penetration test?

No. It reads information your services already publish to anyone — certificate-transparency logs, DNS, and the version a service returns to a normal visitor — and matches that to published CVEs. No exploitation, no credential guessing, no attacks. It's a starting point for a conversation, not an assessment of your defences.

The version we expose is old, but we backported the fix. Will you cry wolf?

That's exactly why a person reviews findings, not just a scanner. A public version string can lag reality — distro backports, mitigations. The check flags what looks exposed; confirming whether it truly is, is part of the work. Flagging a patched system as critical is the fastest way to lose a competent admin's trust, and we don't do it.

Isn't a WAF or firewall enough?

For some flaws, a WAF rule can temporarily blunt a known exploit — but it's a bypassable stop-gap, and for whole classes (authentication bypass, access-control and logic flaws) it does nothing, because the malicious request looks legitimate. The only reliable fixes are patching the software or taking it off the internet. You can't WAF your way out of this.

Will patching interrupt our operations?

No. Updates are planned and applied outside your business hours — evenings or weekends — on tested, backed-up systems with a rollback ready. An update pushed during the working day can cost more in lost productivity than the fix itself, so that's never how it's done.

Why not just move everything to SaaS?

Where you can, often you should — and we'll tell you so. But most companies run things that can't move: legacy and industry-specific software, on-prem systems kept for compliance, internal tools, OT. For those, patching is a need, not a choice — and that's the work.

What happens if the engineer on your account is unavailable?

Coverage doesn't hinge on any one person: monitoring and alerting run continuously, every environment is documented in runbooks, and there's a named escalation path. For larger projects, we bring in additional vetted engineers.

Do I have to migrate anything to work with you?

No. The core service is patching what you already run. If a system needs rebuilding or moving off dead-end software before it can realistically be kept current, we can do that too — but it's optional, not a precondition.

Get in touch

Find out what needs patching — and who'll keep doing it.

Tell us your domain and what you run. We'll come back with a short, honest read of where you stand and what it would take to keep it patched. No obligation.

Your details are used only to reply to you. See the privacy notice.