FLEET-WIDE PATCHING & JOBS SERVICES
What we do.
01
OS & package patching
Linux and Windows patching in controlled waves with maintenance windows per environment.
02
Scheduled fleet jobs
Recurring jobs on your timetable — log clean-up, backups checks, certificate renewals, config enforcement, security scans and compliance audits.
03
On-demand fleet jobs
Need something run across every host now? Scripts, config changes, agent installs, credential rotation or incident commands — requested, tested on a canary and rolled out safely.
04
Canary & wave rollouts
Start with 1%, check health, then expand — automatically stopping on error thresholds.
05
Automatic rollback
Snapshots, blue/green or package pinning so failed changes revert without manual firefighting.
06
Inventory & drift
Know every host, OS version and package — and what’s out of compliance right now.
07
Kubernetes & containers
Node image rotation, rolling updates and base-image patching for EKS, AKS, GKE and OKE.
08
Compliance reporting
Patch compliance dashboards for CIS, PCI DSS, ISO 27001 and SOC 2 evidence.
09
Zero-day response
Emergency fleet-wide remediation when a critical CVE lands — planned, tested and rolled out fast.
010
Tooling & automation
We use the right proven automation for your estate — cloud-native or your existing tools — all built and versioned as code.
WHAT YOU GET
Built for scale. Designed for safety.
Every fleet job runs through the same guard rails: inventory, canary, health checks, progressive waves, automatic stop and rollback, then a report.
✓Full fleet inventory and patch baseline
✓Wave plan with health gates and stop conditions
✓Automated rollback for every job
✓Real-time job dashboard
✓Compliance reports for auditors
✓24/7 critical CVE response option
CERTIFIED TEAM
Led by certified cloud architects.
Fleet operations run by certified cloud and platform engineers.
AWSAWS Certified SysOps Administrator
MICROSOFTAzure Administrator Associate
CNCFCertified Kubernetes Administrator
RED HATRed Hat Certified Engineer
PRICING
Simple monthly or annual plans.
50% OFFLaunch sale — plus an extra 20% off with code EXTRA20
STARTER
Up to 500 hosts
£2,900
£1,450/mo
per month, billed monthly
+ £2,450 one-off onboarding (regular £4,900)
✓Monthly OS patch cycle
✓Canary + 3-wave rollout
✓Automatic stop & rollback
✓Patch compliance report
✓3 scheduled job types
✓5 on-demand job runs / mo
✓Business-hours support
SCALE
Up to 10,000 hosts
£9,900
£4,950/mo
per month, billed monthly
+ £7,950 one-off onboarding (regular £15,900)
✓Everything in Starter
✓Weekly patch cycles
✓15 scheduled job types
✓25 on-demand job runs / mo
✓Kubernetes node rotation
✓Critical CVE response in 24h
ENTERPRISE
10,000 to millions of hosts
£19,900
£9,950/mo
per month, billed monthly
+ £19,500 one-off onboarding (regular £39,000)
✓Everything in Scale
✓Multi-cloud & multi-region waves
✓Custom health gates & CAB integration
✓Unlimited scheduled & on-demand jobs (fair use)
✓Dedicated fleet engineer
✓24/7 on-call & SLAs
✓Volume pricing beyond 50,000 hosts
ONE-OFF OPTION
Fleet readiness assessment
One-off: full inventory, tooling review, risk snapshot and a rollout plan for your fleet — credited against onboarding if you go ahead.
£3,900£1,950
Order →✓ No setup fees on annual plans✓ Rolling monthly after 3 months✓ You own every account & asset✓ UK-based specialists✓ Prices exclude VAT
Onboarding covers fleet discovery, agent rollout, patch baselines, wave and rollback design, dashboards and runbooks. New custom jobs are built from £395 each (sale price); re-runs are included in your plan. Any third-party licence or cloud usage costs are billed to your own accounts. Volume rates quoted beyond 50,000 hosts.
RESULTS & REVIEWS
Proof, not promises.
Google4.9 ★★★★★120+ reviews
Clutch4.9 ★★★★★40+ reviews
SUCCESS STORY · SOFTWARE
120,000 hosts patched every week
120khosts per weekly cycle
99.7%patch compliance
0customer-facing incidents
Canary-first waves with automatic stop and rollback across three clouds, plus scheduled and on-demand fleet jobs.
Read the story →
SUCCESS STORY · SOFTWARE
AWS bill cut by 43% with no performance loss
−43%monthly AWS bill
£186ksaved per year
0minutes downtime
Rightsized EC2 and RDS, moved to Graviton, added Savings Plans and removed idle resources — then codified it all in Terraform.
Read the story →
★★★★★
“Compliance went from 71% to 99.7% without a single customer incident.”
Andrew T.Head of Platform, global SaaS
★★★★★
“Critical CVE rolled out across the whole estate in under a day.”
Priyanka S.Director of Infrastructure, telco
★★★★★
“On-demand jobs across 40,000 servers used to take a week. Now it’s hours.”
Lars E.SRE Lead, marketplace
FREE · NO OBLIGATION
Book a free fleet assessment.
✓ Free fleet assessment with a senior engineer
✓ Current patch compliance and risk snapshot
✓ Recommended tooling and rollout plan
GUIDES & INSIGHTS
Learn from our engineers.
CLOUD · 7 MIN READFinOps for beginners: how to control cloud costs as you growWhat FinOps is, the Inform–Optimise–Operate cycle, and practical first steps for AWS, Azure, Google Cloud and Oracle Cloud users.Read the guide →CLOUD · 9 MIN READAWS migration checklist: plan a move with zero surprisesAn interactive AWS migration checklist covering discovery, landing zone, security, migration waves, testing and cost optimisation.Read the guide →CLOUD · 8 MIN READHow to bring existing cloud infrastructure under TerraformA practical approach to converting click-ops infrastructure into Terraform — import blocks, state, modules and reaching a zero-change plan.Read the guide →
Fleet-wide patching & jobs questions, answered.
Yes — scheduled jobs (for example nightly clean-ups, weekly compliance scans, certificate renewals) and on-demand jobs (scripts, config changes, agent installs, emergency commands). Every plan includes a set number of scheduled job types and on-demand runs; Enterprise is unlimited within fair use.
Existing jobs can run within hours. New jobs need writing and canary testing first — usually 1–2 working days, or same day for emergencies on Scale and Enterprise.
One requested execution of a job across the hosts you choose — whether that is 50 servers or 50,000.
Onboarding is a one-off project: we discover and inventory every host, roll out or connect agents, define patch baselines, design canary waves and rollback, and build dashboards and runbooks. It is quoted up front and discounted by the launch offer and EXTRA20.
Software licences only give you the tool — you still need people to design waves, test, monitor and fix failures. We run the whole service end to end, on cloud-native automation or the tools you already own.
Yes — with the right orchestration, rate-limited waves and health gates, fleets of any size can be patched progressively.
The rollout stops automatically when error thresholds are hit, and affected hosts roll back. Only the canary wave is exposed.
Yes — plus containers and Kubernetes node images.
AWS, Azure, Google Cloud, Oracle Cloud and on-prem data centres.
Yes — config changes, certificate rotation, agent installs, scripts and audits across the whole fleet.
Our launch prices are already 50% off. EXTRA20 takes a further 20% off your first term — enter it above or mention it when you request a quote.
Yes — bundles across SEO, ads, email and tracking get an additional multi-service discount.