salix · operations

How we run what we build.

Anyone can write that they care about reliability. This page says what actually happens after launch day: what runs on a schedule, what gets checked, who is responsible, and what we do not offer.

Written for the person doing the due diligence: a board member, a school IT lead, or anyone who has been burned by a developer who disappeared after invoicing.

§ 01 · While it is running

What keeps a live
site live.

For sites we host. If you host it yourself, these become your jobs, and we say so in the handover rather than letting you find out.

Backups, off site

Databases are backed up nightly, and the copy is held somewhere other than the machine it came from. A backup on the same server as the thing it protects is not a backup.

Patching and certificates

Dependencies are updated and TLS certificates renew automatically. A shop whose certificate lapses shows every customer a browser warning, and it happens to sites nobody is watching.

One monthly number

Hosting, backups, patching and certificates are one fixed monthly figure, written into the quote. Nothing is metered, so a busy month does not produce a surprise invoice.

A person, by name

Support goes to a human who already knows your build, on 021 297 1074 or info@salixtech.co.nz. There is no ticket queue, because there is no one to hand you to.

§ 02 · Checked on a schedule

Checks that run
without being remembered.

Every control here exists because relying on someone to remember is how things get missed. They run whether or not anyone is thinking about them.

A weekly sweep of every deployment

Every Monday morning an automated job walks every project we run and reports three things: what each one is costing, whether any service that should idle when unused has stopped doing so, and whether the automated tests are passing on every repository. The report is written to a dated file whether it finds anything or not, so a week with no report is itself a signal.

A scan of what strangers can actually reach

Databases behind our applications are queried with the same public credentials any visitor has, table by table, and any table that answers with real rows is a failure. The question is not whether a security policy exists. It is what a stranger actually gets back.

A scan of the code we ship to browsers

A separate check downloads the JavaScript our live sites serve, over the public internet, the way anyone could, and looks for credentials that should never leave a server. It reads the built file rather than the source, because a key can be correct in the code and still be published by one wrong setting at build time. That class of mistake does not exist in any repository, so no amount of reading the source would catch it.

Accessibility, measured rather than asserted

This site was audited against WCAG 2.1 AA with axe-core across ten pages, at desktop and phone widths. It found 229 colour-contrast failures on nine pages, almost all traceable to a single grey used as small text. They were fixed and re-measured to zero, and the two colours involved now carry their measured ratios in the code so nobody reaches for them as type again.

§ 03 · If you leave

Nothing here is
a hostage.

The test of a software supplier is not how it behaves while you are happy.

Your domain is yours

Registered in your name, not ours. It is the one thing that makes every other option possible, and the most common thing a departing supplier turns out to be holding.

Your data, on request

A full export of your content, products, customers and orders, whenever you ask, without a reason and without a fee.

The manual is already published

The documentation we hand over is on this site, readable now, before you have signed anything.

We will help you move

Including to a competitor. What we will not claim is that a shared platform can be lifted out and run elsewhere as it stands, because it cannot, and that is said in the quote rather than at the exit.

§ 04 · What we do not offer

The limits, before
you ask.

A page like this is only worth reading if it also says what is missing. If one of these is a dealbreaker, better to know now than in month four.

No 24/7 on-call

Support is weekdays, New Zealand hours. Urgent things outside them get looked at when they are seen, which is often but not contractually. If you need a guaranteed overnight response, we are the wrong supplier and will say so.

No uptime SLA with money attached

We do not sell a credit-backed availability guarantee. The infrastructure underneath is the same managed platform larger companies use, but the promise would be ours to keep and we will not write one we cannot staff.

No formal certification

Salix holds no ISO 27001, SOC 2 or equivalent audit. The practices on this page are real and documented, and they are not the same thing as an external auditor having checked them. If your procurement requires one, we will not pass it.

A small team, which cuts both ways

One person who knows your system well is faster and more accountable than a rotating team, and is also a single point of failure. Source code, credentials and documentation are structured so another developer could pick the work up, which is the mitigation, not a denial of the risk.

Not GST registered

Salix Limited is under the registration threshold, so quotes carry no GST. If you are claiming GST back on the work, there is none to claim, and that is worth knowing before you budget.

§ 05 · Contact

Ask us something
awkward.

We read every enquiry ourselves and reply within two working days. Quick chats, long briefs, half-formed ideas: all welcome.

If there is a question this page did not answer, it is probably the one worth asking. Send it over, and you will get a straight answer or an honest no.

Phone
Call or text: you get Vakkas, not a queue.