Your websites : online, up to date and secure. At all times, without you having to watch them.
2009
24
0
1
The problem
An unmaintained website: a measured risk, not a hypothesis
63 → 5 days
The average time between a vulnerability being published and its mass exploitation fell from 63 days in 2018-2019 to 5 days in 2023. Quarterly maintenance arrives after the battle.
Google Mandiant, Time-to-Exploit Trends 2023
Hacking: massive, automated, opportunistic
Outdated components (CMS, extensions, themes) are the leading cause of infection: 39% of CMSs were out of date at the time of the breach. Bots don't discriminate; the size of the website offers no protection. (Sucuri / GoDaddy)
Delisting and downtime
A compromised website gets blacklisted by Google: months to regain its ranking. And over a year, the gap between 99.9% and 99.5% availability is 8.7 hours of downtime versus more than 43. (Bpifrance, Kinsta)
Silent decay
The most common risk isn't the spectacular outage: it's the website that ages while nobody is watching. Broken forms, slow pages: leads lost every week, invisible in the dashboards.
What's at stake
Securing any website that collects personal data is a legal obligation (GDPR, art. 32), assessed over time, not on launch day. Regulators sanction inadequate measures even when no breach has occurred.
What the bots see
Your website, seen from the attacker's side
Three vulnerabilities, an extension unmaintained for 14 months: the target is locked.
PHP version out of support, headers missing, outdated CMS: all of it readable from outside, with no access whatsoever.
Our free audit performs exactly the same reading, before the bots do. No access to your environments, nothing to install: what an attacker sees, you see first.
A commitment that your website works, not a bundle of hours
Agencies, hosting providers, freelancers: your current set-up works, and we don't replace it. But it rests on best-effort commitments, hour-capped, reactive rather than proactive. Nobody monitors, nobody commits to uptime, and the unexpected fix ends up as a quote. Our contract transfers to Merkatis what used to stay with you: the burden of monitoring, detecting and fixing.
Monitor continuously
Availability checked 24/7; performance, forms, critical journeys, versions and vulnerabilities inspected every day.
Qualifies every alert
Each signal is qualified by an operator according to its severity, then handled under the protocol agreed upon: routine actions carried out directly, sensitive areas never touched without your approval.
Covers the fix
Bug, outage, incompatibility, vulnerability, broken page: handled within 24 business hours, with no cap on interventions and no quotes. You never again wonder "is this included?".
Proves the work
Every intervention is dated, checked by a project manager and published. The monthly report is drawn from it: it doesn't tell, it shows.
A dedicated platform, not a promise
Your portal: every website, in plain language
Readable without being a technician
A health score out of 100, a one-word status (healthy, ageing, at risk) and the number of findings per severity. Last scan, next scan: you always know where you stand.
Findings in plain language
Per monitoring area, every finding is dated, explained and rated: critical, important, info. Anything that cannot be measured is flagged as such.
What Merkatis has done for you
Every intervention is dated, signed and published after review by a project manager. The monthly report is drawn from it: it doesn't tell, it shows.
Screens from the Merkatis portal on a demo site. The dashboard shows observed facts only, refreshed every night.
Scope
What the contract covers
Everything that keeps your websites working is included, with no cap on interventions.
Fixes
Bugs, outages, incompatibilities, recovery after an incident: handled with no quotes, whatever the workload.
Prevention of known vulnerabilities
Watch on vendors' security patches, application prioritized by severity, configuration according to best practice.
Updates
CMS, extensions, themes, technical components and PHP versions: tested, then applied, with no service interruption.
Guaranteed restoration
Guaranteed rollback to the last valid backup. Backups run by your host, checked by us: real restoration tests, scheduled in the contract.
Monitoring
Availability checked 24/7; performance, forms, critical journeys, versions and vulnerabilities inspected every day. Alerts qualified by the team.
Monthly report
What was done, what was prevented, the overall state of your platforms and the points to watch next.
A problem with how the website works is never subject of a quote. It's covered by the contract. A backup that has never been tested is not a backup.
Plans
Two plans, one commitment that your website works
Continuity plan
The full guarantee
Your website works, at all times, without you having to watch it.
- Permanent monitoring and prioritized security updates
- Fixes with no cap and no quotes
- Response within 24 business hours
- Guaranteed restoration to the last valid backup
- Dedicated account manager, tracking portal and monthly report
Operations plan
Continuity + the day-to-day life of the website
You decide the content, we put it online. Your teams keep control of the message.
- Everything in Continuity
- Three content requests per month included: page, news item, form, document, visual
- Requests sent to your dedicated contact, qualified, scheduled, executed, published on the portal
- Beyond that: each request at the flat rate in your price list, known in advance
As an extra, in both plans: enhancements. New features, custom development, partial redesigns: quoted before any work starts, billed the month they’re carried out, by the team that already knows your platform.
Commitments
Four contractual commitments, not four promises
Response to any incident
Reported by your teams or detected by our monitoring. Estimated time to recovery communicated on pick-up, then updated at a fixed cadence until resolution.
Named, not an anonymous ticket
A dedicated manager knows your platforms, your history and your priorities. They are the one who commits, arbitrates and reports back to you.
A mutual commitment over time
Or six months for a first engagement: continuous monitoring cannot be promised month to month. In return, leaving is simple: two months' notice, full reversibility, access and documentation handed back.
Guaranteed, tested, not assumed
In case of disaster, your website is restored to the last valid backup, according to the policy documented in the contract. A guarantee backed by real, scheduled restoration tests.
Written, measured and reported commitments : that is what separates a continuity contract from a maintenance package.
How it works
Starting the contract, in four steps
Onboarding audit
Technical state of your platforms: versions, dependencies, security, backups, weak points. If your websites are healthy, the contract starts immediately; if not, the upgrade is precisely quoted. The audit also sets your content-update price list.
Upgrade if needed
The weak points identified are fixed on the basis of the approved quote. You enter the contract on a sound footing: we commit to a state we know.
Handover without interruption
Access to back offices and environments, history, review of the backup policy and first restoration test.
Monitoring goes live
Monitoring is deployed, the intervention protocol agreed upon is activated, your dedicated contact is named. The first health report arrives at the end of the first month.
Technical scope
Whatever the technology stack, a single point of contact
CMS and frameworks
Including custom development and comparable environments.
WordPress
Drupal
Laravel
PHP
Custom
Websites and portals
Corporate websites, catalogues, customer portals, multi-site and multilingual set-ups.
Security
Component security patches, configuration best practice, recovery after an incident, in coordination with your host.
Performance
Load times, technical optimisation, availability: measured and maintained over time.
Critical journeys
Forms, contact requests, logged-in areas: monitored and kept working continuously.
Enhancements
Content updates at flat rates from your price list; development and partial redesigns on quote, billed when carried out.
Our role is technical, not legal. We keep your platforms up to date with the latest security standards; your overall compliance remains managed by your advisers or cybersecurity providers.
Before any commitment
A two-stage audit, with no obligation
- The free audit. Our diagnostic tool analyses your website from the outside, with no access and nothing to install: versions detected, known vulnerabilities, performance, availability, certificates. Debriefed in a meeting.
- The in-depth audit. For platforms that warrant it, a full read-only review: dependencies, backups, weak points, any upgrade quoted item by item.
- The proposal. A contract sized to your real situation: technology stack, criticality, number of platforms, recommended plan and your website's own content-update price list.
You leave with an objective assessment of your platforms and any upgrade quoted, and you decide afterwards.
Unmaintained: frozen design, missing images, "best viewed with Internet Explorer 9".
Under contract: the same website, up to date, fast, secure.
Pricing
A simple boundary: covered, price list or quote
Covered by the contract
Everything that keeps the existing website working: the website as it is, online, up to date, secure, fast. If your host has an incident, we detect it, alert you and coordinate the resolution with them.
Content updates, from the price list
Pages, news, forms, documents: every routine request matches a flat rate known in advance, set in a price list established for your platform and appended to the contract. Depending on your plan, a monthly volume is already included.
Enhancements, on quote
New features, custom development, partial redesigns: quoted before any work starts, billed when carried out, delivered by the team that already knows your platform.