Skip to content
Proactive security updates
Maintenance & updates

White-Label Maintenance for Agency Client Sites

Agencies build shops, then care slips. How white-label maintenance works: cooperation models, SLA boundaries, tenant separation and reports in your own brand.

13 min read White-LabelAgenturpartnerSLAReportingWartungsvertrag

The shop is built, signed off and live -- and then begins the part for which the project plan had no field. Anyone building online shops as an agency or freelancer knows the pattern: the next project starts, care for the previous one runs alongside, and at some point the last update is a year old. External pressure grows faster than in-house capacity. In the reporting period from July 2024 to June 2025, the German Federal Office for Information Security counted a worldwide average of 119 (BSI, Situation Report 2025) newly disclosed vulnerabilities per day, around 24 percent (BSI, Situation Report 2025) more than in the previous period. At the same time, 87 percent (Bitkom, Wirtschaftsschutz 2025) of German companies were recently affected by data theft, espionage or sabotage. This guide shows how ongoing care for client projects can be handed to a partner without giving up the client relationship: which cooperation models exist, what belongs in the agreement, how tenants and logins stay separated, and what a monthly report looks like that the agency can pass on unchanged.

Key takeaways

  • Maintenance loses out structurally in project business: new builds tie up the same people, and the German economy is short of roughly 109,000 (Bitkom, IT labour market 2025) IT specialists -- cover cannot simply be bought in at short notice.
  • The threat landscape sets the pace: 119 (BSI, Situation Report 2025) newly disclosed vulnerabilities per day cannot be worked off between two sign-offs; they need a fixed rhythm.
  • Outages are expensive: 57 percent (Uptime Institute) of operators surveyed put their most recent major outage at more than USD 100,000, and almost 40 percent (Uptime Institute) of the organisations surveyed had a major outage caused by human error in the past three years.
  • White-label means the end client stays the agency's client. Reporting, incident notices and escalation run under your brand; the technical work happens in the background.
  • Three points carry the arrangement: an agreement that separates responsibility cleanly, separate logins per project, and a monthly report that can be passed on without rework.

Why maintenance slips in project business

Project work and operations follow different logics. A new build has a budget, a deadline and an end; the care that follows has neither, but does have a permanent claim on attention. In practice the project wins almost every time: it is visible, it is costed, and it pays in larger amounts. Maintaining twelve shops, by contrast, consists of many small tasks that are hard to plan and even harder to interrupt. When a security update lands on a Thursday evening, it competes with Friday morning's sign-off -- and loses. Making matters worse, the necessary capacity cannot simply be topped up: 85 percent (Bitkom, IT labour market 2025) of the companies surveyed report a shortage of qualified IT staff, and an open IT position stays vacant for almost eight months (Bitkom, IT labour market 2025) on average.

On top of that comes a coverage problem in time. A shop runs around the clock; an agency, as a rule, from Monday to Friday. If checkout fails on a Saturday afternoon, the damage is not decided by technical skill but by whether anyone picks up the phone at all. On-call duty is not a minor item: it costs money even when nothing happens, and in a team of three it is hard to staff without holiday and sickness gaps. Precisely in those gaps the expensive part of incidents arises. Almost 40 percent (Uptime Institute) of the organisations surveyed had a major outage caused by human error in the past three years, and 85 percent (Uptime Institute) of those incidents arose because procedures were not followed or were faulty. Silent failures in background processes surface especially late -- a separate article describes how cron jobs and imports can be monitored in their own right.

What white-label maintenance means in this article

White-label maintenance means a partner takes over the ongoing care of a shop while the agency remains the visible point of contact. The end client keeps their contract with the agency, receives reports in the agency's design, and reports incidents through the agency's channels. In the background, updates, monitoring, backups and emergency support run to a fixed procedure. What is not meant is the resale of anonymous standard packages: every project has a named scope, its own login and a record the agency can inspect at any time.

Six gaps that open up in agency day-to-day work

Anyone reviewing their own maintenance honestly tends to find the same six places where it thins out. None of them stems from negligence; they are side effects of an organisation built for projects. The economic backdrop makes them uncomfortable, though: cyber attacks now cause 202.4 billion euros (Bitkom, Wirtschaftsschutz 2025) in damage to the German economy each year, and 34 percent (Bitkom, Wirtschaftsschutz 2025) of companies were recently hit by ransomware. A shop whose security updates have been outstanding for months is an easily reached target.

Capacity taken by new builds

Sign-offs and milestones have dates; maintenance does not. In busy weeks it slides to the back and stays there.

No on-call cover

Outside office hours nobody is reliably reachable. A weekend incident only becomes a task on Monday.

Holiday and sickness gaps

In small teams, care hangs on one person. If they are out, there is no stand-in who knows the current state.

Missed security updates

Weeks rather than days pass between advisory and deployment. Automated attacks target exactly that window.

Missing evidence

Without records it is hard to show later what was done when -- to the end client as much as to an insurer.

Unclear ownership

When hosting, shop and extensions sit with different parties, the search for who is responsible delays every response.

What in-house care really costs per month

The decision for or against outsourced care is often made on gut feeling, because the effort is spread across many small tasks. A worked example brings clarity. Assume an agency looks after ten Shopware and WordPress projects of comparable size. The figures below are illustrative and can be replaced with your own; what matters is the structure of the items, not their exact amount.

Item per monthIn-house across ten projectsOutsourced care
Reviewing, testing and releasing updatesaround 15 hoursincluded in the per-project package price
Reviewing monitoring output and alertsaround 5 hoursincluded in the per-project package price
Backups and restore testsaround 4 hoursincluded in the per-project package price
Monthly reports for ten end clientsaround 4 hoursgenerated, in your own design
On-call cover outside office hoursretainer plus call-out timebundled across the portfolio
Tooling, test environment, recordsset up and maintained in-houseincluded in the per-project package price
Cover during holidays and sicknessfrom your own teamhandled by the on-call team

Pure working time adds up to roughly 28 hours per month. At an internal rate of 95 euros per hour that is around 2,660 euros -- time that does not flow into billable project work in the same period. The real lever, however, lies elsewhere: in on-call cover. It costs regardless of whether anything happens, and it can only be staffed sensibly above a certain team size. Cut it, and the risk shifts to the emergency itself. That price can be quantified: in 2023 the average loss per reported cyber incident was 45,370 euros (GDV), and 48 percent (GDV, Forsa survey 2025) of the companies surveyed have no emergency plan at all. Which services belong in a dependable arrangement is set out in the article on what a maintenance contract should include.

On-call cover is the item that is rarely costed

Maintenance hours can be estimated; on-call cover cannot. It requires two people in rotation, a documented handover and a practised procedure -- otherwise it is just a phone number. For an agency with a handful of projects, that effort bears no sensible relation to the return. Bundled across a portfolio of many shops, the same effort is spread across many shoulders. That is the economic core of outsourcing.

Three models of cooperation

Outsourcing does not mean handing over the client. Which model fits depends on how much administration the agency wants to keep and whether care is offered as a service of its own. All three variants can be mixed project by project -- one large long-standing client can be handled differently from three small shops. When care moves from a previous provider to a new one, the same diligence applies as in any maintenance handover without shop downtime.

ModelWho invoices the end clientFits when
Care in the agency's namethe agencythe client relationship should stay entirely with the agency
Rebate to the agencythe agency, at an agreed margincare is offered as your own service and should generate lasting revenue
Direct billing to the end clientthe maintenance partnerthe agency wants to hand over administration and only refer the client
  • Who is the end client's contracting party, and whose name appears on the invoice?
  • Under which brand do reports, incident notices and maintenance windows go out?
  • How is the tiering by project count arranged, and at what point does the next tier apply? Our maintenance packages form the basis for this.
  • May the partner contact the end client directly in an emergency, and from which point onwards?
  • What happens if an end client leaves the agency or hands the project on?
  • Which notice periods apply per project rather than to the whole portfolio?

Drawing the line: what belongs in the agreement

The most common friction in a white-label arrangement is not technical but sits at the boundary of responsibility. Who decides on a major update that forces changes to the theme? Who owns a custom-built extension that stops working after a core update? An SLA maintenance contract answers these questions in advance rather than during an incident. That such clarity is missing is the rule rather than the exception: 77 percent (GDV, Forsa survey 2025) of the companies surveyed consider themselves adequately protected against cyber attacks, while 52 percent (GDV, Forsa survey 2025) rate their IT security position better than it actually is. Which response times are realistic and how they can be measured is explored in the article on response times and emergency support.

  • Scope per project: core, extensions, theme, server, database -- what is included and what is expressly not?
  • Service hours and response times per severity level, separated into office hours and on-call cover.
  • Ownership of custom-built code: who checks it after an update, and who fixes the knock-on errors?
  • Approval rules: which changes may the partner deploy independently, and which need the agency's consent?
  • Handling of third-party services such as hosting, payment integration or shipping that sit outside your own access.
  • Data processing under data protection law, including the sub-processor relationship between agency, partner and end client.

Tenant separation and per-project access rights

As soon as a partner looks after several of an agency's client projects, separation becomes a core requirement. A collective account that fits ten shops is convenient and devastating in a breach: if it is compromised, every project is affected at once. The clean approach is the opposite -- one login per project, assigned to a person, with multi-factor authentication and tightly scoped rights. Changes run through a test environment first, as described in the article on staging environments for safe updates, and only then into the live system.

  1. Take stock per project: which logins exist, who holds them, and which are orphaned?
  2. Dissolve collective accounts and replace them with personal logins protected by multi-factor authentication.
  3. Trim rights to what is needed: maintainer, agency and end client each get a different role.
  4. Route server and database access through a shared jump host so every access is recorded.
  5. Provide a test environment per project, separate from the live system and without real customer data.
  6. Store records with a fixed retention period and keep them permanently visible to the agency.
project-access.yml
# Example: access and reporting matrix per client project
# One entry per shop, no shared collective accounts

project: client-a-shop
owner: sample-agency
visible_as: sample-agency

environments:
  live:    { jump_host: yes, mfa: required }
  staging: { jump_host: yes, mfa: required }

roles:
  maintainer: [server, database, shop-backend]
  agency:     [shop-backend, reports, records]
  client:     [shop-backend]

records:
  retention: 24 months
  access: agency, any time

report:
  cadence: monthly
  layout: agency
  send_to: agency

The report belongs to the agency

A white-label report is not an internal log with someone else's letterhead. It is written so the agency can pass it on without rework: understandable for the end client, free of internal tool names, with no trace back to the partner -- and with a clear statement of what was done during the month and what comes next.

Monthly reports you can pass on unchanged

The monthly report is the most visible product of outsourced care -- for the end client often the only one. It answers three questions: what happened, what was done, what is next? That includes availability in the reporting month, the updates deployed with dates and a reference to the relevant vulnerability, open items with a recommendation and an effort estimate, and the results of backup and restore tests. How security advisories can be turned into such a report in a traceable way is shown in the article on handling security advisories and vulnerabilities.

Just as important is what the report does not contain: internal ticket numbers, tool names or hints at the partner in the background. A good report reads like a service of the agency, because from the end client's point of view that is what it is. It becomes dependable through evidence rather than assertion -- a restore test only counts once it has actually been carried out and recorded, as the article on backup strategies for online shops describes in detail. The underlying data comes from ongoing monitoring, which records availability, response times and error patterns continuously anyway.

The escalation path when the client calls

The emergency decides the value of the agreement. If an end client phones the agency on a Saturday evening because checkout is stuck, there is no time to work out who is responsible. The path has to be in place beforehand and practised. That preparation pays economically: German online retail is expected to turn over around 92.4 billion euros (Handelsverband Deutschland) in 2025, and for the promotional days around Black Friday and Cyber Monday retail as a whole is forecast at roughly 5.8 billion euros (Handelsverband Deutschland) -- an outage during those hours hits especially hard. The fact that 57 percent (Uptime Institute) of operators surveyed put their most recent major outage at more than USD 100,000 underlines the same point. What such a procedure looks like in detail is described by our emergency support.

  1. The end client gets in touch through the agency's channel -- phone, form or inbox, exactly as they know it.
  2. The message lands in a shared inbox that is also watched outside office hours.
  3. On-call takes over according to the agreed severity level and confirms receipt back to the agency.
  4. Initial analysis and immediate measures run in the affected project's separate login, not through a collective account.
  5. The agency receives an interim update in a form it can pass on to its client unchanged.
  6. Once resolved, a short report follows with cause, measure and prevention -- built on a prepared emergency plan for the worst case.

How a white-label engagement starts

At the beginning there is no contract but a stocktake of the portfolio. For every project it is recorded which system runs in which version, how the server is built, which extensions and custom changes are in use, where the logins sit and when it was last updated. From that stocktake comes a grading: projects with catching up to do are brought to a clean state first, everything else moves straight into the ongoing rhythm. The portfolio is then taken over step by step, typically two to four projects per wave, so that procedures and report format can settle before the volume grows.

Outsourced care is working well when the end client notices nothing about it -- except that their shop is running and the monthly report arrives on time.

Principle of white-label care

The model works economically because monitoring, backups and on-call cover can be bundled across an entire portfolio instead of being arranged project by project. The enquiry option "Outsource maintenance" is designed for exactly that: it asks how many client projects need looking after, because the tiering follows that number -- from a handful of shops to a portfolio of more than 25. The starting point is the stocktake, which you can request without obligation: an honest assessment of which projects run cleanly today, which need catching up, and what continuous care would mean per month.

Sources and Studies

This article is based on data from BSI (Situation Report 2025), Bitkom (Wirtschaftsschutz 2025 and IT labour market 2025), GDV (Forsa survey 2025), Uptime Institute and Handelsverband Deutschland. The figures cited refer to the status at the time of their respective publication.

Related Articles