Answer · after launch

How do I maintain my app after launch?

Updated 11 September 2026

Maintenance after launch is five jobs you repeat. Keep dependencies patched. Fix the errors real users hit. Keep the tests and CI green. Make small improvements users ask for. And watch security. You can buy that work as an agency retainer, hire a part time developer, or do it yourself on a schedule. Or you can run an autonomous dev loop on the repo. The mistake is to treat maintenance as optional. An unmaintained app does not stay still. It decays, because its dependencies and platforms keep moving under it.

Compare the options on what they give you. An agency retainer buys accountability. It also buys human judgement. A loop buys throughput for a flat monthly fee. Most small products need throughput more weeks than they need judgement. On the weeks that matter, a human can step in.

What to do, in order

  1. Automate dependency updates

    Turn on automated pull requests for dependency updates. Check that CI runs on them. Most security risk in a small app comes from old libraries. Code people wrote is rarely the problem.

  2. Put error monitoring in front of your users

    You cannot fix what you never see. An error tracker tells you which failures real users hit and how often, which is a far better backlog than guessing.

  3. Keep the test suite and CI green

    A red build that everyone ignores is the same as no tests at all. Whoever keeps the app has to keep the gate useful. Every later safety net depends on it.

  4. Ship small improvements on a rhythm

    Work that only ever fixes things feels like decline. A small improvement each week keeps users happy. It also keeps the people who pay for the work engaged.

  5. Review security on a cadence

    Review the whole repo on a set date. Look at code, secrets in history, libraries, and infra config. Monthly is fine for most small apps.

What maintenance actually costs

Agencies pay for a team and for accountability. They are right when you need someone to own outcomes. A part time freelancer costs less, but depends on one person's time. Keelen is a monthly tier ($29 for Indie, $79 for Operator). You also pay for your own model use at cost. It supplies throughput rather than accountability. Pick the one you are short of.

See the plans →

How a loop covers the recurring jobs

Requests become roadmap items and tasks. The loop does eligible work. A separate reviewer then looks at the diff. A verified test command lets a failing test come first. It also runs the suite on a clean checkout. Merge then follows the required checks and your project policy. An outside agent or scheduler can call the scan tools through MCP. Use it for regular security review. Failed runs fall into 30 kinds. Small infrastructure blips and provider limits retry on a budget. They never count against your work. A real dead end becomes one plain English card in your Needs-you queue, with a recommended action. The project pauses instead of burning quota.

Keeping a human in the decisions that need one

Autonomy is a setting you pick for each project. Plan review makes a human approve the plan before any code is written. Manual merge means Keelen opens the pull request and you click merge. Branch-only means it pushes a branch and never opens a pull request at all. Pause one project or the whole fleet whenever you want the keyboard back.

What runs where, and what it can touch

Each run gets its own single use VM. It runs as a user without root and is destroyed when the run ends. Network egress goes through a proxy that denies by default. The GitHub token a run holds works on one repository for about an hour. It cannot change your CI workflows.

The security model →

Repeat reviews as the software changes

Reading new evidence is part of maintenance too. Look at code risk, legal exposure, and gaps in controls. Run a review after a big change. Or set a cadence in an outside scheduler. That scheduler calls Keelen's MCP tools. Triage the results before you pick code fixes. A legal review is not legal advice. A controls report is not a certification.

Recurring project reviews →

When Keelen is not the answer

  • You need someone accountable on a phone at 3am. A loop is not an engineer who is on call, and Keelen makes no uptime promise about your app.
  • Your app is closed source. It is not in a Git repo that Keelen can connect to.
  • You want a single human who holds the whole product in their head. That is a hire.

Hand the work to a loop

Connect a repository and write what you want in plain language. Review the tested pull requests that come back.

FAQ

How much should app maintenance cost per month?

It depends on what you are buying. Agency retainers price a team and accountability. A freelancer prices hours. An autonomous loop prices throughput: Keelen is $29 to $79 a month plus your own model subscription at cost. Compare on what you are short of. The headline number matters less.

Can AI handle maintenance on its own?

It can do the work you repeat: library updates, error fixes, small changes, and test upkeep. It cannot own the results of a decision. Keep a human on approvals for anything you cannot undo. Plan review and manual merge are there for that.

What happens if a change breaks production?

Nothing merges while a required CI check is red. Your own suite also runs on a clean checkout first. If something still gets through, the fix is the same as with any team. Revert the pull request. Every change is one pull request you can review and undo. That is the reason for it.

Does it work on a repository someone else wrote?

Yes. That is the common case. It reads the repository, detects the stack and the test command, and works from there. On an inherited codebase, run a security scan first so you know what you have before changing it.