Response by severity
Write a table with at least three severity levels, a definition for each, a response time for each, and the hours during which the clock runs. P1 is the store not taking orders, whether the site is down, checkout is broken or payments are failing. P2 is a function broken with a workaround. P3 is everything else. Then write the resolution target separately, because an agency that answers a P1 in 15 minutes and fixes it in two days has met a response SLA and failed the store. Ask what happens when the incident turns out to be on the host's side, and write that the response commitment survives the handoff.
This site's published reference points, read on 22 September 2026, follow. JetRails states a 15-minute emergency response SLA as an enterprise add-on, for infrastructure. Rocket Web states next-business-day urgent response on its $5,500 plan and same-business-day emergency response on its $9,500 plan, both within business hours. scandiweb states a first response within 24 hours and that showstoppers are triaged first, with no time per severity. Shero Commerce states a 2-hour response on critical issues for its Pro and custom Shopify plans, which does not transfer to a Magento contract. No agency on this site publishes an out-of-hours application response time, so that line will be negotiated from nothing.
Patch deadline
Write a number of days from Adobe's release to deployment in production for each patch type Adobe ships, meaning the annual full patch in May, the security-only -p releases, and the isolated security patches released between them. Write a shorter number for hotfixes. Then write the condition Adobe's own documentation imposes: an isolated security patch applies only to a store on the latest -p release of its line, so the contract must name who keeps the store there and within how many days of each -p release. Write who pays for the regression run on each patch and what the regression suite covers.
The published reference points are few. Rocket Web states security patches within five days of release and automated full-regression testing against changes and patches on its $3,500 plan. scandiweb's page says patches are applied on schedule and gives no number. The other six pages read publish no patch commitment. Adobe's versions page listed 2.4.8-p5, 2.4.7-p10 and 2.4.6-p15 as the 12 May 2026 patch levels; ask any candidate which -p release your store is on today and how long it took to get there.
Version and dependency clauses
Write the current version, the target version, the upgrade date and the budget line into the retainer for any store on 2.4.6 or older, because Adobe's lifecycle page shows those versions past standard support and, for 2.4.4 and 2.4.5, inside a security-only period with no quality fixes that ends 31 May 2027. For a Cloud store, write Adobe's enforcement date: from 1 June 2027 Adobe states it will stop maintaining Cloud environments on unsupported versions. Then write which dependencies the retainer keeps on supported versions, because Adobe states it does not patch PHP, MariaDB, OpenSearch, Redis or RabbitMQ, and lists PHP 8.1 end of life as 31 December 2025 and PHP 8.2 as 31 December 2026.
Exit terms
Write the notice period on both sides. Write the handover list, which means repository access with history, hosting and third-party credentials, environment variables, documentation of every custom patch applied and why, and the CI/CD configuration itself. Write that the automation, monitoring and documentation built during the retainer belong to the merchant. Write a transition period during which the outgoing agency answers questions from the incoming one, and a price for it. Of the eight pages read, one publishes a contract term of this kind: JetRails states there are no lengthy contracts and services are billed hourly. None publishes a notice period, a handover list or an ownership clause, so all of it is negotiated from nothing.
The ownership boundary
Write who holds root access, who owns firewall and CDN configuration, who owns the deploy pipeline, and who leads an out-of-hours incident when the cause is not yet known. Most incidents on a mature store land on the seam between host and agency, such as a firewall rule and a deploy in the same window, a certificate on a CDN nobody administers, or a Cloud deploy that fails on a setting the host owns. JetRails publishes the infrastructure half of the list, with a web application firewall, daily backups and PCI DSS Level 1 on its hosting page. The application half is not published by anyone on this site beyond Rocket Web's regression statement.
What the ranked agencies publish
| Agency | Response by severity | Patch deadline | Exit term | Source page |
|---|---|---|---|---|
| Rocket Web | Two levels, business hours | Five days | Not published | Managed services page |
| JetRails | 15-minute emergency, infrastructure, add-on | Not published | No lengthy contracts; hourly | Magento hosting page |
| scandiweb | 24-hour first response, no split | 'On schedule' | Not published | Magento support page |
| integer_net | Not published | Not published | Not published | Services page |
| Aureate Labs | Not published | Not published | Not published | Homepage |
| Classy Llama | Not published | Not published | Not published | Homepage |
| Shero Commerce | 2-hour critical, Shopify plans only | Not published | Not published | Shopify support page |
| SwiftOtter | Not published | Not published | Not published | Homepage |
The checklist
- Severity table with definitions, response time per level, clock hours, and a separate resolution target
- Days from release to production for full, security-only and isolated patches, and for hotfixes
- Who keeps the store on the latest -p release, and within how many days
- Who pays for the regression run on each patch, and what the suite covers
- Current version, target version, upgrade date and budget line
- Dependencies kept on supported versions, named one by one
- Notice period, handover list, ownership of automation, transition period and its price
- Owner of root access, firewall and CDN configuration, deploy pipeline, and out-of-hours incident lead
Every published term on this page is the agency's own statement, read on the date in the evidence ledger, and none is evidence that the term has been met. The contract is where a statement becomes a commitment. The buying guide covers how to shortlist, and the pricing guide covers what the price buys.