faq
the questions, all of them
everything people ask before they hire us, pulled from every page on the site. each question has its own page, so you can send someone the one answer they need.
39 questions · 7 topics
39 questions
man home
working with us
see the pageQ:what does a "technical partner" mean?
it means one team owns everything technical so you don't have to hold it together yourself. we build the software, run the servers, fix the thing that broke on a saturday, and market what you ship. most clients start with one project and keep us on a small monthly retainer for everything after. you get a team you can talk to, not a ticket queue.
Q:will you take on a small or weird project?
yes, and those are often the best ones. migrating a mailbox, rescuing a site the last agency walked away from, turning a spreadsheet into a real tool, setting up backups that were never configured. if it's technical and it's blocking you, ask. if it isn't something we should do, we'll tell you and point you at who should.
Q:how fast can you ship?
a marketing site usually ships in 1–3 days. a custom web app depends on scope, but we break it into pieces you can click as we go rather than one big reveal at the end. you get a real date in the quote.
Q:is the price really fixed?
once we scope your project we give you one fixed number for that scope. it doesn't move unless you change what you're asking for, and if you do, we tell you the new number before we touch it. retainers are a flat monthly rate.
Q:do you do security on apps you didn't build?
yes. the security work stands alone. point us at a site or app you already have and we'll find the ways in, show you each one, and hand you a report with the fixes ranked, most serious first. we can do the fixes too, or your own team can.
Q:do we have to use you for all three things?
no. plenty of clients only want the build, or only the security review, or only the growth work. the three practices exist because most companies eventually need all of them, and it's cheaper and faster when the people running your ads also know how it's built.
Q:i'm not technical. is that a problem?
not at all, and most of our clients aren't. we explain things in terms of what you control and what you'll see, without the jargon. you describe the goal; we handle the rest and tell you where things stand in words you already use.
Q:what happens if we want to leave?
you leave. there's no lock-in: you own the code, the domains, the cloud accounts, and the analytics from day one. we hand over documentation and access, and we don't hold anything hostage. retainers are month to month.
man services
services
see the pageQ:can we start with one service and add others later?
yes, and most clients do. a build usually comes first, security follows before launch, and growth starts once there's something worth sending traffic to. nothing is bundled. you add a practice when you need it.
Q:do you work with our existing developers or agency?
often. we do the parts they don't cover (usually security, infrastructure, or paid ads) and stay out of their way on the rest. we'll agree who owns what in writing so nothing lands in the gap between us.
Q:what does a retainer cost?
it depends on the hours and the response time you need. we quote it after one call, and it's a flat monthly number with no per-ticket charges. if you use less than you booked, the balance rolls over one month.
Q:what if we only need a few hours of advice?
that's fine and it's cheap. book a call, bring the problem, and leave with a written recommendation you can act on with or without us. email hello@rebootworks.dev and say what you're stuck on.
man software
software
see the pageQ:who owns the code?
you do, from the first commit. it lives in your git account and you can take it to anyone. we don't use licence terms, private frameworks, or hosting tricks that make leaving expensive.
Q:can you work on an existing codebase?
yes. we start with a short review (what it does, what shape it's in, what's risky) and give you a written assessment before we change anything. sometimes the honest answer is that a rewrite costs less than the repairs.
Q:do you use AI to write the code?
we use it the way any current team does: scaffolding, tests, review. a human still reads every line before it ships. what we don't do is bolt an AI feature onto your product because it's fashionable.
Q:what about ongoing changes after launch?
either you take it over with the handover doc, or you keep us on a retainer for changes as they come up. small text and image edits are usually something your own team can do, because we set it up that way on purpose.
Q:do you do mobile apps?
we build web apps that work properly on a phone, which covers most of what people mean. for a true native app-store app we'll say whether it's warranted, and refer you on if it isn't our fit.
man growth
growth
see the pageQ:how fast do paid ads show results?
days for data, weeks for a decision. the first two weeks tell you whether the tracking is right and roughly what a lead costs. a month in, you know whether to scale, fix, or stop. search and AI visibility compound over 3–6 months, and anyone promising faster is selling you something.
Q:how much ad budget do we need?
enough to buy an honest answer in a few weeks, which depends on what a click costs in your market. we'll give you the number on the call. if it's less than we think works, we'll say so rather than take it. media spend goes straight to google and meta from your own card; our fee is a flat monthly number, never a percentage of what you spend.
Q:who owns the ad accounts?
you do. google ads, meta business, GA4, the pixel, and every bit of data they collect sit in your name from day one. we're added as a manager and removed the day you want us gone. an agency that owns your account owns your history, and that's leverage they shouldn't have.
Q:do we have to sign a twelve-month contract?
no. it's month to month. long lock-ins exist to protect the agency, not you. if the work is worth it you'll keep paying for it, and if it isn't you should be able to stop.
Q:can you run ads for a site you didn't build?
yes. we'll need enough access to fix what the campaigns depend on: the tracking, the landing pages, the forms. that means the CMS, the repository, or a developer who can ship what we send. if none of those exist, fixing that is usually step one.
Q:what happened to SEO, content, and GEO?
still here, as the layer that keeps paying after the ads stop. paid buys you results now and a fast read on which pages and messages convert. search and AI visibility make those pages keep working without a budget behind them. we run both and report them separately, so you can see which one is doing what.
Q:what is GEO, exactly?
generative engine optimisation: making sure AI assistants name you when someone asks a question you should own. it rewards clear, specific, well-structured source material and being cited elsewhere, far more than keyword density.
man it-security
IT & security
see the pageQ:who actually does the testing?
a person, not a scanner. the tester holds OSCP (Offensive Security Certified Professional, OffSec) and CPTS (Certified Penetration Testing Specialist, Hack The Box), and works the signed scope by hand. business-logic abuse and chained findings are the part no automated tool reports, and they are where most real breaches come from.
Q:is a pentest legal to run on our own systems?
yes, with written authorisation from whoever owns the system. we agree a scope, the testing window, and the rules of engagement in writing before anything starts, and we get sign-off from your hosting provider where they require it. we only ever test what's on that signed scope.
Q:how much does a pentest cost?
it's driven by the size of the attack surface: number of applications, roles, and integrations. a single web app with two user roles is a few days' work. we quote one fixed number after a short scoping call, and the retest is included.
Q:how often should we test?
annually as a baseline, plus after any significant change to authentication, payments, or your hosting setup. if you ship continuously, a lighter quarterly review usually beats one big annual exercise.
Q:can you help us pass a client security questionnaire?
yes. this comes up constantly when you start selling to larger companies. we'll answer the technical sections, write the policies you're missing, and fix the gaps the questionnaire exposes rather than wording around them.
Q:do you replace our IT support?
for a small team, usually yes. for a larger one we tend to sit alongside whoever handles helpdesk and take the infrastructure, cloud, and security side. we'll tell you which of those you need.
Q:what if you find nothing?
you get the report saying so, with the scope and methods documented, which is exactly what you hand a client or insurer who asked. it happens, and it's a good outcome, not a wasted fee.
man about
about us
see the pageQ:how big is the team?
deliberately small and senior. you talk to the people doing the work, and we bring in specialists we've worked with before when a project needs one. we'd rather turn work down than staff it with someone we can't vouch for.
Q:where are you based?
we work remotely and take clients internationally. everything runs over email, a shared channel, and calls when they're useful, the same way most engineering teams already work.
Q:what industries do you know well?
healthcare and clinics, logistics, trades and field services, professional services, and early-stage software products. we've also done enough one-off rescues to be comfortable in unfamiliar territory quickly.
Q:can you sign an nda?
yes, and we'll sign yours rather than insisting on ours. for security work we sign a scope and rules-of-engagement document as well, which protects both sides.
man contact
before you write
see the pageQ:what should I include in the first message?
what you're trying to achieve, roughly when, and any constraint that matters: a budget ceiling, a deadline, an existing system you have to keep. links to what you already have help more than a long description.
Q:do you charge for the initial call?
no. scoping conversations and the written plan that follows are free. we only invoice once you've agreed a scope and a number in writing.
Q:we're tiny. is there a minimum?
small projects are welcome, and a landing page or a one-day fix is real work. if something is too small to be worth engaging us for, we'll say so and tell you how to do it yourself.
Q:can you sign an nda before we talk?
yes. send yours over and we'll sign it before the first call. we're happy to work under your paperwork rather than insisting on ours.