do we have to use you for all three things?
no. plenty of clients only want the build, or only the security review, or only the growth work. the three practices exist because most companies eventually need all of them, and it's cheaper and faster when the people running your ads also know how it's built.
the three practices are a menu, not a bundle. each one is scoped and priced on its own, and plenty of clients only ever buy one. the reason they live under one roof is what happens when a job crosses the line between them, which most jobs do eventually.
where the lines get crossed
- the paid ads report says the pixel double-fires and the landing page takes six seconds on a phone. at most agencies that becomes a ticket in someone else's developer queue. here the same people fix it that week
- the pentest finds a broken access check. the fix is a code change, and the person who found it can make it
- the new internal tool needs hosting, backups, and access for the staff who'll use it. that's IT, and it's ready on launch day instead of six weeks later
one contract also means nobody gets to say "that's not our part".
if you already have people for some of it
then we do the parts they don't cover, usually security, infrastructure, or paid ads, and stay out of their way on the rest. who owns what goes in writing so nothing lands in the gap. clients who do add practices usually go in this order: build first, security before launch, growth once there's something worth sending traffic to. see can we start with one service? and working with your existing developers.