Ship & Sleep / Handbook

How we operate. Public, so you can hold us to it.

This is the working handbook behind every Ship & Sleep engagement — the defaults, rituals, and mechanics. It's published because trust that can't be inspected is just marketing.

Defaults

What happens when nobody is sure what should happen.

Fail closed

In any ambiguous situation the default action is the one that cannot destroy anything: pause the migration, hold the update, ask the owner. Speed is recoverable; data usually isn't. This default comes from operating systems where a wrong guess prices itself within minutes.

Written before risky

Anything beyond routine patching is proposed in writing and approved before it happens. The message is short — what, why, risk, rollback — but it exists, and it's in your report archive afterwards.

Evidence beats assertion

"It works" is a claim; a log line is evidence. Reports quote the evidence: restore timings, patch verifications, incident timelines.

Rituals

The recurring work that prevents the exciting work.

The restore drill

On a fixed schedule — quarterly on Care and Standard, monthly on Priority — we recover the app from backup for real and write down how long it took. Not a checkbox in a dashboard: an actual recovery, end-to-end. The timing goes in your monthly report. A backup that was never restored is a rumor.

The patch pass

Security and dependency updates on schedule, each verified against the app's money-and-data paths afterwards. Anything that could break payments waits for written approval per the fail-closed default.

The monthly report

What ran, what broke, what changed, what it cost — including the things that make us look ordinary, like "nothing happened this month." Quiet months are the product.

The postmortem

Every incident ends with a short written postmortem: what happened, why, what changed so it doesn't repeat. Numbered, archived, yours.

Mechanics

The plumbing of accountability.

Credentials

Least privilege, stored in a dedicated vault, never in chat logs or plaintext files. Access changes are logged in your report. On exit, access is revoked, credentials rotated, and both confirmed in the handover document.

The runbook

Every adopted app has one from day one: architecture, credential map, deploy path, known risks, recovery steps. It's yours, it's current, and it deliberately makes us replaceable — which is why clients stay.

SLA credits

Committed response times are tracked against actual response times. A miss credits 10% of the month automatically, capped at 50%. No claim form, no discussion — the mechanism doesn't care whose fault it was.

Capacity

The roster is deliberately limited. When it's full, the intake says so and offers a waitlist instead of degrading everyone's service. Growth that breaks the SLA isn't growth.

Hold us to all of it.

The Health Check is where you watch this handbook applied to your own app — read-only, $249, guarantee-backed.

Request a Health Check