Website practice · design, build, host, maintain

Websites that are measured before they are promised.

MshenguX Websites designs, builds, hosts and maintains websites for public bodies and businesses. Every engagement starts the same way: we assess the site you have today, from an ordinary browser, and give you the findings in writing before we propose anything. Then one documented process takes the site from discovery to launch, and a monthly report keeps it that way.

The assessment

Six pages about your site, before you have paid us anything.

01

At a glance

What the site runs on and how it performs: platform and version, theme and plugins, web server, certificate, response time, and Google Lighthouse scores on desktop and mobile.

  • Platform
  • Certificate
  • Lighthouse
02

Findings and fixes

Every finding ranked critical, high, medium or low, with why it matters and the specific fix. Written for the person who owns the site, not for a vendor.

  • Ranked
  • Plain language
  • Actionable
03

Usability and accessibility

Automated checks mapped to WCAG 2.2 success criteria, Core Web Vitals on a phone, page language, alternative text, and what a manual audit adds.

  • WCAG 2.2
  • Core Web Vitals
  • Mobile first
04

Compliance signals

Whether a visitor can find the POPIA privacy notice, the PAIA manual, an accessibility statement, terms, a cookie notice and a way to contact you.

  • POPIA
  • PAIA
  • Accessibility statement
05

Security posture

Protective headers, transport security, version disclosure and files that should not be public, read from the outside the way a visitor's browser reads them.

  • Headers
  • TLS
  • Exposure
06

The first thirty days

What we would fix in week one, what we would measure and fix in weeks two to four, and what it takes to keep the site healthy after that.

  • Week 1
  • Weeks 2–4
  • Ongoing
Method
The assessment is passive and external: a few dozen ordinary page requests and two Lighthouse page loads, the same traffic any visitor's browser generates. No login attempts, no form submissions, no intrusive testing, and nothing that needs your permission. It is a snapshot, not an audit; a penetration test is a separate engagement under written authorisation, which we arrange with a specialist partner.
How we work

One process, six stages, a signed document at the end of each.

Discover. We assess the site, interview the people who own it, read the analytics, and agree in writing what the new site must do.
Weeks 1–2
01

Discover

Assessment, stakeholder interviews, analytics, content inventory, the ten tasks visitors come for, the legislative checklist.

Signed requirements
02

Design

Sitemap and information architecture, wireframes for the task pages, a design system with accessible contrast, two visual routes.

Chosen design · migration map
03

Build

The content management system your constraints call for, a staging site on our hosting standard, accessibility built in, forms with POPIA consent, the editor guide written as we go.

Staging site · editor guide
04

Test

WCAG 2.2 AA audit, Lighthouse on the task pages, browser and device matrix, security posture, page-by-page content sign-off, user acceptance.

Test report · acceptance
05

Launch

DNS cut-over with a rollback, redirects verified, monitoring switched on, credentials in your password manager, architecture note, backup and restore procedure.

Live site · handover pack
06

Maintain

Patches within seven days (critical within 48 hours), uptime and certificate monitoring, daily backups, quarterly restore test, quarterly re-assessment, annual accessibility review.

Monthly report · SLA
You own the domain, the hosting account and the codeYou sign at the end of every stageYou see uptime, speed, security and hours every month

Hosting, security and compliance

Hosting standard

Sites are hosted in South African data centres with an edge layer in front for TLS, a web application firewall, DDoS protection and caching. Where a tender mandates a particular cloud, we host there instead.

  • Daily off-site backups; a restore is tested every quarter
  • Uptime and certificate expiry monitored, with a named on-call person
  • Hosting passed through at the provider's price plus a stated management fee
  • Your organisation owns the domain, the hosting account and the code

Security, in two clearly separated levels

Level 1 is the passive posture review in every assessment: headers, transport security, version disclosure, public exposure and outdated libraries. It is included, and repeated every quarter under a maintenance agreement.

Level 2 is an authorised security test after award, under a signed authorisation naming scope, dates and source addresses, arranged with a specialist partner and priced separately. We do not claim it as an in-house capability.

Compliance

Every site we build meets WCAG 2.2 Level AA, carries a POPIA privacy notice with consent on every form, publishes the PAIA manual where a public body requires one, and states the site owner's details as the ECT Act expects.

Service levels in the maintenance agreement

PriorityDefinitionResponse
P1Site down, defaced, or data exposed4 hours, 24/7
P2Key function broken; security patch availableNext business day
P3Content change, minor defect, improvementFive business days

Public sector

We answer website RFQs and RFPs from national and provincial departments, legislatures, municipalities and public entities. Every proposal carries the assessment of the buyer's current site, the plan against the buyer's own timeline, and the statutory pack. Our supplier details are on the Bid Office page.

Stated plainly

This is a new practice. Our website reference list is being built, and every proposal says so. What we bring today is a measured assessment, a documented process, a supplier standing that is already in order, and the discipline of saying exactly what we hold.

Request a free assessment

Send us the address. We send back six pages about your site.

No obligation and nothing to install. The assessment is the same document we put in front of tender evaluators, written for whoever owns the site.

What we need
  1. The site address, and any others that belong to it.
  2. A contact who owns the site on your side.
  3. What you are considering: a redevelopment, a new host, maintenance, or a tender.
  4. A date, if there is one.