Canopus Software & Engineering — home
For web, design and marketing agencies

A white-label development partner for WordPress and WooCommerce — invisible to your client.

You sell the site; your client only ever talks to you. We write the theme, plugins, WooCommerce logic and integrations — inside your own tooling: accounts you created, a repository you own, staging on your domain. Nothing carries our name.

NDA before you send a briefLive in 2–4 weeksIP assigned onward to your client
What a white-label development partner is

A white-label development partner builds under another agency's brand. For white-label WordPress and WooCommerce development that means our engineers work inside your repository, your ticket system and your staging domain, carrying no reference to us. Your client sees one supplier: you. We never contact them, during the project or after.

2–4 wksfrom first call to first commit, including NDA and process setup
100%IP assigned to you on payment, with onward assignment to your client
30 daysdefect warranty on what we build, then an optional retainer you resell
Zerodirect contact with your client — contractual, with a non-solicit term
Signature

The eight invisibility rules — every surface our name could leak through

Most white-label promises stop at "we won't tell anyone". A subcontractor's name rarely escapes through a person — it escapes through a staging subdomain, a plugin header or a commit email. Here is every surface, including the one we can't close alone.

The eight surfaces of a white-label WordPress engagement where a subcontractor's name can appear, and how each is handled. Seven surfaces are closed by configuration at kickoff: the proposal uses your template; the repository is your GitHub or Bitbucket organisation; documentation uses your template and tone; staging URLs sit on your domain; tickets live in your Jira, Linear or ClickUp; deploy notifications reach your Slack from your CI; and plugin and theme file headers name your agency. The eighth, commit author email addresses on a repository we do not control, is flagged at kickoff and closes only if you issue us addresses on your domain. SEVEN CLOSED BY CONFIGURATION · ONE HONEST RESIDUAL RISK 01 · The proposal 02 · The repository 03 · Documentation 04 · Staging URLs 05 · The ticket system 06 · Deploy alerts 07 · Plugin file headers 08 · Commit metadata Your template, your logo. We have no route to your client at all. Your GitHub or Bitbucket org, your branch and commit convention. READMEs and runbooks in your tone — forwardable unedited. staging.yourdomain.com. Never a canopussoft.com subdomain. Your Jira, Linear or ClickUp, on accounts you create and revoke. Your CI to your Slack, under your app name — not our bot. Author and Plugin URI name your agency, in every plugin we ship. A determined client can read a commit email. Flagged at kickoff. Rule 07 is the one nobody asks about: a plugin header reading "Author: Canopus" survives every NDA you sign.
Seven close with configuration at kickoff; the eighth we name before you sign.

01 · The proposal

Your template, logo and pricing. We never publish suggested resale rates — that would put a floor under your pricing.

02 · The repository

Your GitHub, GitLab or Bitbucket organisation from the first commit. Never "transferred later" — a transfer leaves a history.

03 · Documentation

READMEs, runbooks and licence register in your template, written to forward to your client unedited.

04 · Staging URLs

A subdomain on your domain or your client's — never a URL anyone could search and find us behind.

05 · The ticket system

Your Jira, Linear, ClickUp or Basecamp, on accounts you create and revoke. No parallel board to glimpse in a screen share.

06 · Deploy notifications

Alerts reach your Slack from your CI, under your app name. A bot called "canopus-ci" undoes the other seven rules in one message.

07 · Plugin and theme headers

The Author and Plugin URI fields in every plugin and theme name your agency — WordPress prints them in the admin plugin list.

08 · What we can't close alone

Commit emails on a repository we don't control. Issue us accounts on your domain and it closes; otherwise it stays a stated risk.

Every rule is configuration you can inspect on a call before signing. Comparing partners? Ask rule 07: whose name goes in the plugin header? It's the leak that survives longest — in your client's WordPress admin for the life of the site.

What we build

WordPress and WooCommerce first, then whatever the brief needs behind it

Most agencies arrive because a WordPress project outgrew plugins or a store outgrew its theme. The rest exists because those projects keep needing an API behind them.

Most requested

Custom WordPress themes, blocks and plugins

Builds where the design can't be bought and the logic can't be plugged in. Business logic lives in a plugin, never the theme, so a redesign can't delete the integrations.

  • Custom block patterns and block-theme work, editable by your client's staff
  • Advanced Custom Fields or native block bindings, modelled as structured fields

How we build WordPress

Stores and B2B

WooCommerce and B2B commerce beyond theme options

Stores that outgrew what plugins can express: tiered B2B pricing, quote-to-order approval, subscriptions, ERP-reconciled stock — built on High-Performance Order Storage.

  • Custom pricing rules, customer groups and negotiated price lists
  • Payment gateways — Stripe, Razorpay, PayPal, PayTabs — with 3-D Secure 2 handled properly
  • Stock, order and invoice sync to SAP Business One, Dynamics 365, Odoo, Zoho or Xero

How we build WooCommerce

When WordPress isn't the answer

Headless front ends, portals and the APIs behind them

The project you were going to decline: a client portal, a booking engine, a Next.js front end reading from WordPress. Same invisibility rules, different stack.

  • Next.js or React front ends over the WordPress REST API or GraphQL
  • Authenticated areas with roles and permissions, in Laravel, Node.js or .NET
  • CRM and ERP integrations — HubSpot, Salesforce, Zoho — with idempotency keys and visible failures
Continuous overflow

A reserved engineer or squad on your backlog

When the pipeline is steady. A named engineer works only on your accounts and attends your standups.

  • Same person month to month — they learn your standards instead of relearning them
  • You own the priorities, the backlog and the client conversation
  • Three-month minimum, then 30 days' notice either way

How reserved teams work

How it runs

Six steps, and what you hold at the end of each

Every step produces an artefact you can forward to your client without editing it first. That's the test we design the process against.

NDA, then the brief — with the client's name redacted

Signed before you send anything. We scope from the requirement, not the logo, and give you a straight yes or no on whether we should take the job.

An estimate written to be forwarded

Ranges with each assumption printed beside them, plus a list of what we weren't told. You re-price and send your own. A firm number needs a written scope — a forwarded email gets a range, and we'll say so.

Kickoff inside your tools, with the eight rules configured

Accounts in your repository, tickets and Slack. Commit identities, plugin headers and staging domains set before the first push — a corrected history is still a history.

Two-week increments, each ending on a staging URL

On your domain, so you forward the link with no caveat. A slip shows a fortnight in, not a week before launch, and reaches you in writing the day we see it.

Handover into your account

Runbook, licence register and editing notes in your template. Credentials transferred, our access removed, and recorded walkthroughs your client's staff can watch without meeting us.

After launch, still through you

A 30-day defect warranty at no cost on what we built: you raise the ticket, we fix it, you report it fixed. Ongoing updates and monitoring run as a retainer you resell, endable on 30 days' notice.

The commitments

Five things that are in the agreement, not just on this page

Agency–subcontractor relationships fail in the same five ways. Promises are cheap, so these are clauses.

Non-solicit

We never contact your client independently — not for a testimonial, a case study or follow-on work, and not after the partnership ends. If they approach us, we tell you and decline.

Commercials

You are the client — scope changes reach us as change requests from you. We don't negotiate with your customer or comment on your pricing.

Escalation

Bad news reaches you first, always — a date at risk reaches you before anyone else, blunt internal version included. You should never be surprised alongside your client.

Ownership

IP assigns to you on payment, with onward assignment rights — to your client, on your terms. We retain nothing and licence nothing back.

Exit

Either side can stop on 30 days' notice — with a full handover of documentation, credentials and known issues. A partnership that's painful to leave isn't one.

WordPress coreWooCommerce & HPOSAdvanced Custom Fields Block themes & patternsWP-CLIWordPress REST API Next.js & ReactLaravelNode.js.NET MySQL & PostgreSQLStripe & RazorpayCloudflareGitHub Actions

If a brief needs something we don't run in production — Salesforce or SAP configuration, say — we tell you before you quote it. For your client's security questionnaire, see what we hold and what we don't.

Commercials

Three structures, and who carries the estimate risk in each

The shape you pick decides who absorbs an overrun — worth choosing deliberately.

Fixed fee per milestone

Quoted per SOWWe carry the estimate risk

Against a written scope with acceptance criteria. Suits a defined build you've already sold, with a number you can mark up.

  • No monthly commitment
  • Costs more, because the overrun is ours
Send a scope

Reserved engineer

MonthlyCapacity guaranteed to you

A named engineer reserved to your agency, allocated across your clients. It prices better for steady volume and removes the availability question.

  • Same person month to month — learns your standards
  • You set priorities and run the standups
  • Three-month minimum, then 30 days' notice
  • Roll unused days forward one month
Reserve capacity

Time and materials

Per dayYou carry the estimate risk

Cheaper per unit of work, because you absorb the variance. Right for discovery or a backlog that isn't written yet.

  • Weekly burn reporting you can forward
  • Stop or pause between sprints
  • Not suitable if your client needs a fixed number
Compare the models

White-label work we turn down

  • Website projects under $3,000. The same floor as direct work — below it, coordination eats both margins, and a good template serves your client better.
  • Discovery-heavy scopes where we never reach anyone who understands the requirement. "The client wants a portal" is a paid discovery, not a build — we won't quote a fixed fee against a guess.
  • Reselling our marketing services to marketing agencies. You'd be reselling a competitor's core offer. Engineering only.
  • Direct approaches from your client. We tell you and decline — that rule is worth more than any job it costs.
Before you commit

What actually goes wrong in a white-label partnership

Three are the fears agency owners name on the first call. The fourth nobody asks about until it happens.

Your client works out the build was subcontracted

It rarely leaks through a person — it leaks through a staging subdomain, a plugin header, a commit email or a PDF author field.

How we handle it: seven of the eight surfaces are configured at kickoff. The eighth, commit authorship, we flag before you sign — your decision, not our omission.

The brief reached us third-hand and was wrong

The real limit of white label: it works on defined scopes and badly on discovery, where the requirement arrives two conversations removed.

How we handle it: no fixed fee on discovery-heavy work. We quote a paid discovery, run through you, and hand back a specification you can price.

A date slips and you carry the blame

You promised a date built on our estimate. When it moves, your client hears it from you, and the damage lands on your side.

How we handle it: two-week increments, each ending on a staging URL you can open, so a slip surfaces early — in writing, the day we see it.

The relationship starts drifting toward us

Your client meets our engineer, likes them, and starts asking questions directly. Six months later they wonder what your margin is for.

How we handle it: direct approaches go back to you, and we tell you it happened. Every engineer is briefed on that before repository access.

Questions

Licences, headers, support and who owns what

Whose name goes in the plugin and theme headers?

Yours. The Author, Author URI and Plugin URI fields in every plugin and theme name your agency, set before the first commit. It matters more than most of the NDA: WordPress prints them in the admin plugin list, in front of your client for the life of the site. Ask any partner this — it shows fast whether they've done it before.

Who buys the premium plugin and theme licences?

Your client does, in their own name, with a licence register listing every renewal date. We won't put an ACF Pro key or WooCommerce extension on our account — that dependency breaks when the partnership ends. Agency-level licences work too, if decided at kickoff rather than discovered at renewal.

How long does a white-label WordPress or WooCommerce build take?

A marketing site runs four to seven weeks once content is ready; a content-heavy build eight to fourteen; a WooCommerce store six to sixteen, depending on catalogue and integrations; anything behind a login twelve or more. The usual delay is content and third-party access, not code, so we set a content deadline in week one.

Can we put our own developers on the same repository?

Yes — often your developer on templates and ours on the plugin and integration layer. It works when the boundary is drawn at kickoff and enforced in code review: who owns which directories and whose conventions win. It fails when both sides edit the same functions file, so we draw that line before starting.

What happens when our client asks to speak to the developer?

You decide. By default you're the only voice and clarifications round-trip through you. Some partners put us on calls as their named technical lead, under their branding — fine if agreed in advance. What never happens is us contacting your client independently, during or after the partnership. That part is contractual.

Who supports the site after launch, and does our client ever hear from you?

Never. A 30-day defect warranty at no cost covers bugs in what we built: you raise the ticket, we fix it, you tell your client. Beyond that, updates, backups and security patching run as a retainer you resell at your own margin — the AMC shape under dedicated teams and support, endable on 30 days' notice.

Who owns the code, and can we assign it onward to our client?

You do — the code lives in your repository from the first commit. IP assigns to you on payment for the milestone in which it was written, with the right to assign onward to your client. We retain nothing and licence nothing back. The same position applies across every engagement model we offer.

How quickly can a new partnership start?

Two to four weeks from first call to first commit, covering NDA, agreement, accounts and conventions; later work usually starts within a week. Make the first project contained, before a flagship account is on the line.

Last updated: Maintained by Canopus partnerships

Become a partner

Send us a brief with the client's name taken out.

Thirty minutes with an engineer, not a salesperson. Bring the scope you're about to quote, or the late project you need off your team — you'll leave with a range and its assumptions.

Partnership enquiry

One business day, from a delivery lead. NDA before anything client-specific.
Call WhatsApp Get a Quote