[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CASTLER SRP

The world's first AI-assisted Software Escrow & Recoverability Platform

Signed Proof of Recovery across your entire software vendor estate — at speed, using AI, verified by engineers

HDFC BankSBICanara BankUnion BankIndian BankIndia Post PaymentsNSDL PaymentsPine LabsMahindra Finance
HDFC BankSBICanara BankUnion BankIndian BankIndia Post PaymentsNSDL PaymentsPine LabsMahindra Finance

THE PROBLEM

If a critical vendor stopped supporting you tomorrow, how fast could you recover?

You run core operations on software you did not build. When a vendor becomes unavailable, the business halts and the loss compounds until recovery. It has already happened, in five different ways.

Different causes. Identical outcome: the software stops, and the loss grows until recovery.

4060

critical vendors in a typical Software Estate

23

covered by deep verification today

Recoverability Audit · live scan

Core Banking

core ledger · v9.x

SCANNING

Payment Switch

payment rails

SCANNING

Risk & Fraud

real-time scoring

SCANNING

KYC Orchestrator

identity stack

SCANNING

Lending Origination

loan lifecycle

SCANNING

Treasury & Reconciliation

settlement stack

SCANNING

Never rebuilt

The deposit has not compiled outside the vendor's infrastructure.

Never deployed

The runtime and operating procedure remain untested.

Never proven

No signed evidence shows the system runs without the vendor.

Stale by design

The stored release may no longer match production.

THE COVERAGE GAP

Most institutions have verified 1 or 2 vendors. Ever

Not by choice. By economics. Human-led verification makes 100% vendor coverage too slow and too expensive, leaving the majority of critical vendors as unverified risk.

01

$10–15K

per verification per codebase

02

2–4 weeks

per verification

03

1–2

vendors ever verified

SOFTWARE ESTATE · COVERAGE SCAN

40 critical vendors

38 UNVERIFIED

98%

TYPICAL ESTATE
NEVER INDEPENDENTLY VERIFIED

The risk is not one vendor

It is the unverified estate around it.

Castler turns estate-wide recoverability from a costly exception into the default

INTRODUCING THE SOLUTION

Castler SRPSoftware Escrow & Recoverability Platform

We take your vendor's software, rebuild it from scratch, and prove it runs — without the vendor

Every verification is reviewed and signed by a Castler engineer. You receive audit-grade evidence your regulator, board and risk team can rely on.

01 · Custody

Always-current source, configuration and scripts. Never stale, never lost.

02 · Agentic Verification

AI agents rebuild, deploy and replicate your vendor's application in a clean environment. No vendor involvement. No documentation required.

03 · Engineer's Seal

A named Castler engineer reviews the evidence and signs it.

Signed Proof of Recovery
app.castler.com/recovery/core-banking
Proof of Recovery
IN PROGRESSLIVE

core-banking-platform · v9.4

java/spring · postgres · kubernetes

Build ReportRUNNING...
SBOM (847 components)QUEUED
Deployment RunbookQUEUED
Replication TestQUEUED
SEAL #POR-2026-04821 · Verification Engineer

Estimated completion: 47 min

TIME TO EVIDENCE

2–4 weeks per codebase

6–18 hours

COST PER CODEBASE

Five figures per engagement

90% less than current verification cost

COVERAGE

~1% of your Software Estate

100% of your Software Estate

Output

TRADITIONALStored source code

CASTLERSigned Proof of Recovery

Verification time

TRADITIONAL14+ days per codebase

CASTLERHours

Coverage

TRADITIONAL1–2 vendors

CASTLERYour critical Software Estate

Frequency

TRADITIONALOne-off engagement

CASTLEREvery verified release

Regulatory answer

TRADITIONALWe have an agreement

CASTLERHere is the signed evidence

How AI-agent software verification works →

WHAT YOU RECEIVE

One signed pack. Per vendor. Per release

Castler rebuilds the software in a clean environment and records the result. You receive a signed set of audit-grade artefacts for the verified release.

SEALED

Castler · Certificate of Recoverability

Aurora Core · Release 24.11.3

Seal №POR-2026-04821
Date2026-06-10 · UTC
StatusVERIFIED
SBOM Components847 verified
Build Report
Deployment Runbook
Replication
SBOM

A. Mehta, Verification Engineer

castler.io/verify/POR-2026-04821

verify.castler.com/POR-2026-04821 · selected: Build Report

Regulator readinessAUDIT READY
EU DORA96%
RBI IT §12(f)92%
SEBI CSCRF88%
IRDAI CS 202384%
Verification queueLIVE

core-banking-engine

v9.4 · 847 SBOM

VERIFIED12m

payments-gateway

v3.2 · rebuild

RUNNINGnow

risk-engine

v1.8 · queued

QUEUED

kyc-orchestrator

v5.1 · 412 SBOM

VERIFIED2h
Recoverability scoreSEALED
A−

Aurora Core · v24.11

Independently verified

Posture92 / 100
Build Report Runbook Replication SBOM
Open the platform

THE GLOBAL REGULATORY MANDATE

The regulator stopped asking “Do you have escrow?” It now asks “Can you prove recovery?”

Across financial regulation, cyber-resilience rules and global assurance standards, the direction is converging: critical third-party software must remain current, testable and recoverable when its provider fails.

17

MANDATES

9

JURISDICTIONS

European UnionUnited KingdomUnited StatesAustraliaSingaporeSaudi ArabiaUnited Arab EmiratesGlobal StandardsIndia
Explore every mandate and evidence map

TRUSTED BY INDIA'S LEADING INSTITUTIONS

The institutions that cannot afford to be wrong already chose Castler

RELATIONSHIP PROOF

100%

customer retention

100+

Enterprise customers

150+

Escrow agreements executed

17

Regulatory mandates covered

9

Jurisdictions

SELECTED INSTITUTIONS

Banks, payment networks and financial platforms

HDFC Bank
SBI
Canara Bank
Union Bank
Indian Bank
India Post Payments
NSDL Payments
Pine Labs
Mahindra Finance
ASSURANCEISO 27001SOC 2 Type IICERT-InPCI DSSBest Cybersecurity Startup of the Year · Government of India

INDEPENDENT RECOGNITION

Awards & Recognition

See all awards
KPMG Global Tech Innovator Competition 2026 — India Finalist recognition

KPMG Global Tech Innovator Competition 2026 — India Finalist

KPMG India

PICUP Fintech Awards 2026 — Finalist recognition

PICUP Fintech Awards 2026 — Finalist

FICCI & Indian Banks' Association, knowledge partner Boston Consulting Group

Best Cybersecurity Startup of the Year recognition

Best Cybersecurity Startup of the Year

Time2Leap National Awards — MSME & Startup Innovation Summit, Government of India & Government of Delhi

Finalist — Award of Excellence, Innovation in Digital Transformation recognition

Finalist — Award of Excellence, Innovation in Digital Transformation

16th Aegis Graham Bell Award, supported by MeitY, Government of India

India's Top 5 — Best Digital Banking Platform & Best Payment Solution recognition

India's Top 5 — Best Digital Banking Platform & Best Payment Solution

Global Fintech Awards 2025, Global Fintech Fest & IAMAI

Best Escrow-as-a-Service Platform recognition

Best Escrow-as-a-Service Platform

Wealth & Finance International Fintech Awards 2025

FREQUENTLY ASKED QUESTIONS

Software recoverability, answered

What is software recoverability?

Software recoverability is the ability to rebuild, deploy and operate critical vendor software without relying on the vendor. Castler verifies this independently and records the result as a signed Proof of Recovery.

How is Castler SRP different from traditional software escrow?

Traditional escrow stores source code. Castler SRP adds independent build, deployment and replication verification so regulated institutions receive current evidence that the deposited release can actually be recovered.

What does a signed Proof of Recovery include?

Each verified release can include a Build Report, Deployment Runbook, Replication Report, SBOM, Confidence Score and an Engineer’s Seal from the named Castler engineer who reviewed the evidence.

Can Castler verify an entire Software Estate?

Yes. Institutions can begin with one critical application and expand verification across their Software Estate as new vendors and releases enter the platform.

Read all frequently asked questions →

SOFTWARE RECOVERABILITY

Find out how much of your Software Estate is actually recoverable

A 15-minute briefing. We will walk your Software Estate, name the regulation that applies to you, and show you a real signed Proof of Recovery.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day