[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CLOUD CUSTODY / SOFTWARE ESCROW

Software escrow that starts with the vendor contract—and stays current through every release

Castler establishes the escrow agreement during vendor onboarding, captures the first complete deposit before the application becomes a live dependency, and keeps source code, build inputs, configuration, and release history continuously current in neutral, encrypted custody.

Established at vendor onboardingEvery release capturedGlobal cloud residency

THE CUSTODY CHAIN

Every release enters one controlled evidence chain

Capture, seal, isolate and retain the software materials your recovery procedure depends on.

01

Capture

GitHub · GitLab · Bitbucket · SFTP

02

Seal & inspect

AES-256 · SHA-256 integrity seal

03

Store

Multi-region · beneficiary isolation

04

Retain

versioned · tamper-evident

Cloud custody

AWS · Google Cloud Platform · Microsoft Azure · in-region localisation

Physical vault option

Delhi · Mumbai · Bangalore

THE CUSTODY STANDARD

Not a backup. A governed software continuity record

A category-leading escrow service combines legal control, automated deposits, secure storage, and a release process that can be evidenced before an incident. Castler brings those controls into one operating record from contract signature onward.

Neutral third-party control

The vendor, beneficiary, and Castler operate under one executed agreement with defined obligations.

Continuous release capture

Repository integrations keep the escrow record aligned with the software that is actually in production.

Encrypted, isolated custody

Deposits are protected in transit and at rest with role-scoped access and a complete audit trail.

Governed release conditions

Trigger events, notifications, evidence, approvals, and controlled release are defined before they are needed.

WHAT IS SOFTWARE ESCROW?

Software escrow protects access to software you depend on but do not control

Software escrow is a legal and technical arrangement between the software vendor, the enterprise beneficiary, and a neutral escrow agent. The vendor deposits the source code and the materials required to understand, build, and maintain the application. Castler holds them under agreed access, residency, update, and release rules.

The arrangement should begin when the vendor contract is signed—not after implementation, after the application is live, or when a regulator asks for evidence. Establishing escrow during onboarding makes the first complete deposit, update cadence, release conditions, and responsibilities part of the relationship from day one.

Secure custody protects access. Continuous repository sync keeps the deposit aligned with current production releases. Castler Software Recoverability can then rebuild, deploy, and seal that same deposit as a signed Proof of Recovery—turning a current escrow record into evidence that recovery can work.

WHAT CLOUD CUSTODY INCLUDES

Everything a compliant escrow deposit requires. And everything verification needs to run

The custody layer is designed for the full lifecycle of the vendor relationship: agreement, initial deposit, automatic updates, access control, audit evidence, and controlled release.

Always-current deposit

Castler integrates with GitHub, GitLab, Bitbucket, Azure DevOps, and private Git repositories to capture every release automatically. There is no manual re-filing cycle and no stale code forgotten after the original procurement. The deposit remains aligned with the production release.

Versioned and auditable

Every deposit is versioned with a timestamp, commit hash, release identifier, depositor, and source repository. The complete audit trail shows who deposited what and when, giving auditors an unbroken chain of custody from onboarding to the latest production release.

Encrypted and isolated

Deposits are encrypted in transit and at rest, logically isolated by customer, and protected through role-based access. Named parties receive only the permissions required by the tripartite agreement; repository and release activity remains recorded in the audit log.

Multi-party agreement management

Castler manages the tripartite software escrow agreement between the vendor, enterprise beneficiary, and Castler as escrow agent. Standard templates, custom clauses, digital signing, obligations, deposit schedules, and agreement changes are managed through one operating record.

Release-condition management

Define insolvency, acquisition, discontinuation, support failure, and other negotiated trigger conditions under which the deposit may be released. Castler manages the declaration, notification, evidence, and controlled release process when a contractual trigger occurs.

Global cloud residency

Deposits can be held in the agreed cloud region, including India, the UK, the EU, the US, Singapore, and the UAE, subject to service availability and the executed agreement. India customers can also select physical vault custody in Delhi, Mumbai, or Bangalore. This supports residency, customer, and regulatory requirements without limiting the platform to one market.

REGULATORY SOFTWARE ESCROW

For regulated institutions, custody must exist before the audit

Software escrow requirements differ by regulator, entity type, criticality, and deadline. The cards below summarise the key software-custody obligations; follow each link for the official reference, compliance timeline, detailed scope, and Castler evidence mapping.

THE UPGRADE PATH

Custody is the start. Recoverability is the standard

Cloud Custody establishes the deposit and keeps it current. It satisfies the foundational requirement to have software escrow and source-code access in place. But custody alone answers only half the question regulators, insurers, and boards increasingly ask.

The full question is: can you prove the software can be recovered?

A current deposit is necessary. It is not sufficient. Castler Software Recoverability adds agentic verification — rebuilding, deploying, and replicating the application from the deposit — and produces a signed Proof of Recovery. The upgrade uses the deposit and agreement already in Castler; the vendor does not start again.

Upgrade to full recoverability
Cloud CustodyCloud Custody + Software Recoverability
What you haveA current, versioned depositA deposit plus signed recovery evidence
Regulatory answer“We have software escrow”“We have a signed Proof of Recovery”
Requirement levelBasic escrow and source-code accessDeep recoverability evidence
Insurer signalBaseline custody controlIncreasingly relevant for cyber and technology E&O
VerificationNot includedBuild, deploy, replicate, and engineer seal
See published tier pricing

Software escrow, globally

Establish neutral third-party custody for critical vendor software across the regions your contracts and regulators require.

Current source code custody

Capture source, build inputs, runtime configuration, documentation, and release history in one continuously updated record.

Established during vendor onboarding

Put escrow in place when the vendor contract is signed—before implementation, production go-live, or regulatory scrutiny.

CLOUD CUSTODY

Establish software escrow when the vendor relationship begins

Put the agreement, first deposit, release schedule, residency, and release conditions in place before the application becomes a live dependency—or an audit issue. Upgrade the same custody record to full Software Recoverability when your programme is ready.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day