| What is stored | Source and named documents | Source with arrival record | Source, dependencies and build inputs | Full deposit, recovery inputs and release evidence |
| Is the code ever compiled | No | No | Yes | Yes, independently |
| Is it ever deployed | No | No | No | Yes |
| Is the production architecture replicated | No | No | No | Yes |
| Who tests it | Nobody | Custodian checks arrival | Build specialist | Castler agents and a named engineer |
| Is there a signed artefact | Deposit receipt | Integrity report | Build report | Signed Proof of Recovery |
| How often is it refreshed | Contract dependent | Contract dependent | Scheduled engagement | Per verified release |
| Typical coverage of the Software Estate | Selected contracts | Selected contracts | One or two codebases | Critical-Software Estate programme |
| Who bears discovery work at release | Your incident team | Your incident team | Your incident team after build | Procedure already documented |
| What your auditor receives | Agreement and deposit record | Integrity record | Build evidence | Build, deploy, replication and signed evidence |