ESCROW TYPES
Every type of software and technology escrow. One platform
Escrow is not one thing. Source code, SaaS environments, AI models, data assets, and intellectual property each carry different custody requirements and regulatory implications. Castler handles all of them with agentic verification and signed Proof of Recovery for every deposit and release.
THE COVERAGE PROBLEM
One word. Six completely different risk exposures
When a CTO says “we have escrow,” they usually mean a legal agreement storing a copy of vendor source code. That may satisfy an audit checkbox. It does not prove recovery.
The assets inside that agreement are rarely verified. Assets outside it, including SaaS environments, AI models, proprietary datasets, and licensed IP, are usually not covered at all.
This is how a covered institution still cannot recover when a vendor fails. The agreement was real. The coverage was not.
1–2
Critical vendors with any escrow agreement
0%
Typically verified against actual recovery
5
Distinct asset types requiring different custody approaches
WHAT CASTLER COVERS
Choose your asset type
Each asset type has a dedicated page explaining the custody model, verification approach, and regulatory mandates that apply.
Source Code Escrow
Source code, configuration, build scripts, and dependencies, deposited, versioned, and agentic-verified to prove the codebase compiles and runs without the vendor.
RBI · SEBI · IRDAI · EU DORA · PRA SS2/21
Source Code EscrowSaaS Escrow
The full application stack: source, infrastructure-as-code, environment configuration, data export mechanisms, and the evidence that the service can run independently.
EU DORA · PRA SS2/21 · MAS TRM · APRA CPS 230
SaaS EscrowAI & Model Escrow
Model weights, inference pipelines, prompt configuration, fine-tuning datasets, evaluation harnesses, and the environment required to operate the AI system.
EU AI Act · EU DORA · RBI §12(f)
AI & Model EscrowData Escrow
Structured databases, unstructured datasets, schemas, and export pipelines with integrity verification on every deposit.
EU DORA · NIS2 · SEBI CSCRF
Data EscrowIP Escrow
Patents, trade secrets, proprietary algorithms, technical specifications, and licensed technology held under a defensible custody and release framework.
ISO 27001 · EU CRA · FFIEC TPRM
IP EscrowDocument Escrow
Contracts, regulatory filings, audit records, technical specifications, and compliance documentation held independently with completeness verification.
EU DORA · ISO 27001 · SEBI CSCRF
Document EscrowESCROW FORMAT
What format of escrow do you actually need?
The asset determines what must be deposited. The mandate determines what must be proven. The deployment model determines how verification must work.
| Requirement | Traditional Escrow | SaaS / Cloud Escrow | Castler Agentic Verification |
|---|---|---|---|
| What is deposited | Source code archive | Source, IaC, and configuration | Source and full runtime environment |
| Verification method | Manual audit or consultant PDF | Limited or none | AI-agent rebuild and replication |
| Output | We have an agreement | Code is stored | Signed Proof of Recovery |
| Frequency | One-off | Occasional | Every release |
| Regulatory answer | Checkbox | Partial | Full evidence package |
| Time to evidence | 2 to 4 weeks | 2 to 4 weeks | 6 to 18 hours |
Not sure which format applies? A 15-minute briefing will map your vendor estate to the right escrow type and mandate.
Book a briefingREGULATIONS COVERED
One platform. Coverage across every mandate
Every escrow type maps to one or more active regulatory requirements.
GET STARTED
Find out which escrow types apply to your vendor estate
A 15-minute briefing. We map your critical vendor estate against the assets they deploy, the mandates that apply, and the coverage gaps that currently exist.
Book a 15-min briefing