[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

DOCUMENT ESCROW

The documents that define your regulatory position should never live exclusively with a vendor

Contracts, regulatory filings, audit records, licence agreements, technical specifications, and compliance documentation — when these are held only by a third-party vendor, their failure, acquisition, or commercial dispute puts your legal rights and regulatory standing at risk. Castler custodies critical documents independently, verifies completeness on every deposit, and provides structured release when it matters most.

ISO 27001 · SOC 2 Type II · CERT-In · PCI DSS

Escrow scope
ContractsLayer 1
FilingsLayer 2
EvidenceLayer 3
ReleaseVerified
Custody mapped to signed evidence

WHAT IT IS

Document escrow, precisely defined.

Document escrow is a custody arrangement in which a vendor — or a party that holds critical documents on behalf of an enterprise — deposits those documents with an independent third party. The deposit is held in custody and released to the beneficiary if defined conditions are met: vendor failure, licence termination, regulatory access requirement, or commercial dispute where the vendor refuses to cooperate with document access requests.

The assets within scope are broader than most organisations initially recognise. The obvious cases are signed contracts and licence agreements — the legal instruments that define an organisation's rights to use vendor technology or services. But the full scope extends to regulatory filings made on the enterprise's behalf by a vendor; audit reports and evidence packs produced by a third-party auditor; technical specifications and integration documentation that exist only in the vendor's systems; and compliance records that regulators may request directly from the enterprise but which are held by the vendor.

Document escrow is not a document management system and it is not a backup. It is an independent continuity arrangement specifically designed to protect the enterprise's access to documents that define its legal rights, regulatory standing, and operational capability — against the specific risk that the holding party becomes unable or unwilling to provide access.

THE PROBLEM

Three document continuity failures that no other escrow type prevents.

01

The vendor holds the only signed copy of a critical agreement

A software licence agreement, a data processing agreement, or a regulatory undertaking: in many vendor relationships, the original signed document exists only in the vendor's document management system. If the vendor is acquired, enters administration, or is subject to a legal dispute, access to that document — the instrument defining your rights — may be blocked, contested, or lost entirely. Reconstructing the terms from memory or incomplete records is not a viable legal position.

02

Regulatory filings made on your behalf are inaccessible during an audit

Many regulated entities rely on vendors — managed service providers, IT outsourcers, audit firms — to make regulatory filings or maintain compliance records on their behalf. When a regulator requests evidence and the vendor is unavailable, the institution is held responsible for a gap in records it did not control. Document escrow ensures that every filing made on the institution's behalf is independently accessible regardless of the vendor's operational status.

03

Technical documentation that proves your compliance position disappears with the vendor

Security audit reports, penetration test results, vulnerability assessments, and system configuration documentation: these records underpin an institution's compliance posture. When produced by a third-party vendor and held only in that vendor's systems, a vendor failure can leave the institution unable to demonstrate historic compliance — at precisely the moment when a regulator or auditor requires it.

ASSET SCOPE

The document types held under Castler document escrow

Contracts and licence agreements

Master service agreements, software licence agreements, data processing agreements, SLAs, and any contractual instrument that defines the enterprise's rights in a vendor relationship — deposited as executed originals in PDF/A or equivalent archival format.

Regulatory filings and submissions

Filings made with RBI, SEBI, IRDAI, FCA, DORA-competent authorities, or any other regulator on behalf of the enterprise — including supporting evidence packs, certifications, and regulator correspondence — deposited at the time of submission and updated with every subsequent filing.

Audit reports and compliance evidence

Third-party audit reports, SOC 2 reports, ISO certification evidence, penetration test findings, vulnerability assessment results, and any compliance documentation produced by a vendor for the enterprise — deposited upon completion and version-tracked with each new engagement.

Technical specifications and integration documentation

API specifications, integration design documents, data model documentation, system architecture diagrams, and interface control documents that define how the enterprise's systems connect to the vendor's — critical for business continuity if the vendor relationship ends and integration must be replicated.

Licence and certificate records

Software licence keys, certificate files, cryptographic credentials, and third-party software entitlements that are managed by a vendor on behalf of the enterprise — deposited with expiry dates, renewal terms, and access instructions.

Board and governance documentation

Signed board resolutions, outsourcing governance records, vendor risk assessments, and due diligence documentation required by regulatory outsourcing frameworks — ensuring the institution's governance paper trail is independently accessible.

THE CASTLER APPROACH

Independent custody with completeness verification on every deposit.

Document escrow at Castler is not a file storage service. Every deposit is verified for completeness against the declared scope, checked for format integrity, and logged in a tamper-evident chain of custody. The result is an independently maintained document record that is legally reliable, regulatorily defensible, and accessible without vendor cooperation.

1

Deposit process

Documents are deposited via Castler's secure intake pipeline in agreed formats — PDF/A for signed originals, structured archives for multi-document packages. Every deposit is assigned a unique reference, timestamped, and added to a version-controlled inventory. The depositor receives a Certificate of Deposit confirming the asset inventory and the deposit timestamp.

2

Verification

On every deposit, Castler's verification process checks: that all documents declared in the deposit scope are present; that each document is in the declared format and is not corrupted; that metadata (document date, signatory fields, version identifiers) is consistent with the declaration; and that the deposit inventory is complete. For regulatory filings, verification includes a cross-reference check against the filing schedule maintained in the escrow agreement. Verification results are logged and available in the beneficiary's dashboard.

3

Update cadence

Document escrow is configured to match the update cadence of the document type. Contracts are updated at signature or amendment. Regulatory filings are deposited at submission. Audit reports are deposited at completion. The deposit schedule is defined at onboarding and enforced automatically, with alerts to both parties if a scheduled deposit is overdue.

4

Release

Release conditions are defined in the escrow agreement and typically include: vendor insolvency or administration; vendor acquisition where the successor entity declines to honour document access obligations; regulatory access requirement where the vendor is unable or unwilling to provide documents directly; and commercial dispute where the vendor has withheld or contested document access. Release delivers the complete document inventory in the agreed format, with the chain-of-custody record, to the beneficiary.

THE CASTLER APPROACH

Independent custody, verification, and release in one controlled record.

The beneficiary receives a Certificate of Deposit confirming the asset inventory and timestamp. On a valid release trigger, Castler delivers the complete document inventory in the agreed format together with the independent chain-of-custody record.

Document custody controls

PDF/A signed originals

Structured multi-document archives

Unique deposit references

Timestamped version inventory

Declared-scope completeness checks

Format integrity checks

Metadata consistency checks

Automated overdue-deposit alerts

Verification pipeline

Every deposit is checked against its declared scope, required format, metadata, and filing schedule. Verification results are logged in the beneficiary dashboard with a tamper-evident chain of custody.

Signed output

The beneficiary receives a Certificate of Deposit confirming the asset inventory and timestamp. On a valid release trigger, Castler delivers the complete document inventory in the agreed format together with the independent chain-of-custody record.

REGULATORY MANDATE

Document continuity obligations under active regulatory frameworks.

EU DORA

Financial entities must maintain complete and up-to-date documentation of their ICT third-party arrangements. Where critical documentation is held by the ICT provider, DORA's information and audit rights provisions create an obligation to ensure access — independently if necessary. Document escrow provides the structural mechanism.

Evidence map

EU NIS2

Essential and important entities must maintain documentation sufficient to demonstrate compliance with risk-management measures. For regulated entities that rely on third-party vendors for compliance operations, document escrow ensures that evidence packs remain accessible regardless of vendor status.

Evidence map

SEBI CSCRF — India

Cyber security and cyber resilience framework requirements include documentation of outsourced functions and evidence of ongoing oversight. Market infrastructure institutions must be able to produce this documentation on regulatory request — which requires independent custody when the vendor holds the originals.

Evidence map

RBI IT Directions 2023 — India

Exit strategy obligations for outsourced IT services implicitly require that all contractual and technical documentation governing the outsourcing arrangement is available to the institution independently of the vendor. Document escrow formalises this requirement.

Evidence map

ISO 27001

Information security management systems require organisations to maintain documented information as evidence of the operation of the ISMS — including records produced or held by third-party providers. Document escrow is a demonstrable control for this requirement.

Evidence map

ISO 22301

Business continuity management systems require access to critical documentation as a prerequisite for effective continuity response. Documents held exclusively by vendors represent a single point of failure in the continuity plan.

Evidence map
See all 17 mandates

CASTLER VS STANDARD DOCUMENT STORAGE

What document escrow provides that standard document management does not.

ComparisonVendor Document StorageInternal DMSCastler Document Escrow
IndependenceNone — vendor controls accessYesYes — third-party neutral custodian
Release on vendor failureNoN/AYes — defined release conditions
Completeness verificationNoNoYes — every deposit
Chain of custody recordNoLimitedYes — tamper-evident log
Regulatory defensibilityLowMediumHigh
Update cadence enforcementNoneNoneAutomated — alerts on overdue deposits
Audit trailVendor-controlledInternalIndependent third-party
Format integrity checkNoNoYes — every deposit

FREQUENTLY ASKED

Questions about this escrow type

What document formats does Castler accept?

Castler accepts all standard document formats for custody. Signed originals should be deposited as PDF/A (the ISO archival standard for long-term PDF preservation), which ensures the document remains readable without dependency on specific software versions. Supporting documentation may be deposited in standard formats including DOCX, XLSX, XML, JSON (for structured data exports), and standard image formats for scanned originals. Castler's intake team will specify the appropriate format at onboarding.

Can document escrow cover documents that are updated frequently?

Yes. The deposit schedule is configured at onboarding to match the update cadence of each document category. For frequently updated documents — regulatory filings, rolling audit reports, monthly compliance packs — Castler's automated deposit pipeline can accept and verify updates on the same schedule as the underlying document production cycle. The beneficiary's dashboard maintains a version history for every deposited document.

Is there a minimum or maximum number of documents that can be held in custody?

There is no minimum or maximum by document count. Escrow agreements are scoped by document category and volume at onboarding, and pricing reflects the deposit and storage volume. Most document escrow arrangements cover between 20 and 200 discrete document records across 4 to 8 categories, but both smaller and significantly larger scopes are supported.

How does document escrow interact with our existing document management system?

Document escrow operates independently of and in parallel with your internal DMS. The two systems serve different purposes: your internal DMS is an operational tool for day-to-day document management; Castler document escrow is an independent custody arrangement protecting your access rights against vendor failure. Documents deposited with Castler do not need to be removed from your internal DMS, and Castler's deposit pipeline can be integrated with common DMS platforms to automate deposit updates when documents change.

Can Castler hold documents in multiple languages?

Yes. Castler accepts documents in any language. For regulatory filings and compliance documents in non-English languages, the deposit inventory records the document language and the depositor may optionally include a translated summary for the benefit of Castler's verification team. The deposited original in its source language is always the authoritative version in custody.

GET STARTED

Identify which documents in your vendor relationships need independent custody.

A 15-minute briefing. We will map your critical vendor relationships, identify the document categories that currently sit exclusively within vendor-controlled systems, and show you what a structured document escrow arrangement looks like in practice.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day