The operating environment is missing
A SaaS application running on Kubernetes, managed databases, private networking, and vendor APIs cannot be recovered from source code alone. The infrastructure and configuration are part of the system.
SAAS ESCROW
SaaS means you never hold the software. A traditional source code deposit does not change that. Castler captures and verifies the full SaaS application stack: source, infrastructure, configuration, and data export mechanisms, tested in a clean environment without vendor involvement.
WHAT IT IS
SaaS escrow is a continuity arrangement for software delivered entirely as a cloud-hosted service. The vendor runs the application, controls the infrastructure, manages updates, and controls access. The enterprise dependency is total.
A source code deposit assumes the beneficiary can take the code and run it. SaaS applications often depend on vendor-managed infrastructure, databases, multi-tenant orchestration, and private APIs. Source alone addresses only one layer of the recovery problem.
SaaS escrow must cover source code, infrastructure-as-code, environment configuration, database schemas, data export mechanisms, integration maps, and operational runbooks. Castler verifies the entire stack in a clean environment.
THE PROBLEM
A SaaS application running on Kubernetes, managed databases, private networking, and vendor APIs cannot be recovered from source code alone. The infrastructure and configuration are part of the system.
Multi-tenant applications require a documented way to isolate one organisation's data and configuration. That recovery path is rarely present in a standard code deposit.
A rebuilt SaaS application is useless without a current operational dataset, schema history, export format, and tested restore procedure.
THE CASTLER APPROACH
SaaS recovery is an infrastructure problem, not only a code custody problem. The deposit, verification pipeline, and evidence pack must reflect the full cloud-native architecture.
Application source and build artefacts
Terraform and Helm charts
Docker and OCI-compliant container images
Kubernetes manifests for EKS, GKE, AKS, and on-premises clusters
Environment configuration templates
Database schemas and migrations
Data export pipeline definitions
API integration maps
Tenant isolation documentation
Independent deployment runbooks
Agents provision the declared infrastructure, initialise the database schema, deploy the containers, and execute a functional replication test in a clean cloud environment without access to vendor credentials.
Signed Proof of Recovery with Build Report, Infrastructure Deployment Trace, Replication Report, Data Schema Validation Report, SBOM, Confidence Score, named engineer seal, and public verification URL.
REGULATORY MANDATE
EU DORA
Critical ICT third-party risk frameworks must address recoverability of cloud and SaaS services.
Evidence mapUK PRA SS2/21
Material SaaS outsourcing arrangements require exit plans and independent continuity evidence.
Evidence mapMAS TRM
Financial institutions must maintain continuity for critical systems delivered by third-party technology providers.
Evidence mapAPRA CPS 230
Regulated entities must continue critical operations within tolerance during service-provider disruption.
Evidence mapRBI IT Directions 2023 §12(f)
The outsourced IT exit obligation applies across delivery models, including SaaS.
Evidence mapCASTLER VS TRADITIONAL ESCROW
| Comparison | Traditional Source Code Escrow | Castler SaaS Escrow |
|---|---|---|
| Source code | Included | Included |
| Infrastructure-as-code | Not included | Included |
| Container images | Not included | Included |
| Database schema and migrations | Rarely | Included |
| Data export pipeline | Not included | Included |
| Environment configuration | Not included | Structure included |
| Verification | None | Agentic full-stack deployment |
| Output | Stored archive | Signed Proof of Recovery |
FREQUENTLY ASKED
In many cases, yes. The deposit relationship may be established through vendor cooperation or a managed exit provision in the licence agreement. The scope depends on the platform and contractual rights.
Regulatory and procurement requirements give enterprises leverage to require escrow in new contracts and renewals. Castler provides deposit specifications and agreement support.
Verification can provision AWS, Google Cloud Platform, and Microsoft Azure environments. Multi-cloud scope is agreed at onboarding and includes the IaC for each required component.
AI model weights, prompts, inference pipelines, and evaluation artefacts are handled through AI & Model Escrow, which can be combined with SaaS escrow in one scope.
GET STARTED
A 15-minute briefing. We identify which SaaS vendors require escrow and show you what a full-stack SaaS Proof of Recovery looks like.
Book a 15-min briefing