[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CASTLER SRP · FOR CONSULTANTS

You bring the expertise and the client. We give you the engine

If you already perform software escrow verifications, Castler SRP is the platform that makes you faster, more thorough, and able to take on more engagements than your current process allows. Your sign-off. Our agents. Their Proof of Recovery.

Used to verify software supplied to HDFC Bank, SBI, Canara Bank, Pine Labs and NSDL

verify.castler.com/recovery
Proof of Recovery
IN PROGRESSLIVE

castler-certified · current-release

java/spring · postgres · kubernetes

Build ReportRUNNING...
SBOM (847 components)QUEUED
Deployment RunbookQUEUED
Replication TestQUEUED
Engineer-sealed Proof of Recovery

Estimated completion: 47 min

THE CONSTRAINT TODAY

Human-led verification caps what you can deliver

Time per engagement

A thorough L3 verification takes two to four weeks of consultant time per codebase. Environment reconstruction, dependency resolution, build chain repair — all manual. Your throughput is bounded by hours in the day.

Inconsistent artefacts

Every consultant produces slightly different documentation. Clients get varying report formats, varying depth, varying defensibility. When the auditor pushes back, the artefact may not hold.

Scalability ceiling

A client with 20 critical vendors needs 20 verifications. At your current rate, that is a multi-year programme. Most clients settle for covering two or three. You leave scope — and revenue — on the table.

THE PLATFORM

AI agents run the technical work. You review and sign

Castler's verification engine resolves dependencies, reconstructs environments, repairs build chains, generates the SBOM, and produces the full evidence set — in hours. You review the output, apply your professional judgement, and sign the artefact. Your expertise is the seal. Our engine is the scale.

Hours, not weeks

The AI-agent pipeline completes a full L3-equivalent verification in 6 to 18 hours. You can run multiple engagements in parallel. Your throughput multiplies without adding headcount.

Standardised artefact pack

Every engagement produces the same six-part signed pack: Build Report, Deployment Runbook, Replication Report, SBOM, Confidence Score and Certificate of Recoverability. Consistent, audit-grade, defensible.

You remain the signatory

The Castler platform produces the evidence. You review it and apply your engineer's seal. The certificate carries your name and professional sign-off — not ours — if that is what your client arrangement requires.

Every release, not just the first

The platform can re-verify on every material release automatically. Your clients stay current without commissioning a new engagement each time. Recurring revenue for you, continuous coverage for them.

WHAT EACH ENGAGEMENT PRODUCES

One signed pack. Every time. For every codebase

Build Report

Independent build evidence for the deposited release.

Deployment Runbook

A procedure that can be executed without the vendor.

Replication Report

Evidence that the declared production architecture was recreated.

SBOM

A release-specific inventory of dependencies and components.

Confidence Score

A current measure of verified recoverability.

SEALED

Castler · Certificate of Recoverability

Aurora Core · Release 24.11.3

Seal №POR-2026-04821
Date2026-06-10 · UTC
StatusVERIFIED
SBOM Components847 verified
Build Report
Deployment Runbook
Replication
SBOM

A. Mehta, Verification Engineer

castler.io/verify/POR-2026-04821

The artefact pack is designed to satisfy RBI IT §12(f), SEBI CSCRF, IRDAI CS Guidelines, EU DORA, UK PRA SS2/21 and MAS TRM requirements. Every artefact is timestamped, versioned and linked to a specific release. The Confidence Score gives your client a defensible recoverability rating they can take to their board or regulator.

HOW IT WORKS

Your client. Your engagement. Our engine

01

Onboard your client's vendor

The software vendor deposits their codebase via the Castler platform under a standard escrow agreement. You manage the onboarding conversation with the vendor on behalf of your client. Castler provides the legal framework.

02

Run the verification

Log into your consultant dashboard and initiate the verification. Castler's AI agents take over — resolving dependencies, reconstructing the environment, compiling, deploying, replicating. You monitor progress in real time and receive alerts at each stage.

03

Review, sign and deliver

You review the full evidence set, apply your professional judgement, and issue the signed artefact pack to your client. The certificate is in your name. The delivery is yours. The engine was ours.

CONSULTANT PRICING

The same published pricing, used across client engagements

Consultants select the same Castler SRP product layers published on the pricing page. Plans are per application, per year, with no separate consultant platform subscription fee.

Cloud Storage

$1,000

1 application / year

Up to 10 applications / year: $5,000. Secure custody, documentation, in-region storage, inspection, and a deposit report.

Request access

Standard Verification

$2,500

1 application / year

Up to 10 applications / year: $10,000. Adds build verification, dependency evidence, SBOM and CBOM generation.

Request access
Most popular

Premium Recoverability

$5,000

1 application / year

Up to 10 applications / year: $30,000. Adds independent rebuild, deployment and run, plus signed Proof of Recovery.

Request access

Coverage for more than 10 applications is available on request. Contact us to discuss a practice agreement.

JOIN AS A CONSULTANT

Tell us about your practice

We onboard a small number of verification consultants each quarter. Share your current verification practice and the types of clients you serve. We will respond within one business day.

Request consultant access

No spam · Reply within one business day · ISO 27001 and SOC 2 Type II certified