Time per engagement
A thorough L3 verification takes two to four weeks of consultant time per codebase. Environment reconstruction, dependency resolution, build chain repair — all manual. Your throughput is bounded by hours in the day.
CASTLER SRP · FOR CONSULTANTS
If you already perform software escrow verifications, Castler SRP is the platform that makes you faster, more thorough, and able to take on more engagements than your current process allows. Your sign-off. Our agents. Their Proof of Recovery.
Used to verify software supplied to HDFC Bank, SBI, Canara Bank, Pine Labs and NSDL
castler-certified · current-release
java/spring · postgres · kubernetes
Estimated completion: 47 min
THE CONSTRAINT TODAY
A thorough L3 verification takes two to four weeks of consultant time per codebase. Environment reconstruction, dependency resolution, build chain repair — all manual. Your throughput is bounded by hours in the day.
Every consultant produces slightly different documentation. Clients get varying report formats, varying depth, varying defensibility. When the auditor pushes back, the artefact may not hold.
A client with 20 critical vendors needs 20 verifications. At your current rate, that is a multi-year programme. Most clients settle for covering two or three. You leave scope — and revenue — on the table.
THE PLATFORM
Castler's verification engine resolves dependencies, reconstructs environments, repairs build chains, generates the SBOM, and produces the full evidence set — in hours. You review the output, apply your professional judgement, and sign the artefact. Your expertise is the seal. Our engine is the scale.
The AI-agent pipeline completes a full L3-equivalent verification in 6 to 18 hours. You can run multiple engagements in parallel. Your throughput multiplies without adding headcount.
Every engagement produces the same six-part signed pack: Build Report, Deployment Runbook, Replication Report, SBOM, Confidence Score and Certificate of Recoverability. Consistent, audit-grade, defensible.
The Castler platform produces the evidence. You review it and apply your engineer's seal. The certificate carries your name and professional sign-off — not ours — if that is what your client arrangement requires.
The platform can re-verify on every material release automatically. Your clients stay current without commissioning a new engagement each time. Recurring revenue for you, continuous coverage for them.
WHAT EACH ENGAGEMENT PRODUCES
Independent build evidence for the deposited release.
A procedure that can be executed without the vendor.
Evidence that the declared production architecture was recreated.
A release-specific inventory of dependencies and components.
A current measure of verified recoverability.
Castler · Certificate of Recoverability
Aurora Core · Release 24.11.3
A. Mehta, Verification Engineer
castler.io/verify/POR-2026-04821
The artefact pack is designed to satisfy RBI IT §12(f), SEBI CSCRF, IRDAI CS Guidelines, EU DORA, UK PRA SS2/21 and MAS TRM requirements. Every artefact is timestamped, versioned and linked to a specific release. The Confidence Score gives your client a defensible recoverability rating they can take to their board or regulator.
HOW IT WORKS
The software vendor deposits their codebase via the Castler platform under a standard escrow agreement. You manage the onboarding conversation with the vendor on behalf of your client. Castler provides the legal framework.
Log into your consultant dashboard and initiate the verification. Castler's AI agents take over — resolving dependencies, reconstructing the environment, compiling, deploying, replicating. You monitor progress in real time and receive alerts at each stage.
You review the full evidence set, apply your professional judgement, and issue the signed artefact pack to your client. The certificate is in your name. The delivery is yours. The engine was ours.
CONSULTANT PRICING
Consultants select the same Castler SRP product layers published on the pricing page. Plans are per application, per year, with no separate consultant platform subscription fee.
$1,000
1 application / year
Up to 10 applications / year: $5,000. Secure custody, documentation, in-region storage, inspection, and a deposit report.
Request access$2,500
1 application / year
Up to 10 applications / year: $10,000. Adds build verification, dependency evidence, SBOM and CBOM generation.
Request access$5,000
1 application / year
Up to 10 applications / year: $30,000. Adds independent rebuild, deployment and run, plus signed Proof of Recovery.
Request accessCoverage for more than 10 applications is available on request. Contact us to discuss a practice agreement.
JOIN AS A CONSULTANT
We onboard a small number of verification consultants each quarter. Share your current verification practice and the types of clients you serve. We will respond within one business day.
Request consultant accessNo spam · Reply within one business day · ISO 27001 and SOC 2 Type II certified