[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CASTLERCERTIFIED · FOR SOFTWARE VENDORS

Win enterprise deals faster. Your code, certified

Give your buyer one signed evidence pack that answers software continuity before procurement stalls, so the conversation stays on your product and the deal keeps moving.

CASTLERCERTIFIED

Certificate of Recoverability

Application name

Aurora Core

Release version

24.11.3

Seal number

POR-2026-04821

Verification date

2026-06-10 · UTC

Confidence score

98.4 / 100

SBOM components

847 verified

Artefacts sealed

Build ReportDeployment RunbookReplication ReportSBOM

A. Mehta

Verification Engineer

castler.com/verify/POR-2026-04821

Scannable. Shareable. Defensible to your buyer's auditor.

INTRODUCING A NEW SERVICE CATEGORY

CastlerCertifiedVendor-owned certification

The world's first software escrow certification for software vendors.

CastlerCertified is a new service category: software escrow certification owned by the vendor, ready before procurement begins.

Traditional escrow begins after selection, when the buyer initiates an agreement and the vendor reacts. CastlerCertified starts before procurement.

You deposit once, Castler independently verifies the release, and a named engineer seals the evidence. The result is an auditable Certificate of Recoverability you can carry into every buyer conversation.

CATEGORY SHIFT

Vendor owned

TRADITIONAL

Buyer asks first

Escrow begins after selection and becomes a new diligence workstream.

CASTLERCERTIFIED

Vendor arrives ready

Current, engineer-sealed evidence is ready before procurement begins.

1

Deposit

2

Verify

3

Engineer seal

4

Share

OUTPUTSigned Certificate of Recoverability

TRADITIONAL ESCROW

CASTLERCERTIFIED

Starts

After buyer selection

Before procurement

Owner

Buyer initiates

Vendor owns the evidence

Verification

Separate engagement

Included in the certification

Speed

Weeks to coordinate

Agents run it in hours

Sales value

Evidence stays with one process

Certificate travels across buyer conversations

A new category for vendors who want to own the procurement conversation

WHO ASKS FOR THIS

Every large enterprise that buys critical software asks the same question.

Software escrow and vendor continuity evidence extend beyond banking. Wherever mission-critical software is purchased, buyers need a credible answer to vendor failure, loss of support, and operational dependency. CastlerCertified gives them an answer they can examine.

Banks, NBFCs and payment companies

Covered institutions face explicit source-code access, software escrow, and critical-application continuity obligations under RBI and related Indian financial-sector frameworks.

Insurance and capital markets

IRDAI and SEBI frameworks create vendor-risk, source-code availability, and continuity expectations for insurers, market infrastructure institutions, and regulated intermediaries.

Global financial institutions

EU DORA, PRA SS2/21, MAS TRM, APRA CPS 230, and FFIEC guidance put third-party continuity, exit planning, and source-code access at the centre of technology risk management.

Defence and aerospace

Mission-critical procurement programmes often require formal software escrow, controlled release terms, and supplier continuity evidence independent of a specific financial regulation.

Healthcare and life sciences

Hospitals, clinical platforms, and medical-technology buyers use continuity and supplier-risk controls to protect access to critical applications, data, configurations, and operating documentation.

Energy, telecom and government

Infrastructure operators and public-sector buyers treat critical vendor software as an operational dependency that needs documented continuity, controlled access, and recovery evidence.

If your buyer is a large enterprise anywhere in the world, CastlerCertified speaks their language

THE DEAL YOU ALMOST WON

You were shortlisted. Then procurement asked about escrow.

01

Selection

Your application passed the technical evaluation. You were shortlisted. The deal was moving.

02

Diligence

Technology risk, compliance, and legal asked for your escrow agreement, verification evidence, release conditions, and signed continuity artefact.

03

Delay

You had no current deposit, no verification, and no artefact. Setting it up from zero became a new workstream between selection and contract.

04

The outcome

The buyer chose a competitor who arrived ready, or the deal closed months later than it should have.

“CastlerCertified turns a buyer's compliance requirement into your procurement advantage.”

THE CERTIFICATION

Stop losing deals to the escrow question. Start winning them with the answer.

CastlerCertified is built on Castler SRP. Castler agents rebuild, deploy, and replicate your application in a clean environment. A named engineer reviews the output and seals the evidence. You receive a signed artefact pack in hours, not weeks.

Carry that pack into enterprise sales conversations. When risk, compliance, or procurement asks about escrow, share the Certificate before the question becomes a blocker.

AI-agent-led verification

Castler agents rebuild, deploy, and replicate your application in a clean environment. Your team provides the initial deposit, then follows progress while the verification runs.

Engineer-sealed Proof of Recovery

A named Castler engineer reviews every verification run and applies a seal. The Certificate is designed for examination by your customer's risk team, auditor, regulator, and board.

Renewable on every release

Certify each material release so buyers receive evidence linked to the version you actually ship, not a certificate issued against software no longer in production.

Win deals faster across buyer types

Use one release-specific Certificate across enterprise sales conversations. Customer-specific legal terms begin with verified technical facts instead of a blank page.

WHAT YOU RECEIVE

One signed pack. Ready to share with every buyer.

Sealed

Certificate of Recoverability

The signed, scannable primary artefact with application, release, verification, confidence, SBOM, and engineer details.

Sealed

Build Report

Independent evidence that the deposited release can be compiled from source without vendor assistance.

Sealed

Deployment Runbook

A step-by-step procedure for environment provisioning, configuration, launch, health checks, and rollback.

Sealed

Replication Report

Evidence that the declared production architecture was recreated in a clean environment and the procedure worked.

Sealed

SBOM

A release-specific inventory of dependencies and third-party components for security, procurement, and regulatory review.

The Certificate and artefact pack help covered customers evidence vendor recoverability obligations. Applicability to a specific requirement remains subject to the institution, application criticality, governing agreement, and relevant regulation.

INTELLECTUAL PROPERTY

Your source code is never disclosed.

Castler holds the deposit under a tripartite escrow agreement in an ISO 27001 and SOC 2 Type II certified custody environment. Your customer receives access only if a defined trigger event occurs, such as insolvency, discontinued support, or another contractually agreed condition.

The verification runs inside Castler's controlled environment. Your buyer receives the Certificate and evidence pack, not your source code. The proof demonstrates recoverability while your intellectual property remains protected.

ISO 27001 CertifiedSOC 2 Type IITripartite escrow agreement

Evidence for the buyer. Access only under the agreement

HOW IT WORKS

Certified in three steps.

01

Deposit your codebase

Connect your Git repository or upload through Castler. Include source code, build scripts, environment specifications, and configuration files. No restructuring is required.

02

Castler agents verify

Castler agents rebuild, deploy, and replicate the application in a clean environment, in the customer's jurisdiction when required. You receive a live progress record.

03

Receive your Certificate

A named Castler engineer reviews the evidence and issues the signed Certificate of Recoverability and artefact pack for buyer diligence.

Typical completion: 4 to 8 hours from a complete deposit

PRICING

Priced per application, per year. Every application. Every release.

Each application gets one full verification cycle and a signed artefact pack, valid for 12 months. Custody is included. Plans bundle applications together, so the per-application rate falls as your certified estate grows.

Standard Verification

$2,500

/ application / year

$2,500 / year · 1 application

Up to 10 applications / year: $10,000. Includes custody, build verification, dependency evidence, SBOM and CBOM generation, and one verification per year.

Certify my application
Most popular

Premium Recoverability

$5,000

/ application / year

$5,000 / year · 1 application

Up to 10 applications / year: $30,000. Adds independent rebuild, deployment and run, plus an engineer-signed Proof of Recovery.

Certify my application

Custody for vendor deposits is included in all plans. Enterprise and multi-year pricing is available on request.

GET CASTLERCERTIFIED

Make software escrow a reason to choose you, not a reason to delay the deal.

Start with the application you sell most often into large enterprise accounts. In one briefing, we will scope the deposit, verification path, release cadence, and evidence pack your buyers need. Most applications can be certified within a week of the first session when the deposit is complete.

Certify my application

No spam · Reply within one business day · ISO 27001 and SOC 2 Type II certified