[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
INSOLVENCY

The vendor goes bust. The software stops. The money disappears

In April 2024, Synapse Financial Technologies filed for bankruptcy. Its partner banks held accounts associated with $265 million in customer balances, while court filings exposed an $85 million reconciliation gap. More than 100,000 customer accounts were documented as locked, across a platform that had reported roughly 10 million total end users.

What happened

Synapse operated as a Banking-as-a-Service middleware layer — the invisible glue between consumer fintech apps and the regulated banks that held their deposits. When Synapse filed for Chapter 11 bankruptcy in April 2024, that glue dissolved overnight.

The apps that depended on Synapse — including Yotta, Juno and Copper — could no longer reconcile their ledgers with the underlying partner banks. The court-appointed trustee reported that users were owed $265 million while partner banks held roughly $180 million associated with those accounts, an $85 million gap. More than 100,000 customers were documented as locked out while reconciliation continued.

The software that ran those reconciliation processes was Synapse's proprietary platform. When the vendor became unavailable, customers and banks lacked a shared operational path for reconstructing the ledger quickly.

Incident at a glance

Customer balances associated
$265M
Documented locked accounts
100,000+
Platform end users reported in filing
~10M
Apps disrupted
Yotta, Juno, Copper
Reconciliation gap reported
$85M
Escrow in place
None reported

The root cause

Synapse's customers — the fintech apps — had built their user-facing layer on top of software they did not own and could not operate independently. When the vendor became unavailable, there was no shared runbook, verified rebuild path or independently proven operating state.

This is the gap Castler exists to close. Not after the fact. Before.

What would Proof of Recovery have changed?

  • A Castler-signed Proof of Recovery would have confirmed that the core reconciliation logic could be rebuilt in a clean environment, without Synapse's infrastructure.
  • The deployment runbook would have given an operations team an executable recovery path without the original vendor's engineers.
  • The shortfall investigation could have started from a known-good, independently verified software state rather than a disputed operational baseline.
  • Recovery would still have been hard. But months of complete operational paralysis could have been reduced materially.

The apps had no way to operate the ledger without Synapse. There was no independent runbook or verified recovery state. When the vendor stopped, everything stopped.

The regulatory consequence

The Synapse failure accelerated regulatory attention on BaaS middleware risk in the United States. Globally, regulators including the RBI, the UK FCA and the EU under DORA require stronger continuity, exit and recovery arrangements for critical outsourced technology.

How much of your Software Estate would stop if a vendor failed today?

Book a briefing