[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

DEFENCE & AEROSPACE

Mission-critical support systems need a recovery path that does not depend on the OEM

Defence PSUs, aerospace manufacturers and dual-use technology companies depend on specialist OEM software for maintenance, logistics, simulation and programme support. Castler produces signed Proof of Recovery for scoped support applications so continuity is backed by independent evidence.

On-premise optionsAir-gapped optionsNDA on request

DEFENCE SUPPORT SOFTWARE ESTATE

Independent recovery evidence for scoped support systems

01Maintenance · logistics
RECOVERY PATH
02Simulation · training
RECOVERY PATH
03Programme · support
RECOVERY PATH

DEPLOYMENT OPTIONS

Cloud · on-premise · air-gapped for scoped engagements

THE PROBLEM

OEM dependency can become an operational continuity risk

Commercial defence and aerospace programmes often depend on specialist support software, restricted know-how and supplier operating teams. Corporate change, export constraints or contractor concentration can interrupt support before a replacement path is ready.

Export or support restriction

A foreign OEM can no longer provide support for a commercial defence or aerospace software system. The programme office needs an independent recovery path while replacement or approved modification is arranged.

OEM acquisition

A maintenance or simulation software supplier is acquired and its India support contract changes. The operator retains the deployed system but not a tested path to rebuild it independently.

Key-person dependency

A bespoke support platform depends on a small contractor team. Staff departure leaves source, deployment knowledge and operating procedures fragmented across people and systems.

THE POLICY CONTEXT

Self-reliance does not automatically mean source-code access

DAP 2020 prioritises indigenisation and self-reliance. DRDO's 2025 ToT policy states that software is normally transferred without source code, with source-code transfer requiring exceptional approval. That makes contractual custody, defined trigger rights and independently tested recovery evidence important controls for scoped commercial and PSU software dependencies.

Defence Acquisition Procedure 2020

Self-reliance, indigenisation, Make, Design & Development and Strategic Partnership

Custody record + independently tested recovery evidence

DRDO ToT Policy 2025

Software ToT normally excludes source code; source-code transfer requires a justified exceptional approval

Multi-party custody + contractual trigger framework

NCIIPC CII guidance

Protection, disaster recovery and business-continuity controls for critical infrastructure

Proof of Recovery + Deployment Runbook

THE SOLUTION

Verified recoverability for scoped defence-support software

Castler supports standard cloud-hosted custody and scoped on-premise or air-gapped deployments for sensitive commercial and PSU contexts. The verification process rebuilds vendor software in a controlled environment, and a named engineer signs the resulting recovery pack.

01

Maintenance and logistics

Maintenance-management, logistics and fleet-support software kept current in custody and backed by release-specific recovery evidence.

02

Simulation and training

Commercial simulation, training-management and scenario platforms independently rebuilt and verified against the declared architecture.

03

Support and management software

Programme, communication-support and infrastructure-management applications covered under defined agreements. Operational weapon systems are outside this page's scope.

Sensitive-deployment note

Deployment architecture is scoped engagement by engagement. This public page covers commercial and PSU support software only; classified systems and operational weapon systems are not described here.

REPRESENTATIVE PROGRAMME

A practical path from OEM dependency to verified indigenous control

This is an illustrative defence-PSU remediation model, not a claimed customer engagement. Scope and timelines depend on system classification, deployment restrictions, contractual rights, deposit quality and OEM cooperation.

01

Define the permitted scope

Identify maintenance, logistics, simulation and support applications suitable for contractual custody and independent verification.

02

Establish controlled custody

Agree multi-party rights, bring approved source and deployment artefacts into the selected environment, and reconcile missing dependencies.

03

Verify and sign

Rebuild each scoped release independently, test the permitted recovery procedure and issue the signed Proof of Recovery pack.

OUTPUT PACKCustody recordDeployment RunbookReplication ReportSBOMSigned Proof of Recovery

DEFENCE & AEROSPACE

Map the defence-support Software Estate to the recovery evidence it needs

Bring your commercial or PSU maintenance, logistics, simulation and support-software estate. Deployment requirements, including isolated environments, can be discussed under NDA on request.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day