[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

GOVERNMENT & PUBLIC SECTOR

Public services run on vendor software. Prove they can keep running

Central and state departments, PSUs and civic bodies depend on third-party citizen-service, revenue-management and enterprise software. Castler independently rebuilds critical vendor applications and produces signed Proof of Recovery to support strategic control, tested continuity and public-sector cyber resilience.

ISO 27001SOC 2 Type IICERT-InPCI DSS

PUBLIC-SECTOR SOFTWARE ESTATE

Independent recovery evidence for essential digital services

01Citizen services
RECOVERY PATH
02Revenue systems
RECOVERY PATH
03PSU platforms
RECOVERY PATH

SIGNED OUTPUT

Proof of Recovery · per application · per verified release

THE PROBLEM

Digital public services have created deep vendor dependencies

Government functions increasingly run on outsourced applications and vendor operating knowledge. Without current custody, exit documentation and an independently tested recovery path, contract change or supplier failure can become a public-service continuity event.

Vendor contract expiry

A department's application-maintenance contract ends without a workable transition plan. The service continues to run, but source, deployment knowledge and operational control remain concentrated with the outgoing vendor.

IT vendor acquisition

A supplier supporting several public-service applications is acquired and its product roadmap changes. Multiple departments face the same discontinuation risk at the same time.

Key-person dependency

A bespoke e-governance platform depends on a small technical team. Staff departure or supplier failure leaves the department with code and documentation that have never been tested for independent recovery.

THE GOVERNANCE REQUIREMENT

Strategic control requires source, documentation and tested continuity

MeitY guidance for outsourced government projects calls for control over source code and associated documents, exit planning, disaster recovery and business continuity. CERT-In's government-entity guidelines require BCP/DR preparation and annual testing, while its SBOM guidance recommends software-inventory requirements in public-sector procurement.

MeitY strategic-control guidance

Government control over source code, documentation, exit planning and outsourced-project continuity

Custody record + Deployment Runbook

CERT-In SBOM guidance

SBOM requirements recommended for government, public-sector and essential-services procurement

SBOM + release-specific evidence pack

THE SOLUTION

Signed recovery evidence for the public-sector software estate

Castler's agentic verification engine rebuilds critical government software in a clean environment without depending on the vendor's operating team. A named Castler engineer reviews the evidence and signs the resulting recovery pack.

01

Citizen-service platforms

E-governance portals, service-delivery applications and grievance systems kept current in custody and backed by release-specific recovery evidence.

02

Revenue and land management

Revenue collection, registration and land-record platforms covered under a verified public-sector Software Estate programme.

03

PSU enterprise systems

ERP, HRMS, procurement and supply-chain platforms independently rebuilt and verified against the declared architecture.

REPRESENTATIVE PROGRAMME

A practical path from outsourced dependency to verified strategic control

This is an illustrative public-sector remediation model, not a claimed customer engagement. Scope and timelines depend on application complexity, procurement terms, deposit quality and vendor cooperation.

01

Prioritise essential services

Map citizen-service, revenue, land, ERP and PSU systems by public impact, supplier concentration and transition readiness.

02

Establish controlled custody

Bring source, documentation, deployment definitions, exit plans and runbooks into controlled custody and identify missing artefacts.

03

Verify and sign

Rebuild each scoped release independently, test the recovery procedure and issue the signed Proof of Recovery pack.

OUTPUT PACKSource custody recordDeployment RunbookExit documentationSBOMSigned Proof of Recovery

GOVERNMENT & PUBLIC SECTOR

Map the public-sector Software Estate to the recovery evidence it needs

Bring your critical citizen-service, revenue, land-management and PSU vendor estate. We will map custody, verification and signed evidence in a 15-minute briefing.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day