[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

LEARNING HUB

Software escrow and recoverability glossary

Plain-English definitions of the custody, verification and signed evidence terms used across Castler's Software Recoverability Platform.

GLOSSARY

Software escrow and recoverability terms, in plain English

Software Escrow

A legal and technical arrangement in which a software vendor deposits source code and supporting materials with a neutral third party for the benefit of a customer. The deposit may be released when a negotiated trigger event occurs. Modern software escrow should keep every production release current rather than preserve only the original filing.

Source Code Escrow

Source code escrow is the custody layer of software escrow. It normally includes source code, build scripts, technical documentation, dependencies and runtime configuration. The purpose is to preserve access to the materials required to maintain or transition critical software if the vendor is unavailable.

Proof of Recovery

A Proof of Recovery is a signed, numbered evidence pack showing that a specific vendor software release was independently rebuilt, deployed and verified. It connects the tested release to build logs, deployment instructions, architecture replication, an SBOM, a confidence score and a named engineer’s seal.

Emergency Deployment Runbook

An Emergency Deployment Runbook is the operational guide used to deploy recovered vendor software without the original vendor present. It documents environment setup, databases, configuration, health checks, operating dependencies and rollback procedures. Castler authors it during the reconciliation and authoring stages.

SBOM — Software Bill of Materials

An SBOM is an inventory of the libraries, packages, runtimes and components included in a software release. It supports supply-chain visibility, vulnerability management and reproducible builds. Castler generates the SBOM for the exact release included in each Proof of Recovery.

Agentic Verification

Agentic verification uses software agents to map dependencies, reconstruct build environments, compile applications, run checks and capture evidence. It reduces the time and consultant effort required for traditional verification while retaining a named human engineer for final review and accountability.

Escrow Trigger Event

A trigger event is a contractual condition that may permit the beneficiary to receive the escrow deposit. Common triggers include vendor insolvency, acquisition, product discontinuation, prolonged support failure or another negotiated breach. The executed agreement defines the evidence and release process.

Recoverability Score

A recoverability score is a numeric assessment of confidence that a specific release can be rebuilt and operated without the vendor. It reflects build completeness, dependency resolution, deployment success, replication fidelity and unresolved exceptions. The score should always be read with the underlying evidence.

Multi-party Escrow Agreement

A multi-party escrow agreement governs the vendor depositor, enterprise beneficiary and escrow agent. It defines deposit obligations, update frequency, access controls, trigger conditions, release procedures and responsibilities. Castler manages the agreement and audit trail alongside the technical deposit.

Verification Engineer

A verification engineer is the named professional who reviews the technical evidence produced during recovery testing. The engineer validates the build, deployment, replication, exceptions and confidence score before signing the Proof of Recovery. The seal creates accountable evidence rather than an anonymous automated output.

LEARNING HUB

Put the terminology to work

Book a 15-min Demo to discuss how these terms apply to your vendor agreements and recovery evidence.

Book a 15-min Demo
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day