[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

THE PLATFORM

Your entire Software Estate. One live control plane

Castler brings custody, verification, exceptions, regulatory evidence, and engineer accountability into one system — so recoverability is continuously visible, not periodically assumed.

Regulator readinessAUDIT READY
EU DORA96%
RBI IT §12(f)92%
SEBI CSCRF88%
IRDAI CS 202384%
Verification queueLIVE

core-banking-engine

v9.4 · 847 SBOM

VERIFIED12m

payments-gateway

v3.2 · rebuild

RUNNINGnow

risk-engine

v1.8 · queued

QUEUED

kyc-orchestrator

v5.1 · 412 SBOM

VERIFIED2h
Recoverability scoreSEALED
A−

Aurora Core · v24.11

Independently verified

Posture92 / 100
Build Report Runbook Replication SBOM

ONE VIEW

Every vendor, every release, one live view

The platform turns a scattered vendor-resilience programme into a visible operating system.

Portfolio control plane

See every critical vendor, release, verification state, exception, and Proof of Recovery in one view.

Live verification status

Track mapping, rebuild, deployment, replication, and engineer review as each release moves through the engine.

Release-by-release history

Keep a current evidence trail instead of a report that becomes stale the moment the vendor ships again.

Exceptions that demand action

Surface missing dependencies, documentation drift, failed builds, and unverified critical systems before an incident.

Audit-ready evidence

Give boards, regulators, auditors, insurers, and customers signed, numbered artefacts they can examine.

Jurisdiction-aware controls

Run verification in the cloud and region you choose with role-based access and immutable audit trails.

Software Estate COVERAGE

Your resilience programme is only as strong as the critical vendor you have never tested.

Software Estate COVERAGE

Scan the whole Software Estate — not the two vendors with budget

Traditional verification is too slow and expensive to scale. Castler is designed to cover the critical systems that normally remain untested.

Recoverability Audit · on Castler
6/6 sealed

Core Banking

Core platform vendor

SCANNING

Payment Switch

Payments vendor

SCANNING

Risk Engine

Risk technology vendor

SCANNING

KYC / KYB

Identity vendor

SCANNING

Lending

Lending platform vendor

SCANNING

Treasury

Treasury vendor

SCANNING

Hours

Verification cycle

~90%

Lower verification cost

100%

Critical-Software Estate coverage

Per release

Evidence stays current

Map

Inventory dependencies and runtime

Rebuild

Compile in a clean environment

Run

Deploy and replicate architecture

Seal

Named engineer signs the evidence

PLATFORM DEMO

An agreement is not a proof

Bring one critical application. We’ll show you the control plane, the recovery workflow, and the signed evidence it produces.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day