[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CASTLER SRP · PRICING

Three products. Each one answers one more question

Every tier includes the one before it, then adds one more layer of evidence. Nothing is removed as you step up. All prices are per application, per year.

01Cloud StorageSecure custody
02Standard VerificationProve it builds
03Premium RecoverabilityProve it runs
LAYER 1

Cloud Storage

Secure escrow custody and documentation with in-region cloud storage across AWS, Google Cloud Platform or Microsoft Azure, folder-structure inspection and a detailed deposit report. Answers: Do we have an escrow arrangement in place?

1 Application / Year

$1,000

Best value

Up to 10 Applications / Year

$5,000

More than 10 applications

Talk to Us
LAYER 2

Standard Verification

Everything in Cloud Storage, plus service and infrastructure detection, compilation to a working executable with logs, SBOM and CBOM generation, one verification per year. Answers: Is the code we hold real, complete and buildable?

1 Application / Year

$2,500

Best value

Up to 10 Applications / Year

$10,000

More than 10 applications

Talk to Us
LAYER 3

Premium Recoverability

Everything in Standard Verification, plus independent rebuild, deployment and run of the software, engineer-signed Proof of Recovery per verified release, subsequent verification on new releases, multi-location storage. Answers: If the vendor disappeared tomorrow, could we run the business on this?

1 Application / Year

$5,000

Best value

Up to 10 Applications / Year

$30,000

More than 10 applications

Talk to Us

* Physical vault storage is available for customers in India

Prices are per application, per year. Each layer includes everything in the layer before it — nothing is removed as you step up. For estate and partner pricing, use the Talk to Us button on the relevant product.

WHAT'S INCLUDED

Cumulative scope, made explicit

Cumulative scopeCloud StorageBase custody layerStandard VerificationAll of Cloud Storage, plus:Premium RecoverabilityRecommendedAll of Standard, plus:
Secure escrow custody and documentation — 1 applicationYesYesYes
Cloud storage (AWS / Google Cloud Platform / Microsoft Azure), data localised in-regionYesYesYes
Folder-structure inspection and detailed deposit report [1]YesYesYes
Multi-location storage with auto-syncYes
Service and infrastructure detection report [2]YesYes
Source code compiled to an executable, with logs [3]YesYes
SBOM / CBOM generation — included by default [4]YesYes
Independent rebuild, deployment and run of the software [5]Yes
Engineer-signed Proof of Recovery per verified releaseYes
Subsequent verification on a new release or code change [6]Yes
Verifications included per yearNone11
Best suited forContractual coverAudit evidenceFull continuity

WHAT THE DIFFERENCE BUYS

Each tier answers a different internal question

CLOUD STORAGE

Do we have an escrow arrangement in place?

Answered. The deposit exists, is held securely in-region, and its structure has been checked on arrival. Nothing has been opened, built or run.

STANDARD VERIFICATION

Is the code we hold real, complete and buildable?

Answered. The deposit has been inspected, its dependencies inventoried, and it has been compiled into a working executable with logs and a bill of materials.

PREMIUM RECOVERABILITY

If the vendor disappeared tomorrow, could we run the business on this?

Answered. Castler has independently rebuilt, deployed and run the software, and signed a Proof of Recovery.

Adding Layer 2 — Standard Verification

WHAT LAYER 1 ALONE CANNOT TELL YOU

  • Whether the deposit contains the whole application, or only the parts the vendor chose to send
  • Whether the code compiles at all — a folder of files is not a system
  • Which frameworks, services and infrastructure the application actually depends on
  • Which open-source components are inside it, and what those licences oblige you to do
  • Whether the cryptography in the stack meets your own security standard

WHAT LAYER 2 ADDS ON TOP

  • Service and infrastructure detection — a documented inventory of what the system is built on
  • Compilation to a working executable with full build logs
  • SBOM and CBOM by default — component list, vulnerability severity, licence summary, cryptographic inventory
  • One verification per contract year

Why it matters: This is the first point at which anyone independently tests whether the escrow would work. It converts a contractual promise into documented evidence — the form in which RBI, SEBI, IRDAI, DORA and FCA expect source-code arrangements to be demonstrated, not merely asserted.

Adding Layer 3 — Premium Recoverability

WHY ‘IT COMPILES’ IS NOT ‘WE CAN OPERATE IT’

  • A build can succeed and the application still refuse to install or start
  • Environment and infrastructure configuration usually lives outside the source repository
  • Database schema, migrations and reference data are routinely left out of deposits
  • The system may quietly call a vendor-hosted service or licence server that dies with the vendor
  • Nobody other than the vendor has ever stood the system up, so no deployment path exists

WHAT LAYER 3 ADDS ON TOP

  • Independent rebuild, deployment and run of the software, end-to-end, without vendor involvement
  • Engineer-signed Proof of Recovery for each verified release
  • Subsequent verification when the vendor ships a new release, so the deposit never goes stale
  • Multi-location storage with automatic sync

Why it matters: At Standard Verification, recovery still begins with a discovery project — run during the outage, under pressure, with the vendor gone. At Premium Recoverability the path has already been walked once and documented. That is the difference between holding code and holding a business that can keep operating.

THE FAILURE-MODE MATRIX

What each tier catches before the day you need it

Escrow arrangements rarely fail because the contract was wrong. They fail because the deposit was never tested, and the gap only surfaces at the moment of release.

Failure mode at the moment of releaseCloud StorageStandard VerificationPremium Recoverability
Deposit is corrupt, encrypted without keys, or unreadableDetectedDetectedDetected
Repository incomplete — source files or modules missingPartially detectedDetectedDetected
Dependencies undeclared, or held in private vendor repositoriesNot detectedDetectedDetected
Source code does not compile; no usable build can be producedNot detectedDetectedDetected
Build instructions absent, incomplete or incorrectNot detectedDetectedDetected
Undisclosed third-party or open-source licence exposureNot detectedDetectedDetected
Weak, deprecated or non-compliant cryptography in the stackNot detectedDetectedDetected
Build succeeds but the application will not install or startNot detectedNot detectedDetected
Environment and infrastructure configuration missingNot detectedNot detectedDetected
Database schema, migrations or reference data missingNot detectedNot detectedDetected
Hidden runtime dependency on a vendor-hosted service or licence keyNot detectedNot detectedDetected
No deployment path — the system has never been stood up by anyone but the vendorNot detectedNot detectedDetected
Deposit silently goes stale after a mid-year vendor releaseNot detectedPartially detectedDetected
Detected before you need itPartially detectedNot detected — discovered during the outage

Cloud Storage

You are handed a deposit. Whether it is complete, buildable or operable is unknown until your team opens it. Discovery, gap analysis and remediation all begin from zero during the incident, with no one left to ask.

Standard Verification

You know the deposit is genuine and that it compiles. Environment configuration, deployment and data remain unsolved, so a live service still has to be engineered from a working build under time pressure.

Premium Recoverability

The rebuild has already been performed and signed off by a Castler engineer on an identifiable release. Recovery becomes the repetition of a documented procedure rather than an investigation.

The one question to put to any escrow arrangement you already hold

Has anyone outside the vendor ever compiled and run the deposited code? If the answer is no, the arrangement has never been tested, and the first test will be the day it is needed.

WHAT YOU RECEIVE

One signed pack. Per vendor. Per release

Build ReportIndependent build evidence for the deposited release.
Deployment RunbookA procedure your team can execute without the vendor.
Replication ReportEvidence that the declared production architecture was recreated.
SBOMA release-specific inventory of dependencies and components.
Confidence ScoreA current measure of verified recoverability.
SEALED

Castler · Certificate of Recoverability

Aurora Core · Release 24.11.3

Seal №POR-2026-04821
Date2026-06-10 · UTC
StatusVERIFIED
SBOM Components847 verified
Build Report
Deployment Runbook
Replication
SBOM

A. Mehta, Verification Engineer

castler.io/verify/POR-2026-04821

Engineer-sealed Certificate of Recoverability

HOW WE COMPARE

What the market charges for the same coverage

Castler SRPEscodeVaultinumCodekeeperEscrow LondonEscrowTechPRAXIS
Custody / Storage · annual pricing1 application / year$1,000~£1,600+~€960–€1,320~$1,668$1,895~$2,590$5,500+
Up to 10 applications / year$5,000Quote onlyQuote only~$16,680~$18,950Quote only~$45,000+
Verification / Recoverability · annual pricing1 application / year — full recoverability$5,000Quote onlyQuote onlyQuote only$9,000–$10,000Quote onlyQuote only
Up to 10 applications / year$30,000Not availableNot availableNot available~$90,000–$100,000Not availableNot available
AI-agent-led verificationYesNoNoNoNoNoNo
Signed Proof of RecoveryYesNoNoNoNoNoNo

PRICING FAQ

How the subscription works

How does the subscription work?+

Castler SRP is sold per application, per year. Choose Cloud Storage, Standard Verification, or Premium Recoverability, then select pricing for one application or up to 10 applications. Each product includes every layer before it, and the whole contract renews on one date.

When does my subscription start?+

Your subscription begins on the date payment is received. That is your contract start date, and your renewal date is exactly 12 months later regardless of when you deposit your first codebase. This keeps your renewal simple and predictable.

What happens if I add an application close to my renewal date?+

An application added during the contract year is covered until the shared contract end date, then renews with the rest of your subscription. If the additional application moves you beyond your current application band, the pricing team will confirm the required adjustment.

Can I upgrade my product mid-contract?+

Yes. You can move from Cloud Storage to Standard Verification or Premium Recoverability during the contract year, or expand beyond your current application band. The pricing team will confirm the difference due, and your renewal date stays the same.

Why is the pricing structured in cumulative layers?+

Each product answers one additional operational question. Cloud Storage confirms the arrangement exists. Standard Verification tests whether the deposit is complete and buildable. Premium Recoverability proves the software can be independently rebuilt, deployed and run. Nothing is removed as you step up.

Is Recoverability included in the custody subscription?+

No. Cloud Storage, Standard Verification and Premium Recoverability are cumulative product layers. Cloud Storage covers custody and deposit documentation. Standard Verification adds build verification, infrastructure detection, SBOM and CBOM. Premium Recoverability adds independent rebuild, deployment and engineer-signed Proof of Recovery.

How does Recoverability pricing work?+

Premium Recoverability is priced per application, per year: $5,000 for one application or $30,000 for up to 10 applications. Each application receives one full verification cycle per contract year, with subsequent verification available when a new release or material code change is submitted.

What is included in each custody deposit?+

Every Cloud Storage deposit includes secure escrow custody and documentation, in-region cloud storage across AWS, Google Cloud Platform or Microsoft Azure, folder-structure inspection, and a detailed deposit report confirming the integrity of what was received.

Is there a setup fee?+

No. There is no setup fee on any Castler SRP product. You pay the annual contract fee and onboarding begins immediately.

GET A WRITTEN QUOTE

Tell us your application count. We will respond within one business day

Share your tier, application count, jurisdiction and verification cadence. This routes directly to the pricing team.

Pricing request