[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

PROOF OF RECOVERY

What is in the signed evidence pack

Each verified vendor release has a numbered Proof of Recovery. Its supporting artefacts document the rebuild, deployment, architecture replication and engineer review.

SEALED

Castler · Certificate of Recoverability

Aurora Core · Release 24.11.3

Seal №POR-2026-04821
Date2026-06-10 · UTC
StatusVERIFIED
SBOM Components847 verified
Build Report
Deployment Runbook
Replication
SBOM

A. Mehta, Verification Engineer

castler.io/verify/POR-2026-04821

WHAT CASTLER PRODUCES

One signed pack. Per vendor. Per release

For every critical vendor deposit, Castler’s agentic verification engine rebuilds the software in a clean environment, deploys it, replicates the declared production architecture, and generates a structured set of audit-grade artefacts. A named Castler verification engineer reviews and signs the result.

The full pack is delivered as a sealed, numbered Proof of Recovery certificate. It is examinable, linked to the exact release tested, and refreshed when the vendor ships a new version.

Build Report

A complete log of the build process: compiler, dependencies, build tools, errors encountered and resolved, and final binary outputs. It is evidence that the code compiles from the deposit alone rather than from undocumented knowledge held only by the vendor.

Deployment Runbook

A step-by-step operational guide for deploying the application in your environment if a trigger event occurs. It is written so your team can execute it without the vendor present, including environment setup, configuration, health checks, and rollback instructions.

Replication Report

Evidence that the declared production architecture — database, network topology, service configuration, and environment variables — has been replicated and validated. This proves recovery extends beyond compilation to an operable system.

SBOM

A complete inventory of every dependency, library, runtime, and component included in the verified release, formatted to SPDX and CycloneDX standards. The SBOM creates an auditable software-supply-chain record for the exact release tested.

Confidence Score

A numeric score from 0–100 representing verified recoverability confidence for the release. It reflects build completeness, dependency resolution, deployment success, replication fidelity, and the remaining exceptions that require action.

Engineer’s Seal

A numbered, dated signature from a named Castler verification engineer. It is not a probabilistic output: it is an auditable artefact with an accountable professional behind the claim and a public verification reference.

PROOF OF RECOVERY

See the evidence for your next release

Book a 15-min Demo to discuss the signed evidence pack for your critical vendor software.

Book a 15-min Demo
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day