[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

TRUST CENTER

Security. Privacy. Your jurisdiction

Castler is evaluated by regulated institutions before it is trusted with critical software. This is the control surface they examine.

SECURITY ARCHITECTURE

Six control layers. One continuous audit trail

Encrypted ingress

TLS channels · repository allowlist

Integrity sealing

SHA-256 fingerprint · version identity

Segregated storage

Per-beneficiary isolation

Region replication

Residency-aware copies

Time-boxed access

MFA · least privilege

Audit trail

Every action linked end-to-end

ISO 27001

Information security management

SOC 2 Type II

Security and availability controls

PCI DSS

Payments-grade controls

Regional

Hosting and verification options

SECURITY CONTROLS

The custody record is only as strong as the controls around it

Need-to-know access

Time-boxed, role-scoped grants with accountable identities.

Residency and exit

Regional placement with return or verified destruction on exit.

Independently audited

Control evidence aligned to the current assurance package.

Encrypted and isolated

Encryption in transit and at rest with customer separation.

Integrity and visibility

Release fingerprints, SBOMs and immutable version history.

Full chain of custody

Every deposit, access, verification and release is recorded.

One evidence chain—from repository access to controlled release

SECURITY PRACTICES

Controls built for regulated procurement

Encryption

AES-256 at rest and TLS 1.2+ in transit, with customer-managed keys available for regulated deployments.

Access controls

Role-based access, SSO/SAML, MFA for privileged operations, and least privilege by default.

Immutable audit trail

Every deposit, build, verification, and seal is logged and tied to an accountable identity.

Sub-processors

A vetted, minimal set of sub-processors with customer notice before material changes.

Regional hosting

Rebuild and verification can run in the selected region and cloud to support jurisdiction and residency needs.

Platform resilience

Castler is built to the recoverability standard it asks critical vendors to meet.

CERTIFICATION AND CONTROL MATRIX

What each assurance layer covers

ISO 27001Information-security management and supplier controls · current reports available under NDA
SOC 2 Type IIOperating effectiveness for security and availability · current reports available under NDA
CERT-InIndian incident-response and cyber-assurance alignment · current reports available under NDA
PCI DSSPayments-grade protection of card-data environments · current reports available under NDA
Sub-processor classPurpose
Cloud infrastructureRegional custody and verification environments
Security monitoringThreat detection and audit evidence
Transactional emailOperational notifications only

WHERE DOES MY CODE GO?

Verification runs where your data is allowed to live

The deployment model can be configured around the selected cloud, region, access model, and jurisdiction. Your Proof of Recovery is signed against that controlled environment.

Trust is a property of the whole system

Custody, access, build environments, audit trails, regional controls, and engineer accountability are designed as one evidence chain.

SECURITY PACKAGE

Ready for your security review

Request Castler’s current certifications, sub-processor information, DPA, and architecture brief for your jurisdiction.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day