[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

WHY CASTLER

Software escrow stored the promise. Castler proves the outcome

For forty years, the industry protected critical software with a contract and a copy of the code. Castler replaces that act of faith with a repeatable, signed recovery procedure.

IndependentPer releaseEngineer-sealed

BEFORE AND AFTER

From bespoke assurance to an operating system

TIME TO EVIDENCE2–4 weeks per codebase6–18 hours
COST PER CODEBASEFive figures per engagementA fraction, no new headcount
Software Estate COVERAGERoughly 1% of the Software Estate100% of the critical Software Estate

TRADITIONAL ESCROW VS CASTLER SOFTWARE RECOVERABILITY

Storage preserves a copy. Recoverability proves an outcome

The difference is not where the source code sits. It is whether the software has been independently rebuilt, deployed, tested, and sealed before you need it.

Traditional EscrowCastler Software Recoverability
Primary outputStored source code and an agreementSigned Proof of Recovery
Recovery confidenceAssumed until a release eventDemonstrated before an incident
Verification cyclePeriodic, manual, and project-basedRepeatable and release-aware
Software Estate coverageA small number of selected vendorsDesigned for the full critical Software Estate
EvidenceDeposit records and contractual termsBuild, deployment, test, and engineer-sealed artefacts
AccountabilitySplit across vendor, escrow agent, and advisersOne Recovery Authority with a named engineer

THE DIFFERENCE

From escrow arrangement to Recovery Authority

Castler gives institutions an independent authority that can make, test, and stand behind the recoverability claim.

  • Every release captured and versioned
  • Dependencies and runtime mapped
  • Application rebuilt in a clean environment
  • Deployment and replication demonstrated
  • Evidence sealed by a named engineer
  • Proof renewed as the software changes

Institutional proof

Trusted across Castler’s regulated infrastructure network

A growing network of banks, payment institutions and financial-services leaders relies on Castler’s trust infrastructure for controlled, accountable money movement.

Named institutions across banking, payments and lending
Castler trust networkApproved institutions
HDFC Bank
SBI
Canara Bank
HDFC Bank
SBI
Canara Bank
HDFC Bank
SBI
Canara Bank
Union Bank
Indian Bank
India Post Payments
Union Bank
Indian Bank
India Post Payments
Union Bank
Indian Bank
India Post Payments
NSDL Payments
Pine Labs
Mahindra Finance
NSDL Payments
Pine Labs
Mahindra Finance
NSDL Payments
Pine Labs
Mahindra Finance
BanksPayment institutionsNBFCsFintech

World’s first

Software Escrow & Recoverability Platform

Hours

Verification cycle

~90% lower

Cost per verification

100%

Critical-Software Estate coverage goal

WHY CASTLER

An agreement is not a proof

Bring one critical vendor release. We’ll show you the build, the deployment, and the signed evidence.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day