- The exposure: software you don't control can fail.
- The shift: from holding the code to proving it comes back.
- The model: applications, then a protection for each, then a level.
- The proof: the certificates, Agentic Verification and the Exit Exercise.
- The next step: book a demo, or get the sample evidence pack.
Keep your software running. Whatever happens.
Codekeeper protects the applications your business can't lose, the ones you build and the ones you buy. We hold what it takes to bring each one back and prove it works. When one fails, we release it to you, recover it for you, or keep it switched on while we do.
- Trusted by 3,500+ teams
- ISO/IEC 27001:2022 certified
- 10+ years securing software
Applications
4 protected · + Add protectionTrusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors
The exposure
Your business runs on software you don't control.
Every company depends on applications built by someone else, and on its own systems staying up. When one fails, you feel it first. Without a plan already in place, recovery becomes improvisation.
The vendor disappears
Insolvency, an acquisition or a change of strategy can take an application away overnight, along with the people who know how to run it.
An attack takes it down
Ransomware and supply-chain attacks hit live systems and backups alike. Getting back depends on a clean copy kept somewhere else.
The regulator asks for your exit plan
Auditors, clients and regulators now ask whether you could actually leave a supplier and keep running, and what proof you have.
Case study · Jaguar Land Rover, 2025
When JLR's systems were hit, production stopped for about five weeks.
A single IT shutdown rippled through one of the UK's largest supply chains. Recovery took weeks, not hours. The lesson for every business is the same: downtime is the cost, and a recovery you've planned and proven is the answer.
Source: Cyber Monitoring Centre estimate, reported October 2025 (report). Read the JLR case study
What's new
From holding the code to proving it comes back.
Having the code is the start. Having the application back is the goal. Escrow Pro, Resilience, Continuity and Agentic Verification take protection all the way there.
How it works
One account. Every critical application.
Add the applications you can't lose, in-house or from a vendor. Attach the protection each one needs. Choose the level.
Escrow
Everything you need to be protected.
Your vendor's code with a neutral party, under clear release terms. Checked and certified.
From $199per application per month
Explore EscrowEscrow Pro
Everything you need to recover.
Escrow plus Agentic Verification: proof the deposit builds, and a Recoverability Certificate.
From $449per application per month
Explore Escrow ProResilience
We run the recovery.
The deposit comes to Codekeeper. If the application fails, we bring it back for you.
From $399per application per month
Explore ResilienceResilience Pro
Proven before we need it.
Resilience plus Agentic Verification, so recovery starts from a deposit we know builds.
From $649per application per month
Explore Resilience ProContinuity
Full continuity.
Everything in Resilience Pro, plus we keep the live environment paid and switched on for an agreed period while we recover.
From $1,449per application per month
Explore ContinuityEscrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on. Need daily backups of your own systems? Software Backup attaches the same way. See all prices
The proof
Proof beats promises.
Every protection comes with evidence you can put in front of an auditor, a client or your board. The higher you go, the more it proves.
Software Resilience Certificate
The deposit is held, and an automated check confirms what's in it, with a vault report.
Proves: it's there.
Recoverability Certificate
AI agents rebuild the deposit in a sealed sandbox, with no help from the vendor, in hours. You also get the run report, an SBOM and an Exit workbook.
Proves: it builds. Agentic Verification
Tested Exit Report
Our specialists rebuild by hand in a clean room and test the business functions you rely on, without the original developers.
Proves: you could exit and keep working. Exit Exercise
Agentic Verification
Proof it builds. In hours, not weeks.
Press run. AI agents work out how your deposit is built and rebuild it in a sealed sandbox. Anything missing is flagged. A successful run issues a dated Recoverability Certificate.
- Four rebuilds a year included, on supported technology stacks
- Codekeeper's own models. Your code never leaves our environment
- Replaces the Validated, Verified and Certified levels
Why now
Regulators now expect an exit plan that works.
Financial regulation has moved on from "do you have a contract?" to "could you actually leave, and keep running?"
“Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically.”
“Firms should take reasonable steps to test exit plans; in particular, those relating to stressed exits.”
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
Who it's for
Whichever side of the software you're on.
You rely on vendor software
Put release rights in writing before you sign, and know who brings the application back if the vendor can't. Resilience
You sell software to enterprises
Show buyers their application is protected and proven to build, so due diligence doesn't stall the deal. Escrow Pro
You run systems you can't lose
Protect in-house applications as well as vendor ones, from daily backups to full continuity. Continuity
Customers
What teams say after setting it up.
We've had a great experience with CodeKeeper. The setup process was smooth, and the team made everything very straightforward. Knowing our critical software assets are securely protected gives us real peace of mind.
We worked with Codekeeper as our escrow provider for major enterprise deployments and found them to be extremely professional, responsive, and flexible throughout.
I scheduled a demo to better understand the possibilities. Very easy! It was a clear and straightforward meeting, focused exactly on what I needed.
Built to stay current
Connect once. Your deposits keep themselves up to date.
Codekeeper syncs with the systems your teams already use, so the deposit keeps pace with the version you run.
- 50+ integrations, including GitHub, GitLab, Bitbucket, Azure DevOps, AWS, Azure and Google Cloud
- Deposits sync daily, with no per-deposit fees
- ISO/IEC 27001:2022 certified, with AES-256 encryption at rest
- Beneficiaries typically have access within two to three hours of a verified release
Sample evidence pack
See what your auditor would receive.
An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.
- Recoverability Certificate
- Run report
- SBOM and Exit workbook excerpts
Questions
Good questions to ask first.
What's the difference between Escrow, Resilience and Continuity?
It's what happens when you need it. With Escrow, the deposit is released to you and you run the recovery. With Resilience, the deposit comes to Codekeeper and we run the recovery. Continuity does that and also keeps the live environment paid and switched on for an agreed period while we recover.
What is an "application"?
Any system your business can't lose: vendor software, a SaaS platform, an AI system or something you built yourself. Prices are per application, with separate rows for software, SaaS and AI.
What happened to Validated, Verified and Certified?
Agentic Verification replaces them. It's included in Escrow Pro, Resilience Pro and Continuity. Escrow and Resilience include an automated check and a Software Resilience Certificate.
I'm already a customer. Does my plan change?
No. Your current plan stays as it is until renewal. Your account manager can walk you through the new options, including Pro and Continuity, whenever you're ready.
Is my code safe with you?
Codekeeper is ISO/IEC 27001:2022 certified. Deposits are encrypted at rest, and Agentic Verification runs on our own models: your code never leaves our environment. See the Trust Center.
Will this make us compliant with DORA or NIS2?
Codekeeper gives you evidence for your file, such as certificates, run reports, SBOMs and Tested Exit Reports. Whether it meets a specific requirement is for you and your assessor to decide.
Keep your software running. Whatever happens.
See it on the applications you can't lose. We'll walk through your stack and show you what each protection covers.