NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why the homepage changed. Production leads with "We protect your software so it never fails you". That's an absolute we can't keep, and it describes no product. The new homepage tells the whole story once, in the order every other page follows:
  • The exposure: software you don't control can fail.
  • The shift: from holding the code to proving it comes back.
  • The model: applications, then a protection for each, then a level.
  • The proof: the certificates, Agentic Verification and the Exit Exercise.
  • The next step: book a demo, or get the sample evidence pack.
The headline is the approved launch line. The hero shows the product (applications with protections attached) instead of a stock image, so the model is clear before anyone reads a word.
Software Resilience

Keep your software running. Whatever happens.

Codekeeper protects the applications your business can't lose, the ones you build and the ones you buy. We hold what it takes to bring each one back and prove it works. When one fails, we release it to you, recover it for you, or keep it switched on while we do.

  • Trusted by 3,500+ teams
  • ISO/IEC 27001:2022 certified
  • 10+ years securing software
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Step 1, the exposure: name the risk once, calmly. Production spreads four risk tabs, a probability table and a "Are you sure you want to leave your software unprotected?" line across the page. Here the risk gets one section: three causes, then the production stats (kept as agreed, each flagged until the team supplies a source). The NIS2 figure is checked against Article 34(4) NIS2: Member States must allow fines of a maximum of at least €10M or 2% for essential entities (€7M or 1.4% for important entities, Art. 34(5)). Have legal confirm it. No fear lines.

The exposure

Your business runs on software you don't control.

Every company depends on applications built by someone else, and on its own systems staying up. When one fails, you feel it first. Without a plan already in place, recovery becomes improvisation.

The vendor disappears

Insolvency, an acquisition or a change of strategy can take an application away overnight, along with the people who know how to run it.

An attack takes it down

Ransomware and supply-chain attacks hit live systems and backups alike. Getting back depends on a clean copy kept somewhere else.

The regulator asks for your exit plan

Auditors, clients and regulators now ask whether you could actually leave a supplier and keep running, and what proof you have.

2 in 10vendors fail within three years
200+applications most companies rely on, so that's 40+ systems at risk
99%chance at least one of ten critical vendors fails
€10M or 2%of worldwide annual turnover, whichever is higher: the fine every EU country must at least allow for essential entities under NIS2Directive (EU) 2022/2555, Art. 34(4)
One real event instead of a wall of statistics. The JLR case comes from production, now with a public source: the Cyber Monitoring Centre's estimate, October 2025. "About five weeks" is the stop before JLR's limited restart in early October 2025. Recheck both figures before launch. The link goes to the existing production case study.

Case study · Jaguar Land Rover, 2025

When JLR's systems were hit, production stopped for about five weeks.

A single IT shutdown rippled through one of the UK's largest supply chains. Recovery took weeks, not hours. The lesson for every business is the same: downtime is the cost, and a recovery you've planned and proven is the answer.

Source: Cyber Monitoring Centre estimate, reported October 2025 (report). Read the JLR case study

£1.9bnestimated cost to the UK economy
Up to 5,000UK organisations affected through the supply chain
Step 2, the shift. This is where the launch lives on the homepage. The "What's new" story from the launch site is folded in here, so the homepage and the launch tell one story. The film comes first because it's the fastest way to understand the line-up. The table then shows exactly what changed, using only confirmed facts. The announcement bar on every page links here.

What's new

From holding the code to proving it comes back.

Having the code is the start. Having the application back is the goal. Escrow Pro, Resilience, Continuity and Agentic Verification take protection all the way there.

Until now
Now
Verification
Weeks of specialist engineering work
Hours, done by AI agents
Cost
Priced for the largest contracts
Included in every Pro plan and in Continuity
Recovery
You receive the code and run the recovery
With Resilience, we run it for you
Continuity
Recovery alone
The live environment kept paid and switched on while we recover
Evidence
A certified record of what's deposited
Plus proof it builds: a Recoverability Certificate, SBOM and Exit workbook
Step 3, the model, with prices on the homepage. Applications, then a protection, then a level. The five cards are the whole line-up in one row, so visitors find their rung without opening a menu. Showing the "from" prices removes the most common reason to leave ("how much is this?"). The sentence under the cards is the agreed price logic. Backup is mentioned as the lighter peer protection, so it's never framed as a lesser Escrow.

How it works

One account. Every critical application.

Add the applications you can't lose, in-house or from a vendor. Attach the protection each one needs. Choose the level.

Released to you

Escrow

Everything you need to be protected.

Your vendor's code with a neutral party, under clear release terms. Checked and certified.

From $199per application per month

Explore Escrow
Released to you

Escrow Pro

Everything you need to recover.

Escrow plus Agentic Verification: proof the deposit builds, and a Recoverability Certificate.

From $449per application per month

Explore Escrow Pro
Recovered by us

Resilience

We run the recovery.

The deposit comes to Codekeeper. If the application fails, we bring it back for you.

From $399per application per month

Explore Resilience
Recovered by us

Resilience Pro

Proven before we need it.

Resilience plus Agentic Verification, so recovery starts from a deposit we know builds.

From $649per application per month

Explore Resilience Pro
Kept switched on

Continuity

Full continuity.

Everything in Resilience Pro, plus we keep the live environment paid and switched on for an agreed period while we recover.

From $1,449per application per month

Explore Continuity

Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on. Need daily backups of your own systems? Software Backup attaches the same way. See all prices

Step 4, the proof. It's the core of the new positioning. Production lists Validated, Verified and Certified as three "assurance options". Those levels are replaced. The ladder shows the three proofs a customer can hold, what each shows, and where it comes from. The certificate copy keeps the agreed line: the Recoverability Certificate documents the rebuild and doesn't grant release rights.

The proof

Proof beats promises.

Every protection comes with evidence you can put in front of an auditor, a client or your board. The higher you go, the more it proves.

Every protection

Software Resilience Certificate

The deposit is held, and an automated check confirms what's in it, with a vault report.

Proves: it's there.

Escrow Pro · Resilience Pro · Continuity

Recoverability Certificate

AI agents rebuild the deposit in a sealed sandbox, with no help from the vendor, in hours. You also get the run report, an SBOM and an Exit workbook.

Proves: it builds. Agentic Verification

Add-on to any plan

Tested Exit Report

Our specialists rebuild by hand in a clean room and test the business functions you rely on, without the original developers.

Proves: you could exit and keep working. Exit Exercise

Agentic Verification

Proof it builds. In hours, not weeks.

Press run. AI agents work out how your deposit is built and rebuild it in a sealed sandbox. Anything missing is flagged. A successful run issues a dated Recoverability Certificate.

  • Four rebuilds a year included, on supported technology stacks
  • Codekeeper's own models. Your code never leaves our environment
  • Replaces the Validated, Verified and Certified levels
Let the regulation create the urgency, with sources. Both quotes are verbatim and checked against the primary text. The line under them keeps us on the right side of the claim: Codekeeper provides evidence, and the customer and their assessor decide whether it meets a requirement. Production says things like "DORA certified" in places; that's gone. Legal should review the quotes and the disclaimer before launch.

Why now

Regulators now expect an exit plan that works.

Financial regulation has moved on from "do you have a contract?" to "could you actually leave, and keep running?"

EUDORA
“Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically.”
Regulation (EU) 2022/2554, Article 28(8)
UKPRA SS2/21
“Firms should take reasonable steps to test exit plans; in particular, those relating to stressed exits.”
PRA Supervisory Statement SS2/21, paragraph 10.24

Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.

Three audiences, three reasons. Production splits audiences by team (compliance, management, DevOps, legal). Buyers recognise themselves faster by situation: they're buying critical software, selling it to enterprises, or running systems they can't lose. Each card links to the page that answers that situation.

Who it's for

Whichever side of the software you're on.

You rely on vendor software

Put release rights in writing before you sign, and know who brings the application back if the vendor can't. Resilience

You sell software to enterprises

Show buyers their application is protected and proven to build, so due diligence doesn't stall the deal. Escrow Pro

You run systems you can't lose

Protect in-house applications as well as vendor ones, from daily backups to full continuity. Continuity

Customer voice after the claims, not before. These are the three production reviews, quoted as they appear there. Add each reviewer's role and company if they agree (production shows names only). Better still: replace one with a regulated customer talking about a certificate in an audit. That's the story the new line-up sells.

Customers

What teams say after setting it up.

We've had a great experience with CodeKeeper. The setup process was smooth, and the team made everything very straightforward. Knowing our critical software assets are securely protected gives us real peace of mind.
Jordan AdlerCustomer review
We worked with Codekeeper as our escrow provider for major enterprise deployments and found them to be extremely professional, responsive, and flexible throughout.
Ross KilshawCustomer review
I scheduled a demo to better understand the possibilities. Very easy! It was a clear and straightforward meeting, focused exactly on what I needed.
Thiago MendesCustomer review
The platform facts that remove friction. These come from production and stay true across the new line-up: integrations, daily sync, security. The release-time line comes from the Trust Center FAQ and is flagged until operations confirm it. "Military-grade" is gone; we name the actual standard.

Built to stay current

Connect once. Your deposits keep themselves up to date.

Codekeeper syncs with the systems your teams already use, so the deposit keeps pace with the version you run.

  • 50+ integrations, including GitHub, GitLab, Bitbucket, Azure DevOps, AWS, Azure and Google Cloud
  • Deposits sync daily, with no per-deposit fees
  • ISO/IEC 27001:2022 certified, with AES-256 encryption at rest
  • Beneficiaries typically have access within two to three hours of a verified release
Image to produceIntegrations constellationBrief: the Codekeeper symbol in the centre with 10–12 integration logos (GitHub, GitLab, Bitbucket, Azure DevOps, AWS, Azure, Google Cloud…) on soft mint rings, thin teal lines showing a daily sync. Flat, light background, no people. Reuse production's integration logos from /integrations.
The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
Answer the questions the launch raises. Existing customers will ask what happened to Verified and Certified, and whether their plan changes. New visitors ask how the three protections differ. The answer on existing plans reflects the internal decision: the new list is for new customers, and existing plans stay as they are until renewal. Customer success should confirm the wording.

Questions

Good questions to ask first.

What's the difference between Escrow, Resilience and Continuity?

It's what happens when you need it. With Escrow, the deposit is released to you and you run the recovery. With Resilience, the deposit comes to Codekeeper and we run the recovery. Continuity does that and also keeps the live environment paid and switched on for an agreed period while we recover.

What is an "application"?

Any system your business can't lose: vendor software, a SaaS platform, an AI system or something you built yourself. Prices are per application, with separate rows for software, SaaS and AI.

What happened to Validated, Verified and Certified?

Agentic Verification replaces them. It's included in Escrow Pro, Resilience Pro and Continuity. Escrow and Resilience include an automated check and a Software Resilience Certificate.

I'm already a customer. Does my plan change?

No. Your current plan stays as it is until renewal. Your account manager can walk you through the new options, including Pro and Continuity, whenever you're ready.

Is my code safe with you?

Codekeeper is ISO/IEC 27001:2022 certified. Deposits are encrypted at rest, and Agentic Verification runs on our own models: your code never leaves our environment. See the Trust Center.

Will this make us compliant with DORA or NIS2?

Codekeeper gives you evidence for your file, such as certificates, run reports, SBOMs and Tested Exit Reports. Whether it meets a specific requirement is for you and your assessor to decide.

More answers in the FAQ

The same close on every page. The homepage closes on the launch headline, so the first and last thing a visitor reads is the same promise. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Keep your software running. Whatever happens.

See it on the applications you can't lose. We'll walk through your stack and show you what each protection covers.