NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why this page looks like this. This is the Agentic Verification page in the Verification section, rebuilt from the sandbox /verification page for conversion. The main changes:
  • One conversion path. The sandbox had about eight calls to action. This page has the two the whole site uses: book a demo, or get the sample evidence pack.
  • One name. The sandbox used five names for the same thing. This page uses only "Agentic Verification", and "a rebuild" for one run.
  • Prices and plans from the 6 Oct list. There's no "Standard" tier, and Continuity is included.
  • Confirmed claims only. No absolutes, no "industry first".
  • Shorter. About 40% less text, with no stock photography.
Agentic Verification

Proof your software builds. In hours, not weeks.

AI agents rebuild your deposit in a sealed environment, with no help from the vendor. Every successful run issues a dated Recoverability Certificate you can put in front of an auditor, a client or your board.

Included in Escrow Pro, Resilience Pro and Continuity. Four rebuilds a year, on supported technology stacks.

  • Trusted by 3,500+ teams
  • Own models, no third-party AI
  • Your code never leaves our environment
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Name the gap without knocking the base plans. Escrow and Resilience are complete protection. This section explains what only a rebuild can show. The sandbox's three small visuals were the best thing on that page, so they stay. The fear lines go ("Don't stake your reputation", "unfounded recovery promises").

Why it matters

Knowing your deposit is safe is reassuring. Knowing it builds is proof.

Sooner or later someone asks a sharper question: has anyone shown it can be rebuilt? It might be an auditor, a client's security review or a procurement team. A rebuild answers three questions before a recovery has to.

Deposit contents 1 of 4 confirmed
Source code
?Build scripts
?Environment files
?Credentials

Everything it takes to build

Recovery needs build scripts, environment files and credentials as well as source code. A rebuild shows whether they're all there.

Your application
?Private registry package ?External library ?Licensed component

The parts you don't control

Software depends on packages from private registries, external libraries and licensed components. A rebuild finds them ahead of time.

v2.8 recovery testedTested
v2.9 released
v3.0 released
v3.1 running todayUntested

The version you run today

Every release changes what the software needs. Evidence from v2.8 says little about v3.1. Rebuild whenever the deposit changes.

Make "hours, not weeks" concrete. The 59-second film comes first: it's the fastest way to understand the product. Then three steps, one sentence each, and a side-by-side with manual verification. Every line uses confirmed facts. "Simulate your recovery" became "rebuild", because it's a real build. The comparison is with a typical manual build test, not with Codekeeper's own Exit Exercise, which tests more than the build. The line under the table says so and links to it.

How it works

Press run. The agents do the rest.

No engineers to book and no quotes to approve. Start a rebuild whenever you need fresh evidence.

1

Start a run

Pick the application and press run, before an audit, after a release or whenever the deposit changes. The depositor can add or remove materials at any point.

2

Agents rebuild it, sealed off

The agents work out how the software is built and build it, in a sandbox cut off from production, development and the open internet. Anything missing is flagged, and the depositor is asked to add it.

3

Collect the evidence

Every run returns a report. A successful rebuild also issues a dated Recoverability Certificate and produces a deployable copy, held by the depositor until a release event.

A typical manual build test
Agentic Verification
Time
Weeks of specialist work
Hours
Starting a test
Engineers to book, quotes to approve
Press run, whenever you choose
Cost
Priced for the largest contracts
Four rebuilds a year included
The vendor
Often relies on the vendor's engineers
No help from the vendor
Evidence
A report at the end of the engagement
A report every run, and a certificate for every successful rebuild

Need people to test the whole exit, including the functions you rely on? That's an Exit Exercise.

Show the deliverable, then offer it. People buy the evidence, not the agents. Three tabs show the certificate, a run report and the SBOM as they'd appear in the product, so visitors can picture filing them. The run report also proves a claim made higher up: it shows a missing package being flagged and added. The CTA sits right under the tabs, offering the same three documents. The certificate copy keeps the agreed line: it documents the rebuild, and it doesn't grant release rights.

What you get

Evidence you can put on file.

Every run adds to a dated record of what was tested and when.

Get the sample evidence packCertificate, run report and SBOM excerpt

Recoverability Certificate

A dated record of the rebuild and its result, ready for your DORA Article 28 or PRA SS2/21 file.

A report after every run

What compiled, what was missing and what the agents did, step by step.

An SBOM, every rebuild

Your software bill of materials refreshes with each run, so the inventory stays current.

Exit workbook

The recovery process, step by step, bundled with every run report.

A deployable copy

The depositor holds a ready-to-deploy copy when a run completes. The customer gains access on a release event.

Monitoring between runs

We compare the deposit with the live repositories and flag what changed, so you know when to rebuild.

Answer the first AI objection before it's raised. Every security question about AI starts with where the code goes. This section uses confirmed facts only. "Zero chance of IP leakage" is gone: an absolute promise invites the objection it's trying to answer.

Security

Your code never leaves our environment.

Agentic Verification runs on Codekeeper's own models and infrastructure. No third-party AI ever sees your deposit.

10+years securing software
3,500+teams trust Codekeeper

Own models, own infrastructure

Rebuilds run on Codekeeper's models in Codekeeper's environment. Source code never leaves it.

A sealed sandbox for every run

Each rebuild gets its own sandbox, cut off from production, development and the open internet.

You stay in control

Runs are self-serve. The depositor can step in at any point to add or remove materials.

Customer quote goes here: one or two sentences on what the certificate did for an audit or a deal.Use a real, approved quote from a named customer in a regulated sector, with name, role and company.

Price transparency removes a reason to leave. The plans and prices are the approved list from 6 Oct, and the base is never called "Standard". Each plan is described by its job, as on the launch site. The add-ons use the prices you confirmed. There's one row of calls to action instead of three "View pricing plans" buttons.

Pricing

Included in three plans.

Agentic Verification comes with Escrow Pro, Resilience Pro and Continuity. Prices are per application per month.

Released to you

Escrow Pro

From$449per application per month

The deposit is released to you and you run the recovery, from a deposit you already know builds.

  • Four rebuilds a year
  • Recoverability Certificate
  • SBOM and Exit workbook
  • Deployable copy
We run the recovery

Resilience Pro

From$649per application per month

The deposit comes to Codekeeper and we run the recovery, starting from a tested deposit.

  • Four rebuilds a year
  • Recoverability Certificate
  • SBOM and Exit workbook
  • Deployable copy
We keep it switched on

Continuity

From$1,449per application per month

Everything in Resilience Pro, plus we keep the live environment paid and switched on for an agreed period while we recover.

  • Four rebuilds a year
  • Recoverability Certificate
  • SBOM and Exit workbook
  • Deployable copy

12 rebuilds a year

$299 a month more

Fresh evidence every month, for teams that release often.

Exit Exercise

From $12,000

A human-run, clean-room rebuild with functional testing, added to any plan. See the Exit Exercise

Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on. Setup is $499 per arrangement, or $999 for Continuity. Escrow (from $199) and Resilience (from $399) include an automated check and a Software Resilience Certificate, without rebuilds. Rebuilds run on supported technology stacks.

The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
Handle objections in the order sales hears them. Each answer is short and specific, and repeats nothing from above. Native accordions keep the page short and accessible.

Questions

Before you ask your auditor.

What is Agentic Verification?

AI agents read your deposit, work out how it's built and build it, in a sealed sandbox with no help from the vendor. A successful run issues a dated Recoverability Certificate. It replaces our previous Validated, Verified and Certified levels.

Does my code go to a third-party AI?

No. Rebuilds run on Codekeeper's own models and infrastructure, and source code never leaves our environment.

Does the vendor have to help?

No. The agents build without the vendor's engineers. If something is missing, the run flags it and the depositor is asked to add it.

Which technology stacks are supported?

Rebuilds run on supported technology stacks. Tell us what your application is built with and we'll confirm before you start.

What does the Recoverability Certificate prove?

It's a dated record of the rebuild and its result, ready for a DORA Article 28 or PRA SS2/21 file. It documents the rebuild. It doesn't grant release rights; those come from your agreement.

What happens if a rebuild fails?

The run report shows what compiled and what was missing. The depositor adds the missing parts and you run it again.

How is this different from an Exit Exercise?

Agentic Verification proves the deposit builds, up to four times a year. An Exit Exercise is a human-run rebuild in a clean room that also tests the functions you use every day, done without the original developers. It's an add-on to any plan, from $12,000.

The same close on every page. No new choices this late: the same two actions as the hero. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Know it builds before you need it.

See Agentic Verification on one of your own applications, or get the sample evidence pack first.