- Ten topics in the model's order: who we are, the protections, applications and pricing, the proof, then agreements, security, compliance, getting started, billing and existing customers.
- The jump list is the hero visual, so every topic is one click away above the fold on desktop, and right after the intro on phones. The counts are the number of questions in each topic.
- Production's search box and "Chat with us now" block are gone. No kit component exists for search; add HubSpot's back if the team wants it. The final CTA replaces the chat prompt.
- Production template text removed: "Viewing results for "software escrow" 1‒9 of 1000+ results" and the "bulletproof" closing line.
Good questions. Clear answers.
How Codekeeper works, what each protection does, what it costs and what proof you'll hold, grouped by topic. Can't find yours? Ask us on a demo.
- Trusted by 3,500+ teams
- ISO/IEC 27001:2022 certified
- Securing software since 2014
4 questions
About Codekeeper
What does Codekeeper do?
Codekeeper keeps the software your business depends on running, whatever happens. We protect the applications you build and the applications you buy: we hold what it takes to bring each one back and prove it works. When one fails, depending on the protection you choose, we release it to you, recover it for you, or keep it switched on while we recover it.
What does Codekeeper offer?
Software Resilience: one account for every critical application. You add the applications you can't lose, attach a protection to each one (Escrow, Resilience, Continuity or Backup) and choose a level. Each protection comes with proof you can file, from a Software Resilience Certificate to a Recoverability Certificate from Agentic Verification. How it works
Why do teams trust Codekeeper?
We've been securing software since 2014, and 3,500+ teams use Codekeeper, including Airbus, Intuit and Pfizer. We're ISO/IEC 27001:2022 certified, audited by BSI. Our security documentation is in the Trust Center.
What makes Codekeeper different?
Three things. Deposits keep themselves current: 50+ integrations sync them daily, with no per-deposit fees. The proof goes further than custody: Agentic Verification rebuilds the deposit in hours, not weeks. And onboarding is guided, with dedicated contacts for legal, technical, compliance and billing questions. Why Codekeeper
8 questions
Software Resilience and protections
What's the difference between Escrow, Resilience, Continuity and Backup?
It's what happens when you need it. With Escrow, the deposit is released to you and you run the recovery. With Resilience, the deposit comes to Codekeeper and we run the recovery. Continuity includes everything in Resilience Pro, and we also keep the live environment paid and switched on for an agreed period while we recover. Backup has a lighter job: your systems, backed up and restorable.
What is software escrow?
A neutral third party holds an application's source code and the materials needed to run it, under an agreement. If an agreed release condition is met, for example the vendor stops supporting the software, the deposit is released to the beneficiary. At Codekeeper, that's the Escrow protection. Explore Escrow
What's the difference between Escrow and Escrow Pro?
Escrow is everything you need to be protected: custody of the deposit, release under the Escrow Agreement, an automated check of what's deposited with a vault report, and a Software Resilience Certificate. Escrow Pro is everything you need to recover. It adds Agentic Verification: four rebuilds a year on supported technology stacks, build steps, an SBOM, an Exit workbook, a deployable copy and a Recoverability Certificate.
What is Resilience?
With Resilience, the deposit comes to Codekeeper under a Resilience Arrangement. If the application fails, we run the recovery for you, on a best-effort basis, and the recovery work is billed to the claimants who need it. Resilience Pro adds Agentic Verification, so recovery starts from a deposit we already know builds. Explore Resilience
What is Continuity?
Our most complete protection, with a single level. It includes everything in Resilience Pro. At setup, we also map the live environment: where the application runs, the accounts it depends on and the services it needs. We keep that map current, reviewing it when the deposit changes and with each rebuild. If the vendor stops, we keep the environment paid and switched on for an agreed period while we recover, and recharge the bills at cost. Explore Continuity
How long does Continuity keep the live environment switched on?
For an agreed period, set per arrangement. We agree it with you when the arrangement is set up.
What is Software Backup?
A peer protection with a lighter job: your systems, backed up and restorable. Deposits sync daily, the three latest versions are kept, and you can restore and download them from your dashboard. Explore Software Backup
What can be deposited?
Whatever it takes to rebuild and run the application: source code, databases, documentation, deployment configuration, third-party dependencies and hosting credentials. Source code is only one part of a deposit. For SaaS and AI applications, the deposit can also cover infrastructure, data exports, models and pipelines.
- Backup keeps production economics. The plan card says $99 annual and $129 monthly; the Backup pricing FAQ says $89 and $119. Both prices are flagged until the team confirms.
- The claimant definition is ours: production never defines it. Confirm the wording with legal, and whether the add-on rate will be published.
- Left out: production's "Codekeeper charges $199 per hour for release processing services, which are available 24/7" (pricing FAQ). It's not on the confirmed list and "24/7" conflicts with the brief. Confirm whether a release fee still applies, and add it here if it does.
9 questions
Applications and pricing
What is an application?
Any system your business can't lose: vendor software, a SaaS platform, an AI system or something you built yourself. Each application gets its own protection and level, and prices are per application per month, with separate rows for Software, SaaS and AI.
What counts as one SaaS application?
The complete environment that delivers the service: its source code, data, infrastructure configuration, deployment setup, access credentials and the external services it depends on.
How much does it cost?
Prices are per application per month. Escrow from $199, Escrow Pro from $449, Resilience from $399, Resilience Pro from $649 and Continuity from $1,449, with Software, SaaS and AI priced separately. Setup is $499 per arrangement for Escrow and Resilience, and $999 for Continuity. See pricing
Why does Resilience cost more than Escrow?
Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on.
What's a claimant, and how many are included?
A claimant is a party the protection is there for, such as the customer that relies on the application. One claimant is included with each arrangement. Extra claimants are available as an add-on; ask us for the rate.
What's Cost coverage?
Cost coverage puts the cost of a recovery under an agreed service level. It's available for Resilience and Continuity, and quoted per arrangement.
Do you offer enterprise plans?
Yes. Enterprise: talk to us for a quote. We tailor each arrangement to the number of applications, the integrations, the legal complexity and the compliance scope.
Do we pay per repository or per deposit?
No. Prices are per application. You can include every repository the application needs, and deposits sync daily with no per-deposit fees.
How much is Software Backup?
From $99 per application per month billed annually, or $129 billed monthly, with a $249 setup fee. It includes 1 TB of storage and keeps the three latest versions.
- Confirm before launch: the Exit Exercise price "from $12,000" has no published unit.
- No named stacks: the stacks answer stays generic until the supported list is confirmed.
9 questions
Verification and proof
What happened to Validated, Verified and Certified?
Agentic Verification replaces them. It's included in Escrow Pro, Resilience Pro and Continuity. Escrow and Resilience include an automated check of what's deposited, with a vault report and a Software Resilience Certificate. If you have one of the previous levels today, see Existing customers.
What is Agentic Verification?
AI agents read your deposit, work out how it's built and rebuild it in a sealed sandbox, with no help from the vendor. A rebuild takes hours, not weeks. Every run returns a report, and a successful rebuild issues a dated Recoverability Certificate. How Agentic Verification works
How many rebuilds are included?
Four a year with Escrow Pro, Resilience Pro and Continuity. You start them when you choose: before an audit, after a release or whenever the deposit changes. If you need fresh evidence more often, the 12 rebuilds a year add-on is $299 a month more.
Which technology stacks are supported?
Rebuilds run on supported technology stacks. Tell us what your application is built with and we'll confirm before you start.
What happens if a rebuild fails?
The run report shows what built and what was missing. The depositor adds the missing parts, and you run it again.
What does each certificate prove?
The Software Resilience Certificate shows the deposit is held and an automated check has confirmed what's in it. The Recoverability Certificate shows the deposit builds: AI agents rebuilt it in a sealed sandbox, with no help from the vendor. The Tested Exit Report, from an Exit Exercise, shows you could exit and keep working.
Does the Recoverability Certificate give us release rights?
No. It documents the rebuild and its result. Release rights come from your agreement.
What's an Exit Exercise?
Codekeeper specialists rebuild the application by hand in a clean room, from the deposit alone and without the original developers. Then they test the business functions you nominate. You receive a Tested Exit Report (pass or fail, any gaps, and the date) with an annex mapped to your framework, such as DORA. Either party to the agreement can request one. It's an add-on to any plan, from $12,000, and the timeline is agreed at scoping. Agentic Verification proves the deposit builds; an Exit Exercise tests the whole exit. Explore the Exit Exercise
How do we know if we need verification?
If a contract, a client or a regulator asks for proof that the application could be brought back, not just that the code is held, choose a Pro level or Continuity. We can look at it together on a demo.
Sample evidence pack
See what your auditor would receive.
An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.
- Recoverability Certificate
- Run report
- SBOM and Exit workbook excerpts
8 questions
Agreements and release
Which kinds of agreement can we use?
Two-party agreements between the vendor and Codekeeper, so protection can extend to any client who asks. Three-party agreements, which also name one beneficiary. Multi-party agreements, which name several, each with its own release conditions. You choose the structure during account setup.
Are we the depositor or the beneficiary?
If you supply the software, you're typically the depositor. If you rely on it, you're typically the beneficiary. Not sure? We'll work it out with you on a demo.
What triggers a release?
The release conditions in your Escrow Agreement. The most common are the vendor's insolvency, a failure to maintain or support the software, and a breach of contract. When a condition is met, we verify it before anything is released.
What happens when a release is requested?
We validate the request before any materials become accessible: a legal review, verification of the release condition and authentication of the beneficiary. Once release conditions are verified, beneficiaries typically have access within two to three hours.
What changes with Resilience instead of Escrow?
Under a Resilience Arrangement, the deposit comes to Codekeeper instead of to the beneficiary, and we run the recovery. Recovery is best effort, and the work is billed to the claimants who need it.
Can we use our own template, or mark up yours?
Yes to both. You can use Codekeeper's templates or your own. Download the agreement we generate, mark it up in Word or PDF, and upload it for our legal team to review. To start from your own template, request a custom agreement or email it to us. If you need to sign outside the dashboard, we can send the agreement by email or as a PDF.
Will the agreement work in our jurisdiction?
Our legal team prepares the agreement for the jurisdiction and agreement type you choose, and reviews any changes your lawyers propose.
Why isn't the beneficiary's information in our three-party agreement yet?
The beneficiary's details appear once they accept the invitation and complete onboarding. Until they log in, their section stays blank.
6 questions
Security
How do you protect deposited code and data?
Deposits are held in encrypted vaults, with AES-256 encryption at rest and TLS in transit. Accounts are protected with multi-factor authentication. We only access a deposit when a release or verification requires it, and all access is logged and audited.
Which security certifications do you hold?
Codekeeper is ISO/IEC 27001:2022 certified, audited by BSI. Policies and audit summaries are in the Trust Center.
Does Agentic Verification send our code to a third-party AI?
No. Rebuilds run on Codekeeper's own models and infrastructure, and the code stays in Codekeeper's environment. Each run gets a sealed sandbox, cut off from production, development and the open internet.
Can we choose where our data is hosted?
Our platform supports a choice of hosting region. Tell us your data handling requirements and we'll recommend the right configuration.
What documentation can you provide for due diligence?
Security policies, audit summaries, business continuity procedures and more, through the Trust Center. Some documents are public. For confidential documents, we ask for an NDA first.
How often is your security documentation updated?
We review and update it regularly, so it reflects our current security posture, compliance activities and certifications.
5 questions
Compliance
Will Codekeeper's evidence satisfy our regulator?
Codekeeper gives you evidence for your file: certificates, run reports, SBOMs, Exit workbooks and, with an Exit Exercise, a Tested Exit Report. It supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
Which documents can go in a DORA Article 28 or PRA SS2/21 file?
The Software Resilience Certificate shows the deposit is held and checked. With Pro and Continuity, the Recoverability Certificate, run report, SBOM and Exit workbook show it builds and how you would exit. A Tested Exit Report adds functional testing, with an annex mapped to your framework. You can see examples in the sample evidence pack.
What does DORA say about exit plans?
Article 28(8) of Regulation (EU) 2022/2554: “Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically.” It applies to ICT services supporting critical or important functions. Read the regulation · Evidence for DORA
What does the PRA expect in the UK?
PRA Supervisory Statement SS2/21, paragraph 10.24: “Firms should take reasonable steps to test exit plans; in particular, those relating to stressed exits.” Read SS2/21 · Evidence for PRA SS2/21
We're a vendor. Can this help with our customers' due diligence?
Yes. Share your Software Resilience Certificate, and with Escrow Pro your Recoverability Certificate, with your customers' risk and procurement teams, so due diligence doesn't stall the deal.
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
8 questions
Getting started
What's the first step?
Book a demo. We'll look at the applications you rely on, walk you through the platform and build your proposal.
Which protection do we need?
Start with what should happen if the application fails. If you want the deposit released to you so your team can recover it, that's Escrow. If you want us to run the recovery, that's Resilience. If the live service also has to stay switched on, that's Continuity. We'll help you decide for each application.
How can we assess our software risk?
Take the free risk assessment. Based on your answers, you get a report on where you might be exposed, such as supplier failure or gaps in your evidence, with recommended next steps.
How long does setup take?
Once your teams are involved, setup usually takes one to two weeks, depending on your internal response times. Some customers have set up and activated in a day.
What are the steps to activation?
Account setup, inviting your team from the dashboard, configuring settings, creating and signing the agreement, then activating deposits. To begin, you'll need your company details, team contacts and technical preferences. It helps to know which protection you want and the agreement structure.
How do deposits work?
Connect your systems once through our 50+ integrations and deposits sync daily. For GitHub, you connect repositories with OAuth and choose the branches or assets to include. For AWS and similar platforms, you give us the details, such as bucket names or URLs, and we pull in what's needed. You can make manual deposits on the same plan too.
Why can't we deposit yet?
Deposits open once the agreement is signed. Check that every agreement step is complete, including approvals and signatures.
Will someone help us through setup?
Yes. Onboarding is guided, with dedicated contacts for compliance, legal, technical and billing questions. Our technical specialists can walk you through setup, configuration and your first deposit.
- Written for escrow. Confirm whether the same renewal, notice, approval and refund rules apply to Resilience Arrangements, Continuity and Backup, and adjust the wording.
- Not stated: annual or monthly billing for the new list, discounts and production's "Save 20%" offer, until sales confirms them.
- Links go to production's /cancel and /purchasing-form pages, which stay live.
9 questions
Billing and cancellation
How can we pay?
By credit card at checkout, or by invoice if your agreement qualifies. You choose the payment method during checkout. If you're working with a Codekeeper representative, they can send you a personal checkout link set up for your agreement and billing preferences.
Where do we send a PO number or invoice details?
Send your PO number, any billing instructions and your invoice contacts to your account manager, or share them during onboarding using the purchasing form.
Our procurement team needs to approve you as a vendor. Can you help?
Yes. We'll provide the business, tax and banking details for vendor registration, and the business and security documentation your team needs, and we'll help with any required forms. We also support onboarding through procurement platforms such as SAP Ariba: send us your supplier link or vendor request form to start.
Do subscriptions renew automatically?
Yes. Subscriptions renew automatically unless you tell us, at least 30 days before the period ends, that you don't want them to. That notice is separate from the three-month notice for ending a live escrow.
How do we cancel if we don't have a live escrow?
Submit a change request in your account and we'll validate it. Billing runs to the end of the current period, and unused time isn't refunded. How to cancel
How do we end a live escrow?
Give Codekeeper written notice and get the beneficiary's approval, then we validate the request. A three-month notice period runs from when the parties confirm. Where the escrow agreement and the website terms differ, the escrow agreement applies.
Why does the beneficiary have to approve, and what is the three-month notice for?
Escrow is there to protect the beneficiary, so ending it without their approval would defeat the purpose. A live escrow is a legal relationship. The notice lets any problems surface, keeps the deposit valid and keeps every party protected until termination takes effect.
Is ending an escrow the same as cancelling our account?
No. One account can hold more than one escrow, so ending an escrow leaves the account in place. If you want the subscription to stop as well, cancel the account separately once the escrow has ended.
Where do we start?
Submit a change request in the app, or email support@codekeeper.co with the account name and “termination” in the subject line. The full process is at codekeeper.co/cancel.
6 questions
Existing customers
I'm already a customer. Does my plan change?
No. Your current plan stays as it is until renewal. The new list prices are for new customers. Your account manager can walk you through the new options, including Pro and Continuity, whenever you're ready.
We have Verified or Certified today. What happens now?
It continues as agreed in your current plan until renewal. Agentic Verification now provides that proof in Escrow Pro, Resilience Pro and Continuity, with four rebuilds a year. Your account manager can show you what a move would include.
What happened to Continuity Escrow?
Continuity Escrow was our previous name for keeping a vendor's critical services running. Continuity now does more: it includes everything in Resilience Pro, and we keep the live environment paid and switched on for an agreed period while we recover. If you have Continuity Escrow today, your plan stays as it is until renewal, and we'll talk the options through with you before then.
Can we move to a new plan before renewal?
Yes. Talk to your account manager about moving an application to Escrow Pro, Resilience Pro or Continuity.
How do we get support?
Email contact@codekeeper.co or use the support page. To change or end an arrangement, see Billing and cancellation.
Where do we log in?
Still have a question? Ask us directly.
Book a demo and we'll answer it on your own applications. Not ready to talk? The sample evidence pack shows the proof first.