NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why this page looks like this. Production opens with "When your critical software vendors fail, your ISO 27001 controls crumble" and later says "Without it, you can't demonstrate the supplier risk controls that certification requires". The first is a fear line; the second is an absolute we can't support. The new page tells the five-step story for an ISMS owner:
  • The exposure: the Annex A controls auditors ask about for suppliers, disruption and backup.
  • The shift: from a control on paper to evidence that it works.
  • The model: applications, each with a protection.
  • The proof: an evidence map from each control to the documents that support it.
  • The next step: book a demo, or get the sample evidence pack.
ISO text is copyright, so the page names controls by number and title only. Titles were checked against BSI's public "NIS2 to ISO/IEC 27001 Mapping Tool" (bsigroup.com), with 5.19 to 5.22 cross-checked on a DQS article. The standard's title, edition and Amendment 1:2024 come from iso.org/standard/27001. Codekeeper's own certificate (audited by BSI) is a confirmed fact, and it gets its own section, because we're in the customer's supplier register too.
ISO/IEC 27001:2022

Supplier and continuity controls. Evidence on file.

Auditors ask how you manage suppliers and how you'd recover from disruption. Codekeeper protects the applications behind those controls and gives you dated certificates, run reports and SBOMs to show them.

  • Trusted by 3,500+ teams
  • ISO/IEC 27001:2022 certified, audited by BSI
  • 50+ integrations, synced daily
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Step 1, the exposure: the three areas, by control number. Production's "Key ISO 27001 requirements" list paraphrased six activities and called them "foundational controls". This section names the real Annex A controls instead, by number and title (verified titles, no ISO text). Production's "$4.44M average breach cost" and "lost certifications that destroy business credibility" are gone: one is unsourced, the other a fear line.

Where audits get specific

Suppliers, disruption and backup.

Annex A of ISO/IEC 27001:2022 has controls for each. They're where an auditor moves from "do you have a policy?" to "show me".

Suppliers · 5.19 to 5.22

Information security in supplier relationships and supplier agreements, in the ICT supply chain, and in monitoring and changes to supplier services.

Disruption · 5.29 and 5.30

Information security during disruption, and ICT readiness for business continuity.

Backup · 8.13

Information backup, for the systems you build and run yourself.

Step 2, the shift, as a before-and-after table. Each row is one control area. The "with evidence" column uses only confirmed outputs: certificates, agreements, SBOM, rebuilds in hours without the supplier, daily backups.

The shift

A control on paper is the start. Evidence it works is the goal.

On paper
With evidence
Supplier risk
A rating in the supplier register
A protection on each critical supplier application, checked and certified
Supplier agreements
A continuity clause
What's deposited, when it's released and who recovers it, in writing
ICT supply chain
Components listed by the supplier, if at all
An SBOM generated from each rebuild
Continuity
A recovery plan that hasn't been run
A rebuild with no help from the supplier, in hours
Backup
Backups that run
Daily backups you can restore
Step 3, the model, in ISMS order. Scope, protection, evidence, audit. Backup covers in-house systems; Escrow, Resilience and Continuity cover supplier applications. Rebuilds are a Pro and Continuity feature, as step 3 says.

How it works

From supplier register to audit file.

One account for the applications in your ISMS scope, in-house or from a supplier.

1

Start from your register

Add the supplier applications your services depend on, and the in-house systems in scope.

2

Attach a protection

Escrow for supplier applications. Resilience or Continuity for supplier or in-house applications. Backup for systems you run yourself.

3

Collect the evidence

Certificates and vault reports with every protection. Rebuilds, SBOMs and Exit workbooks with Pro and Continuity.

4

Show your auditor

Dated documents per application for internal audits, surveillance audits and recertification.

Step 4, the proof: the evidence map auditors and ISMS owners want. Control numbers and titles only, as the brief requires; titles are exactly as listed in BSI's mapping tool. The right-hand column names confirmed documents. "Supports" is the stance: the auditor decides.
  • Confirm before launch: production says Software Backup includes a Software Resilience Certificate. Confirm it carries over before the 8.13 row names it.
  • The 5.22 row says "rebuild when the deposit changes". Agentic Verification monitoring between runs appears on the older verification site but isn't in the confirmed facts, so it isn't claimed.

Evidence map

Evidence for each Annex A control.

Which documents support which control, and the protection they come with.

ISO/IEC 27001:2022, Annex ACodekeeper evidence
5.19 Information security in supplier relationshipsEach critical supplier application held by a neutral custodian, checked and certified.
Software Resilience CertificateVault reportEscrow · Resilience · Continuity
5.20 Addressing information security within supplier agreementsWhat's deposited, when it's released and who runs the recovery, written into the agreement.
Escrow AgreementResilience ArrangementEscrow · Resilience · Continuity
5.21 Managing information security in the ICT supply chainA software bill of materials and documented build steps for each rebuilt application, so you know what it depends on.
SBOMBuild stepsEscrow Pro · Resilience Pro · Continuity
5.22 Monitoring, review and change management of supplier servicesDeposits sync daily from the supplier's systems, with an automated check. Rebuild when the deposit changes: four rebuilds a year are included.
Vault reportRun reportEvery protection · rebuilds with Pro and Continuity
5.29 Information security during disruptionA planned recovery for critical supplier applications, run by Codekeeper. With Continuity, the live environment is kept paid and switched on for an agreed period while we recover.
Resilience ArrangementLive environment mapResilience · Resilience Pro · Continuity
5.30 ICT readiness for business continuityProof the application rebuilds with no help from the supplier, and an Exit workbook with the recovery steps. Add an Exit Exercise to test the business functions you rely on.
Recoverability CertificateExit workbookTested Exit ReportEscrow Pro · Resilience Pro · Continuity · Exit Exercise as an add-on
8.13 Information backupDaily backups of your in-house applications, with the three latest versions kept and restorable.
Software Resilience CertificateSoftware Backup

Controls are named by number and title only; the full text is in the standard, available from ISO. Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your auditor to decide.

Step 4 continued: the three proofs. Production sells "Verification" with "Software Resilience Certificates for formal compliance records" and "independently verified evidence". Those levels are replaced. This is the agreed ladder, word for word as on the homepage: there, it builds, you could exit.

The proof

Proof beats promises.

Every protection comes with evidence. The higher you go, the more it proves.

Every protection

Software Resilience Certificate

The deposit is held, and an automated check confirms what's in it, with a vault report.

Proves: it's there.

Escrow Pro · Resilience Pro · Continuity

Recoverability Certificate

AI agents rebuild the deposit in a sealed sandbox, with no help from the supplier, in hours. It documents the rebuild; release rights come from the agreement.

Proves: it builds. Agentic Verification

Add-on to any plan

Tested Exit Report

Our specialists rebuild by hand in a clean room and test the business functions you nominate, without the original developers.

Proves: you could exit and keep working. Exit Exercise

Answer the auditor's next question: what about Codekeeper as a supplier? If we hold a customer's deposits, we're in their supplier register under 5.19. Every line here is a confirmed fact: ISO/IEC 27001:2022 certified and audited by BSI, AES-256 at rest, TLS in transit, our own models with no third-party AI, and a sealed sandbox per run. Production badges also show SOC 1/2/3, PCI DSS and other certifications; per the brief, only ISO 27001 is claimed until the team confirms the rest. The card is a summary, not a copy of the BSI certificate, so it doesn't use BSI's mark.

Codekeeper as your supplier

We're in your supplier register too.

If Codekeeper holds your deposits, we fall under your own supplier controls. We hold ourselves to the same standard: Codekeeper is certified to ISO/IEC 27001:2022, audited by BSI.

Encryption, how Agentic Verification handles your code, and more detail on our certification are in the Trust Center.

Step 3 again, as a choice, with prices. The three jobs with the 6 Oct "from" prices and the agreed price logic sentence. Backup is named for in-house systems (8.13) without a price, because its production price still has a $99 vs $89 conflict to resolve.

Choose the protection

Escrow, Resilience or Continuity.

Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on.

Released to you

Escrow

Deposit→Released to you→You recover

When the agreed conditions are met, the deposit is released to you. Escrow Pro adds proof it builds. Explore Escrow

From $199

Recovered by us

Resilience

Deposit→Comes to us→We recover

If the application fails, Codekeeper runs the recovery for you. Resilience Pro starts from a deposit we know builds. Explore Resilience

From $399

Kept switched on

Continuity

Live service kept on+We recover

Everything in Resilience Pro, plus the live environment kept paid and switched on for an agreed period while we recover. Explore Continuity

From $1,449

Prices per application per month. For systems you build and run yourself, Software Backup attaches the same way. See all prices

Three situations, not six industries. Production lists six sectors that pursue ISO 27001. Buyers recognise themselves faster by where they are in the certification cycle, and vendors by who's asking them for evidence.

Who it's for

Wherever you are in the audit cycle.

Preparing for certification

Show how your supplier and continuity controls work in practice, with documents an auditor can read. Verification

Already certified

Keep the evidence current between audits, with four rebuilds a year included in Pro. Resilience Pro

Selling to certified customers

Their supplier controls include you. Give them a certificate and proof your application builds. Escrow Pro

The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
The questions ISMS owners and auditors ask. Production's "three principles", "how hard is it to get" and "ISO 27001 vs SOC 2" answers are general ISO explainers, not about our product, and one carries an unsourced "six to 18 months"; they're cut. Production's transition timeline is cut too: the 31 October 2025 transition deadline has passed, and it came from certification-body rules, not the standard.

Questions

Before your next audit.

Does ISO/IEC 27001 require software escrow?

Codekeeper is one way to put evidence behind the supplier, continuity and backup controls. How you meet each control, and whether the evidence is enough, is for you and your auditor to decide.

Which Annex A controls does the evidence relate to?

Mainly 5.19 to 5.22 for suppliers, 5.29 and 5.30 for disruption and continuity, and 8.13 for backup. See the evidence map for the documents that go with each.

Why don't you quote the controls?

ISO standards are copyright documents, so we name controls by number and title only. Your copy of the standard has the full text.

Is Codekeeper itself ISO 27001 certified?

Yes. Codekeeper is certified to ISO/IEC 27001:2022, audited by BSI. See the Trust Center.

What does our auditor actually receive?

Dated documents for each protected application: Software Resilience Certificates and vault reports, and with Pro or Continuity a Recoverability Certificate, run report, SBOM and Exit workbook. An Exit Exercise adds a Tested Exit Report. The sample evidence pack shows them.

Does this cover systems we build ourselves?

Yes. Software Backup protects in-house systems with daily backups you can restore, and Resilience or Continuity can put their recovery with us. Escrow covers applications you buy from a supplier. All of them sit in one account.

The same close on every page. The ISO page closes on the supplier controls, the area where auditors most often ask for proof beyond policy. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Put evidence behind your supplier controls.

We'll take two or three applications from your supplier register and show you the evidence each protection gives you.