- The exposure: the Annex A controls auditors ask about for suppliers, disruption and backup.
- The shift: from a control on paper to evidence that it works.
- The model: applications, each with a protection.
- The proof: an evidence map from each control to the documents that support it.
- The next step: book a demo, or get the sample evidence pack.
Supplier and continuity controls. Evidence on file.
Auditors ask how you manage suppliers and how you'd recover from disruption. Codekeeper protects the applications behind those controls and gives you dated certificates, run reports and SBOMs to show them.
- Trusted by 3,500+ teams
- ISO/IEC 27001:2022 certified, audited by BSI
- 50+ integrations, synced daily
Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors
Where audits get specific
Suppliers, disruption and backup.
Annex A of ISO/IEC 27001:2022 has controls for each. They're where an auditor moves from "do you have a policy?" to "show me".
Suppliers · 5.19 to 5.22
Information security in supplier relationships and supplier agreements, in the ICT supply chain, and in monitoring and changes to supplier services.
Disruption · 5.29 and 5.30
Information security during disruption, and ICT readiness for business continuity.
Backup · 8.13
Information backup, for the systems you build and run yourself.
The shift
A control on paper is the start. Evidence it works is the goal.
How it works
From supplier register to audit file.
One account for the applications in your ISMS scope, in-house or from a supplier.
Start from your register
Add the supplier applications your services depend on, and the in-house systems in scope.
Attach a protection
Escrow for supplier applications. Resilience or Continuity for supplier or in-house applications. Backup for systems you run yourself.
Collect the evidence
Certificates and vault reports with every protection. Rebuilds, SBOMs and Exit workbooks with Pro and Continuity.
Show your auditor
Dated documents per application for internal audits, surveillance audits and recertification.
- Confirm before launch: production says Software Backup includes a Software Resilience Certificate. Confirm it carries over before the 8.13 row names it.
- The 5.22 row says "rebuild when the deposit changes". Agentic Verification monitoring between runs appears on the older verification site but isn't in the confirmed facts, so it isn't claimed.
Evidence map
Evidence for each Annex A control.
Which documents support which control, and the protection they come with.
| ISO/IEC 27001:2022, Annex A | Codekeeper evidence |
|---|---|
| 5.19 Information security in supplier relationships | Each critical supplier application held by a neutral custodian, checked and certified. Software Resilience CertificateVault reportEscrow · Resilience · Continuity |
| 5.20 Addressing information security within supplier agreements | What's deposited, when it's released and who runs the recovery, written into the agreement. Escrow AgreementResilience ArrangementEscrow · Resilience · Continuity |
| 5.21 Managing information security in the ICT supply chain | A software bill of materials and documented build steps for each rebuilt application, so you know what it depends on. SBOMBuild stepsEscrow Pro · Resilience Pro · Continuity |
| 5.22 Monitoring, review and change management of supplier services | Deposits sync daily from the supplier's systems, with an automated check. Rebuild when the deposit changes: four rebuilds a year are included. Vault reportRun reportEvery protection · rebuilds with Pro and Continuity |
| 5.29 Information security during disruption | A planned recovery for critical supplier applications, run by Codekeeper. With Continuity, the live environment is kept paid and switched on for an agreed period while we recover. Resilience ArrangementLive environment mapResilience · Resilience Pro · Continuity |
| 5.30 ICT readiness for business continuity | Proof the application rebuilds with no help from the supplier, and an Exit workbook with the recovery steps. Add an Exit Exercise to test the business functions you rely on. Recoverability CertificateExit workbookTested Exit ReportEscrow Pro · Resilience Pro · Continuity · Exit Exercise as an add-on |
| 8.13 Information backup | Daily backups of your in-house applications, with the three latest versions kept and restorable. Software Resilience CertificateSoftware Backup |
Controls are named by number and title only; the full text is in the standard, available from ISO. Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your auditor to decide.
The proof
Proof beats promises.
Every protection comes with evidence. The higher you go, the more it proves.
Software Resilience Certificate
The deposit is held, and an automated check confirms what's in it, with a vault report.
Proves: it's there.
Recoverability Certificate
AI agents rebuild the deposit in a sealed sandbox, with no help from the supplier, in hours. It documents the rebuild; release rights come from the agreement.
Proves: it builds. Agentic Verification
Tested Exit Report
Our specialists rebuild by hand in a clean room and test the business functions you nominate, without the original developers.
Proves: you could exit and keep working. Exit Exercise
Codekeeper as your supplier
We're in your supplier register too.
If Codekeeper holds your deposits, we fall under your own supplier controls. We hold ourselves to the same standard: Codekeeper is certified to ISO/IEC 27001:2022, audited by BSI.
Encryption, how Agentic Verification handles your code, and more detail on our certification are in the Trust Center.
Choose the protection
Escrow, Resilience or Continuity.
Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on.
Escrow
Deposit→Released to you→You recover
When the agreed conditions are met, the deposit is released to you. Escrow Pro adds proof it builds. Explore Escrow
From $199
Resilience
Deposit→Comes to us→We recover
If the application fails, Codekeeper runs the recovery for you. Resilience Pro starts from a deposit we know builds. Explore Resilience
From $399
Continuity
Live service kept on+We recover
Everything in Resilience Pro, plus the live environment kept paid and switched on for an agreed period while we recover. Explore Continuity
From $1,449
Prices per application per month. For systems you build and run yourself, Software Backup attaches the same way. See all prices
Who it's for
Wherever you are in the audit cycle.
Preparing for certification
Show how your supplier and continuity controls work in practice, with documents an auditor can read. Verification
Already certified
Keep the evidence current between audits, with four rebuilds a year included in Pro. Resilience Pro
Selling to certified customers
Their supplier controls include you. Give them a certificate and proof your application builds. Escrow Pro
Sample evidence pack
See what your auditor would receive.
An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.
- Recoverability Certificate
- Run report
- SBOM and Exit workbook excerpts
Questions
Before your next audit.
Does ISO/IEC 27001 require software escrow?
Codekeeper is one way to put evidence behind the supplier, continuity and backup controls. How you meet each control, and whether the evidence is enough, is for you and your auditor to decide.
Which Annex A controls does the evidence relate to?
Mainly 5.19 to 5.22 for suppliers, 5.29 and 5.30 for disruption and continuity, and 8.13 for backup. See the evidence map for the documents that go with each.
Why don't you quote the controls?
ISO standards are copyright documents, so we name controls by number and title only. Your copy of the standard has the full text.
Is Codekeeper itself ISO 27001 certified?
Yes. Codekeeper is certified to ISO/IEC 27001:2022, audited by BSI. See the Trust Center.
What does our auditor actually receive?
Dated documents for each protected application: Software Resilience Certificates and vault reports, and with Pro or Continuity a Recoverability Certificate, run report, SBOM and Exit workbook. An Exit Exercise adds a Tested Exit Report. The sample evidence pack shows them.
Does this cover systems we build ourselves?
Yes. Software Backup protects in-house systems with daily backups you can restore, and Resilience or Continuity can put their recovery with us. Escrow covers applications you buy from a supplier. All of them sit in one account.
Put evidence behind your supplier controls.
We'll take two or three applications from your supplier register and show you the evidence each protection gives you.