NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why this page exists, and what changed. This page keeps production's URL (/saas-escrow) and its search intent ("SaaS escrow", "what is SaaS escrow"). In the new model, SaaS is an application type. The page explains why a SaaS deposit is different (the vendor runs the application, so code alone won't bring it back), what we deposit, and which protections fit, with the SaaS price row.
  • Headline: keeps the search phrase and says what makes SaaS different in the sub.
  • Prices: the SaaS row of the 6 Oct list. Production's $199 (and the $179 in the pricing FAQ), the $249 setup and the $199-per-hour release fee are gone.
  • Visual: a SaaS deposit mock with every layer production lists: code, infrastructure, data, access, third-party services.
  • Dropped: "Live in 24 hours", "so disruptions never strand your business", "bulletproof", "guarantees uptime", "Military-grade", the Validated, Verified and Certified tiers.
SaaS escrow

SaaS escrow for the cloud applications you can't run without.

With SaaS, the vendor runs the application for you, so code alone won't bring it back. Codekeeper holds the code, its infrastructure definitions, data exports and access to the cloud accounts, synced daily and checked.

Escrow $249. Escrow Pro $599. Per SaaS application per month.

  • Trusted by 3,500+ teams
  • ISO/IEC 27001:2022 certified
  • 50+ integrations, synced daily
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Step 1, the exposure, answered as the search question. "What is SaaS escrow?" is the query this URL ranks for, so the definition leads, reworded from production's definition and FAQ. The three risks are production's ("Lost access", "Recovery from scratch", "Failed enterprise deals"), calmer. Production's chain of fear lines ("When they fail, your operations break… your business stops") is gone. Production shows a three-party diagram here (what-is-diagram-saas-escrow.png). It couldn't be opened from the kit to check for old product or tier names, so the model is drawn as a product screen instead; swap the diagram back in only after someone has checked it.

What is SaaS escrow?

A neutral party holds what it takes to run the service.

SaaS escrow is an agreement between a cloud software provider, its customer and a neutral escrow agent such as Codekeeper. The provider deposits source code, infrastructure details, data and the access needed to run the application. If an agreed release condition is met, the customer can rebuild or move the service without the provider. It protects against:

  • Lost access. A shutdown or acquisition that halts the service and strands your data.
  • Recovery from scratch. Months spent reverse-engineering a system you have no source code for.
  • Stalled enterprise deals. Procurement and auditors who ask for a continuity plan before they sign.
Step 2, the shift, made specific to SaaS. This is the reason the page exists: a SaaS deposit needs infrastructure, data exports and access to cloud accounts, because the vendor runs the application. Production makes the same point in its FAQ ("Traditional escrow protects on-premises software… SaaS Escrow captures your entire cloud environment"); "entire" is dropped as an absolute. The suggested film is the one planned in MESSAGING.md §10 ("SaaS: what we deposit", about 45 s).

Why SaaS is different

Code alone won't bring a SaaS application back.

On-premise software runs on your servers, so the code and its build files are most of what you need. SaaS runs in the vendor's cloud. If the vendor stops, you also need the infrastructure it runs on, the data, the services it calls and access to the accounts that hold them.

A code-only deposit

  • Source code, with no record of the infrastructure it runs on
  • No data, so the application comes back empty
  • No access to the cloud accounts and services it depends on

A SaaS deposit with Codekeeper

  • Code, infrastructure definitions and deployment configuration
  • Data exports, synced daily with the rest of the deposit
  • The credentials and access needed to deploy, manage or restore it, with its third-party services listed
Suggested film SaaS: what we deposit About 45 s. Open on a SaaS application a business relies on every day. Peel it back layer by layer: the code, the infrastructure-as-code that recreates its environment, the data exports, the cloud account access and the third-party services it calls. Each layer drops into the Codekeeper vault and syncs daily. Close on the certificate and Book a demo.
Step 3 in detail: the six layers of a SaaS deposit. These are production's six asset types for SaaS, reworded. "Secrets, credentials and access" becomes "Credentials and access" and names cloud accounts, as the brief asks. Card links go to production's asset pages to keep that search traffic.

What we deposit

Six layers, held together and kept current.

A SaaS deposit captures the elements of the cloud environment beyond the code, so the application can be rebuilt or moved without the vendor.

Source code

The core code, scripts, libraries and dependencies needed to rebuild and run the application. Source code escrow

Infrastructure and deployment

Deployment packages, infrastructure definitions and the settings needed to get it running on servers. Deployment assets escrow

Data

Database exports, datasets and configuration the application needs to work. Data escrow

Credentials and access

The passwords, access keys and cloud account access needed to deploy, manage or restore it. Credentials escrow

Third-party services

The external services, libraries and dependencies the application relies on to work. Third-party dependencies

Documentation

How the application works, how to set it up and how to maintain it over time. Document escrow

Step 3, the model, in four steps. Production's steps ("Schedule a discovery call", "Select your coverage" with a verification tier, "Activate continuous storing", "Get your resilience certified") are rewritten to the new model. "Drafted by our legal team" is a production claim ("Legal framework included"); confirm it's still part of every plan. Production's "24/7/365 event processing" at "$199 per hour" is left out: no operations service levels, and the fee differs between production pages.

How it works

Map it, agree it, connect it, prove it.

1

Map what it runs on

We review the application with you: code, infrastructure, data, services and accounts.

2

Put the agreement in place

Two-party, three-party or multi-party, drafted by our legal team and managed in the app.

3

Connect and sync

Link repositories and cloud platforms through 50+ integrations. Deposits sync daily, or upload by hand.

4

Check and certify

We check what's deposited and issue a Software Resilience Certificate. With Pro, AI agents rebuild it.

Step 3 continued: which protection fits, with the SaaS price row. The SaaS row of the 6 Oct 2026 list: Escrow $249, Escrow Pro $599, Resilience $449, Resilience Pro $799, Continuity $1,599. The level lines are canonical, and the note is the price logic sentence word for word plus the confirmed setup, claimant, cost coverage and Enterprise terms. Continuity gets a strip of its own because a SaaS application depends on a live environment the vendor pays for; the copy is the confirmed Continuity job, and hands-on operation stays on the Continuity and Pricing pages only.

Protections for SaaS

The whole line-up. One price row for SaaS.

Attach the protection that matches the job. Prices are per SaaS application per month.

Released to you

Escrow

Everything you need to be protected.

Custody, release under the Escrow Agreement, an automated check and a Software Resilience Certificate.

$249per application per month

Explore Escrow
Released to you

Escrow Pro

Everything you need to recover.

Escrow plus Agentic Verification: proof the deposit builds, and a Recoverability Certificate.

$599per application per month

Explore Escrow Pro
Recovered by us

Resilience

We recover it.

The deposit comes to Codekeeper. If the service fails, we run the recovery.

$449per application per month

Explore Resilience
Recovered by us

Resilience Pro

Proven before we need it.

Resilience plus Agentic Verification, so recovery starts from a deposit we know builds.

$799per application per month

Explore Resilience Pro
Kept switched on

Continuity

Full continuity.

Everything in Resilience Pro, plus the live environment kept paid and switched on for an agreed period while we recover.

$1,599per application per month

Explore Continuity

Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on. Setup is $499 per arrangement, or $999 for Continuity. One claimant is included; more are an add-on. Cost coverage is quoted for Resilience and Continuity. Enterprise: talk to us. See all prices

If the service can't stop, choose Continuity.

We map the live environment at setup (where it runs, the accounts it depends on, the services it needs) and keep the map current. If the vendor stops, we keep it paid and switched on for an agreed period while we recover. Bills are recharged at cost.

Explore Continuity
Step 4, the proof: a run report for a SaaS deposit. Production's "Get certified proof of recovery readiness" offered Validated, Verified and Certified; Agentic Verification replaces them. The run report is an example built from the documented component, with fictional values. The copy uses only confirmed facts: sealed sandbox, no vendor help, hours, 4 rebuilds a year, supported technology stacks (none named), our own models. Confirm which SaaS deposits (for example, infrastructure definitions) current supported stacks can rebuild before launch.

The proof

Proof the deposit builds, without the vendor.

Every protection includes a Software Resilience Certificate. Escrow Pro, Resilience Pro and Continuity add Agentic Verification: AI agents rebuild your deposit in a sealed sandbox, cut off from production and the open internet, in hours.

  • 4 rebuilds a year that you start, on supported technology stacks
  • Missing items flagged, so they can be added to the deposit
  • Build steps, an SBOM, an Exit workbook and a deployable copy
  • Runs on Codekeeper's own models. Your code stays in our environment
The platform facts that remove friction. 50+ integrations, daily sync, ISO/IEC 27001:2022, AES-256 at rest and TLS in transit are confirmed. The named integrations match the home page; production's SaaS page also shows Shopify, Stripe and Chargebee logos, left out until the team confirms which integrations to name. Version history, multi-factor authentication and the two dashboards come from production; confirm them. "Military-grade security built into every vault" is gone.

Built to stay current

Connect once. The deposit keeps up with the service.

SaaS changes often. Connect the vendor's repositories and cloud platforms once, and we sync code, data and configuration daily, so the deposit matches what's running.

  • 50+ integrations, including GitHub, GitLab, Bitbucket, Azure DevOps, AWS, Azure and Google Cloud
  • Every deposit logged, with timestamps and version history
  • Vendor and customer each see the deposit's status in their own dashboard
  • ISO/IEC 27001:2022 certified, with AES-256 encryption at rest, TLS in transit and multi-factor authentication
SaaS escrow is bought from both sides. SaaS vendors use it to win enterprise deals (production's SaaS testimonial is about exactly that), customers use it to protect services they can't easily replace, and regulated firms need evidence for exit plans. The DORA card links to the DORA page instead of quoting regulation here.

Who it's for

For the vendor, the customer and the auditor.

SaaS vendors selling to enterprises

Give procurement the continuity answer it asks for, with a certificate and, with Pro, proof the service rebuilds.

Businesses that run on SaaS

Payments, CRM, operations: protect the cloud applications you'd struggle to replace quickly.

Regulated firms

Exit plans need more than a contract. Get evidence for your file, from certificates to run reports. DORA

Route to the other application types, and to Backup. Production's "Need protection for other software types?" is kept as the new model: the other two application types with their own Escrow prices, and Software Backup for systems you run yourself.
The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
Keep the answers people search for. "What is SaaS escrow?", "Can you escrow SaaS software?", "How is it different from software escrow?" and "key requirements" are production questions that bring search traffic, so they stay, reworded. Removed: "guarantee access", "guarantees uptime", "prevents any loss", "ironclad", and the $5,000 and 40+ hours savings (unsourced; the testimonial says EUR, the FAQ says $).

Questions

SaaS escrow, answered.

What is SaaS escrow?

SaaS escrow is an agreement that lets the customers of a cloud application keep access to what it takes to run it. The SaaS provider deposits source code, infrastructure details, data and other essential materials with a neutral escrow agent, such as Codekeeper, who holds them for both parties and releases them if an agreed release condition is met.

Can you escrow SaaS software?

Yes. A SaaS deposit covers more than code: the infrastructure it runs on, data exports, credentials and access, and the third-party services it depends on, synced daily.

How is SaaS escrow different from software escrow?

Software escrow protects applications that run on your own servers, so the code, build assets and documentation are the core of the deposit. SaaS escrow also captures what the vendor runs for you: infrastructure, data, configuration and access to the cloud accounts, synced daily.

What does a SaaS escrow agreement protect?

Source code, infrastructure and deployment assets, data, credentials and access, third-party service details and documentation. The agreement lists what's deposited, and our automated check confirms it's there.

What are the key requirements of a SaaS escrow?

A clear agreement with release conditions, a deposit that covers every layer of the application, and daily syncs, so the deposit matches what's running.

What if the service has to stay on?

That's Continuity. We map the live environment at setup and keep the map current. If the vendor stops, we keep it paid and switched on for an agreed period while we recover, and recharge the bills at cost.

How much does SaaS escrow cost?

For a SaaS application, Escrow is $249 per month and Escrow Pro $599, with a $499 setup per arrangement. Resilience is $449 and Resilience Pro $799. Continuity is $1,599, with a $999 setup. One claimant is included. See pricing

Do we need SaaS escrow if we have a disaster recovery plan?

Your disaster recovery plan covers systems you run. A SaaS application runs in your vendor's environment, so your plan can't restore it. SaaS escrow gives you the materials to redeploy it, or, with Resilience, has us run the recovery.

Which kinds of agreement can we use?

Two-party agreements between the vendor and Codekeeper, so protection can extend to any customer who asks. Three-party agreements that name one beneficiary. Multi-party agreements that name several, each with its own release conditions.

The same close on every page. The close repeats the hero's promise and the first step of the process: mapping what the service runs on. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Protect the cloud applications you can't run without.

We'll map what your SaaS application runs on and match the right protection to it.