NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why this page exists, and what it replaces. Production has two overlapping explainers: /products ("Complete software resilience for your systems") and /how-it-works ("The process behind guaranteed software resilience"). Both describe the old catalogue (Software, SaaS, AI and Continuity Escrow, Custom Escrow, and Validated, Verified and Certified). This one page replaces both and explains the new model in full, in the five-step order every page follows.
  • The headline is the launch line for this page. "Guaranteed software resilience" and "bulletproof" are gone: we can't promise either.
  • The visual is the model itself. One application's record shows the whole chain: the account, the application, the protection attached, the level chosen and the latest proof. Names and dates are fictional.
  • The "from" price is the lowest list price (Software Escrow, 6 Oct list), so nobody leaves to look for it.
How it works

For the software you can't afford to lose.

One Codekeeper account for every critical application, the ones you build and the ones you buy. Attach the protection each one needs, choose the level, and get proof that it comes back.

From $199. Per application per month, by the protection and level you choose.

  • Trusted by 3,500+ teams
  • ISO/IEC 27001:2022 certified
  • 50+ integrations, synced daily
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Step 1, the exposure, in three calm sentences. These are the launch site's three problems, chosen because each one maps to something the model fixes: the vendor (a protection), the recovery owner (Resilience and Continuity) and the gaps in the file (the proof ladder). Production's four risk icons ("failing, being attacked, becoming non-compliant, breaking") and the line "Software protection ensures no single failure… can take control away from your business" are cut: the first is a list without an answer, the second is an absolute. No statistics here; the homepage carries them, flagged.

The exposure

Your business runs on software you don't control.

Your operations depend on applications you build and applications you buy. When one fails, you feel it first. Without a plan already in place, recovery becomes improvisation.

The vendor disappears

Insolvency, an acquisition or a shutdown can take an application away overnight, along with the people who know how to run it.

No one owns the recovery

A copy of the code doesn't bring a system back on its own. Someone still has to rebuild it, configure it and run it.

The file has gaps

Auditors, clients and regulators now ask what happens next, and whether you could leave a supplier and keep working. Every gap costs time and credibility.

Step 2, the shift: name the gap without knocking any plan. The left column describes recovery without a plan, not Escrow. That matters: Escrow is "everything you need to be protected", so it must never read as the weak option. The right column previews the model and the proof, which the next sections explain in turn.

The shift

Having the code is the start. Having it back is the goal.

Proof beats promises. Software Resilience gives every critical application a named job for the day it fails, and evidence that the job can be done.

Recovery as improvisation

  • Critical applications spread across contracts, teams and vendors
  • Nobody named to bring each one back
  • Auditors get assurances, not evidence

Recovery as a plan

  • Every critical application in one account
  • A protection for each: released to you, recovered by us, or kept switched on
  • Evidence on file, from a Software Resilience Certificate to a Tested Exit Report
Step 3, the model, as four nouns. This is the spine of the site: account, then applications, then a protection for each, then a level. Production's "Select your application type / Choose your protection level / Get your resilience certified" said something similar, but mixed application types with escrow products. Here each step is one decision, one sentence. "Base" is used as the comparison label; it's never a tier name.

The model

One account. A protection for each application.

Add the applications you can't lose, attach the protection each one needs and choose the level. Deposits, agreements and certificates all run from the same account.

1

Your account

One place for your team, your agreements, your integrations and every certificate.

2

Applications

Each system your business can't lose: vendor software, SaaS, AI, or something you built yourself. Prices are per application.

3

A protection

Escrow, Resilience, Continuity or Backup, chosen by what should happen if the application fails.

4

A level

The base level is everything you need to be protected. Pro is everything you need to recover. Continuity has one level.

Step 3 continued: the protection is chosen by its job. The same three-job cards appear on the Escrow, Resilience and Continuity pages; here none is outlined because this page sits above all three. Backup sits underneath as a peer protection with a lighter job, so it's never framed as a lesser Escrow. Cost coverage uses the agreed wording only ("the cost of a recovery, under an agreed service level"); it is not called insurance. Prices are the 6 Oct "from" list.

Protections

Choose by what should happen when it fails.

Escrow, Resilience and Continuity can protect the same application. The difference is the job we do on the day you need it.

Released to you

Escrow

Deposit→Released to you→You recover

We hold the deposit as a neutral party. When the agreed conditions are met, it's released to the beneficiary and you run the recovery. Explore Escrow

From $199

Recovered by us

Resilience

Deposit→Comes to us→We recover

The deposit comes to Codekeeper. If the application fails, we run the recovery for you. Explore Resilience

From $399

Kept switched on

Continuity

Live service kept on+We recover

Everything in Resilience Pro, plus we keep the live environment paid and switched on for an agreed period while we recover. Explore Continuity

From $1,449

Backup: your systems, backed up and restorable

A peer protection with a lighter job. Daily backups of the data and artefacts you deposit, ready to restore when you need them. It attaches to an application the same way. Explore Software Backup

Cost coverage, for Resilience and Continuity

Add the cost of a recovery, under an agreed service level. It's quoted per arrangement, so it fits the application and the recovery it would need.

Step 3, the last decision: the level, with prices. The five-card line-up is the whole range in one row, the same as on the homepage. Each card carries its canonical level line and the 6 Oct "from" price (Software row). The sentence underneath is the agreed price logic, word for word, followed by the setup fees. Don't add annual or monthly billing, discounts or the production "Save 20%" offer until sales confirms them.

Levels and prices

Then choose the level.

The base level is everything you need to be protected. Pro is everything you need to recover: it adds Agentic Verification, so you know the deposit builds before you need it.

Released to you

Escrow

Everything you need to be protected.

Custody by a neutral party, release under the Escrow Agreement, an automated check and a Software Resilience Certificate.

From $199per application per month

Explore Escrow
Released to you

Escrow Pro

Everything you need to recover.

Everything in Escrow, plus Agentic Verification: rebuilds, an SBOM, an Exit workbook and a Recoverability Certificate.

From $449per application per month

Explore Escrow Pro
Recovered by us

Resilience

We recover it.

Custody, an automated check and a Software Resilience Certificate. If the application fails, we run the recovery.

From $399per application per month

Explore Resilience
Recovered by us

Resilience Pro

Proven before we need it.

Everything in Resilience, plus Agentic Verification, so recovery starts from a deposit we know builds.

From $649per application per month

Explore Resilience Pro
Kept switched on

Continuity

Full continuity.

Everything in Resilience Pro, plus we keep the live environment paid and switched on for an agreed period while we recover.

From $1,449per application per month

Explore Continuity

Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on. Setup is $499 per arrangement for Escrow and Resilience, and $999 for Continuity. See all prices

Step 4, the proof ladder. Production lists Validated, Verified and Certified as "assurance" options with Basic, Enhanced and Premium certificates; Agentic Verification replaces all three. The ladder shows the three proofs a customer can hold and where each comes from. Two agreed lines are kept: the Recoverability Certificate documents the rebuild and doesn't grant release rights, and the regulation line says "ready for a file", never "compliant". The disclaimer sits directly under it. Legal should review the disclaimer before launch.

The proof

Every protection comes with proof.

Evidence you can put in front of an auditor, a client or your board, ready for a DORA Article 28 or PRA SS2/21 file. The higher you go, the more it proves.

Escrow · Resilience · Continuity

Software Resilience Certificate

The deposit is held, and an automated check confirms what's in it, with a vault report.

Proves: it's there.

Escrow Pro · Resilience Pro · Continuity

Recoverability Certificate

AI agents rebuild the deposit in a sealed sandbox, with no help from the vendor, in hours. You also get the run report, an SBOM and an Exit workbook. The certificate documents the rebuild; release rights come from the agreement.

Proves: it builds. Agentic Verification

Add-on to any plan

Tested Exit Report

Our specialists rebuild by hand in a clean room and test the business functions you nominate, without the original developers.

Proves: you could exit and keep working. Exit Exercise

Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.

The set-up journey: production's five steps, reworked for the new model. Production's steps were "Book a demo and choose a plan, Invite your team and set up an escrow agreement, Upload deposits, Order asset verification, Earn Software Resilience Certificates". Verification is no longer a separate order: it comes with the level. So step 4 is "choose the level" and step 5 is what you receive. The integration and manual-upload facts come from production. To confirm before launch: production says agreements are drafted "in less than a day" and set up "within 24 hours"; both are left out until operations confirms them.

Getting started

From demo to certificate in five steps.

1

Book a demo

We start with the applications your business can't run without, and recommend a protection and level for each.

2

Add applications and set up agreements

Invite your team and add each application. The agreement for each protection is set up in the app, with the terms clear before anyone signs.

3

Connect integrations and deposit

Connect your repositories and cloud accounts once and deposits sync daily, through 50+ integrations. Where automation isn't possible, upload them yourself.

4

Choose the level

Base or Pro for Escrow and Resilience. Continuity has one level, with Agentic Verification included.

5

Receive certificates and, with Pro, rebuilds

We check what's deposited and issue a Software Resilience Certificate. With Pro and Continuity, you start up to four rebuilds a year, and each successful run issues a Recoverability Certificate.

Production's audience angle, kept, because it fits a "how it works" page. The homepage sorts buyers by situation; this page explains how the account works inside an organisation, so the four-team view from /products earns its place. Each line is rewritten to confirmed facts. Cut from production: "24/7 support team for escrow releases", "Real-time monitoring", "Zero manual deposits", "lifetime auto-sync" and "custom liability limits". To confirm: production's "jurisdiction choice" applies to Resilience and Continuity arrangements as well as Escrow Agreements.

Who it's for

One account. Every team gets what it needs.

Compliance gets proof. Management gets control. DevOps gets automation. Legal gets flexibility.

Compliance gets proof

Certificates, run reports, SBOMs and Exit workbooks: dated evidence for your file, ready to share with an auditor.

Management gets control

Every critical application, its protection, its level and its latest proof in one place, with a named job for the day one fails.

DevOps gets automation

Connect once and deposits sync daily. Rebuilds are self-serve, and anything missing is flagged so it can be added.

Legal gets flexibility

Two-party, three-party or multi-party agreements, clear release conditions, and a jurisdiction that fits your contracts.

The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
The questions people ask once they understand the model. Production's FAQ here is escrow-only ("How does software escrow work?", "How quickly can source code protection be implemented?"). These answer the model instead. Two answers need confirming before launch: whether one application can carry more than one protection (agreed internally on 27 Sep, but how it's priced is still open), and the wording for existing customers, which customer success should check.

Questions

How the model works in practice.

What counts as an application?

Any system your business can't lose: vendor software, a SaaS platform, an AI system or something you built yourself. Prices are per application, with separate rows for software, SaaS and AI.

Who runs the recovery?

It depends on the protection. With Escrow, the deposit is released to you and you run the recovery. With Resilience and Continuity, the deposit comes to Codekeeper and we run it, on a best-effort basis. Recovery work is billed to the claimants who need it.

What's the difference between the base level and Pro?

The base level holds the deposit, checks what's in it and issues a Software Resilience Certificate. Pro adds Agentic Verification: four rebuilds a year in a sealed sandbox, build steps, an SBOM, an Exit workbook, a deployable copy and a Recoverability Certificate.

Can one application have more than one protection?

Yes. For example, Backup for your own restorable copy and Escrow for a customer who needs release rights. We'll quote the combination with you.

Where does Backup fit?

Backup is a peer protection with a lighter job: daily backups of the data and artefacts you deposit, restorable when you need them. It suits systems you run yourself. Software Backup

What happened to Validated, Verified and Certified?

Agentic Verification replaces them. It's included in Escrow Pro, Resilience Pro and Continuity. Escrow and Resilience include an automated check and a Software Resilience Certificate.

Will this make us compliant with DORA or PRA SS2/21?

Codekeeper gives you evidence for your file: certificates, run reports, SBOMs and, with an Exit Exercise, a Tested Exit Report. Whether it meets a specific requirement is for you and your assessor to decide.

I'm already a customer. Does my plan change?

No. Your current plan stays as it is until renewal. Your account manager can walk you through the new options, including Pro and Continuity, whenever you're ready.

More answers in the FAQ

The same close on every page. This page explains the model, so it closes on the first step of using it: start with the applications you can't lose. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Begin with the applications that matter most.

We'll walk through your stack and match the right protection and level to each application.