NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why this page looks like this. The Trust Center is read by security reviewers, procurement and auditors, so it states only what production states, and where production contradicts itself it takes the conservative reading. The main changes:
  • One certification, ISO/IEC 27001:2022 (BSI). Production's badge row also shows ISO 27017, ISO 27018, ISO 9001, SOC 1, SOC 2, SOC 3, PCI DSS Level 1 and CSA, while its own text says "SOC 2 aligned operations". None of those badges appears here as a Codekeeper certification until the team confirms them.
  • No absolutes. "Security isn't something we add, it's how we're built", "24/7 monitoring", "without a security incident" for a decade and "Even our own engineers cannot bypass these controls" are left out.
  • A page-specific path for reviewers. The line under the buttons jumps to the documents and the request form. The hero keeps the site's two standard buttons.
  • The hero visual is a summary of the controls set out on this page, not a certificate image, so it can't be mistaken for the certificate itself.
Trust Center

We hold your code to a certified standard.

Codekeeper is certified to ISO/IEC 27001:2022, audited by BSI. Here's how we protect your deposits, how Agentic Verification keeps your code in our environment, and which documents you can request for your review.

Reviewing us as a supplier? Request our security documents

  • ISO/IEC 27001:2022 certified
  • AES-256 encryption at rest
  • Founded 2014
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Step 4, the proof, applied to ourselves: one certification, stated precisely. "ISO/IEC 27001:2022, audited by BSI" comes from production's Trust Center FAQ, as does the annual certification audit. The data centre card keeps production's wording: the ISO 27001 and SOC 2 certifications belong to our hosting partners, not to Codekeeper. Production's "SOC 2 aligned operations" and "aligned with frameworks such as SOC 2" are left out of the visible copy: next to the old SOC badges, "aligned" reads like a certification. Decide whether to restore that wording once the badges are resolved.

Certification

Certified to ISO/IEC 27001:2022.

Our information security management system is certified to ISO/IEC 27001:2022 and audited every year by BSI. We identify and treat information security risks the way the standard requires.

ISO/IEC 27001:2022

Certified, with an annual certification audit by BSI. The certificate and an ISMS summary are available on request.

Certified data centre partners

We don't run our own data centres. Our hosting partners' data centres hold ISO 27001 and SOC 2 certifications.

GDPR and a DPA

We handle personal data in line with GDPR, and our data processing agreement is available to customers on request.

The controls, grouped the way questionnaires ask. Production's seven control categories and its "quick summary" are merged into six cards. Every line is a production statement, reworded without absolutes. Conservative choices, to confirm before launch:
  • Encryption: production says both "AES-256" and "AES-256/512". The page says AES-256. Production's "end-to-end encryption" heading describes encryption at rest and in transit, so that's what the page says.
  • Multi-factor authentication: production says "All accounts are protected with MFA" and the FAQ says 2FA is required for all users, but the encryption answer says "optional multi-factor authentication". The page says MFA without "all" or "required" until one answer is confirmed.
  • Access to deposits: the production FAQ says "no one at Codekeeper has access to your escrowed materials"; the Trust Center says we access deposited code only for release or verification. The page uses the Trust Center version.
  • Incident response: "typically within 24 hours" is production's figure and is flagged until security confirms it. Production's "notification timelines that meet GDPR's 72-hour requirement" is left out; the page uses production's other wording, "without undue delay". Legal should confirm which commitment applies.
  • Testing: plans are "tested at planned intervals" (production's summary). Penetration testing is not claimed: the production FAQ says "We do not currently conduct penetration testing", although its summary lists "third-party audits". Production's "cyber insurance" line is also left out, to keep "insurance" off the site.

Controls

How we protect your deposits.

The controls behind the certificate, grouped the way security questionnaires ask about them.

Data protection

  • AES-256 encryption at rest
  • TLS for data in transit
  • Encryption keys managed through a defined lifecycle, including rotation
  • Deposit operations and access attempts logged

Access control

  • Multi-factor authentication
  • Least-privilege access, reviewed every quarter
  • No access to deposited code except for a release or a verification, and every access is logged
  • Release conditions verified before anything is released

Infrastructure

  • Hosted with major cloud providers
  • Partner data centres with ISO 27001 and SOC 2 certifications
  • Firewalls, intrusion detection and network segmentation between environments
  • DDoS mitigation and continuous vulnerability scanning

People and governance

  • Background checks and confidentiality agreements for team members
  • Security awareness training at onboarding and every year
  • A dedicated information security team
  • Regular risk assessments and vendor security reviews

Incidents and continuity

  • Incidents handled as soon as they're identified, typically within 24 hours
  • Affected customers informed without undue delay
  • Incident response, business continuity and disaster recovery plans, tested at planned intervals
  • Automated, encrypted backups of our databases

Privacy

  • Personal data handled in line with GDPR
  • A data processing agreement on request
  • Customer data deleted on request, from active systems and backups
  • Data kept for the agreed retention period, then erased
New: the first AI question a reviewer asks. Production's Trust Center predates Agentic Verification. Every line here is a confirmed fact from MESSAGING §6: own models, no third-party AI, code stays in Codekeeper's environment, a sealed sandbox for each run (cut off from production, development and the open internet), self-serve runs, and the deployable copy held by the depositor. "Never leaves" is written as "stays in our environment" to keep absolutes out of the copy. The run report is an example.

Agentic Verification

Your code stays in our environment.

Agentic Verification runs on Codekeeper's own models. No third-party AI sees your deposit, and each rebuild runs in its own sealed sandbox.

  • Codekeeper's own models, with no third-party AI
  • Code doesn't leave Codekeeper's environment
  • A sealed sandbox for each run, cut off from production, development and the open internet
  • Self-serve runs: the depositor can add or remove materials at any point
  • The deployable copy is held by the depositor; the customer gains access on a release event
The documents reviewers ask for, as titles only. These are production's thirteen document titles, grouped for scanning. Production splits them into Public and Private tabs, but the split wasn't captured, so every row says "Request access" rather than guessing. The NDA line comes from the production FAQ (an NDA for confidential security documents) and the bulk-download note ("No NDA required" for public documents). Two titles are tidied: "W8-BEN-E/W9 Forms" is written with the official form names (W-8BEN-E, W-9), and "Expert Insights - Software Escrow Agreements" loses the hyphen.

Documents

Documents for your review.

Request what your security review or supplier onboarding needs. General documents are shared without an NDA. Confidential security documents are shared under NDA.

Security and compliancePolicies, certificate and reports
ISO 27001 CertificateRequest access
ISMS SummaryRequest access
Information Security PolicyRequest access
Information Security GuideRequest access
Security Assurance ReportRequest access
Introduction to Software EscrowRequest access
Expert Insights: Software Escrow AgreementsRequest access
Company and procurementFor supplier onboarding
Company Profile OverviewRequest access
Company DetailsRequest access
Chamber of Commerce (KVK) DocumentRequest access
VAT Registration DetailsRequest access
Banking Detail Confirmation LetterRequest access
W-8BEN-E and W-9 FormsRequest access
The reviewer's conversion point. Production uses two forms ("Get access to confidential security documents" and "Bulk download general security documents"), whose fields weren't captured. This is one example form that sends nothing: name, company and email to route the request, plus which set of documents and why, so the team knows whether an NDA is needed first. In production it would connect to the Trust Center's document tool or HubSpot. Have legal confirm the consent wording.

Request access

Request security documents.

Tell us what your review needs. We'll check the request and share the documents, under NDA where they're confidential.

  • The ISO 27001 certificate, ISMS summary and security policies
  • Company, tax and banking details for supplier onboarding
  • Questions answered by our security team

Request documents

Enter your first name.
Enter your company.
Enter a work email, like name@company.com.

This is where the request would go to the team.

This is an example page, so nothing was sent. In production this form sends the request to Codekeeper.

The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
The questions in the order security reviewers ask them. Each answer restates production's Trust Center FAQ in the conservative reading set out above. The certification answer is deliberately precise: Codekeeper holds ISO/IEC 27001:2022, and the SOC 2 certification belongs to the data centre partners. If the team confirms any other certification, add it here and to the certification section. The contact addresses are production's.

Questions

Security questions.

Which certifications does Codekeeper hold?

Codekeeper is certified to ISO/IEC 27001:2022, audited by BSI. The data centres our hosting partners run hold ISO 27001 and SOC 2 certifications.

Where is my source code stored?

Encrypted, with major cloud providers whose data centres hold ISO 27001 and SOC 2 certifications. We don't operate our own data centres. The Security Assurance Report, available on request, describes our network environment in more detail.

Who at Codekeeper can access my deposit?

We don't access deposited code except for a release or a verification, and every access is logged. Access to sensitive information is granted on a need-to-know, least-privilege basis and reviewed regularly.

Does Agentic Verification send my code to an AI provider?

No. Agentic Verification runs on Codekeeper's own models, and your code stays in our environment. Each run gets its own sealed sandbox, cut off from production, development and the open internet.

How do you handle a security incident?

We follow a documented incident response plan: reporting, impact assessment, containment, eradication and root cause analysis. Incidents are handled as soon as they're identified, typically within 24 hours, and affected customers are informed without undue delay. After each incident we review the response and update the plan.

Will you sign a data processing agreement?

Yes. Our DPA sets out how we handle and protect customer data in line with GDPR, including our technical and organisational measures. It's available on request. Data processing agreement

Can you delete our data?

Yes. Customer data is deleted on request, from active systems and from backups. When a service ends, data is returned or deleted in line with the agreement. Request deletion

Do we need an NDA to see your documents?

Only for confidential security documents. General documents are shared without one. Request documents

Who can I contact with a security or privacy question?

For security and compliance questions, email contact@codekeeper.co. For privacy questions, email privacy@codekeeper.co.

The same close on every page. A reviewer who has finished the security check is often the person who books the demo, so the close ties our security back to the product. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Protection you can check, for the software you can't lose.

See how Codekeeper would hold, verify and recover your applications, and what it would show your reviewers.