Source-code and SaaS escrow: the business continuity your enterprise buyers demand in procurement
Large customers must keep running, even if their provider fails. That is why in the vendor security review and in procurement they often require a source-code or SaaS escrow. As a neutral Trusted Third Party we hold source code, build instructions, keys or a live SaaS replication under clearly defined release conditions. This unblocks the deal and complements your ISO 27001 / SOC 2 story, legally led.
An enterprise customer builds critical processes on your software. They must ensure they keep running if your company fails. That is exactly what they require as escrow in procurement.
In the vendor security review and third-party due diligence, the issue is not only security, it is also business continuity. The customer asks: what happens to my operations if the provider becomes insolvent, is acquired or discontinues the service? An escrow gives a contractually secured answer. A neutral, independent third party holds what the customer needs to keep operating and releases it only under pre-defined conditions.
For classic software, the source code is deposited together with build instructions, dependencies and documentation, so the customer can keep running or maintain the application themselves in an emergency. For pure SaaS, source code alone is often not enough: here a SaaS escrow comes into play, with deposited keys, configurations, infrastructure descriptions or a live replication of the environment, so the service stays available even without you.
The release conditions are decisive. The code or the environment is not simply handed over, but only when a contractually defined trigger event occurs, such as insolvency, a permanent loss of support or a material breach of contract. Cleanly drafted conditions protect both sides: the customer against a standstill and you against an unjustified release of your intellectual property.
How SIDD delivers the escrow as Trusted Third Party
We are the neutral third party between you and your customer. We set up the escrow cleanly in law and in practice and hold the deposit securely.
We begin with the escrow agreement. As a legally led house, we draft the agreement between provider, customer and Trusted Third Party so that the deposit object, duties, release conditions, update rhythm and the customer's rights in a release case are clearly governed. This way the escrow fits your other contracts, the data-processing agreement and your security evidence.
We then receive and hold the deposit: source code, build instructions, dependencies, documentation as well as keys and configurations for a SaaS scenario, each encrypted and access-protected. On request we perform a deposit verification, that is a check of whether the deposit is complete, readable and reproducibly buildable. A bare deposit without verification is of little use in an emergency, which is why we recommend this step.
For a SaaS scenario, we design the custody so that in a release case the customer can actually take over or migrate the service, for example via regularly updated keys, infrastructure descriptions or a held replication. We design the release conditions, the key and source-code custody and the update cycles so that the deposit stays current. This escrow does not stand on its own: it unblocks enterprise procurement and complements your ISO 27001 and SOC 2 story, because it answers the business-continuity question that appears in many questionnaires.
Why SIDD as Trusted Third Party
An escrow is only as credible as the third party that holds it. Neutrality, independence and legal depth are not an add-on here, they are the substance.
Neutral & independent
An escrow only works with a third party that belongs to neither you nor the customer. We sell no in-house SOC and no hosting that would play into the escrow. That keeps us the neutral instance both sides can entrust with the custody and the release decision.
Legally led
An escrow stands and falls with the contract. Your mandate is led by doctorate-level lawyers with CIPP/E who draft the deposit object, release conditions and the rights in an emergency on solid ground. So the escrow holds even when it is needed.
A deposit that really holds
A deposited medium that no one has ever checked gives false security. With deposit verification we check whether the deposit is complete and reproducibly buildable, so that in a release case it actually works and does not merely exist on paper.
A sales argument, not a cost centre
A prepared escrow is a ready answer to the business-continuity question in the vendor security review. Instead of negotiating conditions for weeks in procurement, you present a proven model. That accelerates the close and strengthens your position towards the customer.
Part of a whole picture
With us, the escrow sits alongside ISO 27001, SOC 2, the data-processing agreement and the sub-processor list, from one house. So business continuity, security and data protection match in your questionnaire answers, instead of contradicting each other.
Multilingual & Swiss
We set up the escrow in German, French and English, fitting customers and parent companies in CH, EU, UK and US. The custody stays within a clear, Swiss-led framework, which further strengthens the basis of trust for your customers.
Entry packages source-code and SaaS escrow
Source-Code Escrow Setup
Fixed fee / on request
Classic escrow for deposited source code, with agreement, custody and defined release conditions.
Verification of the deposit for completeness, readability and reproducible buildability, so the escrow really holds in an emergency.
Completeness and readability check of the deposit
Check of reproducible buildability from the deposit
Verification report for you and your customer
Repeatable on each updated deposit
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your escrow agreement, concretely: LexCommand drafts the release conditions and trigger events such as insolvency or loss of support as tracked changes in the three-party contract, every legal statement footnoted to its primary source and scoped cleanly to the correct legal system in CH or the EU.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
What is the difference between source-code escrow and SaaS escrow?
With source-code escrow the source code is deposited with build instructions and documentation, so the customer can keep running the software themselves in an emergency. For pure SaaS this is often not enough, because the service depends on infrastructure, keys and configurations. The SaaS escrow therefore additionally deposits keys, configurations or a live replication, so the service stays takeover- or migration-ready.
Who triggers the release, and when?
The release does not happen at will, but only when a trigger event defined in the contract occurs, such as the provider's insolvency, a permanent loss of support or a material breach of contract. As a neutral third party, we check whether the agreed condition is met before we hand the deposit to the customer. This protects both the customer and your intellectual property.
Does SIDD see our source code?
The deposit is held encrypted and access-protected. Inspection takes place only within the agreed scope, for example when you commission a deposit verification in which we check completeness and buildability. We govern the scope and confidentiality in the escrow agreement. Because we work legally led, we treat your content with corresponding confidentiality.
Why not simply deposit a copy with the customer ourselves?
A copy held directly with the customer has two weaknesses: the customer could access it at any time, even without a trigger event, and the neutral instance that checks the release conditions is missing. An escrow via an independent third party solves both. We release only under the agreed conditions, which protects your intellectual property and at the same time gives the customer the assurance they want.
How does the escrow fit our certifications and contracts?
The escrow answers the business-continuity question that sits alongside security and data protection in the vendor security review. Because we also deliver ISO 27001, SOC 2, the data-processing agreement and the sub-processor list from one house, the escrow fits into your questionnaire answers without contradiction. The result is a consistent overall picture of business continuity, security and law.
Related services
How the escrow becomes part of a complete answer to the vendor security review:
Ready to answer the business-continuity question in procurement up front?
We set up your source-code or SaaS escrow as a neutral Trusted Third Party, with agreement, custody, deposit verification and cleanly defined release conditions.