Continuity Escrow Asset
Credentials escrow
Secure the credentials that let you reach, control, and pay for critical suppliers, so your software's continuity holds through any disruption.
Point us at your preferred integration platform
Depositing credentials made easy. Codekeeper links directly with more than 50 hosting, billing, and infrastructure systems to pull deposits automatically. We provide clear steps for manual uploads if you need them.
View all integrations
What is credentials escrow?
Credentials escrow is a legal arrangement in which a software supplier places the logins, billing rights, and authentication materials needed to manage the platforms and services behind their application with an independent third party such as Codekeeper.
Codekeeper secures those credentials and activates them only when a contract-defined continuity event is confirmed, which can be used to keep essential services running until control returns to the supplier.
Credentials escrow forms part of Codekeeper’s wider Continuity Escrow solution.
Why continuity needs credential protection
Reliable software never runs on its own. It leans on hosting platforms, billing systems, infrastructure tools, APIs, and third-party services. For companies subject to resilience requirements under DORA, FCA, or PRA, keeping those services running through a disruption is an obligation. Losing access to them can breach impact tolerances and cause failed audits.
How are critical services managed when internal access is lost?
How do you prevent missed renewals or subscription payments when a disruption hits?
What keeps your supplier credentials current, organised, and ready to use?
How can all parties be assured that critical services will keep running?
Without access to essential credentials, your software can’t operate the way your business needs it to.
Without access to essential credentials, your software can’t operate the way your business needs it to.
Keep your operational continuity intact with Codekeeper
A verified solution for keeping your supporting services available and active.
Safe custody for your essential logins
Codekeeper holds the credentials needed to manage and renew the hosting accounts, billing portals, and third-party platforms your software runs on.
Continuity coverage for service payments
If a continuity condition is triggered, Codekeeper can draw on the escrowed billing access to cover renewals and stop your essential services from lapsing.
Deposit transparency for all parties
Depositors and beneficiaries can view which platforms and payments are held and monitored, giving firms under the FCA or PRA a clear line of evidence when auditors ask.
Hands-on support from setup to activation
Our support team helps with setup, continuity planning, and guided actions during a confirmed event, so everything plays out exactly as defined in your agreement.
How does credentials escrow work?
1
Map the services in scope
List the supporting services to include, your preferred update intervals, and continuity triggers. Our legal team will have your agreement live in 24 hours.
2
Deposit access credentials securely
Follow the platform-specific steps to add billing users, grant access, or upload credentials through encrypted channels.
3
Keep deposits synced and current
As your software and supplier stack shifts, Codekeeper captures updates automatically, so the escrowed credentials always match your live setup.
4
Trigger continuity when you need it
If a continuity condition is met, Codekeeper puts the escrowed credentials to work so your essential services stay operational.
See how it works
From software risk to resilience
“Excellent service. This is easily the best way to handle it for both yourself and the client.”
“Codekeeper is a new service for creating escrow agreements for code, specifying the legal circumstances where source code can be accessed.”
“Source code escrow is a great service, and one that ALL developers who do client contract work should look into.”
The difference independent access control makes
Without credentials escrow
Access to essential suppliers gets harder to coordinate
Services can go offline during transitions or internal changes
Lost credentials hold up operational decisions
Confidence slips when no independent recovery options exist
With credentials escrow
Supplier access is maintained and independently secured
Essential services keep running through continuity disruptions
Teams act faster because continued access persists
Confidence holds because all parties know critical services will continue
Build out your operational continuity coverage
Credentials escrow is one element of Codekeeper’s Continuity Escrow solution, built to keep your software's essential dependencies running by maintaining access, payments, and supporting services for up to 12 months while your recovery plans take effect.
E-BOOK
Learn how credentials escrow prevents service downtime
Read our in-depth overview of how Continuity Escrow guarantees uninterrupted operations during service disruption.
*E-book available only in English
Get your free introduction to continuity escrow
READY FOR Continuity
Guarantee access to your critical services
- Secure constant revenue by avoiding service-related downtime
- Preserve customer trust with uninterrupted service
- Prove service continuity ability under FCA, PRA, and many more
Frequently asked questions
What is credentials escrow?
Credentials escrow is a legal agreement in which a software supplier deposits the logins, billing access, and related account credentials needed to manage the platforms and services behind their application. A neutral third party holds these credentials under contract and uses them only to support continuity when defined conditions are met.
Who needs credentials escrow and why?
Credentials escrow serves software suppliers and the organisations that depend on them. Suppliers use it to preserve access to critical platforms through internal change, while the organisations relying on the software gain assurance that essential services will keep running.
How does credentials escrow work?
Credentials escrow works by having the supplier deposit the agreed credentials, such as logins, billing-user roles, or API keys, with the escrow agent. These are encrypted, stored securely, and kept up to date, and they're released for use only when a validated continuity condition is met under the contract.
What’s included in a credentials escrow deposit?
A credentials escrow deposit can include hosting platform logins, cloud console access, billing portal credentials, subscription management roles, API keys, or any other access tokens needed to keep supporting services active. The exact contents are set out in your continuity escrow agreement.
Are credentials escrow deposits secure with Codekeeper?
Credentials escrow deposits with Codekeeper are encrypted, access-controlled, and stored in ISO 27001-aligned environments. Access follows strict, contract-defined processes, with every action logged, limited, and authorised under the agreement.
How much does credentials escrow cost?
Credentials escrow pricing depends on the number of providers, the types of credentials, and the level of continuity support you need. Codekeeper’s Continuity Escrow plans, which include credentials escrow, start from £359 per month on an annual plan, with additional add-on options for more complex environments or added support.
How do I get started with credentials escrow?
You can get started with credentials escrow by choosing a Codekeeper plan or booking a demo. You then identify the providers in scope and make your first credential deposit through the secure submission process. Codekeeper will keep your escrow current with scheduled updates and documented reviews.
How does credentials escrow fit into the broader Continuity Escrow solution?
Continuity Escrow as a whole protects the elements that keep software running, including credentials, hosting environments, and third-party dependencies. Credentials escrow specifically safeguards the access and billing controls needed to maintain essential services when payment lapses have occurred.
Is key escrow part of credentials escrow?
Yes. Key escrow is part of credentials escrow whenever authentication keys are needed to manage or reach your provider accounts. This covers MFA backups, SSH keys, API keys, and signing keys, all held under the same security controls and release conditions as your other escrowed credentials and used only when a contract-defined continuity or access condition occurs.
What happens to my services if a supplier goes into administration?
If a UK supplier goes into administration, credentials escrow keeps your essential services running instead of letting them lapse. Codekeeper holds the logins and billing access for the hosting and third-party accounts your software depends on. Once a contract-defined continuity condition is confirmed, Codekeeper can cover renewals and payments directly, so those services stay live while you move to a longer-term solution.
Are escrowed credentials protected under UK data protection law?
Escrowed credentials are protected in line with UK data protection law, including the UK GDPR and the Data Protection Act 2018. Codekeeper encrypts every deposit, holds it in access-controlled, ISO 27001-aligned environments, and limits handling to the strict, contract-defined processes set out in your agreement.