What is software verification?
Software verification puts your escrow deposits, source code, configurations, and the rest, through checks that confirm they're secure, complete, and able to run. It proves the deposit could carry business continuity if it were ever released, and issues certificates you can use for operational resilience compliance requirements.
What is the difference between software verification and validation?
The difference between software verification and validation comes down to what each one confirms. Validation confirms the required assets are all present in your deposit. Verification tests whether those assets are usable and reliable, with the depth increasing by tier, up to a full build at the Certified level.
What are the three verification levels?
The three verification levels are Validated, Verified, and Certified. Validated is a free tier that confirms the agreed assets, source code, documentation, and so on, are actually in the deposit. Verified layers on automated review to gauge quality and fit against production needs. Certified goes furthest, running a full software build to prove the deposit is fully operational.
What can be held in escrow?
Escrow can hold whatever software-related materials a recovery would call for: source code, system configurations, technical documentation, and any other critical digital assets needed to bring the software back when required.
Do Codekeeper verification certificates support UK operational resilience requirements?
Codekeeper verification certificates give firms under FCA and PRA operational resilience rules documented proof that a deposit has been tested and can be recovered. Because the certificate shows the software can actually be rebuilt, it stands as evidence toward the recoverability of an important business service, exactly what regulators and the UK Critical Third Parties regime expect firms to demonstrate for the third parties they depend on.
Which verification tier supports UK cyber and resilience regulations?
The Certified tier supports UK cyber and resilience regulations by producing tested, human-reviewed proof that a deposit can be rebuilt and recovered. That evidence helps firms in scope of the UK NIS Regulations 2018, and the expanded duties coming under the Cyber Security and Resilience Bill, show their supply-chain dependencies are recoverable. For firms that also operate in the EU under DORA or NIS2, the same certificate carries across both regimes.
Are verification certificates recognised by UK auditors and clients?
Verification certificates give UK auditors and clients independent, documented proof that your escrow deposit is complete, current, and recoverable. Rather than relying on your assurance alone, they get a Software Resilience Certificate backed by automated checks and, at the Certified tier, expert human review.