Source Code Escrow: Do You Need It?
By CodexierPublished 4 min read
If your business depends on software from a small supplier, a reasonable worry is what happens if that supplier goes bankrupt or simply stops answering. Source code escrow is the traditional answer: a copy of the code is deposited with a neutral third party and released to you if certain events occur. It can be valuable, but it is often recommended in situations where a simpler solution exists. This guide explains how escrow works, when it makes sense and when owning the code is the better protection.
What code escrow is
An escrow arrangement is usually a three-party agreement between the supplier, the customer and the escrow agent. The supplier deposits the source code, build instructions and documentation, and updates the deposit at agreed intervals. The agent stores it securely and releases it to the customer only when a release condition is met and the procedure in the agreement has been followed.
When it makes sense
| Situation | Escrow useful? | Why |
|---|---|---|
| Licensed business-critical system from a small vendor | Yes | You depend on it and cannot get the code otherwise |
| Standard SaaS from a large provider | Rarely | You need data export more than code; the code would not run without their platform |
| Custom software built for you | Usually not | Contract for ownership and repository access instead |
| Software sold with a public-sector procurement | Sometimes required | Procurement terms may demand it |
For SaaS, the practical risk is losing access to your data rather than to the code. A contract clause on data export in a usable format, and a routine for taking regular exports, often protects you better than escrow would.
How release conditions work
- Typical release conditions: bankruptcy or liquidation, the supplier ceasing business, or material failure to maintain or support the software as agreed.
- The customer requests release; the supplier normally gets a period to object.
- Disputes are resolved according to the agreement, sometimes by arbitration.
- After release, the customer usually gets a right to use and modify the code for its own needs, not to sell it.
Read the conditions carefully. A clause that only triggers on bankruptcy does not help if the supplier is acquired and the product discontinued. Have a lawyer review the agreement if the system is critical.
Costs and upkeep
Escrow agents usually charge a setup fee and an annual fee, with verification as an extra service. Verification matters: without it, you do not know whether the deposit actually contains everything needed to build and run the software. A deposit missing configuration, third-party dependencies or build instructions can be worthless when you need it. Agree on who pays, how often the supplier must update the deposit and at what level it will be verified.
Also ask yourself whether you could use the code if released. You would need a developer who can understand it, hosting and time to get it running. Plan for that, or escrow remains a paper safeguard.
Owning the code instead
When software is built for you, the simplest protection is to own it. That means a contract that transfers the intellectual property rights to you on payment, the code in a repository you control from the start, documentation of how to build and deploy it, and admin access to hosting, domain and third-party accounts. Our guides on IP clauses in software contracts and who owns your website go into the details.
When we build an MVP, ownership of the code transfers to you on full payment and it is delivered to your own GitHub repository, so escrow is not needed; prices are on the pricing page. When not to buy from us: if you need a licensed product with a large vendor behind it, escrow and data-export clauses are the right tools, and we are not the right supplier. To check your current contracts, book a free call.
Frequently asked questions
Does escrow protect us if the supplier is acquired?
Only if the release conditions cover it, for example discontinuation of the product or failure to support it. Many agreements only trigger on bankruptcy, which leaves an acquisition uncovered.
Who pays for escrow?
It is negotiable. Often the customer pays because it benefits them, but suppliers who want to win larger customers sometimes include it. Agree in writing who pays setup, annual and verification fees.
Is escrow relevant for SaaS?
Rarely on its own. SaaS code usually depends on the provider's infrastructure. Focus on data export, service levels and exit terms instead, and escrow only for critical, niche services.
What should a code deposit contain?
Complete source code, build and deployment instructions, a list of third-party dependencies and licences, configuration templates and enough documentation for a competent developer to get the system running.
Unsure whether your software contracts protect you?
Tell us which systems your business depends on and how they are licensed. In fifteen minutes we can point out where you need escrow, better data-export terms or simply ownership of the code.
Book a free 15-minute call