Everything you need to know about MeridianData software escrow. If you have a question that is not answered here, email us at hello@meridiandata.eu.
Software escrow is an arrangement in which a neutral third party holds a verified copy of a software supplier's source code on behalf of the software buyer. If the supplier becomes insolvent, ceases trading, or fails to maintain the software, the source code is released to the buyer so they can continue to operate, maintain, or migrate the system.
It is a standard protection mechanism in commercial software licensing and is increasingly required by enterprise buyers, regulated entities, and investors.
If your business depends on third-party software, you are exposed to the risk that the supplier could become insolvent, stop supporting the product, or be acquired and discontinue it. Without escrow, you have no contractual right to access the source code you would need to maintain your systems in that scenario.
Software escrow gives you that right, documented in a legally binding three-party agreement, without requiring you to own or hold the code yourself.
The three parties are the depositor (the software supplier who deposits the source code), the beneficiary (the business that receives the code if a release event occurs), and the escrow agent (MeridianData, who holds the vault and manages the agreement).
All three parties sign the escrow agreement. The depositor and beneficiary each have defined obligations and rights under the agreement.
Any software where the source code is held in a GitLab repository. This includes SaaS platforms, bespoke software applications, internal tooling, and any other software a business depends on that is developed and maintained by a third-party supplier.
The supplier connects their GitLab repository to the MeridianData vault. Deposits happen automatically on each new release. No manual intervention is needed once the integration is set up. The initial setup takes approximately 30 minutes.
Every deposit is verified automatically. We check that the deposited files are complete and readable and that the file hash matches the hash recorded at the time of deposit. This ensures the vault contains exactly what was deposited, without alteration. You receive a monthly integrity report confirming all deposits are intact.
A release is triggered when one of the defined release events in the escrow agreement occurs. Standard triggers include supplier insolvency, cessation of maintenance, material breach of the software licence, and mutual agreement by both parties.
To initiate a release, the beneficiary submits a formal request with supporting documentation. MeridianData validates the documentation against the agreement before releasing the deposit.
Once a valid release request is submitted with complete documentation, we aim to process and release the deposit within two business days. The exact timeline depends on the release trigger and the documentation provided.
The escrow agreement defines the process for disputed releases. MeridianData acts as a neutral party and follows the terms of the agreement. In cases of genuine dispute, the agreement specifies a resolution process. This is why the escrow agreement is drafted carefully at the outset.
DORA (Digital Operational Resilience Act, in force January 2025) requires Irish and EU financial entities to have documented exit strategies and operational continuity plans for critical ICT third-party providers. Articles 28 and 30 specifically address contractual arrangements with ICT vendors.
A MeridianData escrow arrangement provides a documented, contractually defined continuity mechanism that satisfies this requirement. We provide an audit trail and documentation you can present directly to your compliance team or regulator.
Software escrow is most directly relevant to Article 28 (general principles on the use of ICT third-party service providers) and Article 30 (key contractual provisions). Both articles require documented exit strategies and continuity plans for critical ICT dependencies.
NIS2 (Irish compliance deadline October 2026) requires essential and important entities to implement supply chain security measures. This includes assessing and documenting continuity plans for every critical software supplier. Software escrow satisfies the supply chain continuity requirement and provides the documentation needed to evidence compliance.
Yes. The SME and Enterprise plans include a DORA compliance documentation pack. All plans include a GDPR Article 28 Data Processing Agreement. We can also provide documentation mapping the escrow arrangement to specific DORA and NIS2 articles on request.
All vault data is stored on OVHcloud infrastructure in Ireland. OVHcloud is a French company (not subject to the US CLOUD Act) with data centre infrastructure in the EU. Disaster recovery backups are held on Hetzner in Germany. No data is stored outside the EU.
The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) allows US authorities to compel US-incorporated companies to hand over data stored anywhere in the world, including data stored on EU servers, without necessarily notifying the data subject or the EU regulators.
This means that using a US-owned software escrow provider, even one with EU-based servers, may not provide the sovereignty protection your organisation requires. MeridianData is Irish-incorporated and is not subject to the CLOUD Act.
Yes. MeridianData is designed to be GDPR-compliant from the ground up. A GDPR Article 28 Data Processing Agreement is included with every plan. All data is processed and stored within the EU. We maintain a sub-processor register and do not use US-incorporated sub-processors for client data processing.
All MeridianData escrow agreements are governed by Irish law. Disputes are subject to the jurisdiction of the Irish courts. There is no US or UK governing law in any MeridianData agreement.
All deposits are encrypted at rest and in transit. The vault runs on Nextcloud (German, open-source), self-hosted on OVHcloud infrastructure. Access to vault contents is restricted to defined release events only. MeridianData staff do not have routine access to deposit contents.
The vault integrity monitor checks every deposit nightly against the hash recorded at the time of deposit. If any deposit fails the integrity check, you are alerted immediately. Monthly integrity reports confirm the status of every deposit in your vault.
A penetration test of the MeridianData platform is scheduled before the service goes live. The test will be conducted by a CREST-certified firm. Results are available to enterprise clients on request under NDA.
The Startup plan (€75/month) covers 3 repositories, 5 users, and 10GB of vault storage. It is designed for early-stage companies entering enterprise sales or preparing for investor due diligence.
The SME plan (€250/month) covers 10 repositories, 20 users, and 50GB of vault storage. It also includes DORA compliance documentation and priority support. It is designed for established businesses with multiple software dependencies and active compliance obligations.
No setup fees and no long-term contracts. All plans are monthly subscriptions and can be cancelled at any time.
The escrow agreement defines the obligations of the depositor (deposit schedule, notification of material changes), the rights of the beneficiary (inspection rights, release conditions), and the role of MeridianData as escrow agent (vault management, verification, release process). It is drafted under Irish law and is included with every plan.
Yes. Early access clients receive founding member pricing and direct access to the founder. Email hello@meridiandata.eu to discuss.
MeridianData is currently in development. Register your interest at meridiandata.eu to be notified at launch and invited into private beta. Early registrants receive founding member pricing and direct access to the founder.
The supplier connects their GitLab repository to the MeridianData vault and signs the three-party escrow agreement. Setup takes approximately 30 minutes. After that, deposits happen automatically on each new release with no ongoing manual effort required from the supplier.
Yes. Each escrow arrangement covers one supplier relationship. If you have multiple critical software suppliers, each relationship requires a separate three-party agreement and vault. Contact us to discuss multi-supplier arrangements and volume pricing.
Yes. Many software suppliers proactively offer escrow to their clients as a way to close enterprise deals faster and demonstrate commitment to business continuity. If a client requires escrow as a condition of signing, MeridianData can have the arrangement in place quickly. Contact us at hello@meridiandata.eu.