SaaS escrow agent: how is continuity arranged for SaaS?
A SaaS escrow agent guarantees the continuity of your business-critical SaaS applications. Learn how it works, the options, and the legal context.
SaaS applications have become indispensable in the business world. From CRM to financial planning, many business-critical processes run in the cloud. But what happens if your SaaS vendor goes bankrupt, discontinues its services, or is acquired by a party that drastically changes the terms? A SaaS escrow agreement offers a crucial safeguard for the continuity of your business operations.
What is a SaaS Escrow Agent?
A SaaS escrow agent is an independent, neutral third party that facilitates an agreement between a SaaS vendor and the end-user (licensee). This agent holds materials in safekeeping that are necessary to continue the services of a SaaS application if the vendor can no longer meet its obligations. Unlike traditional source code escrow, SaaS involves not only the source code but the entire operational environment.
The core function of the agent is to manage the agreement and release the deposited materials under predefined conditions (the "release conditions").
How is continuity arranged?
Continuity in SaaS can be arranged at different levels, depending on the complexity of the application and the user's risk assessment. The essence is that the user gains access to the necessary resources to (temporarily) host the service themselves or have it hosted by another party.
The materials held in escrow may include:
- Source Code: The most recent, complete, and compilable source code of the application.
- Data: A periodic backup of the end-user's data.
- Technical Documentation: Manuals for installation, configuration, and management of the application and the required environment.
- Access Credentials: Credentials for the production environment, cloud infrastructure (such as AWS, Azure, Google Cloud), and other dependent services.
- Deployment Scripts: Automated scripts to install and configure the application and database on a new server.
Forms of SaaS Escrow
There are two main flavors when it comes to SaaS escrow, each with a different level of assurance.
1. SaaS Escrow with Access to the Environment
In this form, the vendor provides the escrow agent with the necessary access credentials to the live production environment. In the event of a calamity, the end-user (or an IT party designated by them) gains access to this environment via the agent. This allows for a quick takeover.
- Advantage: Fast, relatively simple, and direct access to current data and configuration.
- Disadvantage: Dependence on the existing, vendor-set-up infrastructure remains. Legally, transferring hosting contracts can be complex.
2. SaaS Escrow with Full Replication
This is the most comprehensive form. The escrow agent periodically verifies whether the deposited materials are sufficient to fully build the SaaS service independently on a new, independent hosting environment. This process, the "replication test" or "build verification," offers the highest degree of assurance.
- Advantage: Complete independence from the vendor and its infrastructure. Maximum assurance that continuity can be guaranteed.
- Disadvantage: Higher costs due to the complexity of the verification. Setup requires active cooperation from the vendor.
Legal and Regulatory Context (EU)
For organizations within the EU, specific guidelines play an important role when considering SaaS escrow. The continuity of IT services is a core component of risk management and compliance.
GDPR/AVG: Organizations are and remain data controllers for their data. A SaaS escrow arrangement helps to maintain access to and control over personal data, even after the vendor (processor) ceases to operate. It safeguards the rights of data subjects, such as the right to data portability.
DORA (Digital Operational Resilience Act): This regulation imposes strict requirements on the financial sector regarding the management of ICT risks, including those of third parties such as SaaS vendors. An escrow agreement is a concrete measure to strengthen operational resilience and meet DORA requirements.
NIS2: This directive, aimed at a wide range of essential and important sectors, obliges organizations to take appropriate measures for the security of network and information systems. Ensuring the continuity of critical SaaS services through escrow is one such measure.
Choosing the right arrangement
The choice for a specific SaaS escrow arrangement depends on a risk analysis. How business-critical is the application? How great is the risk of the vendor failing? What are the financial and operational consequences of downtime? For a simple marketing tool, a basic arrangement may suffice, but for an ERP system or a platform in financial services, a comprehensive, verified escrow arrangement is indispensable.
A carefully drafted SaaS escrow agreement, managed by an expert agent, is an essential tool for modern risk management. It provides certainty in a landscape where dependence on external software vendors is only increasing.