
Key takeaways
- Source code escrow provides a crucial safety net, ensuring access to your software in unforeseen circumstances.
- Contractually define ownership and access to all development repositories and cloud deployment accounts from the outset.
- Without explicit clauses, paying for software does not automatically grant you unfettered control over its operational aspects.
- A well-structured contract protects your investment, minimises vendor lock-in, and secures business continuity.
Why Source Code Escrow Matters in UK Contracts
When commissioning custom software, a clear source code escrow UK contract is often overlooked, yet it forms a fundamental safeguard for your business. This clause ensures that a copy of your application's source code is held by an independent third party. Should your development supplier cease trading, fail to meet obligations, or become unresponsive, you gain access to the code. This prevents your business from being left in a critical state without the means to maintain or further develop your essential systems.
Beyond the code itself, understanding who controls the development repositories and the cloud accounts where your software runs is paramount. Many businesses assume that paying for a web application or mobile app automatically confers full operational control. However, without explicit contractual terms, you might find yourself locked out of critical infrastructure or unable to migrate your product. This can lead to costly delays and operational disruption.
Repository and Cloud Account Ownership
Your development team, whether onshore in the UK or an offshore partner, will use version control systems like Git, hosted on platforms such as GitHub, GitLab, or Bitbucket. While the intellectual property (IP) for the code should be assigned to you, the ownership of these repositories and the direct access to them need explicit definition. We recommend that all primary repositories are created under your organisation's accounts from day one, with the supplier granted appropriate access.
Similarly, for deployment, your software will likely reside on cloud infrastructure like AWS, Azure, or Google Cloud. These accounts host your live application, databases, and other critical services. Granting a supplier administrative access to your company's existing cloud accounts is standard practice. However, ensuring you retain full ownership and the ability to revoke access or transfer management at any time is a non-negotiable term. This prevents situations where a supplier could hold your live application hostage.
- Who creates the primary code repositories?
- Which organisation owns the cloud accounts hosting the live application?
- What level of access does your internal team maintain throughout development?
- How will access be revoked or transferred at project completion?

What Escrow Protects and How it Works
A source code escrow agreement acts as an insurance policy. It's particularly vital for mission-critical software where business continuity is paramount. The agreement typically involves three parties: you (the beneficiary), the software supplier (the depositor), and the escrow agent (an independent third party). The supplier regularly deposits the latest version of the source code, build instructions, and any necessary documentation with the agent.
Release conditions are key. These clauses specify the events that trigger the release of the code to you. Common triggers include the supplier's insolvency, breach of contract, or failure to provide agreed-upon maintenance and support. On a recent UK retail build we managed, our client insisted on an escrow arrangement due to the system's integration with their core payment processing. This foresight ensured they had a clear path forward if any issues arose with the original development team, mitigating significant operational risk.
- Supplier insolvency or liquidation
- Breach of contract by the supplier
- Failure to provide ongoing support as agreed
- Acquisition of the supplier by a competitor
- Supplier ceasing to trade or becoming unresponsive
The Practicalities and Costs
Implementing a robust escrow and access strategy involves more than just a legal clause; it requires practical collaboration. For example, ensuring that the deposited code is actually usable involves verifying build environments and dependencies. An escrow agent might offer verification services to confirm the code can be compiled and deployed independently. This proactive step validates the utility of the escrow arrangement, saving potential headaches later.
The cost of an escrow service typically involves an annual fee, usually in the low hundreds of pounds per year, depending on the complexity and verification level. This fee is generally paid by the client, though sometimes shared. Compared to the potential cost of rebuilding or losing access to a critical system, these fees represent a small but vital investment. Ensure your contract specifies who bears this cost and the frequency of code deposits.
When Not to Use Escrow or Complex Access Terms
While crucial for bespoke, mission-critical systems, source code escrow may be overkill for smaller, less complex projects or off-the-shelf solutions. For a simple marketing website or a non-essential internal tool, the administrative overhead and cost of an escrow agreement might outweigh the benefits. In such cases, clear repository ownership and cloud account access terms are usually sufficient.
For projects with very short lifespans or those built on highly volatile, rapidly changing experimental technologies, the value of an escrowed snapshot diminishes quickly. The cost of maintaining a perpetually up-to-date escrow might not justify the protection it offers. Prioritise these clauses for systems that form the bedrock of your business operations or handle sensitive data requiring robust security standards like ISO 27001 compliance.
Secure Your Digital Future
Protecting your software investment goes beyond simply paying for the build. It requires a clear understanding of ownership, access, and contingency planning built into your development contract. As a delivery director, I've seen firsthand how ambiguous clauses around repository access or cloud account control can lead to painful, expensive disputes. A client came to us mid-project with an urgent request to take over a stalled build, only to discover their previous supplier had locked down critical cloud resources, delaying their product launch by months and incurring substantial additional costs.
Techsleight Labs believes in transparency and empowering UK businesses with full control over their digital assets. Our approach ensures that you retain ownership of all code repositories and have direct access to your deployment environments, whether our engineers are onshore in London or part of our offshore team. We prioritise clear, plain-English contract terms so there are no surprises down the line.
Do not leave your business vulnerable. Insist on a comprehensive contract that addresses all aspects of source code and infrastructure control. Prioritising these terms upfront minimises risk, safeguards your budget, and secures the long-term viability of your custom software.
FAQ
Is source code escrow a legal requirement in the UK?
No, source code escrow is not a legal requirement in the UK. It is a commercial agreement and a best practice for risk mitigation, especially for mission-critical software. It provides a contractual safety net for businesses.
Who pays for a source code escrow service?
Typically, the beneficiary (the client business) pays the annual fees for a source code escrow service. Sometimes, the cost is shared with the software supplier. This should always be explicitly defined in your contract.
What should be included with the source code in escrow?
Beyond the source code, the escrow deposit should include all necessary build instructions, dependencies, third-party libraries, documentation, and any unique tools required to compile and deploy the software independently.
How often should source code be updated in escrow?
The frequency of updates depends on the project's velocity and criticality. For active development, quarterly or even monthly updates are common. This ensures the escrowed code remains reasonably current and useful if released.
Ready to build in the UK?
Talk to a senior software team.
Share your roadmap, current stack, and timeline. We will help you choose the right developer, team, or managed project model.
Techsleight Labs is a trading name of Krapton IT Consultancy.