Frequently Asked Questions

Everything you need to know about MeridianData software escrow. If you have a question that is not answered here, email us at hello@meridiandata.eu.

The Basics

What is software escrow?

Software escrow is an arrangement in which a neutral third party holds a verified copy of a software supplier's source code on behalf of the software buyer. If the supplier becomes insolvent, ceases trading, or fails to maintain the software, the source code is released to the buyer so they can continue to operate, maintain, or migrate the system.

It is a standard protection mechanism in commercial software licensing and is increasingly required by enterprise buyers, regulated entities, and investors.

Why do I need software escrow?

If your business depends on third-party software, you are exposed to the risk that the supplier could become insolvent, stop supporting the product, or be acquired and discontinue it. Without escrow, you have no contractual right to access the source code you would need to maintain your systems in that scenario.

Software escrow gives you that right, documented in a legally binding three-party agreement, without requiring you to own or hold the code yourself.

Who are the three parties in an escrow agreement?

The three parties are the depositor (the software supplier who deposits the source code), the beneficiary (the business that receives the code if a release event occurs), and the escrow agent (MeridianData, who holds the vault and manages the agreement).

All three parties sign the escrow agreement. The depositor and beneficiary each have defined obligations and rights under the agreement.

What types of software can be escrowed?

Any software where the source code is held in a GitLab repository. This includes SaaS platforms, bespoke software applications, internal tooling, and any other software a business depends on that is developed and maintained by a third-party supplier.

How It Works

How does the depositor get the source code into the vault?

The supplier connects their GitLab repository to the MeridianData vault. Deposits happen automatically on each new release. No manual intervention is needed once the integration is set up. The initial setup takes approximately 30 minutes.

How do you verify the deposits?

Every deposit is verified automatically. We check that the deposited files are complete and readable and that the file hash matches the hash recorded at the time of deposit. This ensures the vault contains exactly what was deposited, without alteration. You receive a monthly integrity report confirming all deposits are intact.

What triggers a release?

A release is triggered when one of the defined release events in the escrow agreement occurs. Standard triggers include supplier insolvency, cessation of maintenance, material breach of the software licence, and mutual agreement by both parties.

To initiate a release, the beneficiary submits a formal request with supporting documentation. MeridianData validates the documentation against the agreement before releasing the deposit.

How long does a release take?

Once a valid release request is submitted with complete documentation, we aim to process and release the deposit within two business days. The exact timeline depends on the release trigger and the documentation provided.

What happens if the supplier disputes a release request?

The escrow agreement defines the process for disputed releases. MeridianData acts as a neutral party and follows the terms of the agreement. In cases of genuine dispute, the agreement specifies a resolution process. This is why the escrow agreement is drafted carefully at the outset.

DORA and NIS2

How does software escrow help with DORA compliance?

DORA (Digital Operational Resilience Act, in force January 2025) requires Irish and EU financial entities to have documented exit strategies and operational continuity plans for critical ICT third-party providers. Articles 28 and 30 specifically address contractual arrangements with ICT vendors.

A MeridianData escrow arrangement provides a documented, contractually defined continuity mechanism that satisfies this requirement. We provide an audit trail and documentation you can present directly to your compliance team or regulator.

Which DORA articles does software escrow address?

Software escrow is most directly relevant to Article 28 (general principles on the use of ICT third-party service providers) and Article 30 (key contractual provisions). Both articles require documented exit strategies and continuity plans for critical ICT dependencies.

How does software escrow help with NIS2 compliance?

NIS2 (Irish compliance deadline October 2026) requires essential and important entities to implement supply chain security measures. This includes assessing and documenting continuity plans for every critical software supplier. Software escrow satisfies the supply chain continuity requirement and provides the documentation needed to evidence compliance.

Does MeridianData provide compliance documentation?

Yes. The SME and Enterprise plans include a DORA compliance documentation pack. All plans include a GDPR Article 28 Data Processing Agreement. We can also provide documentation mapping the escrow arrangement to specific DORA and NIS2 articles on request.

Data Sovereignty

Where is the source code stored?

All vault data is stored on OVHcloud infrastructure in Ireland. OVHcloud is a French company (not subject to the US CLOUD Act) with data centre infrastructure in the EU. Disaster recovery backups are held on Hetzner in Germany. No data is stored outside the EU.

What is the CLOUD Act and why does it matter?

The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) allows US authorities to compel US-incorporated companies to hand over data stored anywhere in the world, including data stored on EU servers, without necessarily notifying the data subject or the EU regulators.

This means that using a US-owned software escrow provider, even one with EU-based servers, may not provide the sovereignty protection your organisation requires. MeridianData is Irish-incorporated and is not subject to the CLOUD Act.

Is MeridianData GDPR compliant?

Yes. MeridianData is designed to be GDPR-compliant from the ground up. A GDPR Article 28 Data Processing Agreement is included with every plan. All data is processed and stored within the EU. We maintain a sub-processor register and do not use US-incorporated sub-processors for client data processing.

Which law governs the escrow agreement?

All MeridianData escrow agreements are governed by Irish law. Disputes are subject to the jurisdiction of the Irish courts. There is no US or UK governing law in any MeridianData agreement.

Security

How is the source code protected in the vault?

All deposits are encrypted at rest and in transit. The vault runs on Nextcloud (German, open-source), self-hosted on OVHcloud infrastructure. Access to vault contents is restricted to defined release events only. MeridianData staff do not have routine access to deposit contents.

What happens if a deposit becomes corrupted?

The vault integrity monitor checks every deposit nightly against the hash recorded at the time of deposit. If any deposit fails the integrity check, you are alerted immediately. Monthly integrity reports confirm the status of every deposit in your vault.

Has MeridianData been penetration tested?

A penetration test of the MeridianData platform is scheduled before the service goes live. The test will be conducted by a CREST-certified firm. Results are available to enterprise clients on request under NDA.

Pricing and Plans

What is the difference between the Startup and SME plans?

The Startup plan (€75/month) covers 3 repositories, 5 users, and 10GB of vault storage. It is designed for early-stage companies entering enterprise sales or preparing for investor due diligence.

The SME plan (€250/month) covers 10 repositories, 20 users, and 50GB of vault storage. It also includes DORA compliance documentation and priority support. It is designed for established businesses with multiple software dependencies and active compliance obligations.

Are there setup fees or long-term contracts?

No setup fees and no long-term contracts. All plans are monthly subscriptions and can be cancelled at any time.

What is included in the three-party escrow agreement?

The escrow agreement defines the obligations of the depositor (deposit schedule, notification of material changes), the rights of the beneficiary (inspection rights, release conditions), and the role of MeridianData as escrow agent (vault management, verification, release process). It is drafted under Irish law and is included with every plan.

Do you offer discounts for early access clients?

Yes. Early access clients receive founding member pricing and direct access to the founder. Email hello@meridiandata.eu to discuss.

Getting Started

How do I get started?

MeridianData is currently in development. Register your interest at meridiandata.eu to be notified at launch and invited into private beta. Early registrants receive founding member pricing and direct access to the founder.

What does the supplier need to do?

The supplier connects their GitLab repository to the MeridianData vault and signs the three-party escrow agreement. Setup takes approximately 30 minutes. After that, deposits happen automatically on each new release with no ongoing manual effort required from the supplier.

Can I escrow software from multiple suppliers?

Yes. Each escrow arrangement covers one supplier relationship. If you have multiple critical software suppliers, each relationship requires a separate three-party agreement and vault. Contact us to discuss multi-supplier arrangements and volume pricing.

I am a software supplier. Can my clients use MeridianData?

Yes. Many software suppliers proactively offer escrow to their clients as a way to close enterprise deals faster and demonstrate commitment to business continuity. If a client requires escrow as a condition of signing, MeridianData can have the arrangement in place quickly. Contact us at hello@meridiandata.eu.

Still have questions?

Email us at hello@meridiandata.eu and we will get back to you within one business day.

Get in Touch