Your biggest deal of the year is one signature away — and then procurement sends back the contract with a new clause: all source code, build scripts, and deployment materials must be held in escrow by an independent agent, releasable to the customer if your company fails. If you run a small SaaS business, this is the moment a deal you already won can quietly die in legal review. The good news: escrow is a solved problem with standard pricing, standard terms, and straightforward bookkeeping, once you understand what the buyer is actually asking for.
What the Buyer Actually Means by "Source-Code Escrow"
A software escrow agreement is a three-party contract between you (the vendor), your customer (the beneficiary), and a neutral escrow agent. You deposit a copy of your source code and related materials with the agent. The agent holds them under lock and key and releases them to the customer only if one of the agreed release triggers occurs — typically your insolvency, your failure to support the product, or another defined breach.
The buyer's fear is simple: they are about to build a business process on top of software controlled by a company much smaller than they are. If you shut down, get acquired by their competitor, or stop shipping fixes, they need a path to keep the lights on. Escrow is that path. It almost never gets invoked — but enterprise procurement teams, especially in regulated industries like banking, healthcare, and government, increasingly treat it as non-negotiable for business-critical software.
A few things escrow is not:
- It is not a transfer of your IP. You retain full ownership. The deposit is a copy held under strict confidentiality, and the customer gets no rights to it unless a release event occurs.
- It is not a substitute for a good contract. The escrow agreement sits alongside your license or SaaS agreement and needs to reference it cleanly.
- It is not one-size-fits-all. A single-beneficiary agreement covers one customer; a multi-beneficiary agreement lets you add new customers to the same escrow arrangement as you close them, which is usually far cheaper per deal.
Why SaaS Vendors Get Asked Even Though Nobody Ships Code Anymore
The classic escrow model was built for on-premises software: deposit the source, and if the vendor disappears, the customer compiles and runs it. For SaaS, a pile of source code without your cloud environment, databases, deployment pipelines, and operational knowledge may be close to useless. Enterprise buyers know this, which is why "SaaS escrow" or "continuity escrow" has become its own product category.
A SaaS escrow deposit typically goes well beyond code. Depending on the agent and service tier, it can include container images and infrastructure-as-code templates, database schemas and backup procedures, deployment runbooks, third-party service inventories and credentials handling, and documentation for rebuilding the environment. Some providers offer verification services that actually test whether the deposited materials can be rebuilt, plus continuity options where the agent keeps a recovery environment warm so the customer's service continues for a defined window — commonly up to 90 days — after a release event.
If a buyer asks a SaaS vendor for "source-code escrow," clarify early whether they will accept a code-plus-documentation deposit or expect full environment escrow. The price difference is significant, and agreeing to the wrong one either leaves you under-delivering on a contractual promise or overpaying for protection the customer never needed.
What Escrow Costs in 2026
Pricing has become notably more transparent as developer-led providers publish their plans online. Broadly, expect three layers of cost:
Setup fees. Traditional agents often bundle setup into the first year; self-service platforms charge a modest one-time fee — Codekeeper, for example, lists a $249 setup fee on top of monthly plans. Enterprise-led providers such as Escode (formerly part of NCC Group) typically quote custom pricing after a scoping call.
Annual agent fees. This is the core recurring cost. As a rough map of the 2026 market: self-service software escrow plans start around $139 per month (roughly $1,670 per year), with SaaS escrow tiers starting around $199 per month. Mid-market providers with published pricing list base software escrow around £1,695 (about $2,190) per year, SaaS continuity tiers from about £2,995 (about $3,870), and self-service express options from about £889 (about $1,150). Traditional US agents such as EscrowTech land around $2,200 per arrangement based on observed transaction data. Multi-beneficiary structures cost more upfront but bring the per-customer cost down sharply as you add deals.
Verification and extras. Basic deposit confirmation is often included. Technical verification — where the agent's consultants confirm the deposit is complete and buildable — costs extra and is worth itemizing separately in your budget, because enterprise buyers in regulated sectors frequently require it. Release events, legal review of custom terms, and additional beneficiaries can also carry fees.
Who pays is negotiable. There is no market rule that the vendor always pays. Common outcomes include the vendor absorbing the cost as a cost of winning enterprise deals, the buyer paying because they demanded the protection, or a 50/50 split. Smaller vendors with leverage-light negotiating positions often end up paying, but you should always ask — procurement teams with an escrow line item in their own budget will sometimes say yes. Whatever you agree, put it in writing in the escrow agreement itself, not just in an email thread.
How to Book It: Vendor-Side Accounting for Escrow
Here is where SaaS founders tend to overthink it. Escrow accounting is simple if you separate the pieces.
Annual agent fees: prepaid, then amortized
When you pay a year of escrow fees upfront, you have bought twelve months of a service. Book the payment to a prepaid expense asset, then amortize one month at a time into general and administrative expense (a dedicated "Compliance" or "Software subscriptions" sub-account keeps it visible at audit time). The monthly plans from self-service providers can simply be expensed as incurred.
In plain-text accounting, the pattern looks like this:
2026-09-16 * "Escrow agent" "Annual SaaS escrow fee, Sep 2026 - Aug 2027"
Assets:Prepaid:Escrow-Fees 2,388.00 USD
Assets:Checking:Business
2026-09-30 * "Escrow agent" "Amortize September escrow fee"
Expenses:G-and-A:Compliance:Escrow 199.00 USD
Assets:Prepaid:Escrow-FeesSetup and verification fees: expense as incurred
One-time setup fees and periodic verification charges are period costs — expense them when incurred to the same compliance account. Resist the urge to capitalize them as some kind of asset. The escrow arrangement gives you no balance-sheet asset: you already owned the code before the deposit, and you still own it after.
Engineering time spent on deposits: stays in payroll
Preparing deposits — tagging releases, exporting repositories, writing build documentation — is real work, often falling on your most senior engineers. That cost already lives in your payroll and, depending on your capitalization policy for internal-use software, in R&D expense. Do not create a separate capitalized "escrow asset" for the labor. If deposits are automated through a GitHub, GitLab, or Bitbucket integration (most modern agents offer this), the ongoing labor cost drops to nearly zero, which is itself a reason to prefer agents with real integrations over manual-upload workflows.
Customer reimbursements: net them, don't gross them up
If a customer reimburses your escrow fee or pays their share to you, record the reimbursement against the same expense account rather than as revenue. It is a cost recovery, not a sale. Under ASC 606, escrow protection is virtually never a separate performance obligation — it is part of fulfilling the SaaS contract — so there is no revenue-recognition event hiding in the arrangement. Relatedly, escrow fees are contract fulfillment costs that you expense as incurred; the standard's capitalization rules for fulfillment costs (ASC 340-40) technically exist, but for fees tied to service periods of a year or less the practical answer is always to expense.
Tax treatment: ordinary and necessary
Escrow setup, annual, and verification fees are ordinary and necessary business expenses, deductible under Section 162 in the year paid or accrued, consistent with your overall method of accounting. If you are cash-basis, the full annual prepayment is deductible when paid; if accrual-basis, deduct it as the service period elapses. No special elections, no amortization schedules, no drama.
What Goes Into the Deposit (and Why Verification Matters More Than the Contract)
The most common escrow failure has nothing to do with legal drafting: the deposit, when finally needed, turns out to be incomplete or unbuildable. A release event five years into a relationship is worthless if the deposit contains last year's code with no build instructions. Protect yourself — and the deal — by treating the deposit as an engineering deliverable:
- Source code and dependencies, ideally via automated repository sync rather than manual uploads that someone forgets after the second release.
- Build and deployment materials: scripts, container definitions, infrastructure templates, and environment configuration.
- Documentation: architecture overviews, runbooks, credentials inventories (handled per the agent's secrets policy — never plaintext passwords in an unencrypted archive), and third-party service dependencies with license implications noted.
- Data procedures for SaaS: backup formats, restore procedures, and data export tooling, so the customer can recover their own data, not just your code.
- A verification report, at least annually for enterprise accounts, confirming an independent party actually built or reviewed the deposit.
Verification is also a commercial asset: being able to tell the next prospect "our deposits are independently verified quarterly" shortens every subsequent security review.
Release Triggers: Negotiate These Before You Sign
The release conditions are the most negotiated part of any escrow agreement, and the place where a small vendor most needs its own lawyer rather than the buyer's template. Standard triggers include:
- Insolvency events: bankruptcy filings, assignment for creditors, receivership. Define these precisely — "ceases business operations" can be ambiguous for a pivot.
- Material breach of support obligations: failure to provide maintenance or meet SLAs after notice and a cure period. Insist on the cure period; without one, a single bad week could theoretically trigger release.
- Change of control: acquisition by a named competitor is a common buyer ask. Narrow this to named competitors rather than "any acquisition," or your exit options get complicated.
- Discontinuation of the product: if you sunset the product, the customer gets the materials. Fair — but define what "discontinuation" means versus a rebrand or architecture migration.
Push back on triggers like "vendor fails to deliver any feature on the roadmap" or uncapped cure-free breach clauses. And make sure the agreement requires the agent to notify you and give you a chance to dispute before releasing — reputable agents have a formal dispute process, but the timelines vary.
Common Mistakes Small Vendors Make
Treating the deposit as an asset transfer. Nothing leaves your balance sheet. There is no journal entry for the deposit itself — only for the fees. If your bookkeeper asks what account the "escrow asset" goes in, the answer is none.
Letting the renewal lapse. Missed renewals are an embarrassing and surprisingly common way to breach an enterprise contract. The annual fee is small; the contract breach is not. Put renewals on the same calendar as domain and insurance renewals, with a 60-day advance reminder.
Skipping verification to save money. An unverified deposit satisfies the contract checkbox but may fail the actual purpose. For your largest accounts, verification is cheap insurance against the one scenario — a genuine release event — where the details suddenly matter enormously.
Booking fees inconsistently. Pick one home for escrow costs — G&A compliance is the natural one — and keep setup, annual, and verification fees together. Scattering them across COGS, R&D, and legal makes the true cost of your enterprise motion invisible when you later analyze customer acquisition costs.
Forgetting multi-beneficiary economics. If you sign single-beneficiary agreements for your first three enterprise customers and then discover the multi-beneficiary option, you have likely overpaid for two of them. If your pipeline has more than one escrow-demanding prospect, price the multi-beneficiary structure before signing the first agreement.
Keep Your SaaS Finances Organized as You Move Upmarket
Winning enterprise deals brings new kinds of costs — escrow fees, security audits, compliance tooling — that don't fit neatly into the bookkeeping habits of an early-stage SaaS company. Tracking them in dedicated accounts from the start is what lets you see the true cost of moving upmarket instead of discovering it at fundraising due diligence. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.





