Top 5 escrow providers in the Netherlands compared
Looking for the best provider of software escrow, SaaS escrow or cloud escrow in the Netherlands? We compared the five most visible players in the Dutch market. Each approaches the market in its own way.
Read the comparison as it is intended: we hold every provider to the same standard, and that standard is the one we ourselves apply to an escrow agent, with zero-knowledge storage, sovereignty and transparency first. The content of each cell comes from what providers themselves publicly describe about their services. What a provider does not publicly describe, we cannot show; the methodology further down explains how we work.
Meaning of the markings: a green check mark means a feature is publicly described; a red cross that public information shows it is arranged differently; a light grey cross that a feature is not publicly described, or that we did not find it.
Overview
| Softcrow | Escrow4all | Codekeeper | Escrow Alliance | Software Borg | |
|---|---|---|---|---|---|
| Founded | 1991 | 2009 | 2014 | 2011 | 1995 |
| Location | Almere | Amsterdam | The Hague + San Francisco (USA) | Haarlem | Haren |
| Customers | 5,100+ | 3,000+ | 3,500+ | ✗ | 1,000+ |
| Website | visit site | visit site | visit site | visit site | visit site |
Services
| Softcrow | Escrow4all | Codekeeper | Escrow Alliance | Software Borg | |
|---|---|---|---|---|---|
| Software Escrow | ✓ | ✓ | ✓ | ✓ | ✓ |
| SaaS Escrow | ✓ | ✓ | ✓ | ✓ | ✓ |
| Cloud service continuity | ✓ CloudSecure® | ✗ | ✓ Continuity Escrow | ✗ | ✗ |
| Embedded Software Escrow (Firmware) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Data Escrow | ✓ | ✓ | ✗ | ✗ | ✓ |
| AI Escrow | ✓ | ✗ | ✓ | ✗ | ✗ |
| Knowledge Escrow | ✓ | ✗ | ✗ | ✗ | ✓ |
| Domain Name Escrow | ✗ | ✓ | ✗ | ✗ | ✓ |
Technical security
Architecture and storage
| Softcrow | Escrow4all | Codekeeper | Escrow Alliance | Software Borg | |
|---|---|---|---|---|---|
| Zero-knowledge architecture | ✓ Explicit, encryption key never with Softcrow | ✗ | ✗ | ✗ | ✗ |
| Data sovereignty | ✓ Storage and processing 100% within the EU, free from the CLOUD and USA PATRIOT Act | ✗ | ✗ Partly based in the US (San Francisco) | ✗ | ✗ |
| Operational sovereignty | ✓ Independent Dutch company; production systems and deposits managed entirely from the Netherlands | ✗ | ✗ Establishment in the US (San Francisco) | ✗ | ✗ |
| Technological sovereignty | ✓ Open standards and interoperable software: open file format (AES256-ZIP), open-source foundation, no vendor lock-in | ✗ | ✗ | ✗ | ✗ |
| Cloud platform-independent environment | ✓ Built on Debian Linux and open-source tooling | ✗ | ✗ | ✗ | ✗ |
| Storage on private network | ✓ Deposit storage isolated from the public internet | ✗ | ✗ | ✗ | ✗ |
| Append-only storage | ✓ Delivered data cannot be changed | ✗ | ✗ | ✗ | ✗ |
| Deposit integrity check | ✓ Weekly based on SHA256 checksum | ✗ | ✗ | ✗ | ✗ |
Encryption and delivery
| Softcrow | Escrow4all | Codekeeper | Escrow Alliance | Software Borg | |
|---|---|---|---|---|---|
| Client-side encryption | ✓ Supplier encrypts themselves, with their own key, before delivery | ✗ OpenPGP with Escrow4all’s shared public key; with Git synchronisation, content delivered readable | ✗ Direct Git synchronisation, content delivered readable | ✗ | ✗ |
| Key management with supplier | ✓ Fully, Softcrow never receives the key | ✗ Private key shared with Escrow4all | ✗ Encryption at rest | ✗ | ✗ |
| Standard encryption (Cipher) | ✓ AES-256 Symmetric | ✓ OpenPGP/GPG Asymmetric | ✓ AES-256/512 | ✗ | ✗ |
| Quantum-safe | ✓ Symmetric AES-256, 256-bit key | ✗ | ✗ | ✗ | ✗ |
| Own encryption and tooling | ✓ Via web uploader, method set out in deposit specification | ✗ | ✗ | ✗ | ✗ |
| Open standard file format | ✓ AES256-ZIP, opens with 7-Zip/WinZip | ✗ | ✗ | ✗ | ✗ |
Deposit options
| Softcrow | Escrow4all | Codekeeper | Escrow Alliance | Software Borg | |
|---|---|---|---|---|---|
| Web uploader | ✓ | ✓ | ✓ | ✗ | ✓ |
| Command Line Interface (CLI) | ✓ Binary for Windows, macOS, Linux and Unix | ✗ | ✗ | ✗ | ✗ |
| Automated delivery | ✓ Via CLI, script, cron or pipeline | ✓ Git sync | ✓ Git sync | ✓ | ✗ |
| Git synchronisation (source code arrives readable) | ✗ | ✓ | ✓ | ✗ | ✗ |
| Snapshots (incremental) | ✓ | ✗ | ✗ | ✗ | ✗ |
| Upload protocol | HTTPS and SFTP | HTTPS and SFTP | ✗ | ✗ | ✗ |
Verification
| Softcrow | Escrow4all | Codekeeper | Escrow Alliance | Software Borg | |
|---|---|---|---|---|---|
| Verification levels | 2 | 3 | 3 | ✗ | ✗ |
| Key verification | ✓ Free of charge | ✗ | ✗ | ✗ | ✗ |
| Verification audit | ✓ | ✓ | ✓ | ✓ | ✓ |
| Independent executor | ✓ Externally hired NOREA Register IT auditor | ✗ Own consultants | ✗ Own consultants | ✗ | ✗ IT inspector |
Transparency and legal
| Softcrow | Escrow4all | Codekeeper | Escrow Alliance | Software Borg | |
|---|---|---|---|---|---|
| Business model scope | Escrow only | Escrow and consulting | Escrow and consulting | Escrow and consulting | Escrow and consulting |
| Pricing model | One-off + annual, total price | ✗ | Monthly, per component | ✗ | ✗ |
| Prices public | ✓ Fully | ✗ Calculator leads to a quote request, no prices shown | ✓ Via webshop | ✗ | ✗ |
| Legal system | Dutch | Dutch | Dutch | Dutch | Dutch |
| ISO 27001 certified | ✗ (in preparation) | ✓ | ✓ | ✓ | ✓ |
Methodology and correction
Sources and reference date. This overview has been compiled on the basis of publicly available information only, primarily the providers’ own websites and published documentation. Last updated: September 2026. Websites change; we update this overview periodically.
The standard is ours. The criteria in this comparison are the standards Softcrow applies to an escrow agent. Other providers make different choices and set their own accents; their websites describe their offering in their own words.
Not independently verified. This comparison is not an investigation by an independent body and no right of reply has been applied. It is our reading of what providers publicly describe about their services. We believe in the oldest quality principle: say what you do and do what you say. Publicly describing what you do is the first half of that.
Light grey cross. Where a provider does not publicly describe a feature, or where we did not find it, a light grey cross is shown. That does not mean the feature is absent; it means we could not establish it.
Correction. Providers can point us to information we did not find or that was published after the reference date. We will then reassess that information and adjust the table where necessary.
Notes
Zero-knowledge
Softcrow is, in this overview, the only escrow provider that explicitly describes zero-knowledge storage as an architecture principle and anchors it technically. With zero-knowledge, the supplier encrypts the deposit themselves, before delivery, with a key that Softcrow never receives. Access to the contents is thereby technically excluded, not merely contractually prohibited. The deposit is end-to-end encrypted (E2EE): from supplier to beneficiary, without Softcrow being able to view the contents. This layer runs on SecureStorage, Softcrow's own zero-knowledge storage infrastructure.
Sovereignty
The table tests sovereignty along three pillars, each with its own row.
Data sovereignty
Data falls under the law of the country where it is stored and processed, and under the law that applies to the party providing the storage. That second part is often forgotten: a US provider falls under the US CLOUD Act, even if its data centres are in the EU. Data stored on one of the major cloud platforms, such as Microsoft Azure, Amazon Web Services or Google Cloud, is for that reason not sovereign: the parent company is American and can be compelled to hand over data under the CLOUD Act, regardless of the chosen EU region. Data sovereignty means that a deposit stays entirely within the intended jurisdiction, without a foreign entry point. Softcrow's storage infrastructure is 100% hosted within the EU. Softcrow is an independent Dutch company without a US parent or establishment, so the CLOUD Act and USA PATRIOT Act do not apply. That is relevant for anyone who wants to keep data within the EU under the GDPR. Codekeeper is partly based in the US (San Francisco); a provider with a US entity can fall within the reach of US legislation. For the other providers this is not explicitly stated. It should also be noted: even under a legal demand, Softcrow can provide nothing meaningful without the encryption key; the zero-knowledge layer stands apart from the jurisdiction question.
Operational sovereignty
It is not only where data sits that counts, but also who could actually reach it. Whoever manages, maintains and supports systems has access to those systems. If that is done by staff or parties outside the intended jurisdiction, an operational entry point arises that stands apart from the storage location. Operational sovereignty means that management, maintenance and support are carried out by people based within the same jurisdiction. At Softcrow, the management and maintenance of the production systems and deposits, and support, take place entirely from the Netherlands.
Technological sovereignty
Sovereignty also requires autonomy over the technology itself. Whoever builds on proprietary services or closed formats depends on a single vendor for the workings of their own environment; that is vendor lock-in. Technological sovereignty means open standards and interoperable software, so that switching remains possible and material stays usable in the long term. For escrow that weighs extra heavily: a deposit often exists for decades and must remain openable all that time. Softcrow therefore builds on an open-source foundation, runs cloud platform-independently on Debian Linux and uses an open file format (AES256-ZIP) that opens with standard tools.
Cloud platform-independent environment
Modern applications are often built on proprietary services of a single cloud platform; an exit strategy is meant to cover exactly that dependency. The same test applies to an escrow agent: whoever builds its own environment on such services imports the dependency it is supposed to solve for its customers. Softcrow's environment is built cloud platform-independently on Debian Linux and runs on any standard Linux infrastructure. Such an environment is, in effect, a built-in exit strategy, provided the tooling and formats used are open as well. At Softcrow they are: an open-source foundation and deposits in an open file format (AES256-ZIP, extractable with standard tools). For the other providers no public information on this is available. See also the page on exit strategy and digital sovereignty.
Asymmetric encryption
Escrow4all uses OpenPGP/GPG with a key pair that they generate and manage themselves. The supplier encrypts the deposit with Escrow4all's public key. Escrow4all holds the accompanying private key and can decrypt the contents at any time. This is publicly documented in their own manual. That is not zero-knowledge.
AI Escrow
In the table, AI Escrow is named as a separate service, with its own name and its own positioning. The service is aimed at organisations that train or fine-tune their own AI model and host that model internally, not at companies that use AI via a cloud service such as OpenAI or Google. With cloud-based AI there is nothing to deposit: the model belongs to the provider and runs at the provider. The term AI Escrow covers a broad spectrum: from model weights and training data to system prompts and workflow configurations. That spectrum is not equivalent. Model weights of a self-trained or fine-tuned model are a valuable asset in their own right, depositable as software. System prompts and workflow configurations are configuration files. That is not escrow in the classic sense, but version control with a custodian in between. Softcrow deposits AI components such as model weights and training data as part of an ordinary Software Escrow. So far we do this without a separate AI agreement, separate name or separate price; if a specific situation calls for it, we draw up a separate agreement for it. What Softcrow does not offer is a native integration with AI development platforms such as Hugging Face or MLflow. That is an integration feature, not an escrow feature.
Knowledge Escrow
What other providers call knowledge escrow or IP escrow goes further than source code alone: think of design documentation, build and compilation instructions, configurations and other knowledge needed to be able to continue the software. Softcrow arranges this via an additional deposit within an existing Software Escrow, SaaS Escrow or CloudSecure agreement, so that all knowledge belonging to the software sits on the same zero-knowledge, sovereign storage.
Storage encryption
Codekeeper states AES-256/512 encryption. Because their verification service rebuilds the source code, Codekeeper has readable access to the deposit contents, regardless of the type of encryption.
Pricing model
With Codekeeper you assemble an escrow from separate components. Each component has its own price. Together those amounts form the monthly price. On the website you click together all the components you need.
Git synchronisation
Some escrow agents offer a direct integration with Git systems. That raises two objections. First, direct synchronisation is incompatible with zero-knowledge storage: the escrow agent receives the source code in unencrypted, readable form. Second, a Git synchronisation deposits at every commit, not at every release. A deposit in the escrow sense is an identifiable, release-ready version that a beneficiary can actually use in case of need. Interim commits are development snapshots, not a deposit. When every commit is deposited automatically, it is moreover unclear which version is the official one the beneficiary can lay claim to. Softcrow supports automated delivery via the CLI in a pipeline, at the moment of a release, without the escrow agent having access to the unencrypted contents.
Cloud service continuity: legal basis
Not all cloud continuity services offer the same protection. CloudSecure from Softcrow separates the hosting contracts, the intellectual property and the user agreements legally from the operating company. Those assets fall outside the bankruptcy estate, so in a bankruptcy it is immediately clear what does and does not belong to the estate. Codekeeper's Continuity Escrow is an operational service: in case of payment failures or disruptions at infrastructure providers, Codekeeper steps in to keep the service running. That is a different use case and a different legal basis. An approach that is sometimes presented as a continuity solution is storing login credentials for a cloud account in a deposit. That offers no legal protection: a cloud account is an asset of the supplier and falls into the bankruptcy estate in a bankruptcy. The trustee decides what happens with it. The beneficiary has no entitlement to cooperation.
NOREA Register IT auditor
RE is a protected professional title. A Register IT Auditor has completed an academic post-master programme, is obliged to undertake continuing education and falls under the disciplinary law of NOREA. In case of an error or unethical conduct, the title is at stake. That is a fundamentally different responsibility structure than an unprotected job title such as "IT inspector", where only civil liability applies. Formal independence is not a promise for an RE but a hard requirement, monitored by an external supervisory body. The verification report is drawn up and signed by an RE in accordance with ISAE audit standards and thereby has formal evidential value with supervisors and in legal disputes.
Business model scope
Softcrow provides escrow only. Providers who combine escrow with consulting have broader commercial interests: they earn from advising on the content of what they store. That is not by definition problematic, but it is relevant for anyone who deliberately chooses a neutral custodian without other interests.
Storage on private network
Softcrow's deposit storage sits on a private network that is not reachable from the public internet. Upload endpoints (HTTPS and SFTP) are publicly reachable, but shielded from the rest of the world via IP whitelisting and SSH keys. Exception: with the snapshots option for data deposits, the upload endpoint and storage are technically combined. Here too, access is solely via SSH keys.