The code is the easy part. Almost every contract assigns it to the client and almost every studio honours that. The interesting question is whether you own the things without which the code is a folder of text.
The five places ownership leaks
The repository. If it lives in the studio's organisation, your access ends when the relationship does. It should be in your account from the first commit, with the studio invited as a guest.
The domain and DNS. Registered by the studio "for convenience" is the most common hostage situation in this industry, and it surfaces at the worst possible moment.
The servers and the bill. If hosting is resold to you, you cannot see what you are paying for and cannot leave without a migration. Your accounts, your card, studio invited.
The signing keys and store accounts for anything mobile. Nearly impossible to recreate cleanly, and routinely held by the builder.
The framework underneath. Some studios build on an in-house platform. The code is yours in the sense that you have it; it does not run without their licence. Ask directly: is there anything here that stops working if we stop paying you?
The test that settles it
One question makes all five concrete: *if we replaced you next month, what would the next team need from you, and how long would it take?*
A good answer is short and boring: nothing, they clone the repository, here is the runbook. A bad answer contains "we would export", "we would hand over" or "we would need to arrange". Every one of those describes something you do not currently own.
Escrow, and why it is usually theatre
Source code escrow — a third party holding a copy in case the supplier disappears — sounds reassuring and rarely helps. Deposits go stale, build instructions are missing, and nobody has ever tested restoring it. Ownership from day one solves the same fear for less, and you can verify it any afternoon by cloning the repository yourself.
What good looks like
Everything in your accounts, paid by you. The studio as a collaborator whose access can be revoked in a click. A runbook written against your system. And ideally a handover where one of your own people deploys, once, with the studio watching — because the honest test of ownership is not what the contract says. It is whether you could leave. Ownership from the first commit is the default in how we work, not a clause you have to negotiate for.
Worth reading alongside it: what the first version should contain, and what it must not.