{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"cyber-recovery","name":"Cyber recovery & backup resilience","short":"RECOVERY"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"enterprise-backup-recovery","name":"Enterprise backup and recovery platforms","scope":"Compare documented backup-policy, retained-copy and restoration capabilities for mixed enterprise VM, database and file workloads. Rubrik RSC with CDM and vSphere Orchestrated Recovery; Cohesity self-managed DataProtect (not NetBackup or Cloud Protection Service); Veeam Data Platform Premium with Backup & Replication 13 and Recovery Orchestrator 13; Commvault software 11.42 plus explicitly named Air Gap Protect/Cleanroom components. Optional modules count only where the assessment names them. SaaS-only backup, standalone vaults, identity-only recovery and endpoint security are excluded. Scores measure documented capability and operator safeguards, not measured recovery speed or incident success."}],"dimensions":[{"id":"maturity","name":"Operational maturity","question":"How clearly can operators configure retained copies and recover through management failures?","description":"Cumulative safeguards for the scoped recovery path. Does not score company age, customer count, availability guarantees or actual incident performance. All earlier anchors must be supported before crediting a later stage.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: A concrete backup schedule or retention control is documented.","2: Stage 1 plus operator-facing retention or immutability constraints and prerequisites.","3: Stage 2 plus a documented isolated restore or failover test with target and dependency configuration.","4: Stage 3 plus documented recovery of the backup management plane and a rehearsal path that explicitly avoids dependence on the normal production identity service.","5: Stage 4 plus an end-to-end runbook exercising loss of management, recovery credentials, application validation and return to service."],"refinements":[{"base":3,"criteria":[{"id":"management-recovery","label":"Documented recovery of the backup management plane","weight":6},{"id":"independent-identity","label":"Explicit rehearsal without the normal production identity service","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","question":"What shipped workflows go beyond the shared contemporary backup-and-recovery baseline?","description":"Baseline means policy-managed backup, protected retained copies and restoration of supported enterprise data. Stage 3 establishes that integrated baseline, not novelty. Isolation, scanning, orchestration and AI branding alone do not establish superiority; higher anchors require comparative primary evidence.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: One shipped backup or restore workflow is established.","2: Stage 1 plus several baseline components are established, without a complete integrated baseline.","3: An integrated policy, protected-copy and restoration workflow is established.","4: Stage 3 plus one concrete generally available operator-workflow difference beyond the shared contemporary baseline, established by comparative primary evidence.","5: Stage 4 plus multiple complementary differences beyond that baseline, with their dependencies and boundaries established."]},{"id":"breadth","name":"Capability breadth","question":"Which distinct recovery functions are established within the named bundle?","description":"Cumulative functional breadth for enterprise workloads, not a count of every product in the vendor portfolio. Individual workload matrices and additional subscriptions remain evaluation requirements.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: Restoration of one enterprise workload type is documented.","2: Stage 1 plus both whole-machine and granular file restoration are documented.","3: Stage 2 plus application or database data protection is documented.","4: Stage 3 plus an alternate recovery destination and dependency-ordered recovery plans are documented.","5: Stage 4 plus management-plane recovery, application validation and a documented return-to-production workflow are established together."],"refinements":[{"base":3,"criteria":[{"id":"alternate-target","label":"Documented alternate recovery destination","weight":4},{"id":"dependency-order","label":"Documented dependency-ordered recovery plan","weight":6}]}]},{"id":"ecosystem","name":"Ecosystem & integration","question":"Can operators integrate the scoped platform without guessing its permissions and handoff limits?","description":"Scores supported integrations and documented APIs. Counts neither partnership logos nor unsupported community scripts as production support.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: One supported workload or storage integration is documented.","2: Stage 1 plus multiple workload or storage integration families are documented.","3: Stage 2 plus a management API and its authentication and permission boundary are documented.","4: Stage 3 plus an external event or evidence handoff and its operational boundaries are documented.","5: Stage 4 plus an end-to-end least-privilege integration example covering authentication, denied access, event delivery and recovery failure handling."],"refinements":[{"base":2,"criteria":[{"id":"management-api","label":"Documented management API for the scoped platform","weight":4},{"id":"api-boundary","label":"Documented API authentication and permission boundary","weight":6}]}]},{"id":"governance","name":"Governance & control","question":"Which controls constrain backup administration and preserve evidence of changes?","description":"Cumulative policy and administrative controls for the scoped product. Immutability does not certify data cleanliness or prove regulatory compliance.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: A retention policy is documented.","2: Stage 1 plus role-scoped administration is documented.","3: Stage 2 plus independent approval for sensitive changes and an administrative audit trail are documented.","4: Stage 3 plus exportable audit evidence and explicit limits of protected retention are documented.","5: Stage 4 plus a documented governed emergency-access and recovery-approval workflow that preserves independent audit evidence."],"refinements":[{"base":2,"criteria":[{"id":"independent-approval","label":"Independent approval for sensitive administrative changes","weight":4},{"id":"audit-trail","label":"Administrative audit trail identifying control changes or actions","weight":6}]}]},{"id":"operations","name":"Operator enablement","question":"Can a practitioner follow public procedures from backup policy to an observable recovery test?","description":"Cumulative documented operating guidance, not measured staffing savings. Product descriptions alone do not establish executable operator procedures.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: A concrete operator action is documented.","2: Stage 1 plus procedures for creating a backup policy and restoring a protected object.","3: Stage 2 plus a repeatable isolated recovery-test procedure with target configuration.","4: Stage 3 plus recovery result inspection and test cleanup are documented.","5: Stage 4 plus management-plane recovery and a complete validated return-to-production procedure are documented together."]}],"assessments":[{"vendor":"rubrik-security-cloud-recovery","cohort":"enterprise-backup-recovery","edition":"Rubrik Security Cloud with CDM enterprise protection, retention-locked SLA Domains and Orchestrated Recovery for vSphere","asOf":"2026-09-21","status":"research-preview","summary":"The reviewed procedures connect policy, retained snapshots and dependency-ordered test recovery. Management-plane recovery independent of normal production identity remains unverified in this evidence set.","dimensions":{"maturity":{"score":3,"confidence":"low","rationale":"Stages 1–3: SLA scheduling and retention are explicit; lock modes and quorum prerequisites are documented; the vSphere test plan specifies resources, networks and boot order. No management-plane recovery or independent-identity rehearsal credit is established here.","sourceIds":["r-policy","r-lock","r-plan","r-test"]},"innovation":{"score":3,"confidence":"low","rationale":"SLA-managed copies, protected retention and a usable recovery-test workflow establish the shared baseline. No comparative generally available workflow difference beyond that baseline is established; this is not a novelty ranking.","sourceIds":["r-policy","r-lock","r-test"]},"breadth":{"score":4,"confidence":"low","rationale":"Whole-machine and granular recovery plus database protection meet stages 1–3. The recovery-plan procedure adds an alternate target and priority-ordered startup, meeting stage 4. A complete management-plane and production-return workflow is not established.","sourceIds":["r-platform","r-plan","r-test"]},"ecosystem":{"score":2.4,"confidence":"low","rationale":"Multiple enterprise workload families establish stage 2. The SLA GraphQL API earns the documented management-API refinement. A complete API-specific authentication and permission boundary was not verified in these cited pages, so that separate criterion receives no credit.","sourceIds":["r-platform","r-policy"],"refinement":{"base":2,"evidence":[{"criterion":"management-api","rationale":"The developer page supplies GraphQL policy queries and mutations for the scoped RSC platform.","sourceIds":["r-policy"]}]}},"governance":{"score":4,"confidence":"low","rationale":"Retention policy and role isolation establish stages 1–2. Retention-lock quorum approval and indexed cluster-audit documentation of actor-attributed administrative changes establish stage 3. Audit export and documented archive/mode boundaries meet stage 4. The versioned audit source redirects to sign-in; no governed emergency workflow is established.","sourceIds":["r-policy","r-role","r-lock","r-cluster-audit"]},"operations":{"score":4,"confidence":"low","rationale":"SLA policy examples and indexed official recovery-plan/test procedures establish stages 1–3. Indexed recovery information explicitly lists result states, report download and the cleanup action, establishing stage 4. Sign-in redirects prevent fresh authenticated verification; full management-plane-to-production return is not established.","sourceIds":["r-policy","r-plan","r-test","r-result","r-perform"]}},"constraints":["RSC/CDM policy and vSphere orchestration are assessed together; separate SaaS, identity, vault and simulation products are not assumed included.","Rubrik retention-lock documentation in this source set is versioned 9.0. Confirm mode behavior against the deployed CDM release; it is not a claim that 9.0 is the latest release.","No production restore, destructive retention change or performance benchmark was executed.","Non-immutable archive destinations have a different loss boundary; retention lock does not establish clean data.","Some Rubrik operator pages redirected to sign-in. Recovery actions were checked through indexed official documentation excerpts; current authenticated documentation was not accessed. This access and freshness limit reduces all Rubrik confidence ratings to low."],"sources":[{"id":"r-policy","title":"Rubrik: SLA Domains","url":"https://developer.rubrik.com/Rubrik-Security-Cloud-API/Data-Protection/SLA-Domains/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-lock","title":"Rubrik: retention-locked SLA Domains","url":"https://docs.rubrik.com/en-us/9.0/ug/saas/retention_locked_sla_domain.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-plan","title":"Rubrik: vSphere recovery plan","url":"https://docs.rubrik.com/en-us/saas/saas/creating_disaster_rp_vsphere.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-test","title":"Rubrik: test failover","url":"https://docs.rubrik.com/en-us/saas/saas/tests_for_disaster_recovery_failover.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-result","title":"Rubrik: recovery results and cleanup","url":"https://docs.rubrik.com/en-us/saas/saas/recovery_information.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-platform","title":"Rubrik: data protection scope","url":"https://www.rubrik.com/products/data-protection","accessedAt":"2026-09-21","kind":"product"},{"id":"r-role","title":"Rubrik: roles","url":"https://docs.rubrik.com/en-us/saas/saas/common/rsc_roles.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-audit","title":"Rubrik: user audit log","url":"https://docs.rubrik.com/en-us/9.0/sg/security_guide/user_audit_log.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-perform","title":"Rubrik: performing disaster recovery (indexed official procedure)","url":"https://docs.rubrik.com/en-us/saas/saas/performing_disaster_recovery.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-cluster-audit","title":"Rubrik CDM 9.0: cluster audits and syslog export (indexed documentation)","url":"https://docs.rubrik.com/en-us/9.0/sg/security_guide/rubrik_cluster_audits.html","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Rubrik Security Cloud","company":"Rubrik","profileUrl":"/landscape/vendors/rubrik-security-cloud-recovery/"},{"vendor":"cohesity-dataprotect","cohort":"enterprise-backup-recovery","edition":"Cohesity self-managed DataProtect; separate FortKnox, NetBackup, Cloud Protection Service and RecoveryAgent not included","asOf":"2026-09-21","status":"research-preview","summary":"Public materials establish core backup, recovery and access controls. Gated operator documentation prevents a defensible rating of the detailed operating procedures for this specific deployment.","dimensions":{"maturity":{"score":1,"confidence":"low","rationale":"DataProtect describes DataLock retention controls, establishing stage 1. The self-managed operator guide returned HTTP 403, so its retention prerequisites and isolated-test sequence were not verified. Higher anchors remain uncredited; Cloud Protection Service procedures are not substituted.","sourceIds":["c-product","c-docs"]},"innovation":{"score":3,"confidence":"low","rationale":"The DataProtect page establishes an integrated backup, protected-snapshot and restoration workflow matching the contemporary baseline. No comparative evidence establishes a differentiated workflow; related RecoveryAgent and FortKnox claims are outside this edition.","sourceIds":["c-product"]},"breadth":{"score":3,"confidence":"low","rationale":"DataProtect describes whole-VM and granular file recovery plus enterprise database protection, establishing stages 1–3. Alternate-target and ordered-plan documentation for this exact scope was not verified; adjacent orchestration is excluded.","sourceIds":["c-product","c-vm"]},"ecosystem":{"score":2,"confidence":"low","rationale":"Multiple VM, database and storage integrations establish stage 2. The general developer portal includes separate cloud-service APIs; a management endpoint and permission boundary for the scoped self-managed edition were not verified, so stage 3 receives no partial credit.","sourceIds":["c-api","c-vm"]},"governance":{"score":2,"confidence":"low","rationale":"DataLock retention policy and role-based administration establish stages 1–2 in product documentation. The broader data-security page describes quorum, but its precise self-managed deployment scope and audit procedure were not established; stage 3 receives no partial credit.","sourceIds":["c-product","c-security"]},"operations":{"score":null,"confidence":"low","rationale":"A public product description is not an executable backup-to-recovery procedure. The self-managed operator documentation was inaccessible; SaaS procedures would evaluate a different edition, so operator enablement remains unknown.","sourceIds":["c-docs","c-product"]}},"constraints":["Documentation catalog distinguishes self-managed DataProtect, Cloud Protection Service and NetBackup. Their capabilities are not combined.","The documentation host returned HTTP 403 during direct access; indexed descriptions and product pages cannot establish detailed operator safeguards.","Low-confidence ratings establish described capability only. No customer deployment, support portal or lab benchmark was accessed.","FortKnox and RecoveryAgent remain catalog context outside the scored bundle."],"sources":[{"id":"c-product","title":"Cohesity: DataProtect","url":"https://www.cohesity.com/platform/dataprotect/","accessedAt":"2026-09-21","kind":"product"},{"id":"c-security","title":"Cohesity: data security controls","url":"https://www.cohesity.com/solutions/data-security/","accessedAt":"2026-09-21","kind":"product"},{"id":"c-docs","title":"Cohesity: documentation catalog","url":"https://docs.cohesity.com/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c-api","title":"Cohesity: developer portal","url":"https://developers.cohesity.com/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c-vm","title":"Cohesity: virtual-machine protection","url":"https://www.cohesity.com/solutions/virtual/","accessedAt":"2026-09-21","kind":"product"}],"name":"Cohesity DataProtect","company":"Cohesity","profileUrl":"/landscape/vendors/cohesity-dataprotect/"},{"vendor":"veeam-data-platform","cohort":"enterprise-backup-recovery","edition":"Veeam Data Platform Premium: Backup & Replication 13, Veeam ONE and Recovery Orchestrator 13 with a supported hardened repository","asOf":"2026-09-21","status":"research-preview","summary":"The public guides describe repository constraints, isolated recovery testing and restoration of the backup configuration. Recovery authority still depends on separately managed identities, credentials and infrastructure.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Backup job and repository procedures establish stages 1–2, and isolated orchestrated testing establishes stage 3. Configuration database restoration earns six tenths toward stage 4. An explicit rehearsal without the production identity service is not established.","sourceIds":["v-job","v-hard","v-plan","v-control","v-order","v-lab"],"refinement":{"base":3,"evidence":[{"criterion":"management-recovery","rationale":"The configuration restore guide documents recovery to the same or another backup server, including backup selection and database restoration.","sourceIds":["v-control"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"Documented backup, hardened retention and restore verification establish the shared baseline. Orchestration, isolated tests and threat scanning do not alone prove a generally available difference beyond contemporary peers.","sourceIds":["v-job","v-hard","v-test","v-plan"]},"breadth":{"score":4,"confidence":"low","rationale":"Whole-machine and granular restoration plus application protection establish stages 1–3. Orchestrator documents alternate target environments and explicit dependency-aware group processing order, establishing stage 4. Complete validated production return after management-plane loss is not established by this source set.","sourceIds":["v-edition","v-how","v-plan","v-order"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Multiple workload/storage integrations meet stages 1–2. The documented management API identifies bearer authentication, allowed roles and forbidden-access responses, establishing stage 3. A bounded external SOC event handoff is not established by this evidence set.","sourceIds":["v-edition","v-api","v-how"]},"governance":{"score":3,"confidence":"medium","rationale":"Repository retention and assigned backup/security roles establish stages 1–2. Four-eyes approval and its Authorization Events history establish stage 3. Exportable audit evidence is not established here, so stage 4 is not claimed.","sourceIds":["v-hard","v-four","v-api"]},"operations":{"score":3,"confidence":"medium","rationale":"Job creation and documented restore APIs meet stages 1–2. Orchestrator and SureBackup describe repeatable isolated testing with configured targets, meeting stage 3. The cited overview does not establish the complete cleanup procedure needed for stage 4.","sourceIds":["v-job","v-how","v-plan","v-test","v-lab"]}},"constraints":["Premium includes the scoped orchestration components; Data Cloud, Kasten and separate identity products are excluded.","Repository hardening requires supported infrastructure and credential handling; immutability is not a property of every arbitrary backup destination.","Veeam explicitly says four-eyes authorization does not protect infrastructure after compromise of the backup server itself.","API restore coverage differs by endpoint and workload; the cited VBR API guide limits certain file restores to agent-managed objects.","No measured RTO, data-loss guarantee or malware-detection rate is inferred from documentation."],"sources":[{"id":"v-edition","title":"Veeam: Data Platform editions","url":"https://www.veeam.com/products/veeam-data-platform.html","accessedAt":"2026-09-21","kind":"product"},{"id":"v-hard","title":"Veeam: hardened repository","url":"https://helpcenter.veeam.com/docs/vbr/userguide/hardened_repository.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-plan","title":"Veeam: Recovery Orchestrator overview","url":"https://helpcenter.veeam.com/docs/vro/userguide/overview.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-test","title":"Veeam: SureBackup","url":"https://helpcenter.veeam.com/docs/vbr/userguide/surebackup_recovery_verification.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-control","title":"Veeam: configuration database recovery","url":"https://helpcenter.veeam.com/docs/vbr/userguide/vbr_config_restore.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-four","title":"Veeam: four-eyes authorization","url":"https://helpcenter.veeam.com/docs/vbr/userguide/four_eyes_authorization.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-api","title":"Veeam: backup API permissions","url":"https://helpcenter.veeam.com/references/vbr/13/rest/1.3-rev2/tag/Backups/index.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-how","title":"Veeam: API workflow and restore boundaries","url":"https://helpcenter.veeam.com/references/vbr/13/rest/1.3-rev2/tag/SectionHowTo/index.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-job","title":"Veeam: creating backup jobs","url":"https://helpcenter.veeam.com/docs/vbr/userguide/backup_job_console.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-order","title":"Veeam: recovery group processing order","url":"https://helpcenter.veeam.com/docs/vro/userguide/setting_group_order.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-lab","title":"Veeam: lab-group dependencies","url":"https://helpcenter.veeam.com/docs/vro/userguide/creating_lab_groups.html","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Veeam Data Platform","company":"Veeam","profileUrl":"/landscape/vendors/veeam-data-platform/"},{"vendor":"commvault-cloud-recovery","cohort":"enterprise-backup-recovery","edition":"Commvault software 11.42 backup and recovery with supported Storage Lock plus Air Gap Protect and cloud-based Cleanroom Recovery","asOf":"2026-09-21","status":"research-preview","summary":"The documented workflow covers protection plans, immutable-storage constraints and ordered cleanroom recovery. Storage tier and control-plane dependencies are explicit and must be included in the evaluation.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Plans define scheduling/retention, Storage Lock documents irreversible settings and capacity constraints, and cleanroom preparation defines isolation and dependency order: stages 1–3. Recovery of the control plane earns six tenths. An explicit independent-production-identity rehearsal is not established.","sourceIds":["m-plan","m-lock","m-clean","m-control"],"refinement":{"base":3,"evidence":[{"criterion":"management-recovery","rationale":"The recovery procedure restores the control plane in a restricted recovery state before workloads are recovered.","sourceIds":["m-control"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"Policy-managed backups, protected copies and cleanroom restoration establish the integrated contemporary baseline. Cleanroom branding and orchestration alone are not comparative proof of a workflow difference beyond it.","sourceIds":["m-plan","m-lock","m-recover"]},"breadth":{"score":5,"confidence":"low","rationale":"Whole-workload and granular data recovery plus application protection establish stages 1–3. The cleanroom workflow adds alternate destinations, ordered groups, management-plane recovery, explicit validation and migration-to-production steps, meeting stages 4–5 within the named components. This rates documented breadth, not measured success.","sourceIds":["m-product","m-clean","m-recover","m-control","m-validate","m-return"]},"ecosystem":{"score":2.4,"confidence":"low","rationale":"Enterprise workload integrations establish stage 2. REST access-token documentation establishes a management API. The selected sources do not connect a concrete endpoint to its required permissions, so the separate API-boundary criterion remains uncredited.","sourceIds":["m-product","m-api","m-role"],"refinement":{"base":2,"evidence":[{"criterion":"management-api","rationale":"The official current API guide documents bearer access tokens for Commvault REST requests.","sourceIds":["m-api"]}]}},"governance":{"score":2.6,"confidence":"medium","rationale":"Retention and role/entity associations establish stages 1–2. The administrative audit operation list earns six tenths toward stage 3. An independent-approval procedure for sensitive changes was not verified in these scoped sources.","sourceIds":["m-plan","m-role","m-audit"],"refinement":{"base":2,"evidence":[{"criterion":"audit-trail","rationale":"The audit documentation explicitly lists retention changes, deletion attempts, role changes and other administrative operations.","sourceIds":["m-audit"]}]}},"operations":{"score":5,"confidence":"medium","rationale":"Backup-plan creation and cleanroom procedures establish stages 1–3. Separate validation and cleanup instructions establish stage 4. Control-plane restoration and the documented production-migration sequence establish stage 5, including re-enabling backups and manual resource cleanup. Cloud-provider transfer procedures remain required dependencies; no live recovery drill was performed.","sourceIds":["m-plan","m-clean","m-recover","m-control","m-validate","m-return","m-cleanup"]}},"constraints":["Air Gap Protect and Cleanroom Recovery are explicitly included components, not assumed features of every Commvault subscription.","The support matrix distinguishes frequent/infrequent access from archive; archive does not support the same cleanroom and threat-scan operations.","Storage Lock is irreversible and can increase capacity consumption; it is not exercised against production by this educational evaluation.","A documented production-migration step does not remove the need for application-owner approval and incident-response validation.","Public SaaS recovery instructions are used only for the named cloud cleanroom/control-plane component; unrelated SaaS backup products are not credited."],"sources":[{"id":"m-plan","title":"Commvault: backup plans","url":"https://documentation.commvault.com/11.42/software/understand_and_create_backup_plans.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-lock","title":"Commvault: Storage Lock","url":"https://documentation.commvault.com/11.42/software/configuring_storage_lock_01.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-clean","title":"Commvault: cleanroom preparation","url":"https://documentation.commvault.com/11.42/software/get_started_with_cloud_based_cleanroom_recovery.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-recover","title":"Commvault: cleanroom recovery workflow","url":"https://documentation.commvault.com/11.42/software/recover_to_cloud_based_cleanroom_site.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-control","title":"Commvault: recovered control plane","url":"https://documentation.commvault.com/saas/recover_to_cleanroom.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-tier","title":"Commvault: Air Gap Protect support","url":"https://documentation.commvault.com/saas/supported_workloads_and_features_for_air_gap_protect.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-role","title":"Commvault: role boundaries","url":"https://documentation.commvault.com/11.42/commcell-console/roles_overview.html?view=saas","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-audit","title":"Commvault: recorded administrative operations","url":"https://documentation.commvault.com/11.42/software/commvault_console_operations_recorded_by_audit_trail_01.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-api","title":"Commvault: REST API access tokens","url":"https://documentation.commvault.com/11.42/software/access_tokens_for_rest_apis_01.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-product","title":"Commvault: Backup and Recovery","url":"https://www.commvault.com/platform/backup-and-recovery","accessedAt":"2026-09-21","kind":"product"},{"id":"m-validate","title":"Commvault: validate recovered resources","url":"https://documentation.commvault.com/11.42/software/validate_resources_recovered_to_your_cleanroom_site.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-return","title":"Commvault: migrate cleanroom recovery to production","url":"https://documentation.commvault.com/11.42/software/migrate_recovered_resources_and_configurations_from_cleanroom_to_production.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-cleanup","title":"Commvault: clean up cloud cleanroom resources","url":"https://documentation.commvault.com/11.42/software/clean_up_recovered_resources_for_cloud_based_cleanroom_site.html","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Commvault Cloud","company":"Commvault","profileUrl":"/landscape/vendors/commvault-cloud-recovery/"}],"scenarios":[{"id":"compromised-admin","name":"Production administrator compromised","description":"A synthetic incident removes normal production administration while a separate recovery operator must reach retained copies.","priorities":["governance","maturity"],"questions":["Which identity can shorten retention or disable protection?","Can recovery access survive loss of the production identity service?"]},{"id":"minimum-service","name":"Restore the minimum viable service","description":"Recover a small database-backed application and validate a business transaction instead of counting powered-on machines.","priorities":["operations","breadth"],"questions":["Which identity, network, key and application dependencies must return first?","What observable transaction establishes that this recovery worked?"]},{"id":"capacity-retention","name":"Retention with a finite storage budget","description":"A small team estimates changed data, immutable retention and temporary recovery resources before committing to a policy.","priorities":["maturity","governance"],"questions":["Which retention choices are irreversible and how does that affect capacity?","What additional cloud transfer, retrieval or recovery-compute charges apply?"]}],"researchNotes":["First edition on 2026-09-21. This is a new baseline, not historical momentum.","Four named bundles form one enterprise recovery cohort. Scores apply to documented workflows in scope; wider vendor portfolios and acquired products are not merged into scores.","Public sources establish documented controls, not independently measured efficacy, recovery speed or successful incident outcomes. Confidence is at most medium; product-page inferences are low.","Every stage is cumulative. Supported lower anchors retain their credit when a higher prerequisite is unverified. A cell remains unknown only when the first in-scope anchor cannot be established.","Shared decimal refinements credit only distinct parts of the next anchor. Criteria total ten tenths at each base; no jitter, hidden vendor weight or arbitrary tie-breaking is used.","The contemporary baseline already includes policy-managed backup, protected copies and restoration. No offering earns an innovation differentiation claim from AI branding, immutable storage or an orchestration feature alone.","Cohesity operator-documentation access returned HTTP 403 in this pass. Product evidence supports lower capability anchors; self-managed operating procedures remain unknown and are not replaced with Cloud Protection Service procedures.","Source-linked review decisions and limitations are recorded in docs/research/2026-09-21-market-expansion/resilience.md."],"history":{"segment":"cyber-recovery","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"cyber-recovery","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"enterprise-backup-recovery","name":"Enterprise backup and recovery platforms","scope":"Compare documented backup-policy, retained-copy and restoration capabilities for mixed enterprise VM, database and file workloads. Rubrik RSC with CDM and vSphere Orchestrated Recovery; Cohesity self-managed DataProtect (not NetBackup or Cloud Protection Service); Veeam Data Platform Premium with Backup & Replication 13 and Recovery Orchestrator 13; Commvault software 11.42 plus explicitly named Air Gap Protect/Cleanroom components. Optional modules count only where the assessment names them. SaaS-only backup, standalone vaults, identity-only recovery and endpoint security are excluded. Scores measure documented capability and operator safeguards, not measured recovery speed or incident success."}],"dimensions":[{"id":"maturity","name":"Operational maturity","question":"How clearly can operators configure retained copies and recover through management failures?","description":"Cumulative safeguards for the scoped recovery path. Does not score company age, customer count, availability guarantees or actual incident performance. All earlier anchors must be supported before crediting a later stage.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: A concrete backup schedule or retention control is documented.","2: Stage 1 plus operator-facing retention or immutability constraints and prerequisites.","3: Stage 2 plus a documented isolated restore or failover test with target and dependency configuration.","4: Stage 3 plus documented recovery of the backup management plane and a rehearsal path that explicitly avoids dependence on the normal production identity service.","5: Stage 4 plus an end-to-end runbook exercising loss of management, recovery credentials, application validation and return to service."],"refinements":[{"base":3,"criteria":[{"id":"management-recovery","label":"Documented recovery of the backup management plane","weight":6},{"id":"independent-identity","label":"Explicit rehearsal without the normal production identity service","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","question":"What shipped workflows go beyond the shared contemporary backup-and-recovery baseline?","description":"Baseline means policy-managed backup, protected retained copies and restoration of supported enterprise data. Stage 3 establishes that integrated baseline, not novelty. Isolation, scanning, orchestration and AI branding alone do not establish superiority; higher anchors require comparative primary evidence.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: One shipped backup or restore workflow is established.","2: Stage 1 plus several baseline components are established, without a complete integrated baseline.","3: An integrated policy, protected-copy and restoration workflow is established.","4: Stage 3 plus one concrete generally available operator-workflow difference beyond the shared contemporary baseline, established by comparative primary evidence.","5: Stage 4 plus multiple complementary differences beyond that baseline, with their dependencies and boundaries established."]},{"id":"breadth","name":"Capability breadth","question":"Which distinct recovery functions are established within the named bundle?","description":"Cumulative functional breadth for enterprise workloads, not a count of every product in the vendor portfolio. Individual workload matrices and additional subscriptions remain evaluation requirements.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: Restoration of one enterprise workload type is documented.","2: Stage 1 plus both whole-machine and granular file restoration are documented.","3: Stage 2 plus application or database data protection is documented.","4: Stage 3 plus an alternate recovery destination and dependency-ordered recovery plans are documented.","5: Stage 4 plus management-plane recovery, application validation and a documented return-to-production workflow are established together."],"refinements":[{"base":3,"criteria":[{"id":"alternate-target","label":"Documented alternate recovery destination","weight":4},{"id":"dependency-order","label":"Documented dependency-ordered recovery plan","weight":6}]}]},{"id":"ecosystem","name":"Ecosystem & integration","question":"Can operators integrate the scoped platform without guessing its permissions and handoff limits?","description":"Scores supported integrations and documented APIs. Counts neither partnership logos nor unsupported community scripts as production support.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: One supported workload or storage integration is documented.","2: Stage 1 plus multiple workload or storage integration families are documented.","3: Stage 2 plus a management API and its authentication and permission boundary are documented.","4: Stage 3 plus an external event or evidence handoff and its operational boundaries are documented.","5: Stage 4 plus an end-to-end least-privilege integration example covering authentication, denied access, event delivery and recovery failure handling."],"refinements":[{"base":2,"criteria":[{"id":"management-api","label":"Documented management API for the scoped platform","weight":4},{"id":"api-boundary","label":"Documented API authentication and permission boundary","weight":6}]}]},{"id":"governance","name":"Governance & control","question":"Which controls constrain backup administration and preserve evidence of changes?","description":"Cumulative policy and administrative controls for the scoped product. Immutability does not certify data cleanliness or prove regulatory compliance.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: A retention policy is documented.","2: Stage 1 plus role-scoped administration is documented.","3: Stage 2 plus independent approval for sensitive changes and an administrative audit trail are documented.","4: Stage 3 plus exportable audit evidence and explicit limits of protected retention are documented.","5: Stage 4 plus a documented governed emergency-access and recovery-approval workflow that preserves independent audit evidence."],"refinements":[{"base":2,"criteria":[{"id":"independent-approval","label":"Independent approval for sensitive administrative changes","weight":4},{"id":"audit-trail","label":"Administrative audit trail identifying control changes or actions","weight":6}]}]},{"id":"operations","name":"Operator enablement","question":"Can a practitioner follow public procedures from backup policy to an observable recovery test?","description":"Cumulative documented operating guidance, not measured staffing savings. Product descriptions alone do not establish executable operator procedures.","anchors":["0: Affirmative primary evidence establishes no in-scope capability. Missing evidence is unknown, never zero.","1: A concrete operator action is documented.","2: Stage 1 plus procedures for creating a backup policy and restoring a protected object.","3: Stage 2 plus a repeatable isolated recovery-test procedure with target configuration.","4: Stage 3 plus recovery result inspection and test cleanup are documented.","5: Stage 4 plus management-plane recovery and a complete validated return-to-production procedure are documented together."]}],"assessments":[{"vendor":"rubrik-security-cloud-recovery","cohort":"enterprise-backup-recovery","edition":"Rubrik Security Cloud with CDM enterprise protection, retention-locked SLA Domains and Orchestrated Recovery for vSphere","asOf":"2026-09-21","status":"research-preview","summary":"The reviewed procedures connect policy, retained snapshots and dependency-ordered test recovery. Management-plane recovery independent of normal production identity remains unverified in this evidence set.","dimensions":{"maturity":{"score":3,"confidence":"low","rationale":"Stages 1–3: SLA scheduling and retention are explicit; lock modes and quorum prerequisites are documented; the vSphere test plan specifies resources, networks and boot order. No management-plane recovery or independent-identity rehearsal credit is established here.","sourceIds":["r-policy","r-lock","r-plan","r-test"]},"innovation":{"score":3,"confidence":"low","rationale":"SLA-managed copies, protected retention and a usable recovery-test workflow establish the shared baseline. No comparative generally available workflow difference beyond that baseline is established; this is not a novelty ranking.","sourceIds":["r-policy","r-lock","r-test"]},"breadth":{"score":4,"confidence":"low","rationale":"Whole-machine and granular recovery plus database protection meet stages 1–3. The recovery-plan procedure adds an alternate target and priority-ordered startup, meeting stage 4. A complete management-plane and production-return workflow is not established.","sourceIds":["r-platform","r-plan","r-test"]},"ecosystem":{"score":2.4,"confidence":"low","rationale":"Multiple enterprise workload families establish stage 2. The SLA GraphQL API earns the documented management-API refinement. A complete API-specific authentication and permission boundary was not verified in these cited pages, so that separate criterion receives no credit.","sourceIds":["r-platform","r-policy"],"refinement":{"base":2,"evidence":[{"criterion":"management-api","rationale":"The developer page supplies GraphQL policy queries and mutations for the scoped RSC platform.","sourceIds":["r-policy"]}]}},"governance":{"score":4,"confidence":"low","rationale":"Retention policy and role isolation establish stages 1–2. Retention-lock quorum approval and indexed cluster-audit documentation of actor-attributed administrative changes establish stage 3. Audit export and documented archive/mode boundaries meet stage 4. The versioned audit source redirects to sign-in; no governed emergency workflow is established.","sourceIds":["r-policy","r-role","r-lock","r-cluster-audit"]},"operations":{"score":4,"confidence":"low","rationale":"SLA policy examples and indexed official recovery-plan/test procedures establish stages 1–3. Indexed recovery information explicitly lists result states, report download and the cleanup action, establishing stage 4. Sign-in redirects prevent fresh authenticated verification; full management-plane-to-production return is not established.","sourceIds":["r-policy","r-plan","r-test","r-result","r-perform"]}},"constraints":["RSC/CDM policy and vSphere orchestration are assessed together; separate SaaS, identity, vault and simulation products are not assumed included.","Rubrik retention-lock documentation in this source set is versioned 9.0. Confirm mode behavior against the deployed CDM release; it is not a claim that 9.0 is the latest release.","No production restore, destructive retention change or performance benchmark was executed.","Non-immutable archive destinations have a different loss boundary; retention lock does not establish clean data.","Some Rubrik operator pages redirected to sign-in. Recovery actions were checked through indexed official documentation excerpts; current authenticated documentation was not accessed. This access and freshness limit reduces all Rubrik confidence ratings to low."],"sources":[{"id":"r-policy","title":"Rubrik: SLA Domains","url":"https://developer.rubrik.com/Rubrik-Security-Cloud-API/Data-Protection/SLA-Domains/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-lock","title":"Rubrik: retention-locked SLA Domains","url":"https://docs.rubrik.com/en-us/9.0/ug/saas/retention_locked_sla_domain.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-plan","title":"Rubrik: vSphere recovery plan","url":"https://docs.rubrik.com/en-us/saas/saas/creating_disaster_rp_vsphere.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-test","title":"Rubrik: test failover","url":"https://docs.rubrik.com/en-us/saas/saas/tests_for_disaster_recovery_failover.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-result","title":"Rubrik: recovery results and cleanup","url":"https://docs.rubrik.com/en-us/saas/saas/recovery_information.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-platform","title":"Rubrik: data protection scope","url":"https://www.rubrik.com/products/data-protection","accessedAt":"2026-09-21","kind":"product"},{"id":"r-role","title":"Rubrik: roles","url":"https://docs.rubrik.com/en-us/saas/saas/common/rsc_roles.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-audit","title":"Rubrik: user audit log","url":"https://docs.rubrik.com/en-us/9.0/sg/security_guide/user_audit_log.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-perform","title":"Rubrik: performing disaster recovery (indexed official procedure)","url":"https://docs.rubrik.com/en-us/saas/saas/performing_disaster_recovery.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"r-cluster-audit","title":"Rubrik CDM 9.0: cluster audits and syslog export (indexed documentation)","url":"https://docs.rubrik.com/en-us/9.0/sg/security_guide/rubrik_cluster_audits.html","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"cohesity-dataprotect","cohort":"enterprise-backup-recovery","edition":"Cohesity self-managed DataProtect; separate FortKnox, NetBackup, Cloud Protection Service and RecoveryAgent not included","asOf":"2026-09-21","status":"research-preview","summary":"Public materials establish core backup, recovery and access controls. Gated operator documentation prevents a defensible rating of the detailed operating procedures for this specific deployment.","dimensions":{"maturity":{"score":1,"confidence":"low","rationale":"DataProtect describes DataLock retention controls, establishing stage 1. The self-managed operator guide returned HTTP 403, so its retention prerequisites and isolated-test sequence were not verified. Higher anchors remain uncredited; Cloud Protection Service procedures are not substituted.","sourceIds":["c-product","c-docs"]},"innovation":{"score":3,"confidence":"low","rationale":"The DataProtect page establishes an integrated backup, protected-snapshot and restoration workflow matching the contemporary baseline. No comparative evidence establishes a differentiated workflow; related RecoveryAgent and FortKnox claims are outside this edition.","sourceIds":["c-product"]},"breadth":{"score":3,"confidence":"low","rationale":"DataProtect describes whole-VM and granular file recovery plus enterprise database protection, establishing stages 1–3. Alternate-target and ordered-plan documentation for this exact scope was not verified; adjacent orchestration is excluded.","sourceIds":["c-product","c-vm"]},"ecosystem":{"score":2,"confidence":"low","rationale":"Multiple VM, database and storage integrations establish stage 2. The general developer portal includes separate cloud-service APIs; a management endpoint and permission boundary for the scoped self-managed edition were not verified, so stage 3 receives no partial credit.","sourceIds":["c-api","c-vm"]},"governance":{"score":2,"confidence":"low","rationale":"DataLock retention policy and role-based administration establish stages 1–2 in product documentation. The broader data-security page describes quorum, but its precise self-managed deployment scope and audit procedure were not established; stage 3 receives no partial credit.","sourceIds":["c-product","c-security"]},"operations":{"score":null,"confidence":"low","rationale":"A public product description is not an executable backup-to-recovery procedure. The self-managed operator documentation was inaccessible; SaaS procedures would evaluate a different edition, so operator enablement remains unknown.","sourceIds":["c-docs","c-product"]}},"constraints":["Documentation catalog distinguishes self-managed DataProtect, Cloud Protection Service and NetBackup. Their capabilities are not combined.","The documentation host returned HTTP 403 during direct access; indexed descriptions and product pages cannot establish detailed operator safeguards.","Low-confidence ratings establish described capability only. No customer deployment, support portal or lab benchmark was accessed.","FortKnox and RecoveryAgent remain catalog context outside the scored bundle."],"sources":[{"id":"c-product","title":"Cohesity: DataProtect","url":"https://www.cohesity.com/platform/dataprotect/","accessedAt":"2026-09-21","kind":"product"},{"id":"c-security","title":"Cohesity: data security controls","url":"https://www.cohesity.com/solutions/data-security/","accessedAt":"2026-09-21","kind":"product"},{"id":"c-docs","title":"Cohesity: documentation catalog","url":"https://docs.cohesity.com/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c-api","title":"Cohesity: developer portal","url":"https://developers.cohesity.com/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c-vm","title":"Cohesity: virtual-machine protection","url":"https://www.cohesity.com/solutions/virtual/","accessedAt":"2026-09-21","kind":"product"}]},{"vendor":"veeam-data-platform","cohort":"enterprise-backup-recovery","edition":"Veeam Data Platform Premium: Backup & Replication 13, Veeam ONE and Recovery Orchestrator 13 with a supported hardened repository","asOf":"2026-09-21","status":"research-preview","summary":"The public guides describe repository constraints, isolated recovery testing and restoration of the backup configuration. Recovery authority still depends on separately managed identities, credentials and infrastructure.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Backup job and repository procedures establish stages 1–2, and isolated orchestrated testing establishes stage 3. Configuration database restoration earns six tenths toward stage 4. An explicit rehearsal without the production identity service is not established.","sourceIds":["v-job","v-hard","v-plan","v-control","v-order","v-lab"],"refinement":{"base":3,"evidence":[{"criterion":"management-recovery","rationale":"The configuration restore guide documents recovery to the same or another backup server, including backup selection and database restoration.","sourceIds":["v-control"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"Documented backup, hardened retention and restore verification establish the shared baseline. Orchestration, isolated tests and threat scanning do not alone prove a generally available difference beyond contemporary peers.","sourceIds":["v-job","v-hard","v-test","v-plan"]},"breadth":{"score":4,"confidence":"low","rationale":"Whole-machine and granular restoration plus application protection establish stages 1–3. Orchestrator documents alternate target environments and explicit dependency-aware group processing order, establishing stage 4. Complete validated production return after management-plane loss is not established by this source set.","sourceIds":["v-edition","v-how","v-plan","v-order"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Multiple workload/storage integrations meet stages 1–2. The documented management API identifies bearer authentication, allowed roles and forbidden-access responses, establishing stage 3. A bounded external SOC event handoff is not established by this evidence set.","sourceIds":["v-edition","v-api","v-how"]},"governance":{"score":3,"confidence":"medium","rationale":"Repository retention and assigned backup/security roles establish stages 1–2. Four-eyes approval and its Authorization Events history establish stage 3. Exportable audit evidence is not established here, so stage 4 is not claimed.","sourceIds":["v-hard","v-four","v-api"]},"operations":{"score":3,"confidence":"medium","rationale":"Job creation and documented restore APIs meet stages 1–2. Orchestrator and SureBackup describe repeatable isolated testing with configured targets, meeting stage 3. The cited overview does not establish the complete cleanup procedure needed for stage 4.","sourceIds":["v-job","v-how","v-plan","v-test","v-lab"]}},"constraints":["Premium includes the scoped orchestration components; Data Cloud, Kasten and separate identity products are excluded.","Repository hardening requires supported infrastructure and credential handling; immutability is not a property of every arbitrary backup destination.","Veeam explicitly says four-eyes authorization does not protect infrastructure after compromise of the backup server itself.","API restore coverage differs by endpoint and workload; the cited VBR API guide limits certain file restores to agent-managed objects.","No measured RTO, data-loss guarantee or malware-detection rate is inferred from documentation."],"sources":[{"id":"v-edition","title":"Veeam: Data Platform editions","url":"https://www.veeam.com/products/veeam-data-platform.html","accessedAt":"2026-09-21","kind":"product"},{"id":"v-hard","title":"Veeam: hardened repository","url":"https://helpcenter.veeam.com/docs/vbr/userguide/hardened_repository.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-plan","title":"Veeam: Recovery Orchestrator overview","url":"https://helpcenter.veeam.com/docs/vro/userguide/overview.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-test","title":"Veeam: SureBackup","url":"https://helpcenter.veeam.com/docs/vbr/userguide/surebackup_recovery_verification.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-control","title":"Veeam: configuration database recovery","url":"https://helpcenter.veeam.com/docs/vbr/userguide/vbr_config_restore.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-four","title":"Veeam: four-eyes authorization","url":"https://helpcenter.veeam.com/docs/vbr/userguide/four_eyes_authorization.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-api","title":"Veeam: backup API permissions","url":"https://helpcenter.veeam.com/references/vbr/13/rest/1.3-rev2/tag/Backups/index.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-how","title":"Veeam: API workflow and restore boundaries","url":"https://helpcenter.veeam.com/references/vbr/13/rest/1.3-rev2/tag/SectionHowTo/index.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-job","title":"Veeam: creating backup jobs","url":"https://helpcenter.veeam.com/docs/vbr/userguide/backup_job_console.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-order","title":"Veeam: recovery group processing order","url":"https://helpcenter.veeam.com/docs/vro/userguide/setting_group_order.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v-lab","title":"Veeam: lab-group dependencies","url":"https://helpcenter.veeam.com/docs/vro/userguide/creating_lab_groups.html","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"commvault-cloud-recovery","cohort":"enterprise-backup-recovery","edition":"Commvault software 11.42 backup and recovery with supported Storage Lock plus Air Gap Protect and cloud-based Cleanroom Recovery","asOf":"2026-09-21","status":"research-preview","summary":"The documented workflow covers protection plans, immutable-storage constraints and ordered cleanroom recovery. Storage tier and control-plane dependencies are explicit and must be included in the evaluation.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Plans define scheduling/retention, Storage Lock documents irreversible settings and capacity constraints, and cleanroom preparation defines isolation and dependency order: stages 1–3. Recovery of the control plane earns six tenths. An explicit independent-production-identity rehearsal is not established.","sourceIds":["m-plan","m-lock","m-clean","m-control"],"refinement":{"base":3,"evidence":[{"criterion":"management-recovery","rationale":"The recovery procedure restores the control plane in a restricted recovery state before workloads are recovered.","sourceIds":["m-control"]}]}},"innovation":{"score":3,"confidence":"low","rationale":"Policy-managed backups, protected copies and cleanroom restoration establish the integrated contemporary baseline. Cleanroom branding and orchestration alone are not comparative proof of a workflow difference beyond it.","sourceIds":["m-plan","m-lock","m-recover"]},"breadth":{"score":5,"confidence":"low","rationale":"Whole-workload and granular data recovery plus application protection establish stages 1–3. The cleanroom workflow adds alternate destinations, ordered groups, management-plane recovery, explicit validation and migration-to-production steps, meeting stages 4–5 within the named components. This rates documented breadth, not measured success.","sourceIds":["m-product","m-clean","m-recover","m-control","m-validate","m-return"]},"ecosystem":{"score":2.4,"confidence":"low","rationale":"Enterprise workload integrations establish stage 2. REST access-token documentation establishes a management API. The selected sources do not connect a concrete endpoint to its required permissions, so the separate API-boundary criterion remains uncredited.","sourceIds":["m-product","m-api","m-role"],"refinement":{"base":2,"evidence":[{"criterion":"management-api","rationale":"The official current API guide documents bearer access tokens for Commvault REST requests.","sourceIds":["m-api"]}]}},"governance":{"score":2.6,"confidence":"medium","rationale":"Retention and role/entity associations establish stages 1–2. The administrative audit operation list earns six tenths toward stage 3. An independent-approval procedure for sensitive changes was not verified in these scoped sources.","sourceIds":["m-plan","m-role","m-audit"],"refinement":{"base":2,"evidence":[{"criterion":"audit-trail","rationale":"The audit documentation explicitly lists retention changes, deletion attempts, role changes and other administrative operations.","sourceIds":["m-audit"]}]}},"operations":{"score":5,"confidence":"medium","rationale":"Backup-plan creation and cleanroom procedures establish stages 1–3. Separate validation and cleanup instructions establish stage 4. Control-plane restoration and the documented production-migration sequence establish stage 5, including re-enabling backups and manual resource cleanup. Cloud-provider transfer procedures remain required dependencies; no live recovery drill was performed.","sourceIds":["m-plan","m-clean","m-recover","m-control","m-validate","m-return","m-cleanup"]}},"constraints":["Air Gap Protect and Cleanroom Recovery are explicitly included components, not assumed features of every Commvault subscription.","The support matrix distinguishes frequent/infrequent access from archive; archive does not support the same cleanroom and threat-scan operations.","Storage Lock is irreversible and can increase capacity consumption; it is not exercised against production by this educational evaluation.","A documented production-migration step does not remove the need for application-owner approval and incident-response validation.","Public SaaS recovery instructions are used only for the named cloud cleanroom/control-plane component; unrelated SaaS backup products are not credited."],"sources":[{"id":"m-plan","title":"Commvault: backup plans","url":"https://documentation.commvault.com/11.42/software/understand_and_create_backup_plans.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-lock","title":"Commvault: Storage Lock","url":"https://documentation.commvault.com/11.42/software/configuring_storage_lock_01.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-clean","title":"Commvault: cleanroom preparation","url":"https://documentation.commvault.com/11.42/software/get_started_with_cloud_based_cleanroom_recovery.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-recover","title":"Commvault: cleanroom recovery workflow","url":"https://documentation.commvault.com/11.42/software/recover_to_cloud_based_cleanroom_site.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-control","title":"Commvault: recovered control plane","url":"https://documentation.commvault.com/saas/recover_to_cleanroom.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-tier","title":"Commvault: Air Gap Protect support","url":"https://documentation.commvault.com/saas/supported_workloads_and_features_for_air_gap_protect.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-role","title":"Commvault: role boundaries","url":"https://documentation.commvault.com/11.42/commcell-console/roles_overview.html?view=saas","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-audit","title":"Commvault: recorded administrative operations","url":"https://documentation.commvault.com/11.42/software/commvault_console_operations_recorded_by_audit_trail_01.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-api","title":"Commvault: REST API access tokens","url":"https://documentation.commvault.com/11.42/software/access_tokens_for_rest_apis_01.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-product","title":"Commvault: Backup and Recovery","url":"https://www.commvault.com/platform/backup-and-recovery","accessedAt":"2026-09-21","kind":"product"},{"id":"m-validate","title":"Commvault: validate recovered resources","url":"https://documentation.commvault.com/11.42/software/validate_resources_recovered_to_your_cleanroom_site.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-return","title":"Commvault: migrate cleanroom recovery to production","url":"https://documentation.commvault.com/11.42/software/migrate_recovered_resources_and_configurations_from_cleanroom_to_production.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"m-cleanup","title":"Commvault: clean up cloud cleanroom resources","url":"https://documentation.commvault.com/11.42/software/clean_up_recovered_resources_for_cloud_based_cleanroom_site.html","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"compromised-admin","name":"Production administrator compromised","description":"A synthetic incident removes normal production administration while a separate recovery operator must reach retained copies.","priorities":["governance","maturity"],"questions":["Which identity can shorten retention or disable protection?","Can recovery access survive loss of the production identity service?"]},{"id":"minimum-service","name":"Restore the minimum viable service","description":"Recover a small database-backed application and validate a business transaction instead of counting powered-on machines.","priorities":["operations","breadth"],"questions":["Which identity, network, key and application dependencies must return first?","What observable transaction establishes that this recovery worked?"]},{"id":"capacity-retention","name":"Retention with a finite storage budget","description":"A small team estimates changed data, immutable retention and temporary recovery resources before committing to a policy.","priorities":["maturity","governance"],"questions":["Which retention choices are irreversible and how does that affect capacity?","What additional cloud transfer, retrieval or recovery-compute charges apply?"]}],"researchNotes":["First edition on 2026-09-21. This is a new baseline, not historical momentum.","Four named bundles form one enterprise recovery cohort. Scores apply to documented workflows in scope; wider vendor portfolios and acquired products are not merged into scores.","Public sources establish documented controls, not independently measured efficacy, recovery speed or successful incident outcomes. Confidence is at most medium; product-page inferences are low.","Every stage is cumulative. Supported lower anchors retain their credit when a higher prerequisite is unverified. A cell remains unknown only when the first in-scope anchor cannot be established.","Shared decimal refinements credit only distinct parts of the next anchor. Criteria total ten tenths at each base; no jitter, hidden vendor weight or arbitrary tie-breaking is used.","The contemporary baseline already includes policy-managed backup, protected copies and restoration. No offering earns an innovation differentiation claim from AI branding, immutable storage or an orchestration feature alone.","Cohesity operator-documentation access returned HTTP 403 in this pass. Product evidence supports lower capability anchors; self-managed operating procedures remain unknown and are not replaced with Cloud Protection Service procedures.","Source-linked review decisions and limitations are recorded in docs/research/2026-09-21-market-expansion/resilience.md."]},"changes":[]}]},"unassessed":[{"slug":"dell-powerprotect-cyber-recovery","name":"Dell PowerProtect Cyber Recovery","company":"Dell Technologies","profileUrl":"/landscape/vendors/dell-powerprotect-cyber-recovery/"},{"slug":"druva-data-security-cloud","name":"Druva Data Security Cloud","company":"Druva","profileUrl":"/landscape/vendors/druva-data-security-cloud/"},{"slug":"acronis-cyber-protect-cloud","name":"Acronis Cyber Protect Cloud","company":"Acronis","profileUrl":"/landscape/vendors/acronis-cyber-protect-cloud/"},{"slug":"hycu-r-cloud","name":"HYCU R-Cloud","company":"HYCU","profileUrl":"/landscape/vendors/hycu-r-cloud/"}]}