Platform overview
Why Clumio
Most backup tools were built before the cloud and retrofitted afterward. Clumio went the other way.
Four design decisions that traditional vendors can't add later: an air-gapped vault outside your cloud account, a serverless engine that scales without provisioning, an agentless control plane that needs nothing in your account beyond an IAM role, and a delivery model where new capabilities ship without your involvement. The rest of this page is what those four enable.
Architecture
Vault
Pricing
The architecture
Four design decisions you can't retrofit
Most vendors describe themselves with adjectives. The four bets below are decisions Clumio made at the start, and they shape every capability on the platform. Competitors can’t paper over them with a marketing update.
A dedicated, air-gapped vault outside your cloud account
Backups live in an immutable, logically isolated vault that Clumio runs in a separate cloud account and network. Each customer gets a dedicated vault with no shared credentials and no lateral movement between tenants. When your cloud account is compromised or wiped, the vault remains logically isolated from the affected environment.
Clean recovery workflows for ransomware, credential compromise, accidental deletion, and AI misfire.
A serverless, elastic engine
The ingest and recovery engine is serverless. It scales horizontally without provisioning, runs in parallel for high throughput, and has been pushed to tens of billions of objects on object stores and hundreds of billions of records on databases. No capacity planning for peak demand, and no idle infrastructure to manage.
Ingest and recovery performance that scales with your data, not against it. Near-zero RPO where the workload supports it.
An agentless, true-SaaS control plane
Nothing to deploy in your account beyond an IAM role (or service account on GCP). No agents, no proxies, no appliances, no upgrades. Clumio operates the platform end to end and ships new capabilities continuously, without your involvement.
No backup infrastructure to deploy or maintain, no upgrade planning, no version sprawl. Protection that turns on with a permission grant.
A platform that stays out of your way
Most backup tools become another system to manage: another dashboard, another support queue, another upgrade cycle. Clumio doesn’t ask for that ongoing attention. A console you can drive without becoming a backup specialist, proactive support that auto-resolves most issues, and platform updates that ship without your involvement.
Set protection up once and forget it's running. Engineering time stays on engineering work.
How we compare
Native cloud tools, traditional backup, and Clumio side by side
A direct read across the three options most teams evaluate. Native cloud tooling is convenient but lives in your cloud account. Traditional backup vendors retrofitted for cloud bring agents and infrastructure with them. Clumio sits outside your account and runs without customer-managed backup infrastructure.
| Dimension | Native cloud tools | Traditional backup vendors | Clumio |
| Where backups live | Same cloud account as source data | Customer-managed appliance, often same blast radius | Dedicated air-gapped vault outside your cloud, per customer |
| Infrastructure to run | None for service; storage costs land on you | Agents, proxies, media servers, appliances; ongoing version management | None beyond an IAM role (or service account on GCP); fully managed SaaS |
| Recovery granularity | Full resource only (whole bucket, whole table) on most services | Image-level for EC2 and RDS. Object-level on S3 in newer products, bucket-level in older ones. Limited or no DynamoDB support. | S3 / GCS: object · prefix · bucket | DynamoDB: record · partition · table | RDS / Aurora: record (Archive) · instance | EC2 / EBS: file · volume · instance |
| In-place recovery | Restore creates a new resource; manual cutover required | Typically out-of-place; in-place options are workload-specific and rare | Backtrack on S3 and DynamoDB: original resource, no rewiring. Other workloads create a new resource on restore. |
| RPO | PITR on RDS and DynamoDB up to 35 days. Snapshot-only on S3 and EBS. | Schedule-bound; sub-hour RPO often requires premium add-ons | S3 / DynamoDB: 15-min event-driven | RDS: continuous PITR via Clumio-managed AWS backups | EC2 / EBS: hourly to daily |
| Scale ceiling | Service-specific. Each service has its own scale limits. | Bound by the appliance or proxy fleet | S3 / GCS: tens of billions of objects per bucket | DynamoDB: hundreds of billions of records | EBS / RDS: TB-class per resource |
| Ransomware posture | Vulnerable if cloud account credentials are compromised | Depends heavily on deployment topology; often shares credentials | Vault is outside the account, immutable, separate credentials |
| Pricing model | Pay-per-service, storage costs compound silently | License + storage + infrastructure; opaque | Consumption, transparent, no commit, no infrastructure line item |
| Cloud coverage | Single cloud only | Multi-cloud, uneven depth | AWS and GCS today, more clouds on the roadmap |
Proof
What customers do with it
The architectural argument is interesting in a slide deck. These numbers are what it produces in production.
Atlassian
Protects petabyte-scale S3 environments
Clumio helps Atlassian protect large-scale S3 environments, including buckets containing tens of billions of objects, while improving recovery performance and reducing backup costs versus prior tooling.
Duolingo
Reduced DynamoDB backup costs 70%+
Across a 150 TB+ DynamoDB environment, Clumio helped Duolingo reduce backup costs while extending compliance retention and simplifying large-scale recovery operations.
Global Financial Services Firm
700 TB recovered in ~2 hours
A large global financial services institution recovered 700 TB in approximately 2 hours while supporting DORA requirements. Recovery ran 19x faster than native approaches at 40–50% lower cost using auditable air-gapped recovery workflows.
Independent Benchmark
24x faster than a Gartner MQ leader
220 TB of S3 data seeded for the test. Clumio finished in 4 hours; the incumbent took 95 hours for the same workload.
Cox Automotive
Standardized cloud backup
Enterprise-scale AWS estate consolidated on Clumio. Compliance posture improved, backup management consolidated across teams, accounts, and regions onto one platform.
xyzt.ai
Cut AWS backup costs 66.7%
AWS backup workloads moved to Clumio. Spend dropped two-thirds after the switch, and snapshot sprawl with its operational overhead went with it.
Coverage
Works with your cloud stack.
The architectural primitives apply across every supported workload: air-gapped vault, immutable storage, API-first management. Recovery mechanics (granularity, in-place options, RPO floors) vary by workload; the workload pages spell out the specifics.
Common questions
Platform FAQ
Questions from engineering and platform teams evaluating Clumio.
Are platform capabilities available for every workload?
The architectural primitives apply universally: air-gapped storage, immutable storage, API and Terraform coverage. Recovery mechanics are workload-specific. Point-in-time recovery ships in different forms across S3, DynamoDB, RDS, and EBS. Backtrack (in-place restore) is S3 and DynamoDB only. Threat scan, Instant Access, and Granular Record Retrieval are workload-specific too. The workload pages have the per-workload details.
Is cross-region restore available across cloud providers?
Cross-region restore is in-cloud, not cross-cloud. AWS sources can restore to a different AWS region on supported workloads (S3, DynamoDB, RDS). Cross-region restore for GCS is on the roadmap. Cross-cloud restore (AWS to GCP, or back) is not supported and is not planned.
How does air-gapped storage differ from immutable storage?
Two different properties that often get conflated. Immutable storage prevents deletion or modification of objects before their retention expires (S3 Object Lock is an example). Air-gapped storage lives in a separate environment with no network path back to the source account. A backup can be one without the other. S3 Object Lock gives you immutable storage that still sits inside your account and shares its credentials, so it’s not air-gapped. A traditional backup appliance can be air-gapped but still mutable if the operator has direct access to the underlying storage. Clumio’s vault is both: backups live in a separate Clumio-managed cloud account (air-gapped), and the storage layer itself enforces immutability for the retention window (immutable).
Can I manage Clumio entirely through Terraform?
Yes. The Clumio Terraform provider covers policies, protection rules, account and region connections, role bindings, and most day-to-day platform configuration. New API surfaces typically ship with Terraform resources within a release of the API itself. The provider is published on the Terraform registry as ClumioCorp/clumio. A typical setup uses one Terraform module per AWS account, with shared policies and protection rules defined at the organization level.
Where does Clumio store backup data?
Backup data lives in Clumio-managed cloud accounts that are separate from your AWS or Google Cloud accounts. Each customer gets a dedicated vault: no shared storage, no shared credentials, no lateral movement between tenants. By default, backups stay in the same cloud region as the source. You can opt into cross-region storage at the policy level on supported workloads (S3, DynamoDB, RDS) for added durability. Cross-region adds the relevant AWS data transfer cost.
What compliance certifications does Clumio hold?
Clumio maintains an ISO/IEC 27001:2022 certified Information Security Management System and an ISO/IEC 27701:2019 certified Privacy Information Management System, supporting compliance with GDPR and other privacy regulations. Clumio is also SOC 2 Type II attested, with HIPAA Security Rule controls published as an appendix to the SOC 2 report; a Business Associate Agreement (BAA) is available for customers with HIPAA requirements.
Clumio uses FIPS 140-3 validated cryptographic modules, to enable the platform to be suitable for storing ePHI, PCI-protected information, personal data, and other sensitive data.
See the Commvault Trust Center for additional details.
Related resources
Go deeper
Blog posts, guides, and case studies for teams evaluating the platform in detail.
Blog
How the Move to Clumio Delivered 66.7% Savings on AWS Backups
xyzt.ai replaced native AWS snapshots with Clumio and cut backup spend by two thirds. A direct walkthrough of what changed, why it worked, and what the numbers looked like before and after.
Whitepaper
Secure, Immutable, Air-Gapped Data Protection with Clumio
A technical deep-dive into how the Clumio vault architecture works — dedicated per-customer isolation, immutability enforcement, and why the air-gap model outperforms account-resident backup for ransomware recovery.
Solution Brief
Cyber Resilience for Applications, Databases, and Data Lakes on AWS
How Clumio protects S3, DynamoDB, and Iceberg across a complete AWS environment — with a single API surface, consistent recovery semantics, and no backup infrastructure to manage.
GET STARTED
Start protecting critical data in minutes.
Free tier includes one workload. No credit card. Browse workloads to start.