SaaS- Commvault Cloud Metallic AI
Cyber resilience for hybrid cloud data protection is a critical part of any data protection strategy. Commvault Cloud delivers enterprise-proven data security and recovery as a simple, cloud-native solution. Built with proven technology, Commvault Cloud provides data security and cyber recovery that mitigates data loss risks and emerging cyber threats.
Features
- Backup and Recovery for Hypervisors & Kubernetes
- Backup and Recovery for Database applications
- Backup and Recovery for File & Object
- Backup and Recovery for Endpoint & Active Directory
- Backup and Recovery for Microsoft 365
- Backup and Recovery for Microsoft Dynamics 365
- Backup and Recovery for Salesforce
- Backup and Recovery for Cloud storage
- Data Management features include eDiscovery, Archiving & Data Replication
- Cyber Resilience features include Threatwise, Clean Room & AirGap Protect
Benefits
- Broad, single-solution coverage across critical workload.
- Ultimate, layered security for ransomware protection.
- Advanced automation, AI, and threat intelligence.
- Proven performance with fast, granular, and at-scale recoveries.
- Air-gapped, isolated, and immutable data copy.
- Future-proof scalability, from 1TB to 1,000+.
- Reduced management overhead, rapid deployment.
- Unique hybrid cloud storage flexibility for performance and value.
- Commvault GUARDiAN Master Accredited Engineer Access, Training & Demo Functionality.
- Support from GUARDiAN Commvault Master accredited support technicians.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 9 9 1 4 1 7 4 9 4 4 6 0 7
Contact
PRESIDIO SOLUTIONS UK LIMITED
Procurement UK
Telephone: 07717405567
Email: procurementuk@presidio.com
About your service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
- Backup and Recovery Reporting Software
Archiving
- Email Archiving Software
- File and Other Archiving Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- NO Constraints as software supports most of the services
- System requirements
-
- Network Connectivity & Bandwidth availability
- Network Gateway Server
User support
- Email or online ticketing support
- Yes
- Support response times
- Support including questions is targeted between 1 hour for critical severity to 24 hours for Low severity
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- Accessibility testing conducted with screen reader users (JAWS, NVDA) and voice recognition tools. Feedback from assistive technology users was incorporated to improve navigation, readability, and responsiveness.
- Onsite support
- Yes
- Support levels
-
Support is included within the SaaS cost, with the following Targetted Response times
Critical Severity - 1 Hour
High Severity - 2 Hours
Medium Severity - 4 Hours
Low Severity - 24 Hours - Support available to third parties
- No
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- Presidio provides comprehensive onboarding through online training, user documentation, and guided setup via the management console. Optional onsite workshops are available at extra cost. Customers receive step‑by‑step deployment guidance, policy templates, and integration support for SaaS apps, endpoints, and cloud workloads. A dedicated Customer Success team ensures smooth adoption and alignment with compliance requirements.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Customers can export data directly via the management console or API. Bulk export tools support large datasets, with options for CSV, ODF, JSON, and XML formats. Presidio ensures secure transfer and provides guidance for migration to alternative platforms. No additional cost is incurred for standard data extraction.
- End-of-contract process
- Customers can export data directly via the management console or API. Bulk export tools support large datasets, with options for CSV, ODF, JSON, and XML formats. Persidio ensures secure transfer and provides guidance for migration to alternative platforms. No additional cost is incurred for standard data extraction.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Commvault provides an HTML frontend called Command Center which is supported on a number of different web browsers.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- Not Applicable
- API
- Yes
- What users can and can't do using the API
- Commvault REST APIs represent operations that are performed in the CommCell Console. This is implemented on HTTP protocol for common programming language & tools. REST API also available for Datto so can be used for reporting
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Administrators can customise backup policies, retention schedules, reporting dashboards, and role‑based access controls. Customisation is performed via the web console or API. Only authorised administrators can apply changes, ensuring governance and compliance. Buyers can tailor policies to meet organisational, regulatory, and workload‑specific requirements
Scaling
- Independence of resources
- Commvault’s multi‑tenant architecture isolates customer environments, ensuring workloads are logically separated. Elastic scaling automatically provisions additional compute and storage resources as demand increases. Performance is continuously monitored, with proactive load balancing across regions to maintain SLA compliance and prevent service degradation.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Commvault provides detailed metrics including backup success/failure rates, storage consumption, deduplication efficiency, recovery point objectives (RPO), recovery time objectives (RTO), and performance trends. Administrators can monitor workload health, policy compliance, and SLA adherence through dashboards and reports.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Commvault
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data directly through the Commvault management console or via secure API calls. Bulk export tools support large datasets, with options for CSV, ODF, JSON, and XML formats. Exports are encrypted in transit using TLS 1.2+ and can be scheduled or performed on demand. Administrators control access to export functions, ensuring compliance and governance.
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Service Credits of 10% are offered for less than 99.999% availability, and 25% Services Credits is offered for less that 99% availability
- Approach to resilience
-
The Commvault Metallic Service is hosted in Microsoft Datacentres on Azure infrastructure and the physical security is provided by Microsoft.
The following information is supplied by Microsoft and the full document can be accessed here https://docs.microsoft.com/en-us/azure/security/fundamentals/physical-security
Microsoft designs, builds, and operates datacentres in a way that strictly controls physical access to the areas where your data is stored. Microsoft understands the importance of protecting your data and is committed to helping secure the datacentres that contain your data. We have an entire division at Microsoft devoted to designing, building, and operating the physical facilities supporting Azure. This team is invested in maintaining state-of-the-art physical security.
Azure keeps your data durable in two locations. You can choose the location of the backup site. In both locations, Azure constantly maintains three healthy replicas of your data.
Database availability
Azure ensures that a database is internet accessible through an internet gateway with sustained database availability. Monitoring assesses the health and state of the active databases at five-minute time intervals. - Outage reporting
-
Outages are communicated through the HTML Interface dashboard.
And through Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Commvault requires user authentication via MFA, identity federation with enterprise identity providers, or username/password credentials. MFA options include SMS, authenticator apps, or hardware tokens. Federation allows seamless single sign‑on (SSO) integration. All authentication traffic is encrypted using TLS 1.2+.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Security threat detection and response, zero trust authentication, zero trust access, virtual air-gap, immutability.
https://metallic.io/trust - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
At a minimum, the change control process includes the following steps:
• All requests are logged
• Undergoes a preliminary review and is appropriately prioritized
• Authorized by appropriate personnel
• Requirements to implement the change are identified and analyzed
• Dependencies resulting from the change are identified
• Impact analysis to the current environment or business units assessed
• Change approach is identified and reviewed
• Change is tested in a controlled environment
• Acceptance of the change tested and approved
• Implementation and release of the change into production
• Change process from initiation to post-implementation is documented - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Any vulnerability or threat detected through automated or manual scans must be remediated within the timeframes specified below:
Critical - A week from detection date. If vulnerability is detected on a critical server/device, it should be remediated within 24- 48 hours.
High - Within 2 weeks from Within a week if it is a Page Information Technology Vulnerability Management Policy 3 detection date critical server/device.
Medium - Condition based remediation Medium vulnerabilities are not required to be remediated immediately. However, Information Security Team may upgrade the Severity level of vulnerability to High as necessary to ensure appropriate action is taken. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Cloud Alerts are standard Commvault Alerts that syncs to cloud.comvault.com. The Cloud Alert feature is the framework for the Event Monitoring service. Cloud Alerts for event monitoring based around the following purposes:
• Detect when Commvault is operating outside of the normal based on historic data and smart algorithms.
• Detect anomalies using machine learning/AI based code integrated into Commvault’s core.
• Detect thresholds, conditions and standard events that occur within Commvault.
• Detect CommCell events or exceeded thresholds
• Detect parameter configuration changes in the Commvault software its protected data
• Detect failures on CommCell and Job based entities. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Commvault’s Incident Response Plan includes the following processes:
• To protect information and information systems.
• To provide reporting incidents step-by-step.
• To detect attacks or intrusions.
• Restoration process to mitigate effects of incidents and services.
• Closeout process for reporting and documenting lessons learned.
Every incident is different, Guidelines are flexible and unique shaped by the incident. Our IRP documents information about responding to incidents that can be used regardless of hardware platform or operating system. It describes the five stages of incident handling, with focus on preparation, follow-up, including reporting guidelines requirements with defined roles and responsibilities - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Commvault offers a 30‑day free trial with full functionality, including backup, recovery, reporting, and policy management. The trial allows buyers to evaluate performance, compliance, and usability before committing to subscription.
- Link to free trial
- Available on request or via Commvault’s website trial registration page.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- A-Lign Compliance and Security inc
- ISO/IEC 27001 accreditation date
- Monday 1 September 2025
- What the ISO/IEC 27001 doesn’t cover
-
ISO/IEC 27001 provides assurance that our organisation operates a certified Information Security Management System (ISMS); however, it does not guarantee absolute security or address every security requirement in isolation.
Specifically, ISO/IEC 27001 does not:
Guarantee that security incidents will not occur, as it focuses on risk management rather than eliminating risk.
Prescribe specific technical security controls, tools, or configurations, allowing organisations to select controls based on risk and business context.
Validate the effectiveness of real-time operational security or prevent human error or misconfiguration.
Fully address sector-specific or regulatory requirements such as UK GDPR, NCSC Cloud Security Principles, or public sector data classification requirements.
Define customer responsibilities within shared responsibility models for cloud services.
To address these limitations, we supplement our ISO/IEC 27001-certified ISMS with service-specific security controls, alignment to relevant public-sector guidance, technical security standards, and ongoing operational monitoring and assurance. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Monday 26 January 2026
- What the ISO 9001 doesn’t cover
-
Scope limitation: Our QMS certification applies to the provision of cloud service resale and associated support activities delivered from our UK based operations team. It does not cover the design, development, or operation of the SaaS platforms themselves (e.g., Druva, CommVault, Veeam, Mimecast), as these are owned and managed by third-party vendors.
Non-applicable requirements: ISO 9001 clause 8.3 (Design & Development) is not applicable, as we do not design or develop software or cloud platforms; we act solely as a reseller and provide configuration and support services.
Third-party exclusions: Vendor-managed infrastructure, data centres, and security operations for the SaaS products are outside our certified QMS. These remain under the control of the respective vendors’ management systems.
Geographic exclusions: Our certification covers UK-based operations only; offshore vendor facilities and global support centres are not within scope. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 54eff155-3b4c-4a81-9914-e6886f4fac17
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 7b547487-b146-4ebf-8af3-2f843e6350b2
- Other security certifications
- Yes
- Any other security certifications
- NHS DSP Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-