Commvault Systems
Documents
| Document | Verified | Changed | Evidence |
|---|---|---|---|
| Trust center | snapshot | ||
| Subprocessor list vanta | snapshot | ||
| Data processing addendum | snapshot | ||
| Privacy policy | snapshot | ||
| Terms | snapshot |
Subprocessors
9 third parties, 1 affiliate. CSV · Atom
| Name | Purpose | Location | Listed since |
|---|---|---|---|
| Amazon Web Services (AWS) | Applicable for SaaS workloads only; Cloud storage provider In case of cloud storage relevant AWS entity will be determined depending on the configuration choices made by the Customer. List of AWS sub-processors: https://aws.amazon.com/compliance/sub-processors/ | US/Other | |
| Clumio | Commvault has acquired Clumio’s highly scalable cloud data protection technology to support critical cloud data and workloads in AWS, including but not limited to Amazon Simple Storage Service (AWS S3) and Amazon DynamoDB. See our press release [here](https://community.commvault.com/news-events-7/commvault-acquires-clumio-and-extends-cloud-resilience-capabilities-on-aws-9660). For more information on Clumio, see [here](https://www.commvault.com/platform/clumio). Please refer to the following link for the list of Sub-processors engaged by Clumio to support its cloud data protection services, see [here](https://trust.commvault.com/resources?s=c2vh2clsdbhnv5ct4m69oh&name=clumio-sub-processors-list); Integration with Commvault Cloud | US | |
| Egnyte | Applicable for Threatwise only; Security and compliance tools for cloud content | US | |
| Google Cloud Platform | Cloud infrastructure and storage for Commvault SaaS workloads (e.g., Google Workspace Backup); Google Cloud Platform is used to host and store data processed as part of certain Commvault SaaS offerings, including Google Workspace Backup. Commvault manages and controls the deployment of the SaaS dataplane within GCP infrastructure. The specific GCP entity and region used depends on customer configuration and data residency preferences. GCP's list of authorized sub-processors can be found at: https://cloud.google.com/terms/subprocessors | US/Other | |
| Microsoft Corporation | Commvault uses Microsoft for the following services/purposes: - Cloud storage - Security analytics (Sentinel) - Technical support platform - Azure OpenAI Service In case of cloud storage, the relevant Microsoft entity will be determined depending on the configuration choices made by the Customer. EU affiliate: Microsoft Ireland Operations Limited List of Microsoft sub-processors: https://servicetrust.microsoft.com/ViewPage/PrivacyDataProtection | US/Other | |
| Oracle Corporation | Applicable for SaaS workloads only; Cloud storage provider In case of cloud storage relevant Oracle entity will be determined depending on the configuration choices made by the Customer. EU affiliate: Oracle EMEA Ltd List of Oracle affiliates: https://www.oracle.com/corporate/oracle-affiliates.html | US/Other | |
| Persistent Systems Malaysia Sdn Bhd | Mandarin customer support and technical assistance | Malaysia | |
| Satori | Commvault has acquired Satori, a leading data security platform that provides real-time data access controls, visibility, and compliance across cloud and hybrid environments. See our press release [here](https://www.commvault.com/blogs/commvault-closes-acquisition-of-satori). For more information on Satori, see [here](https://satoricyber.com). Please refer to the following link for the list of Sub-processors engaged by Satori to support its cloud data protection services, see [here](https://trust.commvault.com/resources#6903894103d3cf6d6f6b70d4); Integration with Commvault Cloud | US | |
| Triple C Cloud Computing Ltd. | Applicable for Threatwise only; Colocation services | Israel |
Listed as a subprocessor by (2)
Purposes as each company states them.
- Clumio by Commvault clumio.com Commvault staff
TierPoint tierpoint.com Products & Services
Security record
What public security catalogs list for Commvault Systems, in their words.
Known exploited vulnerabilities
2 vulnerabilities in Commvault Systems's software that CISA lists as exploited in the wild.
| CVE | Product | Vulnerability | Listed |
|---|---|---|---|
| CVE-2025-34028 | Command Center | Commvault Command Center Path Traversal Vulnerability | evidence |
| CVE-2025-3928 | Web Server | Commvault Web Server Unspecified Vulnerability | evidence |
Changes
None since tracking began.