Logo
Logo

Backup Is Commoditised. Recovery Is Not.

Vriti Magee | Sep 29th 2026

IMG_2026-09-29-104417.jpeg

"The chatbot, filed under Action. Restored to Romance." Illustrated by DALL·E

A chatbot announced that Love Actually is an action movie. It had lost its data, not its confidence.

At Cloud Field Day 26, Clumio, a Commvault company, built a fictitious movie app called Clumio Final Cut, broke it three ways, and fixed it three ways. When the data beneath the app disappeared, the AI assistant didn't fall silent. On screen, it declared Love Actually an action movie. The commentary from the stage:

"It's not. We all know that."

Midway through came a blunt line about the industry:

"backup is commoditized at this point, right? Everybody provides backups."

The harder question followed:

"Can you recover from any sort of event?"

Three Bad Days

The first failure hit DynamoDB. A code push goes wrong, whether by human or AI agent, and a few partitions are corrupted. Each has a different last known good moment: 1:01pm for one tenant, 2:10pm for another. The traditional route, is a full restore per partition, cherry-picking the good pieces back, then deleting the temporary tables. We can all agree it's:

"recovery hell"

Clumio's route is to pick a point in time per partition and restore only what was damaged, in place. Then:

"there is no step two"

The second hit S3 and a RAG pipeline. The objects vanish, and the vectors built on them are left:

"pointing nowhere"

Hence the film-buff chatbot with a new opinion on romantic comedies. Traditionally that is five steps: restore the whole bucket, recompute the vectors, retire the old store, clean up the old bucket, repoint the model. On screen it was a point in time, the affected objects, and a click. At small scale, the presenters put it at under a minute.

The third hit Apache Iceberg. Someone edits the table structure, dashboards break, and one chart files every film under comedy. An Iceberg-aware restore preserves the metadata and manifests and rolls the table back to source, so nobody rebuilds the dashboards.

Three failures with the same shape. Fewer steps, no reconfiguration, no temporary tables or buckets to tidy afterwards.

🛠️ Architectural View: Two Engines

Two mechanisms sit underneath, and the difference matters.

Backtrack restores at object, prefix or bucket level. In its versioning-based mode it moves no data. Paired with Secure Vault, it works from versions tracked in an air-gapped account. Clumio tracks hundreds of millions of object changes an hour. The rationale is scale: at billions of objects, native versioning is:

"pretty much useless"

Secure Vault is the isolated, air-gapped copy, held outside the customer's own security sphere. It does move data, so it is not instant. Where you restore to is part of the design. After a cyber event, the guidance was a brand new AWS account. After a regional outage, a different region. Clumio cites tests to tens of billions of objects, and S3 scale proven to 70 to 80 billion objects in a single bucket, with the same promised for Google Cloud Storage.

Recovery by Prompt

The most interesting thread was where recovery is heading. Some customers still treat it as code, scripted through APIs and Terraform. The newest trend Clumio sees among customers is agentic: push a prompt to an LLM, and it orchestrates the entire restore.

It fits another number from the session. On average, a user logs into the console once every 37 days, though the presenters allowed for some selection bias in their customer base. A product judged by how rarely you look at it is rare praise in enterprise software.

Clumio is plain about where it stands:

"AI-enabled applications, not AI-native applications."

It works at the data layer, which is a sensible place to stand while everything above it changes.

Closing Reflections

Every application has a bad afternoon in its future. In the DynamoDB scenario, the bug was reported at 2:30pm. Everything before that was recoverable history. The chatbot doesn't care whether the cause was malice or a mistaken deploy. It simply gets the film wrong.

Backup is what you buy. Recovery is what you do at 2:30pm, with the app down, the chatbot improvising and the internet taking notes.

🔍 Links for Further Reference

Watch the full Cloud Field Day 26 sessions:

Recent Articles