{
 "edition": "2026-10-03",
 "years": [
  2016,
  2017,
  2018,
  2019,
  2020,
  2021,
  2022,
  2023,
  2024,
  2025,
  2026
 ],
 "ai_labels": [
  [
   "infra",
   "AI for protection / protecting AI"
  ],
  [
   "stack",
   "AI platform stack"
  ],
  [
   "ops",
   "AI-assisted operations"
  ],
  [
   "agents",
   "Agent openness"
  ]
 ],
 "index_weights": {
  "cap": 35,
  "cred": 20,
  "safety": 20,
  "ai": 10,
  "integ": 10,
  "mom": 5
 },
 "domains": [
  {
   "key": "virtual",
   "label": "Virtual and physical servers",
   "weight": 12
  },
  {
   "key": "apps",
   "label": "Databases and applications",
   "weight": 12
  },
  {
   "key": "recovery",
   "label": "Recovery",
   "weight": 14
  },
  {
   "key": "cyber",
   "label": "Cyber resilience",
   "weight": 14
  },
  {
   "key": "storage",
   "label": "Storage efficiency and targets",
   "weight": 10
  },
  {
   "key": "retention",
   "label": "Long-term retention and tape",
   "weight": 6
  },
  {
   "key": "dr",
   "label": "Replication and DR",
   "weight": 10
  },
  {
   "key": "security",
   "label": "Security and compliance",
   "weight": 8
  },
  {
   "key": "platforms",
   "label": "New-platform support (VMware exit)",
   "weight": 8
  },
  {
   "key": "scale",
   "label": "Management at scale and automation",
   "weight": 6
  }
 ],
 "platforms": [
  {
   "key": "veeam",
   "name": "Veeam Data Platform (Backup & Replication / ONE)",
   "short": "Veeam",
   "kind": "product",
   "group": "leader",
   "since": 2016,
   "archetype": "Portable recovery platform",
   "grade": "A",
   "driver": "C",
   "mix": {
    "V": 7,
    "C": 87,
    "M": 7,
    "U": 0,
    "P": 0
   },
   "idx": 0.07,
   "domains": {
    "virtual": {
     "2016": 3,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "apps": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 4,
     "2020": 4,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "recovery": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4,
     "2020": 4.5,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "cyber": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 2,
     "2020": 3,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "storage": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "retention": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 4,
     "2020": 4,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "dr": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "security": {
     "2016": 2,
     "2017": 2,
     "2018": 2,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 3,
     "2022": 3,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 3.5
    },
    "platforms": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "scale": {
     "2016": 3,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 46 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. ONE12 GA /12.1 (2023-02-14 /2023-12-05): Separate ONE build clock;12 RTM2023-01-30 is not GA Evidence A. [one](https://www.veeam.com/kb4357)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; conference and release announcements are the direction sources. No open-roadmap-tracker reference score is awarded. ONE12 GA /12.1 (2023-02-14 /2023-12-05): Separate ONE build clock;12 RTM2023-01-30 is not GA Evidence A. [one](https://www.veeam.com/kb4357)"
    ],
    [
     "Say-do",
     3.5,
     "Recorded ledger: 27 items; 20 shipped, 2 partial, 0 slipped, 5 pending, 0 dropped. Mature dated prospective cohort: 21; 14 documented within 12 calendar months, 1 later than 12 months, 6 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. ONE 12 feature document (2023-02-14 GA and document footer): Official REST API for infrastructure/jobs/protected workloads and database plug-in protection status; jobs calendar; optional client/web/API action auditing to Windows event log; certificate/CAC authentication and lockdown mode. Microsoft 365 monitoring is separately labelled SaaS-adjacent. Monitoring API does not prove backup-policy execution. Evidence A. [onewn12](https://www.veeam.com/veeam_one_12_0_whats_new_wn.pdf); [one12UpdateKB](https://www.veeam.com/kb4705)"
    ],
    [
     "Lifecycle stability",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: not found. Grade C where current contract/EOS boundaries remain unresolved. 2019-10-29 N2WS blog: N2WS states it announced separation from former parent Veeam that week and would operate independently under its co-founders. Exact sale closing day, consideration and government rationale are not supplied by this primary blog. Evidence C. [n2wsSeparation19](https://n2ws.com/blog/customer-centric-mission)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2018-01-16: Acquired N2WS for USD 42.5 million cash. N2WS\u2019s October 2019 primary statement separately establishes its later separation; exact disposal close day and consideration remain unresolved. Evidence C. [n2ws](https://www.veeam.com/company/press-release/veeam-acquires-n2ws-to-deliver-industry-leading-availability-and-protection-for-aws-cloud.html); [n2wsSeparation19](https://n2ws.com/blog/customer-centric-mission)"
    ],
    [
     "Purchase constraints",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Observed licensing: B&R / Availability Suite / Backup Essentials described in FAQ; exact contemporary Data Platform tier price list not found Evidence A. [license](https://www.veeam.com/faq.html)"
    ],
    [
     "Channel and access",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: extract. VCSP: Service-provider programme with rental licensing and provider services; programme-count claims not independently verified Evidence A. [vcsp](https://www.veeam.com/become-a-partner/service-providers.html?ad=menu-partners-become)"
    ],
    [
     "Owner stability",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Private-equity control plus secondary ownership changes; acquisitions are not treated as feature GA. 2020-03-02: Insight Partners closed acquisition, valuation about $5bn; preserves earlier verified row. 2024-12-04: Announced $2bn secondary shareholder offering at $15bn valuation, led by TPG; not $2bn primary operating funding. Evidence A. [owner](https://www.veeam.com/company/press-release/insight-partners-completes-acquisition-of-cloud-data-management-leader-veeam-for-a-value-of-5-billion-dollars.html); [secondary](https://www.veeam.com/company/press-release/veeam-the-worlds-1-leader-in-data-resilience-welcomes-new-investors-with-a-dollar15-billion-valuation.html)"
    ],
    [
     "Cost of staying supported",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Support/upgrade constraints, distinct from licence-expiry restoration: not found. 2019-10-29 N2WS blog: N2WS states it announced separation from former parent Veeam that week and would operate independently under its co-founders. Exact sale closing day, consideration and government rationale are not supplied by this primary blog. Evidence C. [n2wsSeparation19](https://n2ws.com/blog/customer-centric-mission)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     1,
     "Scored 2026-10-03 from the accepted cutoff fact base. Standalone vendor extract tool works without an installed B&R instance; chain/extent and account-download conditions remain. Backup export: Vendor extract tool works independently of installed B&R on Windows/Linux. Separate download requires registered account. Evidence A. [extract](https://helpcenter.veeam.com/docs/vbr/userguide/extract_utility.html?ver=13)"
    ],
    [
     "Stack coupling",
     1,
     "Scored 2026-10-03 from the accepted cutoff fact base. Software protects several hypervisors and uses disk/object targets; no vendor appliance prerequisite evidenced. Observed by 2026-10-01: 13.1: native Citrix XenServer/XCP-ng/Sangfor plus UHAPI Platform9/VergeOS; Windows/Linux and AIX/Solaris agents are distinct components. Observed by 2026-10-01: 13.1: managed immutable NFS application repository; expanded object archive targets and scale-out options. Evidence A. [wn131](https://www.veeam.com/veeam_backup_13_1_whats_new_wn.pdf); [rn131](https://helpcenter.veeam.com/rn/veeam_backup_13_1_release_notes.html)"
    ],
    [
     "Hardware / cloud coupling",
     0.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Windows/Linux independent extract deployment reduces mandatory service dependence. Backup export: Vendor extract tool works independently of installed B&R on Windows/Linux. Separate download requires registered account. Evidence A. [extract](https://helpcenter.veeam.com/docs/vbr/userguide/extract_utility.html?ver=13)"
    ],
    [
     "Skills and tooling coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. VCSP: Service-provider programme with rental licensing and provider services; programme-count claims not independently verified Evidence A. [vcsp](https://www.veeam.com/become-a-partner/service-providers.html?ad=menu-partners-become)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. VCSP: Service-provider programme with rental licensing and provider services; programme-count claims not independently verified Evidence A. [vcsp](https://www.veeam.com/become-a-partner/service-providers.html?ad=menu-partners-become)"
    ],
    [
     "Multi-tenancy and self-service",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 13.1: REST port 443, malware/HA/repository control and any-to-vSphere/Hyper-V Instant Recovery APIs; AI actions require workflow approval. Evidence C. [wn131](https://www.veeam.com/veeam_backup_13_1_whats_new_wn.pdf)"
    ],
    [
     "API and infrastructure-as-code",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. REST is broad; VeeamHub Ansible is community sample code and Terraform is third-party, limiting IaC credit. Observed by 2026-10-01: 13.1: REST port 443, malware/HA/repository control and any-to-vSphere/Hyper-V Instant Recovery APIs; AI actions require workflow approval. Ansible / support status: VeeamHub veeamhub.veeam is community sample code; VeeamHub explicitly disclaims Veeam R&D development/official QA. Not vendor-supported product IaC. Evidence A. [wn131](https://www.veeam.com/veeam_backup_13_1_whats_new_wn.pdf); [ansible](https://github.com/VeeamHub/veeam-ansible); [hub](https://github.com/veeamhub)"
    ],
    [
     "Skills and certification",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. VMCE announced November 2013 for January 2014 launch, with later confirmation. Certification: VMCE announced 2013-11-19 for 2014-01 launch; later vendor retrospective confirms January-2014 EMEA launch. Evidence A. [vmce](https://www.veeam.com/company/press-release/new-technical-training-and-certification-programs.html); [vmcelaunch](https://www.veeam.com/fr/company/press-release/veeam-annonce-150-pour-cent-de-croissance-sur-le-marche-des-grandes-entreprises-en-region-emea.html)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Veeam is expanding recovery portability and cyber controls around Backup & Replication and ONE. The record links Proxmox, malware analysis and approved AI actions to delivered versions. Product-specific archive formats and private-equity ownership remain dependencies despite the independent extract tool.",
   "report": "reports/01-veeam.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 1,
     "2026": 1
    },
    "ops": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 1,
     "2020": 1,
     "2021": 1,
     "2022": 1,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 5
    },
    "agents": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    }
   },
   "ai_basis": {
    "infra": "2023-12-05; GA: 12.1 inline entropy analysis uses an ML model; suspicious-file index analysis and YARA are separate mechanisms. Evidence A. [wn121](https://www.veeam.com/veeam_backup_12_1_whats_new_wn.pdf)",
    "stack": "2025-05-27 announcement / 2025-11-19 v13.0.1 documentation; announced \u2192 documented release: ONE Intelligence uses RAG and ONE APIs for environment/report analysis; Deep Data Analysis Agent queries saved reports. Price follows product edition; separate AI add-on price not established. RAG over product/report metadata; no general AI service over all backed-up business data. Evidence A. [onepreview](https://community.veeam.com/blogs-and-podcasts-57/sneak-peek-what-s-coming-in-veeam-one-s-monitoring-analytics-v13-10598); [onewn13](https://www.veeam.com/veeam_one_13_whats_new_wn.pdf)",
    "ops": "2026-07-29; 13.1 GA: Intelligence investigates job logs, forecasts capacity and executes workflow-approved operations/recoveries; support-case comment/diagnostic actions documented. Workflow-approved actions and recoveries meet the acting-assistant anchor. Evidence A. [wn131](https://www.veeam.com/veeam_backup_13_1_whats_new_wn.pdf)",
    "agents": "End-2022 checkpoint: 11: backup-server REST API for job/infrastructure administration, in addition to Enterprise Manager API. 11 REST administration shipped2021, carried into the2022 checkpoint. Evidence A. [wn11](https://www.veeam.com/veeam_backup_11_0_whats_new_wn.pdf)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 4 recorded announcement rows; 0 GA/shipped matches, 1 preview/early/limited at announcement, 0 partial, 4 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. B&R/ONE only; VDC MCP and Kasten/Alcion/Securiti acquisitions do not earn core AI GA credit."
  },
  {
   "key": "commvault",
   "name": "Commvault Cloud (Complete Data Protection / HyperScale X)",
   "short": "Commvault",
   "kind": "product",
   "group": "leader",
   "since": 2016,
   "archetype": "Hybrid recovery orchestration",
   "grade": "A",
   "driver": "C",
   "mix": {
    "V": 20,
    "C": 80,
    "M": 0,
    "U": 0,
    "P": 0
   },
   "idx": 0.2,
   "domains": {
    "virtual": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "apps": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 4,
     "2022": 4,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "recovery": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4.5,
     "2026": 4.5
    },
    "cyber": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 4.5,
     "2026": 4.5
    },
    "storage": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "retention": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "dr": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "security": {
     "2016": 2,
     "2017": 2,
     "2018": 2,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 4,
     "2026": 3.0
    },
    "platforms": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 3.5
    },
    "scale": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 21 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Commvault Cloud brand / Arlie (2023-11-08): Announced; rebrand and assistant do not establish software GA Evidence A. [cloud](https://www.commvault.com/news/introducing-commvault-cloud-powered-by-metallic-ai)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; Cloud and AI press announcements used. No open-roadmap-tracker reference score is awarded. Commvault Cloud brand / Arlie (2023-11-08): Announced; rebrand and assistant do not establish software GA Evidence A. [cloud](https://www.commvault.com/news/introducing-commvault-cloud-powered-by-metallic-ai)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 29 items; 7 shipped, 9 partial, 0 slipped, 13 pending, 0 dropped. Mature dated prospective cohort: 17; 2 documented within 12 calendar months, 0 later than 12 months, 15 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. 11.38 changes (Release-family clock; first GA day unresolved): Arlie job/audit metadata analysis; access-token refresh scopes; archive combined tier forced on with micro-pruning; Web Console retirement. Later11.38.35/.37 changes are not backdated to initial11.38. Evidence A. [change38](https://documentation.commvault.com/11.40/software/changes_in_innovation_release_11_38.html)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2.5-year LTS policy coexists with two-month innovation support and platform/control-plane migrations. 2025-06-15 / 2026-06-15: Version-specific end-of-support: 11.28/2022E and 11.20 end 2025-06-15; 11.32/2023E ends 2026-06-15. Other innovation/LTS lines have different endpoints. Control-plane migration, 11.40: Changes table says Windows installation is no longer available for CommServe/Web Server/Command Center. 11.24 clients cannot communicate with11.40-or-later CommServe; upgrade clients first. V4 dedupe databases must be converted toV5. Existing Windows deployment/upgrade support must follow its separate policy; no forced shutdown date inferred. Evidence A. [old](https://documentation.commvault.com/v11/software/deprecated_releases.html); [change40](https://documentation.commvault.com/hitachivantara/11.40/software/changes_in_long_term_support_release_11_40.html)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Bundle/consumption and metric conversion changes documented; no invented currency price rise. 2023-11-08: Four Commvault Cloud bundles announced; exact public list prices not found 2025-11-12: Cloud-native Unity capabilities and consumption pricing reported generally available in AWS/Azure marketplaces; broader Unity rollout has separate later-2025/early-2026 timing. 2026-01 guide: Expired self-managed licence preserves recovery access while stopping new backup/archive/replication; perpetual use persists at the version available when maintenance expires. SaaS expiry follows separate terms; eDiscovery lacks restore-only mode. Evidence A. [cloud](https://www.commvault.com/news/introducing-commvault-cloud-powered-by-metallic-ai); [cloud25](https://www.commvault.com/news/shift-2025-cloud-native-data-protection); [unity25](https://www.commvault.com/news/new-era-in-enterprise-resilience-commvault-cloud-unity-platform-release); [licenseJan26](https://documentation.commvault.com/2023e/software/files/pdf/commvault-complete-license-guide.pdf)"
    ],
    [
     "Purchase constraints",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Metric non-coexistence and edition/add-on constraints; no forced minimum quantity assumed. 2026-01 guide; historical mixed-metric boundary2020-10: Per-socket and per-VM metering cannot coexist in one CommCell. Grandfathered pre-October2020 deployments have separate mixed-metric rules. Licence-unit weights are not currency list prices. Evidence A. [licenseJan26](https://documentation.commvault.com/2023e/software/files/pdf/commvault-complete-license-guide.pdf)"
    ],
    [
     "Channel and access",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: tracks. Ansible: Vendor-owned ansiblev2 collection installs as commvault.ansible via Galaxy; CVPySDK dependency. Legacy module requires v11 SP16+ and WebConsole. Live Galaxy download count not exposed in opened shell. Evidence A. [ansible](https://github.com/Commvault/ansiblev2); [ansibleold](https://github.com/Commvault/ansible); [galaxy](https://galaxy.ansible.com/ui/repo/published/commvault/ansible/)"
    ],
    [
     "Owner stability",
     0.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Vendor is the acquirer in these recorded transactions; no merger of Commvault ownership recorded. 2024-10-01: Clumio closed: FY2025 filing reports final cash consideration $44.311 million after closing adjustment 2025-08-28 blog: Satori acquisition reported closed; exact legal completion day not stated by this blog. Data/AI governance acquisition is separate from backup-product GA. Evidence A. [filing](https://ir.commvault.com/static-files/c431cc43-eae1-4fe5-bc75-aeffe1616e33); [satori](https://www.commvault.com/blogs/commvault-closes-acquisition-of-satori)"
    ],
    [
     "Cost of staying supported",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Support/upgrade constraints, distinct from licence-expiry restoration: LTS: annual line, 2.5-year life, monthly maintenance for first two years. Innovation: monthly line, two-month life; request-form distribution.. 2026-05-18 complaint filed: Imbert v. Commvault Systems, Inc., No. 3:26-cv-05654 (D.N.J.), Document 1: proposed securities class action alleges misleading ARR-growth disclosures for purchasers April 29, 2025\u2013January 26, 2026. Opened filing copy establishes the complaint, not class certification, liability or its outcome at cutoff; live docket remains unverified. Evidence C. [securitiesComplaint26](https://www.dandodiary.com/wp-content/uploads/sites/893/2026/05/2479000-2479335-https-ecf-njd-uscourts-gov-doc1-119123939031-1.pdf)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Self-managed recovery remains after expiry; an independent archive reader is still unverified. Documented licence-expiry / conversion rights, January2026: Self-managed recovery remains available with infrastructure online and retained backups; expired subscription stops new jobs/updates. SaaS and eDiscovery exceptions apply. Changing licence metric can require subscription or signed forfeiture; this guide is not the executed customer contract. Evidence A. [licenseJan26](https://documentation.commvault.com/2023e/software/files/pdf/commvault-complete-license-guide.pdf)"
    ],
    [
     "Stack coupling",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. CommServe metadata recovery: MediaExplorer retrieves DR backups from tape/disk; CloudTestTool used for cloud. This recovers product databases, not an open backup-data format. Evidence C. [dr](https://documentation.commvault.com/v11/commcell-console/retrieval_of_disaster_recovery_dr_backups_from_storage.html?view=saas)"
    ],
    [
     "Hardware / cloud coupling",
     1,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. CommServe metadata recovery: MediaExplorer retrieves DR backups from tape/disk; CloudTestTool used for cloud. This recovers product databases, not an open backup-data format. Evidence C. [dr](https://documentation.commvault.com/v11/commcell-console/retrieval_of_disaster_recovery_dr_backups_from_storage.html?view=saas)"
    ],
    [
     "Skills and tooling coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Ansible: Vendor-owned ansiblev2 collection installs as commvault.ansible via Galaxy; CVPySDK dependency. Legacy module requires v11 SP16+ and WebConsole. Live Galaxy download count not exposed in opened shell. Evidence A. [ansible](https://github.com/Commvault/ansiblev2); [ansibleold](https://github.com/Commvault/ansible); [galaxy](https://galaxy.ansible.com/ui/repo/published/commvault/ansible/)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Ansible: Vendor-owned ansiblev2 collection installs as commvault.ansible via Galaxy; CVPySDK dependency. Legacy module requires v11 SP16+ and WebConsole. Live Galaxy download count not exposed in opened shell. Evidence A. [ansible](https://github.com/Commvault/ansiblev2); [ansibleold](https://github.com/Commvault/ansible); [galaxy](https://galaxy.ansible.com/ui/repo/published/commvault/ansible/)"
    ],
    [
     "Multi-tenancy and self-service",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 11.46 July global encryption policies at storage-pool level; elastic AuxCopy/synthetic-full/verification/DDB compute limited to cloud targets. Arlie Recover AzureVM-only with pause/stop and audit logs. Evidence C. [newsletter1146](https://documentation.commvault.com/11.46/software/newsletter_for_new_features_in_innovation_release_11_46.html)"
    ],
    [
     "API and infrastructure-as-code",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Official Terraform and Ansible plus REST; registry downloads are not unique users or a support SLA. Terraform registry observation2026-10-01: Commvault/commvault: 138,874 total downloads; current version1.2.18, published2026-09-15. Publisher source repository: https://github.com/Commvault/terraform-provider-commvault. Counts are registry requests/downloads, not distinct installations; vendor support obligations are separate. Ansible registry observation2026-10-01: commvault.ansible:69,810 downloads; latest1.0.2; deprecated=false. Registry count is not distinct users or a vendor SLA. Evidence A. [regapi](https://registry.terraform.io/v1/providers/Commvault/commvault); [galaxyapi](https://galaxy.ansible.com/api/v3/plugin/ansible/content/published/collections/index/commvault/ansible/)"
    ],
    [
     "Skills and certification",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Practitioner/Specialist/Professional/Expert structure launched 2026-05-11. Named certification structure launched2026-05-11: Commvault Cloud Practitioner, Specialist, Professional and Expert: coursework, hands-on labs and assessments. No direct progression from former tracks; old credentials remain tied to retired product releases. Announcement is the new structure launch, not the first-ever Commvault certification. Evidence A. [certLaunch26](https://www.commvault.com/blogs/introducing-new-readiverse-courses-and-certification-programs)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Commvault is combining hybrid protection with cleanroom recovery and agent interfaces. Versioned notes document Proxmox recovery, threat scans and bounded Arlie actions, while several wider AI promises remain unresolved. Upgrade and licence conversion rules add operational complexity even though self-managed restoration survives expiry.",
   "report": "reports/02-commvault.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 3,
     "2025": 3.5,
     "2026": 3.5
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0.5,
     "2024": 0.5,
     "2025": 0.5,
     "2026": 0.5
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0.5,
     "2024": 0.5,
     "2025": 3,
     "2026": 4.5
    },
    "agents": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 3,
     "2026": 3.5
    }
   },
   "ai_basis": {
    "infra": "11.40 release family; first feature GA unresolved; Documented protectionML: Threat Scan uses ML to detect encryption in individual files and reduce false positives, plus Azure VM scans at restore and Azure Cleanroom threat analysis. This is protectionAI, distinct from Arlie and from backup of AI workloads. Accuracy is a vendor assertion; no independent efficacy measure provided. Evidence A. [newsletter1140](https://documentation.commvault.com/11.40/software/newsletter_for_new_features_in_long_term_support_release_11_40.html)",
    "stack": "2023-11-08 / 2026-04-13; Announced: Arlie backend Azure OpenAI announced; AI Studio promises custom/built-in agents using MCP. Models, deployment topology and separate inclusion price unresolved. Announced backend; not AI Studio GA. Evidence A. [shift23](https://ir.commvault.com/news-releases/news-release-details/introducing-first-true-cloud-platform-cyber-resilience-hybrid); [ai](https://ir.commvault.com/news-releases/news-release-details/commvault-introduces-innovations-advance-secure-controlled)",
    "ops": "2026-07; Documented available: Arlie Recover runs cyber-recovery plans, AzureVM only. Threat Scan/Cleanroom/AirGap prerequisites, pause/stop and step audit logs. Exact RBAC/action consent and log retention require feature guide. AzureVM-only plans, pause/stop and audit; universal affirmative approval contract incomplete. Evidence A. [newsletter1146](https://documentation.commvault.com/11.46/software/newsletter_for_new_features_in_innovation_release_11_46.html)",
    "agents": "Current observation 2026-10-01; Public implementation documented; precise GA unresolved: Official repo supports job suspend/resume/resubmit/kill and plan/storage/user visibility. OAuth requires 11.42.27+, or access/refresh tokens plus MCP client secret; native secure keyring. Vendor-hosted instructions are separate. Published implementation exceeds an announcement, but explicit first-GA confirmation is incomplete; below GA4. Evidence C. [mcprepo](https://github.com/Commvault/commvault-mcp-server); [mcpdocs](https://documentation.commvault.com/11.42/software/commvault_mcp_server.html?view=saas); [mcphost](https://documentation.commvault.com/11.46/software/deploy_commvault_mcp_server.html)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 13 recorded announcement rows; 2 GA/shipped matches, 0 preview/early/limited at announcement, 3 partial, 8 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "cohesity",
   "name": "Cohesity DataProtect / NetBackup (separate product lines)",
   "short": "Cohesity",
   "kind": "product",
   "group": "leader",
   "since": 2016,
   "archetype": "Merged protection portfolio",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 20,
    "C": 73,
    "M": 7,
    "U": 0,
    "P": 0
   },
   "idx": 0.2,
   "domains": {
    "virtual": {
     "2016": 4,
     "2017": 4,
     "2018": 4,
     "2019": 4.5,
     "2020": 4.5,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "apps": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4.5,
     "2020": 4.5,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "recovery": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "cyber": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 1,
     "2020": 1,
     "2021": 1,
     "2022": 3.5,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "storage": {
     "2016": 4,
     "2017": 4,
     "2018": 4,
     "2019": 4.5,
     "2020": 4.5,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "retention": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "dr": {
     "2016": 2,
     "2017": 2,
     "2018": 2,
     "2019": 3,
     "2020": 3,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "security": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 4,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "platforms": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 3.5
    },
    "scale": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 28 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Data Cloud 7.2 (2024-07-24): OAuth 2.0 Cluster API; IBM FlashSystem incremental protection; NetApp SnapDiff v3; MongoDB zone-sharding support. Kubernetes additions remain adjacent scope. Evidence A. [p72](https://www.cohesity.com/blogs/cohesity-data-cloud-7-2-release/)"
    ],
    [
     "Roadmap transparency",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; release blogs and press announcements used. No open-roadmap-tracker reference score is awarded. Data Cloud 7.2 (2024-07-24): OAuth 2.0 Cluster API; IBM FlashSystem incremental protection; NetApp SnapDiff v3; MongoDB zone-sharding support. Kubernetes additions remain adjacent scope. Evidence A. [p72](https://www.cohesity.com/blogs/cohesity-data-cloud-7-2-release/)"
    ],
    [
     "Say-do",
     3,
     "Recorded ledger: 30 items; 12 shipped, 9 partial, 0 slipped, 9 pending, 0 dropped. Mature dated prospective cohort: 15; 3 documented within 12 calendar months, 0 later than 12 months, 12 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. Data Cloud 7.1 (2023-10-05 release blog; first GA unresolved): TLS 1.3/native PKI renewal; HashiCorp Vault KMS; AHV instant mass restore; EDB PostgreSQL. Evidence A. [docaff01b3a](https://www.cohesity.com/blogs/cohesity-data-cloud-7-1-release-details/)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. DataProtect generally 18 months; NetBackup console retirement clocks conflict across languages. 2025-07 policy revision: DataProtect major releases generally supported 18 months; minor/patch upgrade may be required. Hardware EOS/EOL and SaaS terms differ; do not apply this policy to NetBackup. NetBackup11.1/11.2 versioned notes: Japanese11.1 notes retire Java administration console but retain BARUI/older-version support. English11.2 index labels retirement from11.2. Conflicting version clocks retained. Evidence A. [doc2b2c9f72](https://www.cohesity.com/content/dam/cohesity/agreements-docs/cohesity-product-life-cycle-policy.pdf); [nb111jp](https://jpn.nec.com/backup/netbackup/download/nbu111/NetBackup111_RelNotes.pdf); [nb112index](https://docs.cohesity.com/docs/netbackup/11.2/103228346-171368441-0/v172450863-171368441)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2024-12-10: Cohesity completed combination with Veritas enterprise data-protection business. This does not mean all Veritas businesses. Customer/revenue scale statements are vendor claims. Evidence C. [merge](https://www.cohesity.com/newsroom/press/cohesity-becomes-worlds-largest-data-protection-provider-after-completing-combination-with-veritas-enterprise-data-protection-business/)"
    ],
    [
     "Purchase constraints",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Current pricing: Exact DataProtect/NetBackup tiers, capacity minimums, list prices and transition terms not found Evidence A. [merge](https://www.cohesity.com/newsroom/press/cohesity-becomes-worlds-largest-data-protection-provider-after-completing-combination-with-veritas-enterprise-data-protection-business/)"
    ],
    [
     "Channel and access",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: dev. Developer ecosystem: REST, Postman and SDK links; integrations/recipes are community/best-effort and not covered by vendor support teams. Evidence A. [dev](https://developers.cohesity.com/)"
    ],
    [
     "Owner stability",
     5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Recent combination directly meets the high ownership-change anchor. 2024-12-10: Cohesity completed combination with Veritas enterprise data-protection business. This does not mean all Veritas businesses. Customer/revenue scale statements are vendor claims. Evidence A. [merge](https://www.cohesity.com/newsroom/press/cohesity-becomes-worlds-largest-data-protection-provider-after-completing-combination-with-veritas-enterprise-data-protection-business/)"
    ],
    [
     "Cost of staying supported",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Short major-line support and upgrade obligations; NetBackup policy remains separate. 2025-07 policy revision: DataProtect major releases generally supported 18 months; minor/patch upgrade may be required. Hardware EOS/EOL and SaaS terms differ; do not apply this policy to NetBackup. Evidence A. [doc2b2c9f72](https://www.cohesity.com/content/dam/cohesity/agreements-docs/cohesity-product-life-cycle-policy.pdf)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Heterogeneous nodes limited to Cohesity plus one OEM in this release; no universal appliance requirement assumed for NetBackup. DataProtect 6.5 (2020-02-28 available): vSphere I/O-filter CDP; VMware failover runbooks; SQL migration using file CBT; heterogeneous nodes limited to Cohesity plus one OEM. Evidence A. [p65](https://www.cohesity.com/blogs/cohesity-pegasus-6-5-innovation-doesnt-have-to-be-zero-sum-game/)"
    ],
    [
     "Hardware / cloud coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. APIs are not backup formats: SDK availability establishes automation access, not vendor-independent repository extraction. Evidence C. [dev](https://developers.cohesity.com/)"
    ],
    [
     "Skills and tooling coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Developer ecosystem: REST, Postman and SDK links; integrations/recipes are community/best-effort and not covered by vendor support teams. Evidence A. [dev](https://developers.cohesity.com/)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Developer ecosystem: REST, Postman and SDK links; integrations/recipes are community/best-effort and not covered by vendor support teams. Evidence A. [dev](https://developers.cohesity.com/)"
    ],
    [
     "Multi-tenancy and self-service",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: NetBackup 11.2 Helios unified management; DataProtect 7.2 OAuth2 REST access. Copilot/RecoveryAgent available; general Maestro MCP remains expected later 2026. Evidence C. [nb112](https://www.cohesity.com/blogs/netbackup-11-2/); [p72](https://www.cohesity.com/blogs/cohesity-data-cloud-7-2-release/); [doccfcce01d](https://www.cohesity.com/newsroom/press/cohesity-maestro-data-protection-recovery-and-security-intelligence/)"
    ],
    [
     "API and infrastructure-as-code",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. DataProtect Terraform best-effort contrasts with expressly supported selected NetBackup Ansible playbooks. Terraform support boundary: Vendor-owned Terraform provider targets DataPlatform6.4+; developer recipes/integrations are best-effort and excluded from Support/Field support. Registry downloads do not override this boundary. NetBackup supportedAnsible; observation2026-10-02: Official installation guide supports only specifiedVeritasOS playbooks. Repository handles provisioning, upgrades, certificates/EEBs and lists10.5\u201311.2 builds. This support statement differs from DataProtect Terraform best-effort policy; download count not published here. Evidence A. [dev](https://developers.cohesity.com/); [regapi](https://registry.terraform.io/v1/providers/cohesity/cohesity); [nbAnsibleDocs](https://docs.cohesity.com/docs/netbackup/11.1/27801100-170181151-0/v168313805-170181151); [nbAnsibleRepo](https://github.com/VeritasOS/netbackup-automation-platform/blob/main/README.md)"
    ],
    [
     "Skills and certification",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named current credentials, hands-on requirements and dated Academy launch; first-year gaps retained. Current certification structure: ProtectionAssociate DataProtect/Multicloud,ImplementationProfessional SmartFiles,ProtectionProfessional NetBackup/Appliances,SecuritySpecialist; professional badge combines three credentials. FAQ suggests6\u20139months experience, optional coursework,2-year expiry/14-day retake. Landing page instead suggests3months; record guidance difference. Modern names are not automatically the2021 names. NetBackup certification current observation2026-10-01: Cohesity Certified Protection Professional\u2013NetBackup, COH-284:105minutes,$200USD,65percent pass,2-year expiration,14-day retake; no prerequisite certification. First launch year not stated; programme rename not assumed new launch. Evidence A. [academyCertNow](https://www.cohesity.com/academy/certification/); [academyFAQNow](https://www.cohesity.com/academy/certification/certification-faq/); [cert284](https://www.cohesity.com/academy/certification/exam-vcs-284/)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Cohesity is joining two backup product lines under common management and cyber recovery services. Delivered DataProtect and NetBackup features cover databases, CDP and recovery automation, while broader Maestro and Agent Resilience timing remains open. The combined portfolio brings management and ownership transition work alongside broad workload coverage.",
   "report": "reports/03-cohesity.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 3.5
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0.5,
     "2025": 0.5,
     "2026": 0.5
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 4.5,
     "2026": 4.5
    },
    "agents": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 1.5,
     "2026": 4
    }
   },
   "ai_basis": {
    "infra": "2026-03-19; Available: Sophos malware scanning uses ML; family-specific release/version and accuracy validation pending. Evidence A. [doc429e2258](https://www.cohesity.com/newsroom/press/cyber-resilience-malware-scanning-powered-by-sophos/)",
    "stack": "2024-03-15; GA: Gaia RAG search over backup datasets; initial OneDrive corpus is adjacent SaaS scope, not proof of model/vector-database consistent backup. Initial Gaia corpus is adjacent OneDrive; do not award full on-prem backup-data GA. Evidence A. [gaia](https://www.cohesity.com/blogs/cohesity-gaia-is-available-now/)",
    "ops": "2023-05-23 / 2024-03-15; Announced integration / Gaia GA: Turing/Vertex AI promises and Gaia Azure OpenAI backend are separate clocks and implementations. Gaia SKU required for its MCP functions. RecoveryAgent acts via blueprints and optional manual pauses; mandatory approval everywhere is not established. Evidence A. [doc5fc481bf](https://www.cohesity.com/newsroom/press/cohesity-announces-partnership-with-google-cloud-to-help-organizations-unlock-the-power-of-generative-ai-and-data/); [gaia](https://www.cohesity.com/blogs/cohesity-gaia-is-available-now/); [doccfcce01d](https://www.cohesity.com/newsroom/press/cohesity-maestro-data-protection-recovery-and-security-intelligence/)",
    "agents": "2026-06-16; Available; retrospective launch year 2024: Copilot provides conversational reporting/anomaly analysis/operational actions; exact first GA/build unresolved. Gaia MCP available with RBAC/auth/audit; broad Maestro still future. Scope-specific score. Evidence C. [doccfcce01d](https://www.cohesity.com/newsroom/press/cohesity-maestro-data-protection-recovery-and-security-intelligence/)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 11 recorded announcement rows; 3 GA/shipped matches, 2 preview/early/limited at announcement, 4 partial, 4 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. Gaia initial OneDrive RAG is adjacent scope; its MCP availability does not establish broad Maestro GA."
  },
  {
   "key": "rubrik",
   "name": "Rubrik Security Cloud (data-centre protection)",
   "short": "Rubrik",
   "kind": "product",
   "group": "leader",
   "since": 2016,
   "archetype": "Backup security expansion",
   "grade": "B",
   "driver": "C",
   "mix": {
    "V": 20,
    "C": 80,
    "M": 0,
    "U": 0,
    "P": 0
   },
   "idx": 0.2,
   "domains": {
    "virtual": {
     "2016": 3,
     "2017": 3.5,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "apps": {
     "2016": 3,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "recovery": {
     "2016": 3.5,
     "2017": 4,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "cyber": {
     "2016": 1.5,
     "2017": 2.5,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3.5,
     "2022": 4,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "storage": {
     "2016": 3.5,
     "2017": 4,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "retention": {
     "2016": 2,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "dr": {
     "2016": 3,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "security": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "platforms": {
     "2016": 0,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 4
    },
    "scale": {
     "2016": 3,
     "2017": 3,
     "2018": 3.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    }
   },
   "cred": [
    [
     "Cadence",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. 13 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Ruby (2023-11-07): Announced; earliest GA not found Evidence A. [ruby](https://www.rubrik.com/company/newsroom/press-releases/23/rubrik-introduces-ruby)"
    ],
    [
     "Roadmap transparency",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; press and developer documentation used. No open-roadmap-tracker reference score is awarded. Ruby (2023-11-07): Announced; earliest GA not found Evidence A. [ruby](https://www.rubrik.com/company/newsroom/press-releases/23/rubrik-introduces-ruby)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 34 items; 6 shipped, 14 partial, 0 slipped, 14 pending, 0 dropped. Mature dated prospective cohort: 17; 2 documented within 12 calendar months, 0 later than 12 months, 15 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. RSC shared-cluster MSP capabilities (2026-09-24 early access; GA later2026 target): Tenant accounts,network connectors,cross-cluster replication. Per-tenant cryptographic isolation/customer keys still roadmap. Evidence A. [mspSep26](https://www.rubrik.com/blog/technology/26/9/msp-get-higher-value-services-without-a-dedicated-cluster-per-customer)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Major CDM releases generally 18 months; minor releases inherit major EOS per accepted lifecycle example. 2021-07-20: CDM 6.0.0: GA date from lifecycle example; feature reconstruction not found Evidence A. [life](https://www.rubrik.com/content/dam/rubrik/en/resources/policy/rubrik-end-of-life-policy.pdf)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2024-04-24: IPO priced23.5m ClassA shares at32USD; April25 trading/April29 closing targets are prospective Evidence C. [ipo](https://ir.rubrik.com/news-events/press-releases/news-details/2024/Rubrik-Announces-Pricing-of-Upsized-Initial-Public-Offering/default.aspx)"
    ],
    [
     "Purchase constraints",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. MSP zero-minimum PayGo is documented, but universal enterprise minimums and tier contracts remain unknown. 2026-03-18: MSP PayGo starts with zero minimums then contractual scale; new MSP benefit tiers and24/7 incident response live. Rubrik Verified separately planned for summer. No unit price stated. Evidence C. [mspMarch26](https://ir.rubrik.com/news-events/press-releases/news-details/2026/Rubrik-Deepens-Commitment-to-MSP-Operated-Cyber-Resilience-with-Program-and-Platform-Innovations/default.aspx)"
    ],
    [
     "Channel and access",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: table. Official automation: Python and PowerShell tools; GraphQL/REST; Task-Based REST Beta Evidence A. [dev](https://developer.rubrik.com/api-support/); [tools](https://developer.rubrik.com/SDKs-and-Tools/)"
    ],
    [
     "Owner stability",
     1,
     "Scored 2026-10-03 from the accepted cutoff fact base. IPO is not an acquisition or forced ownership merger; low owner-change risk relative to recently merged portfolios. 2024-04: SEC filing confirms IPO completed during April; exact closing day not established Evidence A. [sec](https://www.sec.gov/Archives/edgar/data/1943896/000194389624000018/rbrk-20240731.htm)"
    ],
    [
     "Cost of staying supported",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Support/upgrade constraints, distinct from licence-expiry restoration: CDM major releases: 18 months from GA; minor/patch releases inherit major EOS. Lifecycle example 6.0 EOS 2023-01-19.. 2021-09-01 settlement announcement: Commvault reports an amicable agreement resolving all outstanding patent litigation with Rubrik. Public blog does not disclose payments or licensing terms; no court finding of infringement or corresponding Cohesity outcome is inferred. Evidence C. [rubrikSettlement21](https://www.commvault.com/blogs/commvault-and-rubrik-reach-settlement-on-patent-litigation)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. API access: RSC GraphQL and CDM REST differ. Product RBAC and entitlements still apply. Evidence C. [dev](https://developer.rubrik.com/api-support/)"
    ],
    [
     "Hardware / cloud coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. API access: RSC GraphQL and CDM REST differ. Product RBAC and entitlements still apply. Evidence C. [dev](https://developer.rubrik.com/api-support/)"
    ],
    [
     "Skills and tooling coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Official automation: Python and PowerShell tools; GraphQL/REST; Task-Based REST Beta Evidence A. [dev](https://developer.rubrik.com/api-support/); [tools](https://developer.rubrik.com/SDKs-and-Tools/)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Official automation: Python and PowerShell tools; GraphQL/REST; Task-Based REST Beta Evidence A. [dev](https://developer.rubrik.com/api-support/); [tools](https://developer.rubrik.com/SDKs-and-Tools/)"
    ],
    [
     "Multi-tenancy and self-service",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: RSC GraphQL / CDM REST; Task-Based REST explicitly Beta Evidence C. [r52](https://www.rubrik.com/company/newsroom/press-releases/20/rubrik-andes-5-2-product-release); [ruby](https://www.rubrik.com/company/newsroom/press-releases/23/rubrik-introduces-ruby); [dev](https://developer.rubrik.com/api-support/)"
    ],
    [
     "API and infrastructure-as-code",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Official Terraform and GraphQL/CDM REST; support entitlements remain separate. Terraform registry observation2026-10-01: rubrikinc/rubrik: 50,978 total downloads; current version1.10.0, published2026-09-07. Publisher source repository: https://github.com/rubrikinc/terraform-provider-rubrik. Counts are registry requests/downloads, not distinct installations; vendor support obligations are separate. Evidence A. [regapi](https://registry.terraform.io/v1/providers/rubrikinc/rubrik)"
    ],
    [
     "Skills and certification",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner credentials/Academy evidence exists, but complete named exam structure is incomplete. Official automation: Python and PowerShell tools; GraphQL/REST; Task-Based REST Beta Evidence C. [dev](https://developer.rubrik.com/api-support/); [tools](https://developer.rubrik.com/SDKs-and-Tools/)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Rubrik is extending backup security into identity and AI-agent resilience. The record establishes Radar, database integrations and Agent Cloud delivery, with several recovery-agent and MCP announcements still outside confirmed GA. Restricted release documentation and unresolved CDM exit terms limit confidence in the broader portfolio scores.",
   "report": "reports/04-rubrik.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0.5
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0.5,
     "2024": 0.5,
     "2025": 0.5,
     "2026": 1
    },
    "agents": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 1.5,
     "2026": 3
    }
   },
   "ai_basis": {
    "infra": "2025-10-22 early access \u21922026-02-18 GA; Separate Agent Cloud service GA: Agent Rewind relates destructive changes to healthy backup snapshots; asset recovery described. This is agent-action resilience, not proved vector/model-registry backup. Agent Rewind GA adds agent-action recovery; no vector/model-consistency assertion. Evidence A. [rac](https://www.rubrik.com/company/newsroom/press-releases/25/new-rubrik-agent-cloud-accelerates-trusted-enterprise-ai-agent-deployments); [racga](https://www.rubrik.com/blog/company/26/2/introducing-rubrik-agent-cloud-control-your-agents-with-ai)",
    "stack": "2025-07 acquisition /2026-08-27 availability claim; Restricted availability: Predibase model customization/serving acquisition plus Annapurna enterprise data layer; Annapurna available to qualified enterprise partners. Not blanket GA of the complete AI stack. Annapurna restricted partners; only half-step for non-GA availability. Evidence A. [sec26](https://www.sec.gov/Archives/edgar/data/1943896/000194389626000013/rbrk-20260131.htm); [results26](https://www.rubrik.com/company/newsroom/press-releases/26/rubrik-reports-second-quarter-fiscal-year-2027-financial-results)",
    "ops": "2026-06-09 /2026-09-15; Launch plus customer-use claim: Rubrik AI reasons/acts across RSC and RAC, orchestrates recovery; auditable/attributable/reversible guardrails claimed. Concrete tool scopes, consent workflow and audit-retention details remain unverified. Customer-use/launch claim without explicit first-GA or tool approval contract; at most half-step over prior preview. Evidence A. [agent26](https://www.rubrik.com/company/newsroom/press-releases/26/rubrik-now-available-as-ai-agent); [mcp](https://www.rubrik.com/company/newsroom/press-releases/26/rubrik-adds-new-mcp-support-to-expand-access-to-agentic-cyber-resilience)",
    "agents": "2026-09-15; private preview: Official MCP. Python tool provides policy gates for write actions; no GA confirmation found. Specific AI openness anchor: official MCP private preview is 3; no GA4/5. Evidence A. [mcp](https://www.rubrik.com/company/newsroom/press-releases/26/rubrik-adds-new-mcp-support-to-expand-access-to-agentic-cyber-resilience); [mcpdocs](https://developer.rubrik.com/SDKs-and-Tools/Rubrik-MCP/)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 6 recorded announcement rows; 0 GA/shipped matches, 1 preview/early/limited at announcement, 3 partial, 3 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "dell",
   "name": "Dell PowerProtect Data Manager / Avamar / NetWorker",
   "short": "Dell",
   "kind": "product",
   "group": "storage",
   "since": 2016,
   "archetype": "Storage coupled protection",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 7,
    "C": 87,
    "M": 7,
    "U": 0,
    "P": 0
   },
   "idx": 0.07,
   "domains": {
    "virtual": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "apps": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4.5,
     "2026": 4.5
    },
    "recovery": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 4,
     "2026": 4
    },
    "cyber": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 0.5,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 4,
     "2026": 4
    },
    "storage": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "retention": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "dr": {
     "2016": 2,
     "2017": 2,
     "2018": 2,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2.5,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 3
    },
    "security": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "platforms": {
     "2016": 2,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 4
    },
    "scale": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 28 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. NetWorker19.10.0 (2024-01-16): Release date in code table; feature notes not retrieved Evidence A. [code](https://www.dell.com/support/kbdoc/en-us/000205512/target-revisions-and-runtime)"
    ],
    [
     "Roadmap transparency",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. NetWorker19.10.0 (2024-01-16): Release date in code table; feature notes not retrieved Evidence A. [code](https://www.dell.com/support/kbdoc/en-us/000205512/target-revisions-and-runtime)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 27 items; 1 shipped, 24 partial, 0 slipped, 2 pending, 0 dropped. Mature dated prospective cohort: 3; 0 documented within 12 calendar months, 0 later than 12 months, 3 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. PowerProtect One /DM5510 software (Platform announcement2026-05-19; code20.1 2026-06-19 /20.3 2026-08-19): Unified platform is complementary packaging/control plane; appliance-code chronology is separate from software-only PPDM and announcement availability. Evidence A. [world26](https://www.dell.com/en-us/dt/corporate/newsroom/announcements/detailpage.press-releases~usa~2026~05~dell-technologies-reimagines-the-modern-data-center-for-the-ai-era.htm); [codeII](https://www.dell.com/support/kbdoc/en-us/000502480/dell-servers-storage-networking-products-minimum-recommended-and-latest-code-versions-ii)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: Avamar Server product-page banner states end of standard support2029-01-31. PPDM minimum-supported code19.17.0 as of2026-09-15; standard contract rules effective2024-08-03 permit denial below minimum. Specific extended terms require contract review.. Grade C where current contract/EOS boundaries remain unresolved. 2026-05-19: PowerProtect One unifies control plane and protection storage. No public unit-price or licence conversion established from announcement. DM551020.1 code date is June19, separate from platform availability. Evidence C. [world26](https://www.dell.com/en-us/dt/corporate/newsroom/announcements/detailpage.press-releases~usa~2026~05~dell-technologies-reimagines-the-modern-data-center-for-the-ai-era.htm); [codeII](https://www.dell.com/support/kbdoc/en-us/000502480/dell-servers-storage-networking-products-minimum-recommended-and-latest-code-versions-ii)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2026-10-01 observation: PPDM primary licence metric is front-end protected TB; no dated price-change or minimum commitment verified Evidence C. [lic](https://www.dell.com/support/manuals/fr-be/enterprise-copy-data-management/pp-dm_20.3_ag/license-types?guid=guid-4efe8856-1c6c-4733-badb-d3560262e50f&lang=en-us)"
    ],
    [
     "Purchase constraints",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. PPDM: FETB licensing documented; list price and Avamar/NetWorker current SKU entitlement not found Evidence A. [lic](https://www.dell.com/support/manuals/fr-be/enterprise-copy-data-management/pp-dm_20.3_ag/license-types?guid=guid-4efe8856-1c6c-4733-badb-d3560262e50f&lang=en-us); [code](https://www.dell.com/support/kbdoc/en-us/000205512/target-revisions-and-runtime)"
    ],
    [
     "Channel and access",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: hub. API: PPDM20.1 REST specification public; official Terraform/Ansible and adoption counts not found Evidence A. [api](https://developer.dell.com/apis/4378/versions/20.1.0/introduction-5962m0)"
    ],
    [
     "Owner stability",
     0,
     "Scored 2026-10-03 from the accepted cutoff fact base. Recorded EMC combination is outside the 2023\u20132026 risk window; no newer owner-control change recorded. 2016-09-07 closed: EMC becomes wholly owned Dell Technologies subsidiary; corporate ownership event includes acquired backup portfolio. Evidence B. [emc16](https://www.sec.gov/Archives/edgar/data/1571996/000157199617000004/delltechnologiesfy1710k.htm)"
    ],
    [
     "Cost of staying supported",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Applicable warranty contracts can deny support below minimum code, advancing to PPDM 19.17 in September 2026. 2024-08-03 effective contract rule;2026-09-15 code change: For applicable standard contracts Dell may deny warranty support below minimum-supported code; PPDM minimum advances19.16\u219219.17, distinct from EOS. Evidence A. [codeII](https://www.dell.com/support/kbdoc/en-us/000502480/dell-servers-storage-networking-products-minimum-recommended-and-latest-code-versions-ii)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. DD/object protection-storage dependency is stronger than general-purpose disk backup; exact supported targets remain version-specific. Observed by 2026-10-01: DD and object targets documented; exact storage certification limits not found Evidence A. [admin](https://www.dell.com/support/manuals/en-us/enterprise-copy-data-management/pp-dm_20.3_ag)"
    ],
    [
     "Hardware / cloud coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Repository and migration: Admin guide separates protection storage from management metadata; Avamar migration requires product-specific procedures. UI data export is not portable backup-chain export. Evidence C. [admin](https://www.dell.com/support/manuals/en-us/enterprise-copy-data-management/pp-dm_20.3_ag); [preface](https://www.dell.com/support/manuals/fr-be/enterprise-copy-data-management/pp-dm_20.3_ag/preface?guid=guid-96454964-7933-4847-96ee-ee6e98dd0eaa&lang=en-us)"
    ],
    [
     "Skills and tooling coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. API: PPDM20.1 REST specification public; official Terraform/Ansible and adoption counts not found Evidence A. [api](https://developer.dell.com/apis/4378/versions/20.1.0/introduction-5962m0)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. API: PPDM20.1 REST specification public; official Terraform/Ansible and adoption counts not found Evidence A. [api](https://developer.dell.com/apis/4378/versions/20.1.0/introduction-5962m0)"
    ],
    [
     "Multi-tenancy and self-service",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: PPDM20.3 assistant: user-deployed approved text/multimodal LLM, administrator enables/configures, selected actions Approve/Reject, scheduled requests tracked in Artifacts; optional System-driven AI six-hour health/SLA briefs. First assistant availability distinct from20.3 component clock. Evidence C. [admin203full](https://dl.dell.com/content/manual45346128-dell-powerprotect-data-manager-20-3-administrator-guide.pdf?language=en-us)"
    ],
    [
     "API and infrastructure-as-code",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: PPDM20.3 assistant: user-deployed approved text/multimodal LLM, administrator enables/configures, selected actions Approve/Reject, scheduled requests tracked in Artifacts; optional System-driven AI six-hour health/SLA briefs. First assistant availability distinct from20.3 component clock. Evidence C. [admin203full](https://dl.dell.com/content/manual45346128-dell-powerprotect-data-manager-20-3-administrator-guide.pdf?language=en-us)"
    ],
    [
     "Skills and certification",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named PPDM deployment certification and dated exam migration; certification does not itself authorize partner service delivery. PowerProtect Data Manager Deploy certification: D-PDM-DY-01: familiarity with19.22;90-minute50-question exam; deployment/initial setup/policy/recovery/troubleshooting. Launch year remains audit pending. Evidence A. [deploycert](https://learning.dell.com/content/dam/dell-emc/documents/Dell%20PowerProtect%20Data%20Manager%20Deploy%20v2%20Exam%20Description.pdf)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Dell is consolidating protection management while retaining PPDM, Avamar and NetWorker roles. The record shows database and tape updates plus an assistant with approved actions, while software and appliance availability clocks remain separate. Protection-storage coupling and minimum-code support rules add operational dependencies.",
   "report": "reports/05-dell.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 1.5
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 5
    },
    "agents": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 2
    }
   },
   "ai_basis": {
    "infra": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "stack": "20.3 guide; code GA2026-08-19; Customer-deployed approved LLM integration: Supports gpt-oss-120b text or Llama-3.2-90B-Vision-Instruct multimodal via external API backend, onprem or managed cloud. Administrator-only connection configuration; certificate verification; uncertified detected models disabled. Retrieval uses official docs, KB and realtime product data, not a bundled general vector workload consistency engine. Approved user-deployed models and product-context retrieval, not a general vector consistency engine. Evidence A. [admin203full](https://dl.dell.com/content/manual45346128-dell-powerprotect-data-manager-20-3-administrator-guide.pdf?language=en-us)",
    "ops": "2026-08 documentation clock; Documented20.3; component GA2026-08-19, first assistant GA unresolved: Read health/logs, recommend protection policies and execute selected requests after Approve/Reject. Approved scheduled requests have Artifacts records; removal stops schedule. Only Administrator enables/configures assistant. Inquiries/output retained for history/improvement; no explicit retention period or full action-audit matrix in assistant section. Selected actions use Approve/Reject and recovery requests; first assistant availability by March 23, current documented in 20.3. Evidence A. [assistant](https://www.dell.com/support/manuals/fr-be/enterprise-copy-data-management/pp-dm_20.3_ag/ai-assistant?guid=guid-ea6cb26a-7eb1-4c9e-8d07-120691e0918a&lang=en-us); [admin203full](https://dl.dell.com/content/manual45346128-dell-powerprotect-data-manager-20-3-administrator-guide.pdf?language=en-us)",
    "agents": "API: PPDM20.1 REST specification public; official Terraform/Ansible and adoption counts not found Documented PPDM REST specification; no official MCP maturity credited. Evidence A. [api](https://developer.dell.com/apis/4378/versions/20.1.0/introduction-5962m0)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 2 recorded announcement rows; 1 GA/shipped matches, 0 preview/early/limited at announcement, 1 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "ibm",
   "name": "IBM Storage Defender / Storage Protect",
   "short": "IBM",
   "kind": "product",
   "group": "storage",
   "since": 2016,
   "archetype": "Governed recovery portfolio",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 0,
    "C": 93,
    "M": 7,
    "U": 0,
    "P": 0
   },
   "idx": 0.0,
   "domains": {
    "virtual": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4.5,
     "2020": 4.5,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "apps": {
     "2016": 2,
     "2017": 2,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "recovery": {
     "2016": 3,
     "2017": 3,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "cyber": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "storage": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "retention": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "dr": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 2.5,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "security": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "platforms": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "scale": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    }
   },
   "cred": [
    [
     "Cadence",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 142 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Defender2.0.0 /Data Protect7.1.1 (2023-12-11): Platform/component package-release clocks; agent and cluster deployment Evidence A. [def20](https://www.ibm.com/support/pages/node/7091491)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. Defender2.0.0 /Data Protect7.1.1 (2023-12-11): Platform/component package-release clocks; agent and cluster deployment Evidence A. [def20](https://www.ibm.com/support/pages/node/7091491)"
    ],
    [
     "Say-do",
     3,
     "Recorded ledger: 27 items; 18 shipped, 9 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 9; 1 documented within 12 calendar months, 0 later than 12 months, 8 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. Storage Protect8.2.2 (GA day unresolved; currency index2026-08-04 /documentation2026-09-04): Server DB backup stacking/reclamation on tape; Call Home support telemetry; object-agent multipart listing/restore optimization; official MCP interface documented. Same-host data TLS opt-out is optional, authentication encrypted; not a general encryption removal. Evidence A. [server822](https://www.ibm.com/docs/en/storage-protect/8.2.2?topic=whats-new); [fix82](https://www.ibm.com/support/pages/node/7253222)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: Data Protect support policy effective2025-08-01: major releases generally18 months; current minor/patch may be required for fixes. Release notes need IBMid linked to tenant.7.4.0 EOS2027-09-30;7.4.1 EOS2027-10-27. Source: IBM support information.. Grade C where current contract/EOS boundaries remain unresolved. 2025-06-20: Plus10.1.17 service packs become upgrade-only; fresh deployments need mod/base then iFix. Fix Central maintenance lacks licence enablement; obtain initial licence package via Passport Advantage. Evidence C. [plus17Download](https://www.ibm.com/support/pages/node/7184652)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Defender RU consumption and paid Essential/trial models are documented; existing licences can continue or convert. 2023; exact original GA day not printed: Primary GA notice introduces consumption Resource Units (RU); existing licences continue or may convert to RUs. A GA assertion, not a reconstructed day. 2024-07-29: DRS2.0.6 introduces60-day Trial and paid Essential subscriptions. Evidence A. [defgacredits](https://www.ibm.com/new/announcements/clients-can-strengthen-defenses-for-their-data-with-ibm-storage-defender-now-generally-available); [drs206](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__title__22)"
    ],
    [
     "Purchase constraints",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Separate families: Defender Data Protect/Replica versus Storage Protect server and VE/SQL components; no unified licence or price inferred Evidence A. [def21](https://www.ibm.com/support/pages/node/7250025); [ve](https://www.ibm.com/support/pages/download-information-ibm-storage-protect-virtual-environments-820); [sql](https://www.ibm.com/support/pages/node/6847283)"
    ],
    [
     "Channel and access",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Fix Central upgrade packages omit licence enablement; initial licences/packages require Passport Advantage. 2025-06-20: Plus10.1.17 service packs become upgrade-only; fresh deployments need mod/base then iFix. Fix Central maintenance lacks licence enablement; obtain initial licence package via Passport Advantage. Evidence A. [plus17Download](https://www.ibm.com/support/pages/node/7184652)"
    ],
    [
     "Owner stability",
     0,
     "Scored 2026-10-03 from the accepted cutoff fact base. OEM partnership broadens portfolio; no recent controlling-owner change recorded. 2023-03-02: IBM/Cohesity OEM collaboration announced; planned2Q2023 availability begins with Storage Protect and Cohesity DataProtect. Pricing/contract quantities not disclosed. Evidence A. [oem](https://newsroom.ibm.com/2023-03-02-IBM-and-Cohesity-Announce-New-Data-Security-and-Resiliency-Collaboration-Advancing-Enterprises-Ability-to-Fight-the-Impacts-of-Breaches-and-Cyberattacks)"
    ],
    [
     "Cost of staying supported",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Defender 1.x/2.0 EOS with no extended support; Plus chained/full-OS upgrade requirements. 2026-06-30 EOS: Defender1.x/2.0 support ends; no extended support available; supported2.1 onward. Plus10.1.17 /2025: Upgrade only from10.1.16.4; vSnap update precedes appliance; pre-upgrade script and full OS replacement. Base plus iFix needed for new installs. Evidence A. [drs215](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__section_9__title__1); [plus17](https://www.ibm.com/docs/en/spp/10.1.17?topic=new-updates-in-version-10117); [plus17Download](https://www.ibm.com/support/pages/node/7184652)"
    ]
   ],
   "lock": [
    [
     "Formats",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. LZ4 archives written by 8.1.12 require an 8.1.12+ client: explicit vendor reader/version coupling. Client8.1.12: LZ4-compressed backups created by8.1.12 can only be restored by8.1.12+ clients. This is an explicit reader-version compatibility boundary. Evidence A. [clientCumulative](https://www.ibm.com/docs/en/storage-protect/8.1.27?topic=new-backup-archive-client-updates)"
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Stack components: Defender installation files include Cohesity-named images/packages on qualified hardware and virtual/cloud editions; IBM product entitlement remains separate Evidence C. [def21](https://www.ibm.com/support/pages/node/7250025)"
    ],
    [
     "Hardware / cloud coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Stack components: Defender installation files include Cohesity-named images/packages on qualified hardware and virtual/cloud editions; IBM product entitlement remains separate Evidence C. [def21](https://www.ibm.com/support/pages/node/7250025)"
    ],
    [
     "Skills and tooling coupling",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Provider multitenancy: DRS2.1.1 organization isolation, user assignment and Service Provider Access impersonation; accounts/roles govern access. Evidence A. [drs211](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__section_5__title__1)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Provider multitenancy: DRS2.1.1 organization isolation, user assignment and Service Provider Access impersonation; accounts/roles govern access. Evidence A. [drs211](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__section_5__title__1)"
    ],
    [
     "Multi-tenancy and self-service",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. DRS 2.1.1 organization isolation and Service Provider Access; billing/self-service breadth incomplete. Provider multitenancy: DRS2.1.1 organization isolation, user assignment and Service Provider Access impersonation; accounts/roles govern access. Evidence A. [drs211](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__section_5__title__1)"
    ],
    [
     "API and infrastructure-as-code",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Official governed MCP and validated webhook integrations; full vendor IaC coverage remains unresolved. First repository commit2026-03-25;v1.0.0 2026-07-16;v1.1.0 2026-09-25; Official open-source MCP integration for commercial product: One MCP process per Protect server; stdio/SSH or HTTP-SSE. Production HTTP requires TLS and OIDC issuer/audience. Dynamic passwords memory-only with15-minute inactivity lease; write identity/correlation recorded in each server ACTLOG. Audit retention not specified by guide. Integration is not a new OSS backup vendor and has as-is/support disclaimer. Threat/incident integrations: DRS2.0.5 QRadar;2.0.8 Splunk;2.2.0 validated Slack/Teams/CrowdStrike/ServiceNow webhooks. Evidence A. [mcpRepo](https://github.com/IBM/storage-protect-mcp-server); [mcpReleases](https://github.com/IBM/storage-protect-mcp-server/releases); [mcpConfig110](https://raw.githubusercontent.com/IBM/storage-protect-mcp-server/v1.1.0/docs/guides/configure-guide.md); [drs205](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__title__23); [drs208](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__title__20); [drs220](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__section_10__title__1)"
    ],
    [
     "Skills and certification",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Historical named Protect credentials exist; withdrawal is indexed and current Defender credential unresolved. Dated2017-11-16 training path: Spectrum Protect8 training path names Test511 IBM Certified Deployment Professional\u2013Tivoli Storage ManagerV7.1, plus8.1.2 implementation/admin training TS616G. Evidence of an existing certification, not a2017 first-launch claim. Historical Spectrum Protect8.1 credentials: Indexed IBM catalogue names Certified Administrator\u2013Spectrum ProtectV8.1, withdrawn2020-05-31 and expiring2020-09-30; Deployment ProfessionalV8.1 badge also indexed. Opened pages returned empty bodies, soB; neither proves a current Defender credential. Evidence B. [training17](https://www.ibm.com/training/pdfs/spectrum_protect_v8.pdf); [admin81Cert](https://www.ibm.com/training/certification/ibm-certified-administrator-spectrum-protect-v81-24011006); [deploy81Badge](https://www.ibm.com/training/badge/ibm-certified-deployment-professional-spectrum-protect-v8-1)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "IBM is connecting established backup engines with recovery governance and threat scanning. Dated Defender notes and Protect documentation show immutable targets, recovery groups and a governed MCP interface. Component entitlements, reader compatibility and phased upgrades remain significant dependencies.",
   "report": "reports/06-ibm.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 3.5
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "agents": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 5
    }
   },
   "ai_basis": {
    "infra": "2026-03-23 /DRS2.1.2; Released feature: Data Protect Threat Scanner: AI scanning, YARA/feed updates, automatic/on-demand scans and anomaly-triggered triage. Sentinel8.15 isolated scanning is separately integrated. AI-labelled scanner plus YARA/feed integrations; not every scanner mechanism is ML. Evidence A. [drs212](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__section_6__title__1)",
    "stack": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "ops": "2024-12-18 blog /2024-12-17 DRS2.0.10; Released: ML discovers VMware VMs and forms recovery groups/governance profiles; automatic restore consent not established. ML-generated recovery groups; recommendations are not a generative acting assistant. Evidence A. [blog24Dec](https://community.ibm.com/community/user/blogs/tony-pearson1/2024/12/18/data-resiliency-technical-news-brief-dec-2024); [drs2010](https://www.ibm.com/docs/en/storage-defender/base?topic=new-updates-in-previous-versions#r_whatsnew_def_previous__title__18)",
    "agents": "First repository commit2026-03-25;v1.0.0 2026-07-16;v1.1.0 2026-09-25; Official open-source MCP integration for commercial product: One MCP process per Protect server; stdio/SSH or HTTP-SSE. Production HTTP requires TLS and OIDC issuer/audience. Dynamic passwords memory-only with15-minute inactivity lease; write identity/correlation recorded in each server ACTLOG. Audit retention not specified by guide. Integration is not a new OSS backup vendor and has as-is/support disclaimer. Released official MCP v1.0/v1.1 with OIDC scopes, least privilege, ACTLOG attribution and optional second-person approval; as-is support disclaimer preserved. Evidence A. [mcpRepo](https://github.com/IBM/storage-protect-mcp-server); [mcpReleases](https://github.com/IBM/storage-protect-mcp-server/releases); [mcpConfig110](https://raw.githubusercontent.com/IBM/storage-protect-mcp-server/v1.1.0/docs/guides/configure-guide.md)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 4 recorded announcement rows; 2 GA/shipped matches, 0 preview/early/limited at announcement, 2 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "zerto",
   "name": "HPE Zerto",
   "short": "Zerto",
   "kind": "product",
   "group": "storage",
   "since": 2016,
   "archetype": "Journal based VM recovery",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 7,
    "C": 93,
    "M": 0,
    "U": 0,
    "P": 0
   },
   "idx": 0.07,
   "domains": {
    "virtual": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 2.5,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 2.5
    },
    "apps": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 1,
     "2020": 1,
     "2021": 1,
     "2022": 1,
     "2023": 1,
     "2024": 1,
     "2025": 1,
     "2026": 1
    },
    "recovery": {
     "2016": 3,
     "2017": 3,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "cyber": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 0.5,
     "2022": 0.5,
     "2023": 0.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "storage": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 3,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "retention": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 2.5,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 2.5
    },
    "dr": {
     "2016": 4.5,
     "2017": 4.5,
     "2018": 4.5,
     "2019": 4.5,
     "2020": 4.5,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "security": {
     "2016": 2,
     "2017": 2,
     "2018": 2,
     "2019": 2.5,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "platforms": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 2.5
    },
    "scale": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 40 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Zerto10 (2023-05 announcement context): Linux appliance and vault direction in primary PDF snippet; GA date not verified Evidence A. [v10](https://www.zerto.com/wp-content/uploads/2023/05/Whats-New-in-Zerto-10_DS.pdf)"
    ],
    [
     "Roadmap transparency",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. Zerto10 (2023-05 announcement context): Linux appliance and vault direction in primary PDF snippet; GA date not verified Evidence A. [v10](https://www.zerto.com/wp-content/uploads/2023/05/Whats-New-in-Zerto-10_DS.pdf)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 15 items; 6 shipped, 5 partial, 0 slipped, 4 pending, 0 dropped. Mature dated prospective cohort: 5; 0 documented within 12 calendar months, 0 later than 12 months, 5 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. 10.0U2-correlated Q4 features (2023-12-07 blog delivery assertion): AWSLinuxVRA architecture; vLCM integration; GUI appliance upgrades; EC2UEFI support. Original guide links corroborateU2 family, but guide bodies unread. Evidence A. [q423mirror](https://www.zrto-dev.com/blog/zerto-platform/whats-new-in-data-protection-at-hpe-and-zerto-updates-and-releases-for-q4-2023/); [vlcmU2](https://help.zerto.com/bundle/Admin.VC.HTML.10.0_U2/page/vLCM.htm); [upgradeU2](https://help.zerto.com/bundle/Linux.ZVM.HTML.10.0_U2/page/ZVM_Appliance_Upgrade.htm)"
    ],
    [
     "Lifecycle stability",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Adjacent-release paired-site upgrades and LTR configuration/restore-only transitions are explicit. Historical8.5 upgrade guide: 6.0\u21926.5 deletes backup/repository configurations;6.5\u21927.0 preserves old repositories/retention sets for restore only. PairedsitesN\u00b11; no directN+2 upgrade. Licence expiry is a separate question. Evidence A. [upgrade85](https://s3.amazonaws.com/zertodownload_docs/8.5_Latest/Zerto%20Virtual%20Replication%20Zerto%20Virtual%20Manager%20%28ZVM%29%20-%20AWS%20Online%20Help/Content/Upgrading_ZVR/Guidelines_to_Upgrading_Zerto.htm)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2021-09-01: HPE acquisition completed for net cash consideration374m USD; historical context Evidence C. [acquisition](https://www.hpe.com/us/en/newsroom/press-release/2021/09/hewlett-packard-enterprise-completes-acquisition-of-zerto.html)"
    ],
    [
     "Purchase constraints",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Current: VM-based packages linked by secondary article; primary pricing/entitlement body not retrieved Evidence A. [secondary](https://cloudnroll.com/2026/06/02/hpe-zerto-10-9-all-features-explained/)"
    ],
    [
     "Channel and access",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: portal. PowerShell8.5: Official cmdlet module built on ZVM REST API; public install/download counts and certification launch audit pending. Evidence A. [z85](https://s3.amazonaws.com/zertodownload_docs/8.5_Latest/Zerto%20Virtual%20Replication%20Release%20Notes.pdf)"
    ],
    [
     "Owner stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. HPE acquisition predates current risk window, while portfolio integration remains material. 2021-09-01: HPE acquisition completed for net cash consideration374m USD; historical context Evidence A. [acquisition](https://www.hpe.com/us/en/newsroom/press-release/2021/09/hewlett-packard-enterprise-completes-acquisition-of-zerto.html)"
    ],
    [
     "Cost of staying supported",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Dated support endpoints and constrained upgrade paths increase maintenance dependence; current policy incomplete. 2022-06-01 historical EOS: 8.0 technical-guidance end; support end2021-05-31. Historical8.5 upgrade guide: 6.0\u21926.5 deletes backup/repository configurations;6.5\u21927.0 preserves old repositories/retention sets for restore only. PairedsitesN\u00b11; no directN+2 upgrade. Licence expiry is a separate question. Evidence A. [oldlife](https://s3.amazonaws.com/zertodownload_docs/8.0_Latest/Zerto%20Virtual%20Replication%20Product%20Version%20Lifecycle%20Matrix.pdf); [upgrade85](https://s3.amazonaws.com/zertodownload_docs/8.5_Latest/Zerto%20Virtual%20Replication%20Zerto%20Virtual%20Manager%20%28ZVM%29%20-%20AWS%20Online%20Help/Content/Upgrading_ZVR/Guidelines_to_Upgrading_Zerto.htm)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Management: Linux ZVM and replication appliance architecture in10 material; exact release constraints and export path unverified Evidence C. [v10](https://www.zerto.com/wp-content/uploads/2023/05/Whats-New-in-Zerto-10_DS.pdf)"
    ],
    [
     "Hardware / cloud coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Management: Linux ZVM and replication appliance architecture in10 material; exact release constraints and export path unverified Evidence C. [v10](https://www.zerto.com/wp-content/uploads/2023/05/Whats-New-in-Zerto-10_DS.pdf)"
    ],
    [
     "Skills and tooling coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. PowerShell8.5: Official cmdlet module built on ZVM REST API; public install/download counts and certification launch audit pending. Evidence A. [z85](https://s3.amazonaws.com/zertodownload_docs/8.5_Latest/Zerto%20Virtual%20Replication%20Release%20Notes.pdf)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. PowerShell8.5: Official cmdlet module built on ZVM REST API; public install/download counts and certification launch audit pending. Evidence A. [z85](https://s3.amazonaws.com/zertodownload_docs/8.5_Latest/Zerto%20Virtual%20Replication%20Release%20Notes.pdf)"
    ],
    [
     "Multi-tenancy and self-service",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 10.9 VMware Enterprise: role-controlled AI assistant plus official local ZVM MCP; separate read-only Analytics MCP authenticates through Cognito. Documentation dates do not establish first GA. Evidence C. [ai109](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant.htm); [ai109sec](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant_Security.htm); [zvmMCP](https://help.zerto.com/bundle/ZVM.MCP/page/zerto_virtual_manager_zvm_model_context_protocol_mcp_server.html); [zaMCPauth](https://help.zerto.com/bundle/ZA.MCP/page/how_the_zerto_analytics_mcp_works.html)"
    ],
    [
     "API and infrastructure-as-code",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Official REST/PowerShell and local MCP; no official Terraform/Ansible asserted. 8.5 automation ecosystem: Official PowerShell cmdlets module distributed through PowerShell Gallery supports VPG/VRA operations, alerts and reports; this is not Terraform/Ansible evidence. 10.9+; documentation2026-05-13; Documented available: Official MCP local deployment for enterprise VMware; protection/RPO/alerts/task queries and starting/stopping failover tests. Overview does not disclose a complete per-tool audit-retention policy. Evidence A. [rn85](https://s3.amazonaws.com/zertodownload_docs/8.5_Latest/Zerto%20Virtual%20Replication%20Release%20Notes.pdf); [zvmMCP](https://help.zerto.com/bundle/ZVM.MCP/page/zerto_virtual_manager_zvm_model_context_protocol_mcp_server.html); [ai109sec](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant_Security.htm)"
    ],
    [
     "Skills and certification",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Associate, Enterprise Engineer lab/exam and partner-only CSP credential; intro courses are not certifications. Certifications / August2019 document path; first-launch unresolved: Zerto Certified Associate; ZCP Enterprise Engineer with hands-on lab/exam; ZCP Cloud Service Provider restricted to Alliance Partners. Azure/AWS Intro courses are training-only, not certifications. ZCP technical tracks / April 2019 path; first launch unresolved: Official PDF names ZCP Enterprise Engineer with hands-on lab and exam, and ZCP Cloud Service Provider restricted to Alliance Partners. AWS/Azure introductory courses and Foundations are explicitly training-only. April 2019 URL is an archive hint, not a printed first-certification launch date. Evidence A. [cert2019](https://www.zerto.com/myzerto/wp-content/uploads/2019/08/myZertoUniversity_Cert_Offering_LN_Aug2019.pdf); [certApr19PDF](https://www.zerto.com/myzerto/wp-content/uploads/2019/04/Zerto7_myZertoUniversity_Cert_update.pdf)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Zerto is extending journal-based VM recovery with vaulting and conversational operator tools. The release record supports cross-cloud failover, long-term repositories and role-controlled failover tests, with current first-GA and matrix gaps retained. VM-focused protection and paired-site upgrade rules constrain its coverage outside disaster recovery.",
   "report": "reports/07-zerto.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 1.5
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 4.5
    },
    "agents": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 4
    }
   },
   "ai_basis": {
    "infra": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "stack": "Documentation2026-05-13/20; Documented: RAG knowledge base; AWS us-east-1 processing; required Bedrock runtime endpoint identifies runtime service, not a specific model. Outbound443/API/S3/logging; blocked endpoints can produce documentation-only fallback. Monthly token quota resets. Bedrock product-context RAG; no general backed-up business-data service established. Evidence A. [ai109how](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant_How_Works.htm); [ai109pre](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant_Before_You_Start.htm); [ai109sec](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant_Security.htm)",
    "ops": "10.9+; documentation2026-05-13, GA day unverified; Documented available: ZVM UI assistant for VMware Enterprise customers: RAG over official docs/live ZVM context. Signed-in user RBAC controls reads, VPG edits and failover tests; view-only cannot change configuration. Available role-controlled VPG changes/failover tests; exact first GA and affirmative approval contract unresolved. Evidence A. [ai109](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant.htm); [ai109how](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant_How_Works.htm); [ai109sec](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant_Security.htm)",
    "agents": "10.9+; documentation2026-05-13; Documented available: Official MCP local deployment for enterprise VMware; protection/RPO/alerts/task queries and starting/stopping failover tests. Overview does not disclose a complete per-tool audit-retention policy. Official available local MCP; complete invocation-log retention/governance insufficient for 5. Evidence C. [zvmMCP](https://help.zerto.com/bundle/ZVM.MCP/page/zerto_virtual_manager_zvm_model_context_protocol_mcp_server.html); [ai109sec](https://help.zerto.com/bundle/Admin.VC.HTML.10.9/page/Zerto_AI_Assistant_Security.htm)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 3 recorded announcement rows; 1 GA/shipped matches, 0 preview/early/limited at announcement, 1 partial, 1 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "opentext",
   "name": "OpenText Data Protector",
   "short": "OpenText",
   "kind": "product",
   "group": "legacy",
   "since": 2016,
   "archetype": "Enterprise engine modernization",
   "grade": "A",
   "driver": "C",
   "mix": {
    "V": 0,
    "C": 100,
    "M": 0,
    "U": 0,
    "P": 0
   },
   "idx": 0.0,
   "domains": {
    "virtual": {
     "2016": 4,
     "2017": 4,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "apps": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "recovery": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 4,
     "2026": 4
    },
    "cyber": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3,
     "2023": 3,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "storage": {
     "2016": 4,
     "2017": 4,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "retention": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "dr": {
     "2016": 2,
     "2017": 2,
     "2018": 2,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "security": {
     "2016": 2.5,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "platforms": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "scale": {
     "2016": 4,
     "2017": 4,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 40 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. 23.4 (2023-10 beginning-of-month release assertion; exact day unresolved): Chart attributes VMware/Hyper-V granular recovery and tagging; GA day not found Evidence A. [chart](https://www.opentext.com/en/media/checklist/data-protector-version-comparison-chart-checklist-en.pdf); [blog234](https://community.opentext.com/portfolio/data-protector/w/tips/46698/what-s-new-in-data-protector-23-4)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. 23.4 (2023-10 beginning-of-month release assertion; exact day unresolved): Chart attributes VMware/Hyper-V granular recovery and tagging; GA day not found Evidence A. [chart](https://www.opentext.com/en/media/checklist/data-protector-version-comparison-chart-checklist-en.pdf); [blog234](https://community.opentext.com/portfolio/data-protector/w/tips/46698/what-s-new-in-data-protector-23-4)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 12 items; 1 shipped, 10 partial, 0 slipped, 1 pending, 0 dropped. Mature dated prospective cohort: 8; 0 documented within 12 calendar months, 0 later than 12 months, 8 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. 25.3 (Released by2025-09-11 blog; first GA day unresolved): StoreOnce ISV immutability; tunable anomaly detection; CM/client token authentication; HANA Pacemaker/ZDB web granular recovery. Public25.3 RN route mismatch remains a separate access finding. Evidence A. [blog253](https://community.opentext.com/portfolio/b/portfolio-blog/posts/opentext-data-protector-25-3-lock-it-boost-it-back-it-up)"
    ],
    [
     "Lifecycle stability",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Three-year LTS commitments documented for 24.4 and 25.4, with staged migration rules. 2024-11-19: 24.4 designated LTS with three-year fully supported lifetime; first day/end date not inferred from blog publication. 2025-11-24: 25.4 designated LTS with three-year support commitment. Exact lifecycle day requires lifecycle table. Evidence A. [blog244](https://community.opentext.com/portfolio/b/portfolio-blog/posts/what-is-new-in-opentext-data-protector-24-4); [blog254](https://community.opentext.com/portfolio/b/portfolio-blog/posts/meet-25-4-the-lts-release-you-ve-been-waiting-for)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2026-10-01 observation: 25.4 separates Data Protector for Cloud Workloads installer from bundled media; exact licensing/inclusion impact not established Evidence C. [r254](https://community.opentext.com/portfolio/data-protector/w/tips/52749/opentext-data-protector-25-4-released)"
    ],
    [
     "Purchase constraints",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Data Protector: Public comparison chart; current price/metric/SKU quote not found; release downloads require active support contract Evidence A. [chart](https://www.opentext.com/en/media/checklist/data-protector-version-comparison-chart-checklist-en.pdf); [r262](https://community.opentext.com/portfolio/data-protector/w/tips/54039/opentext-data-protector-26-2-has-been-released)"
    ],
    [
     "Channel and access",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: matrix. Certification current observation2026-10-01: 5-5461 Data Protector Business Administrator Certification Exam:2 hours; preparation3-5450 Business Administration,5 days. Launch year not printed on current learning path. Evidence A. [cert](https://www.opentext.com/learning-services/learning-paths-data-protector)"
    ],
    [
     "Owner stability",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. OpenText acquisition in the current risk window; prior Micro Focus lineage retained. 2023-01-31: OpenText completed Micro Focus acquisition; Data Protector ownership lineage changes. Evidence A. [otclose](https://www.opentext.com/about/press-releases/opentext-buys-micro-focus)"
    ],
    [
     "Cost of staying supported",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Staged upgrades plus three-year support; no uniform forced annual renewal inferred. 23.4 version clock: Unsupported releases require staged migration through11.01 before current upgrade. 2025-11-24: 25.4 designated LTS with three-year support commitment. Exact lifecycle day requires lifecycle table. Evidence A. [log234](https://docs.microfocus.com/doc/200/25.1/releaselog#What_s_new_in_Data_Protector_23_4); [blog254](https://community.opentext.com/portfolio/b/portfolio-blog/posts/meet-25-4-the-lts-release-you-ve-been-waiting-for)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Administration and changes: Legacy VMware GRE obsolete in25.4; use web GRE. Reporting server replaced in24.4 per primary snippet. Evidence C. [r254](https://community.opentext.com/portfolio/data-protector/w/tips/52749/opentext-data-protector-25-4-released); [r244](https://docs.microfocus.com/doc/Data_Protector/24.4/ReleaseNotes)"
    ],
    [
     "Hardware / cloud coupling",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Administration and changes: Legacy VMware GRE obsolete in25.4; use web GRE. Reporting server replaced in24.4 per primary snippet. Evidence C. [r254](https://community.opentext.com/portfolio/data-protector/w/tips/52749/opentext-data-protector-25-4-released); [r244](https://docs.microfocus.com/doc/Data_Protector/24.4/ReleaseNotes)"
    ],
    [
     "Skills and tooling coupling",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Certification current observation2026-10-01: 5-5461 Data Protector Business Administrator Certification Exam:2 hours; preparation3-5450 Business Administration,5 days. Launch year not printed on current learning path. Evidence A. [cert](https://www.opentext.com/learning-services/learning-paths-data-protector)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Certification current observation2026-10-01: 5-5461 Data Protector Business Administrator Certification Exam:2 hours; preparation3-5450 Business Administration,5 days. Launch year not printed on current learning path. Evidence A. [cert](https://www.opentext.com/learning-services/learning-paths-data-protector)"
    ],
    [
     "Multi-tenancy and self-service",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 24.4 reporting replacement noted in primary snippet; API/IaC and tenant limits unverified Evidence C. [r244](https://docs.microfocus.com/doc/Data_Protector/24.4/ReleaseNotes)"
    ],
    [
     "API and infrastructure-as-code",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: 24.4 reporting replacement noted in primary snippet; API/IaC and tenant limits unverified Evidence C. [r244](https://docs.microfocus.com/doc/Data_Protector/24.4/ReleaseNotes)"
    ],
    [
     "Skills and certification",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named Business Administrator exam and five-day preparation; first-launch date unresolved. Certification current observation2026-10-01: 5-5461 Data Protector Business Administrator Certification Exam:2 hours; preparation3-5450 Business Administration,5 days. Launch year not printed on current learning path. Evidence A. [cert](https://www.opentext.com/learning-services/learning-paths-data-protector)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "OpenText is adding isolation, anomaly analysis and web recovery to an established enterprise backup engine. The version record shows database depth and LTS support alongside gradual interface changes. Storage-specific integrations and staged upgrades preserve operational and skills dependencies.",
   "report": "reports/08-opentext.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 2.5
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 1,
     "2024": 1,
     "2025": 1,
     "2026": 1
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "agents": {
     "2016": 0,
     "2017": 2,
     "2018": 2,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    }
   },
   "ai_basis": {
    "infra": "24.1; exact date not found; documented released feature; GA day not found: Version chart attributes AI backup anomaly detection to24.1; does not establish a generative assistant or autonomous restore. Released anomaly detection; exact GA day unresolved, no autonomous restore. Evidence A. [chart](https://www.opentext.com/en/media/checklist/data-protector-version-comparison-chart-checklist-en.pdf)",
    "stack": "23.4 version; exact GA day unresolved; Released integration: Magellan interactive analytics/reporting integration; future expanded reports explicitly promised. No backup-restoring generative assistant established. Released Magellan reporting integration, not a general AI service over protected application data. Evidence A. [log234](https://docs.microfocus.com/doc/200/25.1/releaselog#What_s_new_in_Data_Protector_23_4)",
    "ops": "24.2 version; exact GA day unresolved; Released enhancement: Anomaly detection extended from24.1 backup activity to incremental backups. Dashboard informs operator; not autonomous recovery. AI anomaly analytics informs operators; no generative assistant. Evidence A. [log241](https://docs.microfocus.com/doc/200/25.1/releaselog#What_s_new_in_Data_Protector_24_1); [log242](https://docs.microfocus.com/doc/200/25.1/releaselog#What_s_new_in_Data_Protector_24_2)",
    "agents": "Data Protector10.00 (Version-specific cumulative release log; GA day not established): TLS1.2 client-to-Cell-Manager connections secured by default with certificate pinning; centralized command execution; REST browse/restore/scheduler APIs; new web scheduler. REST browse/restore/scheduling; no MCP. Evidence A. [log1000](https://docs.microfocus.com/doc/200/2019.08/releaselog#What_s_new_in_Data_Protector_10_00)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 0 recorded announcement rows; 0 GA/shipped matches, 0 preview/early/limited at announcement, 0 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "hycu",
   "name": "HYCU R-Cloud (Hybrid Cloud Edition)",
   "short": "HYCU",
   "kind": "product",
   "group": "challenger",
   "since": 2017,
   "archetype": "Hybrid controller expansion",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 13,
    "C": 87,
    "M": 0,
    "U": 0,
    "P": 0
   },
   "idx": 0.13,
   "domains": {
    "virtual": {
     "2016": null,
     "2017": 2,
     "2018": 2,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 3.5
    },
    "apps": {
     "2016": null,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 4,
     "2026": 4
    },
    "recovery": {
     "2016": null,
     "2017": 2,
     "2018": 2,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "cyber": {
     "2016": null,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 0.5,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 4
    },
    "storage": {
     "2016": null,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "retention": {
     "2016": null,
     "2017": 1,
     "2018": 1,
     "2019": 1,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "dr": {
     "2016": null,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "security": {
     "2016": null,
     "2017": 2,
     "2018": 2,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "platforms": {
     "2016": null,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "scale": {
     "2016": null,
     "2017": 2,
     "2018": 2,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 29 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Hybrid Cloud Edition5.2.0 (2025-09): Release-note cover2025-09; Hyper-V, PostgreSQL PIT restore, size-anomaly detection, HotAdd and LDAP introduced. Exact GA day not found. Evidence A. [rn52](https://hdn.hycu.com/ec/v5.2.0/help/en/HYCU_ReleaseNotes.pdf)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. Hybrid Cloud Edition5.2.0 (2025-09): Release-note cover2025-09; Hyper-V, PostgreSQL PIT restore, size-anomaly detection, HotAdd and LDAP introduced. Exact GA day not found. Evidence A. [rn52](https://hdn.hycu.com/ec/v5.2.0/help/en/HYCU_ReleaseNotes.pdf)"
    ],
    [
     "Say-do",
     3,
     "Recorded ledger: 21 items; 17 shipped, 2 partial, 0 slipped, 2 pending, 0 dropped. Mature dated prospective cohort: 0; 0 documented within 12 calendar months, 0 later than 12 months, 0 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. R-Cloud service feature log2025 (2025-01 /03 /08 /11): AzureLocal/NDB and SnapDiff; near-production malware detection; Azure SQL DB then managed instances. Evidence A. [archive25](https://www.hycu.com/new?page=1)"
    ],
    [
     "Lifecycle stability",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: not found. Grade C where current contract/EOS boundaries remain unresolved. 2020-06-15: Cloud Services Provider programme launches co-branded backup/migration/DR services with pay-as-you-go and no pre-commitments. Technical labs/certification, no-extra-charge advisory services and expanded Authorized-to-Premier incentives are described. This is programme-specific, not a perpetual-to-subscription migration of all on-premises licences. Evidence C. [cspProgram20](https://www.hycu.com/company/newsroom/press-release/hycur-announces-new-cloud-services-provider-program-expands-hycu-and)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2026-10-01 observation: Hybrid pricing names Backup & Recovery, Enterprise Resilience, Unified Resilience; quote route rather than verified numeric list price Evidence C. [pricing](https://www.hycu.com/pricing)"
    ],
    [
     "Purchase constraints",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. CSP no pre-commitment is documented; on-prem bundle minimums and unit prices are unresolved. 2020-06-15: Cloud Services Provider programme launches co-branded backup/migration/DR services with pay-as-you-go and no pre-commitments. Technical labs/certification, no-extra-charge advisory services and expanded Authorized-to-Premier incentives are described. This is programme-specific, not a perpetual-to-subscription migration of all on-premises licences. Hybrid tiers: Named three plans; HTML feature checkmarks ambiguous, so no inferred tier-by-tier entitlement Evidence C. [cspProgram20](https://www.hycu.com/company/newsroom/press-release/hycur-announces-new-cloud-services-provider-program-expands-hycu-and); [pricing](https://www.hycu.com/pricing)"
    ],
    [
     "Channel and access",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: doc53. Certification launch2020-09-23: HYCU Enterprise Cloud Admin Certification launched through Learning Center for Nutanix/VMware protection, with labs, videos and individual sessions; launch promotion free through2020. Evidence A. [certLaunch](https://www.hycu.com/company/newsroom/press-release/hycu-introduces-online-certification-program-through-new-learning-center)"
    ],
    [
     "Owner stability",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Financing rounds change investor exposure; no controlling-owner acquisition is recorded. 2021-03-30: $87.5m Series A closed, led by Bain Capital Ventures with Acrew; Enrique Salem and Stefan Cohen join board. 2022-06-09: HYCU announces $53m Series B for SaaS service expansion; company financing, not a backup-software licence price. Evidence A. [fundA21](https://www.globenewswire.com/news-release/2021/03/30/2201455/0/en/Bain-Capital-Ventures-Leads-87-5m-Series-A-Round-to-Accelerate-Growth-and-Innovation-for-Boston-based-HYCU.html); [seriesb](https://www.hycu.com/company/newsroom/press-release/hycu-secures-53-million-series-b-to-fuel-hypergrowth-for-new-saas-based-service)"
    ],
    [
     "Cost of staying supported",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Support/upgrade constraints, distinct from licence-expiry restoration: not found. 2020-06-15: Cloud Services Provider programme launches co-branded backup/migration/DR services with pay-as-you-go and no pre-commitments. Technical labs/certification, no-extra-charge advisory services and expanded Authorized-to-Premier incentives are described. This is programme-specific, not a perpetual-to-subscription migration of all on-premises licences. Evidence C. [cspProgram20](https://www.hycu.com/company/newsroom/press-release/hycur-announces-new-cloud-services-provider-program-expands-hycu-and)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Architecture: Versioned Hybrid Cloud Edition docs distinct from SaaS application connectors; independent repository extraction not found Evidence C. [rn52](https://hdn.hycu.com/ec/v5.2.0/help/en/HYCU_ReleaseNotes.pdf); [doc51](https://support.hycu.com/hc/en-us/articles/17587193078684-HYCU-R-Cloud-Hybrid-Cloud-Edition-5-1-0-User-Documentation)"
    ],
    [
     "Hardware / cloud coupling",
     1,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Architecture: Versioned Hybrid Cloud Edition docs distinct from SaaS application connectors; independent repository extraction not found Evidence C. [rn52](https://hdn.hycu.com/ec/v5.2.0/help/en/HYCU_ReleaseNotes.pdf); [doc51](https://support.hycu.com/hc/en-us/articles/17587193078684-HYCU-R-Cloud-Hybrid-Cloud-Edition-5-1-0-User-Documentation)"
    ],
    [
     "Skills and tooling coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Certification launch2020-09-23: HYCU Enterprise Cloud Admin Certification launched through Learning Center for Nutanix/VMware protection, with labs, videos and individual sessions; launch promotion free through2020. Evidence A. [certLaunch](https://www.hycu.com/company/newsroom/press-release/hycu-introduces-online-certification-program-through-new-learning-center)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Dated CSP launch and explicit historical revenue/deal-registration schedule; no undated-to-current PACE equivalence. CSP programme launch 2020-06-15: Pay-as-you-go with no pre-commitments, certification curriculum and hands-on enablement; original press statement dates the programme. Named Enterprise Cloud Admin credential has its separate September 2020 launch row. Historical tier schedule / undated official datasheet: On-premises Authorized/Premier/Global Solution Provider: annual revenue thresholds none / USD 50,000 / USD 1,000,000; GSP presence in three countries. Validated deal-registration discounts add 10%/20%/20%. Four complete quarters after enrolment define the revenue window; geography can adjust thresholds. No date or current PACE equivalence is inferred. Evidence A. [cspProgram20](https://www.hycu.com/company/newsroom/press-release/hycur-announces-new-cloud-services-provider-program-expands-hycu-and); [certLaunch](https://www.hycu.com/company/newsroom/press-release/hycu-introduces-online-certification-program-through-new-learning-center); [partnerOverviewUndated](https://assets-global.website-files.com/624c604308a45f0c7a8391c2/627e96114a69458919ebe494_Partner-Program-Overview.pdf)"
    ],
    [
     "Multi-tenancy and self-service",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Multitenant service delivery and multi-controller Manager documented; billing details remain incomplete. PACE partner programme / current page: Partners Accelerating Cloud Environments; reseller/service-provider/alliance tracks and multitenant delivery.500-partner community is a vendor claim; page does not enumerate rank tiers or launch date. 4.0.0 (2019-06 product release): Physical machines; HYCU Manager for many controllers; controller backup/automatic restore; file-share protection. Exact GA day unresolved where only month/cover is stated. Evidence A. [partnerCurrent](https://www.hycu.com/partners); [rn400](https://hdn.hycu.com/ec/v4.0.0/help/en/HYCU_ReleaseNotes.pdf)"
    ],
    [
     "API and infrastructure-as-code",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: 5.3 HYCU Manager upgrades, controller power controls, reports, events and SSO; current API/IaC limits not recovered Evidence C. [rn53](https://hdn.hycu.com/ec/v5.3.0/help/en/HYCU_ReleaseNotes.pdf)"
    ],
    [
     "Skills and certification",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Enterprise Cloud Admin credential launched September 2020 with labs; free promotion is historical. Certification launch2020-09-23: HYCU Enterprise Cloud Admin Certification launched through Learning Center for Nutanix/VMware protection, with labs, videos and individual sessions; launch promotion free through2020. Evidence A. [certLaunch](https://www.hycu.com/company/newsroom/press-release/hycu-introduces-online-certification-program-through-new-learning-center)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "HYCU is expanding hybrid protection while adding cloud database and threat-detection modules. Versioned Hybrid notes show physical-server, database and controller-management gains, while aiR remains early access. Cloud module availability and Hybrid controller entitlement require separate interpretation.",
   "report": "reports/09-hycu.md",
   "ai": {
    "infra": {
     "2016": null,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 3
    },
    "stack": {
     "2016": null,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0.5
    },
    "ops": {
     "2016": null,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0.5
    },
    "agents": {
     "2016": null,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 3
    }
   },
   "ai_basis": {
    "infra": "2026-03 release log; Documented available: R-Shield uses Halcyon-trained models for early ransomware/encryption behaviour; operates independently of backup scanning. DXP blocks exfiltration and key-material remediation captures encryption keys. Halcyon model-based live protection distinct from backup YARA. Evidence A. [new26](https://www.hycu.com/new)",
    "stack": "2026-05-14; Early access waitlist: aiR queries protected records and purpose-built agents inspect sensitive data, insider risk, identity/configuration drift and AI-agent activity. Launch explicitly opens an early-access waitlist; no blanket GA or Hybrid Controller entitlement inferred. aiR early-access waitlist; no general GA. Evidence A. [air26](https://www.hycu.com/company/newsroom/press-release/hycur-wakes-backup-airtm-launch-adds-new-ai-capabilities-across)",
    "ops": "2026-05-14; Early access waitlist: aiR queries protected records and purpose-built agents inspect sensitive data, insider risk, identity/configuration drift and AI-agent activity. Launch explicitly opens an early-access waitlist; no blanket GA or Hybrid Controller entitlement inferred. Early access only, maximum half-step. Evidence A. [air26](https://www.hycu.com/company/newsroom/press-release/hycur-wakes-backup-airtm-launch-adds-new-ai-capabilities-across)",
    "agents": "2026-03 whats-new entry; Introduced per vendor; exact GA unresolved: Central R-Cloud MCP for SaaS/cloud protection policy/orchestration/integration. Do not infer onprem Hybrid Cloud5.3 MCP parity. Identity, permissions and audit detail unverified. Official R-Cloud MCP introduced, GA/governance unresolved; specific official-preview-equivalent openness anchor, not Hybrid controller parity. Evidence C. [new](https://www.hycu.com/new)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 3 recorded announcement rows; 0 GA/shipped matches, 1 preview/early/limited at announcement, 2 partial, 1 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. AI score names R-Cloud vector data/production detection explicitly; aiR is early access and Hybrid entitlement is not inferred."
  },
  {
   "key": "druva",
   "name": "Druva Enterprise Workloads (hybrid VMs / servers / databases)",
   "short": "Druva",
   "kind": "product",
   "group": "midmarket",
   "since": 2016,
   "archetype": "Cloud managed hybrid backup",
   "grade": "B",
   "driver": "V",
   "mix": {
    "V": 47,
    "C": 40,
    "M": 13,
    "U": 0,
    "P": 0
   },
   "idx": 0.47,
   "domains": {
    "virtual": {
     "2016": 3,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "apps": {
     "2016": 2,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "recovery": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3,
     "2020": 3,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "cyber": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 3,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "storage": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "retention": {
     "2016": 2,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "dr": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "security": {
     "2016": 2,
     "2017": 2,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 3.5
    },
    "platforms": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "scale": {
     "2016": 3,
     "2017": 3,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 31 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Enterprise Workloads staged release (2026-06-15): Proxmox proxy introduced7.0.0-958375; component clocks vary Evidence A. [notes](https://help.druva.com/en/articles/8764270-enterprise-workloads-release-notes)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. Enterprise Workloads staged release (2026-06-15): Proxmox proxy introduced7.0.0-958375; component clocks vary Evidence A. [notes](https://help.druva.com/en/articles/8764270-enterprise-workloads-release-notes)"
    ],
    [
     "Say-do",
     3,
     "Recorded ledger: 21 items; 12 shipped, 7 partial, 0 slipped, 2 pending, 0 dropped. Mature dated prospective cohort: 5; 0 documented within 12 calendar months, 0 later than 12 months, 5 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. DruAI service evolution (2024-07/09;2025-08/09): Support guidance and metadata investigations; prompted EC2 recovery; Insights GA versus Lifecycle forthcoming. Native service feature clocks, not an onprem software version. Evidence A. [assist24](https://www.druva.com/blog/introducing-dru-assist); [investigate24](https://www.druva.com/why-druva/about/press-releases/dru-investigate-gen-ai); [agents25](https://www.druva.com/why-druva/about/press-releases/druva-introduces-ai-agents-to-simplify-cyber-resilience); [graph25](https://www.druva.com/why-druva/about/press-releases/druva-announces-dru-metagraph-to-unlock-data-intelligence)"
    ],
    [
     "Lifecycle stability",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: not found. Grade C where current contract/EOS boundaries remain unresolved. 2023-09-07: MSP portfolio adds SP&O/ARR globally; press states MSP program introduced2021. Separate from July2023 Partner+ VAR program and current licences. Evidence C. [msp23](https://www.druva.com/why-druva/about/press-releases/msp-new-security-cyber-resilience-capabilities)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2026-10-01 observation: Consumption credit =1TB-month of deduplicated/compressed stored backup data; not1TB source-data licence Evidence C. [credits](https://help.druva.com/en/articles/8789550-enterprise-workloads-credits)"
    ],
    [
     "Purchase constraints",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Enterprise Data: VM/file/NAS/database protection offered separately from SaaS-app/endpoint plans; exact numeric contracted price not found Evidence A. [pricing](https://www.druva.com/products/resilience-cloud/pricing-plans); [credits](https://help.druva.com/en/articles/8789550-enterprise-workloads-credits)"
    ],
    [
     "Channel and access",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: notes. Partner+ launch2023-07-18: Dated primary press release launches Partner+. Copyright2023 programme guide names Authorized/Certified/Elite tiers; region-dependent accredited sales/technical staffing and revenue requirements. Deal-registration margin protection, Partner Academy, NFR/MDF and selected higher-tier rebates documented. A Certified partner tier is not itself an individual certification name. Evidence A. [partnerLaunch23](https://www.druva.com/why-druva/about/press-releases/global-partner-plus-program-launch); [partnerGuide23](https://www.druva.com/content/dam/druvaincprogram/collateral/ebooks/ebook-partner-plus-guide.pdf)"
    ],
    [
     "Owner stability",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Venture-backed funding recorded; no recent controlling-owner acquisition established. 2021-04-19: $147m financing led by CDPQ with Neuberger Berman; above$2bn valuation is vendor claim. Evidence A. [fund21](https://www.druva.com/why-druva/about/press-releases/druva-secures-147-million-investment-to-extend-market-leadership)"
    ],
    [
     "Cost of staying supported",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Support/upgrade constraints, distinct from licence-expiry restoration: not found. 2023-09-07: MSP portfolio adds SP&O/ARR globally; press states MSP program introduced2021. Separate from July2023 Partner+ VAR program and current licences. Evidence C. [msp23](https://www.druva.com/why-druva/about/press-releases/msp-new-security-cyber-resilience-capabilities)"
    ]
   ],
   "lock": [
    [
     "Formats",
     4,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Hybrid protection depends on the service/control plane; CloudCache does not establish an independent backup engine. Service dependency: Hybrid workload control plane and cloud backup service; regional release staging and agent upgrade needed. Independent raw repository extractor not found. Evidence A. [notes](https://help.druva.com/en/articles/8764270-enterprise-workloads-release-notes); [pricing](https://www.druva.com/products/resilience-cloud/pricing-plans)"
    ],
    [
     "Hardware / cloud coupling",
     5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Mandatory cloud service and AWS DR architecture meet the strongest cloud-coupling anchor. Service dependency: Hybrid workload control plane and cloud backup service; regional release staging and agent upgrade needed. Independent raw repository extractor not found. Phoenix DRaaS2018 architecture: AWS account/EC2 proxy/S3/AMI dependencies; proxy region matches backup storage and resulting AMI. Data copied to customer S3 as decrypted256MB chunks before AMI construction. Evidence A. [notes](https://help.druva.com/en/articles/8764270-enterprise-workloads-release-notes); [pricing](https://www.druva.com/products/resilience-cloud/pricing-plans); [dr18](https://www.druva.com/blog/cloud-disaster-recovery-druva)"
    ],
    [
     "Skills and tooling coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Partner+ launch2023-07-18: Dated primary press release launches Partner+. Copyright2023 programme guide names Authorized/Certified/Elite tiers; region-dependent accredited sales/technical staffing and revenue requirements. Deal-registration margin protection, Partner Academy, NFR/MDF and selected higher-tier rebates documented. A Certified partner tier is not itself an individual certification name. Evidence A. [partnerLaunch23](https://www.druva.com/why-druva/about/press-releases/global-partner-plus-program-launch); [partnerGuide23](https://www.druva.com/content/dam/druvaincprogram/collateral/ebooks/ebook-partner-plus-guide.pdf)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Authorized/Certified/Elite and regional staffing/revenue requirements documented. Partner+ launch2023-07-18: Dated primary press release launches Partner+. Copyright2023 programme guide names Authorized/Certified/Elite tiers; region-dependent accredited sales/technical staffing and revenue requirements. Deal-registration margin protection, Partner Academy, NFR/MDF and selected higher-tier rebates documented. A Certified partner tier is not itself an individual certification name. Evidence A. [partnerLaunch23](https://www.druva.com/why-druva/about/press-releases/global-partner-plus-program-launch); [partnerGuide23](https://www.druva.com/content/dam/druvaincprogram/collateral/ebooks/ebook-partner-plus-guide.pdf)"
    ],
    [
     "Multi-tenancy and self-service",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: Central reporting replaces legacy reports in2026 release notes; API/IaC download counts unverified Evidence C. [notes](https://help.druva.com/en/articles/8764270-enterprise-workloads-release-notes)"
    ],
    [
     "API and infrastructure-as-code",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: Central reporting replaces legacy reports in2026 release notes; API/IaC download counts unverified Evidence C. [notes](https://help.druva.com/en/articles/8764270-enterprise-workloads-release-notes)"
    ],
    [
     "Skills and certification",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Technical certification announced April 2024; named credential/exam requirements incomplete. Technical certification announced2024-04-03: Partner-excellence article announces new technical certification but does not name the credential or first exam day. Programme launch now resolved; named individual credential launch remains open. Evidence C. [partnerUpdate24](https://www.druva.com/blog/celebrating-partner-excellence)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Druva is extending a cloud-managed backup service across alternative hypervisors and cyber recovery workflows. Staged release notes document Proxmox and OpenStack, while DruAI adds metadata investigations and prompted EC2 recovery. Mandatory service dependence and retention-driven credit use remain the main coupling.",
   "report": "reports/10-druva.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 2.5,
     "2022": 2.5,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0.5,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0.5,
     "2024": 3,
     "2025": 4.5,
     "2026": 4.5
    },
    "agents": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 4
    }
   },
   "ai_basis": {
    "infra": "VMware anomaly detection (2023-05). Source: Ledger review fact pass, 2026-10-03",
    "stack": "2024-09-12; Available asserted: Dru Investigate: Amazon Bedrock, isolated LLM/private RAG and metadata-only investigations; available to all customers without added charge. Read/analyze scope; no universal autonomous action claim. Private metadata RAG investigations; backup-content RAG not asserted. Evidence A. [investigate24](https://www.druva.com/why-druva/about/press-releases/dru-investigate-gen-ai)",
    "ops": "2025-08-19; Available asserted: Bedrock AgentCore powers permission-bound Data/Help/Action agents; prompted EC2 recovery example. This supersedes a blanket read-only description of the DruAI suite, without changing narrower MCP interface restrictions. Prompted permission-bound EC2 recovery; exhaustive approval/audit contract unresolved. Evidence A. [agents25](https://www.druva.com/why-druva/about/press-releases/druva-introduces-ai-agents-to-simplify-cyber-resilience)",
    "agents": "Druva MCP server in the Cloud Platform release (2026-06-26). Source: Ledger review fact pass, 2026-10-03"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 8 recorded announcement rows; 4 GA/shipped matches, 1 preview/early/limited at announcement, 2 partial, 2 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "nakivo",
   "name": "NAKIVO Backup & Replication",
   "short": "NAKIVO",
   "kind": "product",
   "group": "midmarket",
   "since": 2016,
   "archetype": "VM recovery and MSPs",
   "grade": "A",
   "driver": "M",
   "mix": {
    "V": 0,
    "C": 40,
    "M": 53,
    "U": 0,
    "P": 7
   },
   "idx": 0.0,
   "domains": {
    "virtual": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "apps": {
     "2016": 2,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 2.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "recovery": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "cyber": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 3,
     "2022": 3,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "storage": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "retention": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 1,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 3.5
    },
    "dr": {
     "2016": 3,
     "2017": 3,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4.5,
     "2026": 4.5
    },
    "security": {
     "2016": 1.5,
     "2017": 2,
     "2018": 2,
     "2019": 2,
     "2020": 2,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 2.5
    },
    "platforms": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3.5,
     "2025": 4,
     "2026": 4
    },
    "scale": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4.5,
     "2026": 4.5
    }
   },
   "cred": [
    [
     "Cadence",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 65 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. 10.10 / 10.11 (2023-10-09 / 2024-01-29): RTR beta; RMAN/Linux index Evidence A. [notes](https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; release notes used. No open-roadmap-tracker reference score is awarded. 10.10 / 10.11 (2023-10-09 / 2024-01-29): RTR beta; RMAN/Linux index Evidence A. [notes](https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm)"
    ],
    [
     "Say-do",
     3,
     "Recorded ledger: 4 items; 3 shipped, 1 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 1; 0 documented within 12 calendar months, 0 later than 12 months, 1 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. 10.8 (2023-01-23 release date): UI\u00a0Facelift for Dashboards; VMware vSphere 8 Full Support; Improved Backup Retention; MSP\u00a0Console Evidence A. [n108](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.8-Release-Notes.htm)"
    ],
    [
     "Lifecycle stability",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published future fix/support endpoints and known support withdrawals; separate commitment clocks. 2027-11-04 scheduled: 11.0 end of support; end of fix2025-11-04. Dates quoted as future lifecycle commitments at cutoff. 2028-10-06 scheduled: 11.1 end of support; end of fix2026-10-06, after cutoff. Evidence A. [n110](https://helpcenter.nakivo.com/Release-Notes/Content/v11-Release-Notes/v11.0-Release-Notes.htm); [n111](https://helpcenter.nakivo.com/Release-Notes/Content/v11-Release-Notes/v11.1-Release-Notes.htm)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Multiple metrics and separate monitoring/RTR exist, but no documented drastic 2023\u20132026 price series. 2026-10-01 observation: Perpetual CPU/socket and subscription workload models; Essentials range5\u201350; monitoring/RTR licensed separately 10.4 guide; release2021-08-02, first model launch unresolved: Perpetual per-source socket for VMware/Hyper-V/AHV; per-machine physical and per-OracleDB EnterprisePlus. Subscription per workload includes24/7support,1physical server or3workstations; OracleEnterprisePlus. This is a versioned model observation, not a dated price/model-change announcement. Evidence C. [lic](https://helpcenter.nakivo.com/User-Guide/Content/Overview/Licensing.htm); [guide104](https://helpcenter.nakivo.com/UserGuidePDF/FullUserGuides/full_user_guide_10_4.pdf); [n104](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.4-Release-Notes.htm)"
    ],
    [
     "Purchase constraints",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Perpetual and subscription choice; Essentials 5\u201350 is a bounded edition constraint, not an enterprise-wide minimum. 2026-10-01 observation: Perpetual CPU/socket and subscription workload models; Essentials range5\u201350; monitoring/RTR licensed separately Evidence A. [lic](https://helpcenter.nakivo.com/User-Guide/Content/Overview/Licensing.htm)"
    ],
    [
     "Channel and access",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: lic. Multi-tenancy / MSP: 3.9 historical multi-tenancy; 11.1 MSP Direct Connect differs from ordinary feature Evidence A. [notes](https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm); [n111](https://helpcenter.nakivo.com/Release-Notes/Content/v11-Release-Notes/v11.1-Release-Notes.htm)"
    ],
    [
     "Owner stability",
     1,
     "2026-10-01 evidence boundary: NAKIVO; no controlling-owner transaction recorded in accepted commercial history. Ownership-risk judgement comes from the recorded corporate/financing events; no unrecorded transaction is assumed. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Cost of staying supported",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 20\u201325% late reinstatement premium and fix/EOS split; perpetual engine is not said to stop at support expiry. 2022 copyright renewal handbook; first policy change unresolved: Perpetual support reinstatement1day+ late costs20\u201325percent more than standard on-time renewal; no reinstatement cutoff. Expired support loses updates/patches and technical assistance; this passage does not say a perpetual backup engine stops. Subscription terms1\u20135years bundle24/7 support. Renewal amount depends on sockets/workloads/databases/users, edition and licence. Not evidence of a universal2026 price increase. 2027-11-04 scheduled: 11.0 end of support; end of fix2025-11-04. Dates quoted as future lifecycle commitments at cutoff. Evidence A. [renewalPolicy22](https://di1.nakivo.com/renewal/nakivo-global-renewals-policy-handbook.pdf); [n110](https://helpcenter.nakivo.com/Release-Notes/Content/v11-Release-Notes/v11.0-Release-Notes.htm)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     1,
     "Scored 2026-10-03 from the accepted cutoff fact base. Software targets local/cloud/dedup appliances; no own-appliance requirement evidenced. Observed by 2026-10-01: 11.0 federated repository; virtual appliance max repository128TB/file16TB End-2022 checkpoint: 10.4 guidep108: stream repository integration with DataDomain/HYDRAstor/StoreOnce(Catalyst).10.6NAS and10.7Azure/B2 additions are later2022 notes; older guide not their matrix. Evidence A. [notes](https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm); [n111](https://helpcenter.nakivo.com/Release-Notes/Content/v11-Release-Notes/v11.1-Release-Notes.htm); [guide104](https://helpcenter.nakivo.com/UserGuidePDF/FullUserGuides/full_user_guide_10_4.pdf); [n106](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.6-Release-Notes.htm); [n107](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.7-Release-Notes.htm)"
    ],
    [
     "Hardware / cloud coupling",
     0.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Windows/Linux/NAS deployment options reduce mandatory hardware/control-plane dependence; no full offline-contract guarantee asserted. End-2022 checkpoint: 10.4 guidepp103\u2013107: vSphere4.1\u20137.0.2,Hyper-V2012/2012R2/2016/2019,AHV5.10/5.15/5.20LTS; physical Windows2008R2\u20132019,Ubuntu16.04\u201320.04/RHEL7.4\u20138.3/SLES12SP3\u201315SP2/CentOS7\u20138. This is an older minimum observation;10.7.2 vSphere8 compatibility remains separate. Evidence A. [guide104](https://helpcenter.nakivo.com/UserGuidePDF/FullUserGuides/full_user_guide_10_4.pdf); [n104](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.4-Release-Notes.htm); [n1072](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.7.2-Release-Notes.htm)"
    ],
    [
     "Skills and tooling coupling",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Multi-tenancy / MSP: 3.9 historical multi-tenancy; 11.1 MSP Direct Connect differs from ordinary feature Evidence A. [notes](https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm); [n111](https://helpcenter.nakivo.com/Release-Notes/Content/v11-Release-Notes/v11.1-Release-Notes.htm)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Basic/Bronze/Silver/Gold qualifications and discounts explicitly documented; observed Oct2, not a historical change date. Partner terms / observed2026-10-02; undated page: Basic/Bronze/Silver/Gold base product discounts10/15/20/25percent. Specific vendor-developed/internal-use/renewal deals can be capped at10percent; no new opportunity in a year can cap renewals at5percent. Bronze/Silver/Gold annual net revenue requirements$2,000/$12,000/$24,000; new-customer sales2/4/6. Current observation is not a historically dated price change. Evidence A. [partnerTerms](https://www.nakivo.com/partner/partner-program/)"
    ],
    [
     "Multi-tenancy and self-service",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Isolated multi-tenant Director/self-service plus MSP Direct Connect; distinct from ordinary Direct Connect. End-2022 checkpoint: 10.4 guidepp73\u201387/143: RESTHTTP API supports Perl/Python/Bash/JS/PHP/Java/C#, isolated multi-tenant Director and self-service portals.10.5ITMonitoring and10.6external productDB are later2022 notes; per-feature first clocks separate. Observed by 2026-10-01: MSP Direct Connect needs no inbound ports; ordinary Direct Connect has different requirements Evidence A. [guide104](https://helpcenter.nakivo.com/UserGuidePDF/FullUserGuides/full_user_guide_10_4.pdf); [n105](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.5-Release-Notes.htm); [n106](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.6-Release-Notes.htm); [notes](https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm); [n111](https://helpcenter.nakivo.com/Release-Notes/Content/v11-Release-Notes/v11.1-Release-Notes.htm)"
    ],
    [
     "API and infrastructure-as-code",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: MSP Direct Connect needs no inbound ports; ordinary Direct Connect has different requirements Evidence C. [notes](https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm); [n111](https://helpcenter.nakivo.com/Release-Notes/Content/v11-Release-Notes/v11.1-Release-Notes.htm)"
    ],
    [
     "Skills and certification",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. NSP/NTP staffing requirements documented; named launch dates and exam detail incomplete. Named partner certifications / launch unresolved: NSP certified sales staffing: Bronze1/Silver1/Gold2; NTP certified technical staffing: Silver1/Gold2. Primary table names credentials but does not state exam curricula or first launch dates. Programme may be revised/cancelled without notice and tiers downgraded for unmet obligations. Evidence A. [partnerTerms](https://www.nakivo.com/partner/partner-program/)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "NAKIVO is extending VM recovery and replication across Proxmox while retaining several licence metrics. Public release notes document recovery, tape and MSP gains, with explicit immutable-target and RTR restrictions. Its narrower database range and separate feature entitlements limit parity with broader enterprise suites.",
   "report": "reports/11-nakivo.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "agents": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    }
   },
   "ai_basis": {
    "infra": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "stack": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "ops": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "agents": "End-2022 checkpoint: 10.4 guidepp73\u201387/143: RESTHTTP API supports Perl/Python/Bash/JS/PHP/Java/C#, isolated multi-tenant Director and self-service portals.10.5ITMonitoring and10.6external productDB are later2022 notes; per-feature first clocks separate. 10.4 guide (release Aug2021) documents HTTP API; no official MCP. Evidence A. [guide104](https://helpcenter.nakivo.com/UserGuidePDF/FullUserGuides/full_user_guide_10_4.pdf); [n105](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.5-Release-Notes.htm); [n106](https://helpcenter.nakivo.com/Release-Notes/Content/v10-Release-Notes/v10.6-Release-Notes.htm)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 0 recorded announcement rows; 0 GA/shipped matches, 0 preview/early/limited at announcement, 0 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "arcserve",
   "name": "Arcserve UDP (other portfolio products labelled separately)",
   "short": "Arcserve",
   "kind": "product",
   "group": "midmarket",
   "since": 2016,
   "archetype": "Recovery validation suite",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 20,
    "C": 53,
    "M": 7,
    "U": 0,
    "P": 20
   },
   "idx": 0.25,
   "domains": {
    "virtual": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "apps": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "recovery": {
     "2016": 3,
     "2017": 4,
     "2018": 4,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "cyber": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 1,
     "2020": 1,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3.5,
     "2025": 4,
     "2026": 4
    },
    "storage": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "retention": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 3.5
    },
    "dr": {
     "2016": 2.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "security": {
     "2016": 2,
     "2017": 2,
     "2018": 2,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "platforms": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "scale": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 27 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. UDP10 (2024-10-15): Launch: backup/pre-restore malware scan; one-to-many replication Evidence A. [p10](https://www.arcserve.com/press-releases/arcserve-launches-udp-10-deliver-enhanced-malware-protection)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; launch-event and press promises used. No open-roadmap-tracker reference score is awarded. UDP10 (2024-10-15): Launch: backup/pre-restore malware scan; one-to-many replication Evidence A. [p10](https://www.arcserve.com/press-releases/arcserve-launches-udp-10-deliver-enhanced-malware-protection)"
    ],
    [
     "Say-do",
     2,
     "Recorded ledger: 7 items; 1 shipped, 3 partial, 1 slipped, 2 pending, 0 dropped. Mature dated prospective cohort: 3; 0 documented within 12 calendar months, 1 later than 12 months, 2 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. UDP11.0 fullRN (2026 family; Jun11press; JapanpromisedAug17download/Aug19licences/Sep10packages): ProxmoxVM protection/recovery/filemount; preservecustomWindows/Linuxagentcertificates; NTFSallocation2MiB; incrementalmalwarescan/ReFS3.1/3.4/3.7. Currentincrementalscan cannot detectmoved/renamedfiles; enhancement explicitly future. Evidence A. [r110features](https://documentation.arcserve.com/Arcserve-UDP/Available/11.0/ENU/Bookshelf_Files/HTML/RelnX/features_enhancements.htm); [jp11price](https://www.arcserve.com/hubfs/jp-resources/20260724-arcserve-info-additional-notice-for-udp11%26crs2+new-price-partner-final.pdf?hsLang=ja); [p11](https://www.arcserve.com/press-releases/arcserve-launches-udp-11-data-resilience-to-simplify-recovery-and-strengthen-resilience)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: Formal UDP version lifecycle policy not found.. Grade C where current contract/EOS boundaries remain unresolved. 2026 Japan11 list price / comparison with2024 Japan10 list: Advanced1TB annual subscription: JPY148,000\u2192251,000 beforetax (69.6percent derived); Premiumsocket annualJPY101,000\u2192172,000 (70.3percent).11AdvancedServer annualJPY52,000 unchanged per exception. Version/region/SKU lists compared, not a global or every-customer renewal rate. Evidence C. [jp10price](https://www.arcserve.com/hubfs/243905555/jp-resources/20241031-info-udp10-release-partner.pdf?hsLang=ja); [jp11price](https://www.arcserve.com/hubfs/jp-resources/20260724-arcserve-info-additional-notice-for-udp11%26crs2+new-price-partner-final.pdf?hsLang=ja)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Japan9 approximately15% increase and selected Japan11 subscription SKUs about70% versus Japan10 are documented; not a global/all-customer increase. 2023-01-13 / Japan9.0 ordersJan23: Approximately15percent price increase versus preceding version, attributed by vendor to inflation/yen exchange changes;8.x prices unchanged. AssuredRecovery becomesAdvanced entitlement (previouslyPremium/PremiumPlus). Japan ordersJan23,shipmentFeb1. 2026 Japan11 list price / comparison with2024 Japan10 list: Advanced1TB annual subscription: JPY148,000\u2192251,000 beforetax (69.6percent derived); Premiumsocket annualJPY101,000\u2192172,000 (70.3percent).11AdvancedServer annualJPY52,000 unchanged per exception. Version/region/SKU lists compared, not a global or every-customer renewal rate. Evidence A. [jp90price](https://www.arcserve.com/hubfs/243905555/jp-resources/20230113-info-udp90-release-partner.pdf?hsLang=ja); [jp10price](https://www.arcserve.com/hubfs/243905555/jp-resources/20241031-info-udp10-release-partner.pdf?hsLang=ja); [jp11price](https://www.arcserve.com/hubfs/jp-resources/20260724-arcserve-info-additional-notice-for-udp11%26crs2+new-price-partner-final.pdf?hsLang=ja)"
    ],
    [
     "Purchase constraints",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Current bundle exclusions: Runbooks and Cyber Resilient Storage paid separately; exact list prices/minimums not found Evidence A. [p11](https://www.arcserve.com/press-releases/arcserve-launches-udp-11-data-resilience-to-simplify-recovery-and-strengthen-resilience)"
    ],
    [
     "Channel and access",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: notes. Partner programme: Partner-success page opened; exact incentives, certification obligations and adoption counts not established Evidence A. [partner](https://www.arcserve.com/partner-success)"
    ],
    [
     "Owner stability",
     2.5,
     "2026-10-01 evidence boundary: Arcserve; controlling-owner chronology not established in accepted fact base, midpoint ownership estimate. Ownership-risk judgement comes from the recorded corporate/financing events; no unrecorded transaction is assumed. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Cost of staying supported",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. UNIX agent support ends April2026; dedicated storage restores stop 31 days after expiry, not all perpetual UDP restoration. JapanUNIX bundled-agent exit: Best-effort support can close case without further assistance if no known fix; all UNIXagent support endsApr30 2026. BundledUDP edition customers are explicitly affected. Storage subscription/capacity enforcement / current2026guide: ACRS/ACS/ACCRS operate withgraduated subscription/capacity restrictions.31days aftersubscriptionexpiry allrecoveryoperations stop andfeaturesaregreyedout. NotassertedallUDPperpetualenginerestores stop; dedicatedstorage-service entitlement boundary matters.10.3RN sayscapacity exhaustionrequiresmorecapacityevenwithactivelicence. Evidence A. [jpunixeol](https://www.arcserve.com/hubfs/243905555/jp-resources/20250318-info-asbu-unix-end-of-support-partner.pdf?hsLang=ja); [storageExpiry](https://documentation.arcserve.com/Arcserve-Licensing/Available/ENU/HTML/LIC/Content/LicensingGuide/subs_storage_expiry_behvr_UDP.htm); [r103features](https://documentation.arcserve.com/Arcserve-UDP/Available/10.0/ENU/Bookshelf_Files/HTML/Update3/features_enhancements.htm)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Dedicated storage expiry obstructs recovery; independent UDP extractor and all engine rights remain unresolved. Storage subscription/capacity enforcement / current2026guide: ACRS/ACS/ACCRS operate withgraduated subscription/capacity restrictions.31days aftersubscriptionexpiry allrecoveryoperations stop andfeaturesaregreyedout. NotassertedallUDPperpetualenginerestores stop; dedicatedstorage-service entitlement boundary matters.10.3RN sayscapacity exhaustionrequiresmorecapacityevenwithactivelicence. Evidence C. [storageExpiry](https://documentation.arcserve.com/Arcserve-Licensing/Available/ENU/HTML/LIC/Content/LicensingGuide/subs_storage_expiry_behvr_UDP.htm); [r103features](https://documentation.arcserve.com/Arcserve-UDP/Available/10.0/ENU/Bookshelf_Files/HTML/Update3/features_enhancements.htm)"
    ],
    [
     "Stack coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Recovery stack: Runbooks operate on Arcserve Cloud Storage/Cyber Resilient Storage sources and deploy real AWS resources; cloud bills/exit rights not audited. Evidence C. [p11](https://www.arcserve.com/press-releases/arcserve-launches-udp-11-data-resilience-to-simplify-recovery-and-strengthen-resilience)"
    ],
    [
     "Hardware / cloud coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Recovery stack: Runbooks operate on Arcserve Cloud Storage/Cyber Resilient Storage sources and deploy real AWS resources; cloud bills/exit rights not audited. Evidence C. [p11](https://www.arcserve.com/press-releases/arcserve-launches-udp-11-data-resilience-to-simplify-recovery-and-strengthen-resilience)"
    ],
    [
     "Skills and tooling coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Partner programme: Partner-success page opened; exact incentives, certification obligations and adoption counts not established Evidence A. [partner](https://www.arcserve.com/partner-success)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Lightning Associate/Premier/Elite routes documented in2025. Partner programme / launch2025: Lightning tiers Associate/Premier/Elite; channel rules, recurring-revenue rewards, deal protection and tier incentives. Evidence A. [lightning25](https://www.arcserve.com/press-releases/arcserve-unveils-new-lightning-partner-program-supercharge-channel-ecosystem)"
    ],
    [
     "Multi-tenancy and self-service",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: UDP11 SaaS or on-prem console; ArcGenie guided answers Evidence C. [p9](https://www.arcserve.com/press-releases/arcserve-unified-data-protection-9.0-boosts-enterprise-data-resilience); [p11](https://www.arcserve.com/press-releases/arcserve-launches-udp-11-data-resilience-to-simplify-recovery-and-strengthen-resilience)"
    ],
    [
     "API and infrastructure-as-code",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: UDP11 SaaS or on-prem console; ArcGenie guided answers Evidence C. [p9](https://www.arcserve.com/press-releases/arcserve-unified-data-protection-9.0-boosts-enterprise-data-resilience); [p11](https://www.arcserve.com/press-releases/arcserve-launches-udp-11-data-resilience-to-simplify-recovery-and-strengthen-resilience)"
    ],
    [
     "Skills and certification",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. UDP Certified Engineer plus sales credential course/assessment; first launch unverified. Certifications / observed2025-06-05; first launch unresolved: UDP Certified Engineer; Certified Sales Enablement\u2013UDP10; course plus assessment; certifications valid two years. SaaS/storage credentials listed separately in source, not on-prem domain evidence. Evidence A. [academy25](https://www.arcserve.com/blog/arcserve-academy-data-resilience-certifications-value-added-resellers)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Arcserve is combining recovery validation with immutable storage and guided management. The record shows delivered malware and anomaly controls, while UDP11 and regional availability clocks need care. Separate storage and runbook entitlements can add dependencies beyond the UDP engine.",
   "report": "reports/12-arcserve.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 2.5,
     "2026": 2.5
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 3
    },
    "agents": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 1.5,
     "2026": 1.5
    }
   },
   "ai_basis": {
    "infra": "UDP10.3 versionedRN; firstfeatureGA unresolved; Documented protectionAI: AIAnomalyDetection is configurable secondarytask overrecoverypoints: baselinebehavior,suspiciousnames,encryptionpatterns,massdeletions/renames; flagsrecoverypoints/reports. Guide onlyWindows andUNC/NFSnodes,notServer2008R2orolder. Plans may includeagentlessVMbackup butWindows eligibility remains; notuniversalLinuxscan. Model/independentaccuracy notpublished. UDP10.3 documented available protection AI, Windows/UNC/NFS eligible; model and first-GA day unresolved. Evidence A. [r103features](https://documentation.arcserve.com/Arcserve-UDP/Available/10.0/ENU/Bookshelf_Files/HTML/Update3/features_enhancements.htm); [aiTask10](https://documentation.arcserve.com/Arcserve-UDP/Available/10.0/ENU/Bookshelf_Files/HTML/SolG/UDPSolnGuide/add_as_AI_anomaly_detection_task.htm)",
    "stack": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "ops": "2026-07 Console SaaS RN; Documented available: ArcGenie provides predefined health/protection/storage/recovery/security summaries, knowledge-base replies and navigation. Limitations explicitly prohibit system actions/configuration changes, uploads and analytics. No on-prem availability inferred from SaaS help. Console SaaS ArcGenie documented available read/guidance; no actions/configuration/analytics, no onprem parity assumed. Evidence A. [arcJuly26](https://documentation.arcserve.com/Arcserve-Console/SaaS/Available/ENU/reln/features_enhancements__July__2026_.htm); [arcAIlimit](https://documentation.arcserve.com/Arcserve-Console/SaaS/Available/ENU/olh/Arcserve%20Console%20-%20SaaS/ai_limitations.htm)",
    "agents": "End-2016 checkpoint: UDP6 console plans, cross-site replication through gateway/NAT, manual replication/merge and WindowsCore CLI; PowerShell interface documented. No exact end2016 scalability matrix established. Documented automation interface only; no official MCP maturity is implied. Evidence A. [v6guide](https://documentation.arcserve.com/Arcserve-UDP/Available/V6/ENU/Bookshelf_Files/PDF/udp_solutions_guide.pdf)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 3 recorded announcement rows; 0 GA/shipped matches, 0 preview/early/limited at announcement, 3 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "acronis",
   "name": "Acronis Cyber Protect (15 / 16 / 17; cloud capabilities labelled separately)",
   "short": "Acronis",
   "kind": "product",
   "group": "midmarket",
   "since": 2016,
   "archetype": "Integrated protection and recovery",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 13,
    "C": 73,
    "M": 13,
    "U": 0,
    "P": 0
   },
   "idx": 0.13,
   "domains": {
    "virtual": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "apps": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "recovery": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "cyber": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 2.5,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "storage": {
     "2016": 3,
     "2017": 3,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "retention": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "dr": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "security": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 2.5,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 3
    },
    "platforms": {
     "2016": 0,
     "2017": 0,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3.5,
     "2026": 3.5
    },
    "scale": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 44 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. 15 U6 builds 37255 / 37420 / 37853 (2024-02-02 / 2024-02-28 / 2024-05-21): Maintenance dates Evidence A. [p15](https://dl.acronis.com/u/cyberprotect/rn/15/user/en-US/AcronisCyberProtect15_relnotes.htm)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; release-note future items used. No open-roadmap-tracker reference score is awarded. 15 U6 builds 37255 / 37420 / 37853 (2024-02-02 / 2024-02-28 / 2024-05-21): Maintenance dates Evidence A. [p15](https://dl.acronis.com/u/cyberprotect/rn/15/user/en-US/AcronisCyberProtect15_relnotes.htm)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 7 items; 4 shipped, 3 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 2; 0 documented within 12 calendar months, 0 later than 12 months, 2 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. 16 Update 4 deployment boundaries (2025-04-28 first listed build 39929; blog updated 2025-05-14): On-premises: optional Active Protection installation, domain rejoin and Rocky Linux management container. Cloud deployment: agentless AHV and Linux EDR. Linux process stop/quarantine/backup recovery shipped; rollback, remote desktop, isolation and restart remain future items in these notes. Evidence A. [p16](https://dl.managed-protection.com/u/cyberprotect/rn/16/user/en-US/AcronisCyberProtect16_relnotes.htm); [update16u4Blog](https://www.acronis.com/en/blog/posts/built-for-whats-next-acronis-cyber-protect-evolves-for-a-new-it-reality/)"
    ],
    [
     "Lifecycle stability",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: Exact supported-version/EOL policy not found; old 15 line has dated fixes in 2026.. Grade C where current contract/EOS boundaries remain unresolved. 2023-01-17: Annual Academy curriculum refresh announces 22 courses including five recertification courses. Vendor claims the annual refresh falls from 20 hours to under three; this is a programme update, not the first certification launch. Evidence C. [academy23](https://www.acronis.com/en/pr/2023/acronis-cyberfit-academy-announces-2023-certification-program/)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. New VM-based licence option and separate cloud peak-usage metering change; neither proves blanket onprem price hike. 2024-10-15 build38690 /16U2: Introduces Azure/EC2 VM-based licence option for on-prem and cloud deployments; no price inferred. Cloud26.09 September2026: Partner billing changes from last-day snapshot to per-customer/per-metric highest daily production usage aggregated monthly; cloud commercial model, not onprem17 price hike. New console no additional partner charge; deployment dates may vary. Evidence A. [p16](https://dl.managed-protection.com/u/cyberprotect/rn/16/user/en-US/AcronisCyberProtect16_relnotes.htm); [cloud2609](https://dl.acronis.com/u/baas/rn/26.09/en-US/AcronisCyberProtectCloud_relnotes.htm)"
    ],
    [
     "Purchase constraints",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Legacy perpetual use remains; subscription/cloud feature boundaries documented, not subscription-only everywhere. 16 Update 4 guide built 2026-09-08: Standard, Advanced and Backup Advanced editions. Subscription validity starts on purchase; on expiry existing protection plans stop and new plans cannot be created. The page does not explicitly establish restore-only access rights. Evidence A. [license16](https://www.acronis.com/en/support/documentation/AcronisCyberProtect_16/editions-and-licensing.html)"
    ],
    [
     "Channel and access",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: guide. Technology partners / integration: Official developer portal and cloud integration guide opened; per-API support obligations not audited Evidence A. [dev](https://developer.acronis.com/en-us/); [guide](https://developer.acronis.com/doc/)"
    ],
    [
     "Owner stability",
     4.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Recent majority/private-equity transition; exact close day not reconstructed. 2024-08-07: EQT announced proposed majority acquisition, expected 2025 Q1\u2013Q2. Closing date not established in opened source. 2025: EQT investor portfolio records Acronis entry2025; exact acquisition closing day not supplied Evidence A. [eqt](https://www.acronis.com/en/pr/2024/eqt-to-acquire-a-majority-stake-in-acronis/); [owner](https://eqtgroup.com/about/current-portfolio/acronis)"
    ],
    [
     "Cost of staying supported",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Maintenance gates updates/support; subscription plans stop at expiry, restore-only rights unstated. 16 Update 4 guide built 2026-09-08: Standard, Advanced and Backup Advanced editions. Subscription validity starts on purchase; on expiry existing protection plans stop and new plans cannot be created. The page does not explicitly establish restore-only access rights. Evidence A. [license16](https://www.acronis.com/en/support/documentation/AcronisCyberProtect_16/editions-and-licensing.html)"
    ]
   ],
   "lock": [
    [
     "Formats",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Version-specific .tib/.tibx vendor archives and password-change compatibility; independent reader unverified. Backup archive format: v11/v12 formats documented; 17 U1 password-change capability limited to v12 .tibx. Independent third-party reader not found. Evidence A. [p15](https://dl.acronis.com/u/cyberprotect/rn/15/user/en-US/AcronisCyberProtect15_relnotes.htm); [p17](https://dl.managed-protection.com/u/cyberprotect/rn/17/user/en-US/AcronisCyberProtect17_relnotes.htm)"
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Backup archive format: v11/v12 formats documented; 17 U1 password-change capability limited to v12 .tibx. Independent third-party reader not found. Evidence C. [p15](https://dl.acronis.com/u/cyberprotect/rn/15/user/en-US/AcronisCyberProtect15_relnotes.htm); [p17](https://dl.managed-protection.com/u/cyberprotect/rn/17/user/en-US/AcronisCyberProtect17_relnotes.htm)"
    ],
    [
     "Hardware / cloud coupling",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Backup archive format: v11/v12 formats documented; 17 U1 password-change capability limited to v12 .tibx. Independent third-party reader not found. Evidence C. [p15](https://dl.acronis.com/u/cyberprotect/rn/15/user/en-US/AcronisCyberProtect15_relnotes.htm); [p17](https://dl.managed-protection.com/u/cyberprotect/rn/17/user/en-US/AcronisCyberProtect17_relnotes.htm)"
    ],
    [
     "Skills and tooling coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Technology partners / integration: Official developer portal and cloud integration guide opened; per-API support obligations not audited Evidence A. [dev](https://developer.acronis.com/en-us/); [guide](https://developer.acronis.com/doc/)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Authorized/Gold/Platinum with no registration fee but certification obligations; current policy not launch-year proof. Reseller programme / current observation: Authorized/Gold/Platinum tiers; Gold adds MDF/account manager/rebates, Platinum dedicated enhanced support; Academy certification required for tier compliance. Entry has no registration fee, certification minimum still applies. Named exam first-launch dates unresolved. Evidence A. [resellerNow](https://www.acronis.com/en/partners/resellers/)"
    ],
    [
     "Multi-tenancy and self-service",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 17 RBAC; U1 on-prem SIEM CEF/JSON; cloud custom child-tenant roles Evidence C. [p17](https://dl.managed-protection.com/u/cyberprotect/rn/17/user/en-US/AcronisCyberProtect17_relnotes.htm)"
    ],
    [
     "API and infrastructure-as-code",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: 17 RBAC; U1 on-prem SIEM CEF/JSON; cloud custom child-tenant roles Evidence C. [p17](https://dl.managed-protection.com/u/cyberprotect/rn/17/user/en-US/AcronisCyberProtect17_relnotes.htm)"
    ],
    [
     "Skills and certification",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Paid hands-on Engineer course documented by2018 and dated2023 curriculum refresh; no invented first-launch year. Acronis Certified Engineer for Acronis Backup: Official datasheet dated August 2018 documents paid two-day hands-on technical training for on-premises and cloud Backup. Certifications are tied to software versions and renewed when new classes are available. Existence by August 2018 is established; first launch year is unresolved. 2023 #CyberFit Academy curriculum: Global announcement on January 17, 2023 introduces the annual curriculum refresh and recertification courses. This is earlier than the February 27 regional Korean announcement; neither date is the first-ever certification programme launch. Evidence A. [academy18](https://dl.acronis.com/u/pdf/AcronisAcademy_datasheet_en-US.pdf); [academy23](https://www.acronis.com/en/pr/2023/acronis-cyberfit-academy-announces-2023-certification-program/)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Acronis is extending combined protection and recovery across additional hypervisors. Versioned notes establish on-prem Proxmox recovery and malware controls, while cloud console and EDR capabilities follow separate clocks. Edition gates, proprietary archives and the EQT ownership transition remain dependencies.",
   "report": "reports/13-acronis.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 3,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "agents": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 2
    }
   },
   "ai_basis": {
    "infra": "2020-09-09 build record; released build; first GA not found: 15 notes describe AI malware protection; no generative assistant inference. Evidence A. [p15](https://dl.acronis.com/u/cyberprotect/rn/15/user/en-US/AcronisCyberProtect15_relnotes.htm)",
    "stack": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "ops": "Cloud26.09 September2026; notes updated2026-09-30; Released cloud console; selected analytics early access: New Cyber Console provides contextual AI answers and user-delegated actions; query visibility respects role/tenant/licence. Console device/policy operations listed, but exhaustive AI tool permissions/confirmation/audit retention not specified. Cyber Intelligence natural-language dashboard/report generation explicitly early access. No onprem17 parity inferred. Released cloud delegated console actions, approval/governance detail incomplete; no onprem parity. Evidence A. [cloud2609](https://dl.acronis.com/u/baas/rn/26.09/en-US/AcronisCyberProtectCloud_relnotes.htm)",
    "agents": "Technology partners / integration: Official developer portal and cloud integration guide opened; per-API support obligations not audited REST/developer APIs, not a product-control MCP endpoint; external MCP monitoring earns no MCP maturity. Evidence A. [dev](https://developer.acronis.com/en-us/); [guide](https://developer.acronis.com/doc/)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 3 recorded announcement rows; 1 GA/shipped matches, 0 preview/early/limited at announcement, 2 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. Cloud console AI is labelled separately; it earns no onprem17 assistant parity."
  },
  {
   "key": "bacula_ent",
   "name": "Bacula Enterprise (Bacula Systems commercial product)",
   "short": "Bacula Enterprise",
   "kind": "product",
   "group": "legacy",
   "since": 2016,
   "archetype": "Plugin based enterprise engine",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 0,
    "C": 73,
    "M": 27,
    "U": 0,
    "P": 0
   },
   "idx": 0.0,
   "domains": {
    "virtual": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "apps": {
     "2016": 2,
     "2017": 2,
     "2018": 2,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "recovery": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "cyber": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 4,
     "2025": 4,
     "2026": 4
    },
    "storage": {
     "2016": 3.5,
     "2017": 3.5,
     "2018": 3.5,
     "2019": 4.5,
     "2020": 4.5,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "retention": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 4.5,
     "2020": 4.5,
     "2021": 4.5,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "dr": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "security": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 3,
     "2022": 3,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3.5
    },
    "platforms": {
     "2016": 0,
     "2017": 0,
     "2018": 3,
     "2019": 3,
     "2020": 3,
     "2021": 4,
     "2022": 4,
     "2023": 4,
     "2024": 4,
     "2025": 4,
     "2026": 4.5
    },
    "scale": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 3.5,
     "2019": 3.5,
     "2020": 3.5,
     "2021": 3.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 4,
     "2025": 4,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 20 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. 16.0 (2023-01-13 release-note date): Storage-daemon encryption; SnapLock/Data Domain immutability; AHV plugin; malware detection in backup/verify jobs. Evidence A. [rn160](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN16.0/index.html)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: Unreleased/work-in-progress items appear in release notes; no dated public forward release schedule established. No open-roadmap-tracker reference score is awarded. 16.0 (2023-01-13 release-note date): Storage-daemon encryption; SnapLock/Data Domain immutability; AHV plugin; malware detection in backup/verify jobs. Evidence A. [rn160](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN16.0/index.html)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 8 items; 6 shipped, 1 partial, 0 slipped, 1 pending, 0 dropped. Mature dated prospective cohort: 3; 0 documented within 12 calendar months, 1 later than 12 months, 2 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. 18.0.7 (2024-12-11 notes;2025 article clocks): AWS authentication token support and aligned-volume read-only truncation fix; StoreOnce new-feature grouping differs from original18.0 notes. Evidence A. [rn180](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN18.0/index.html); [blog1807](https://www.baculasystems.com/technical-blog/bacula-enterprise-18-0-7-released/)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: New-features page says support for the two most recent versions; exact version-specific EOS dates/contract exclusions unresolved. Grade C where current contract/EOS boundaries remain unresolved. 18.2 release family;2025-05-19 notes: Director and allStorageDaemons must be upgraded together to18.2 because they are incompatible with earlier versions.18.0 introduced catalog1027; upgrading18.0\u219218.2 does not require catalog-conversion script. Version coupling, not licence termination. Evidence C. [rn182](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN18.2/index.html)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Current endpoint/core metrics are known; historical subscription transition and price series unresolved. 2026-10-01 observation: Commercial annual-subscription metric: endpoints/support; HPC core-based tiers. Original switch date and historic prices unresolved. Evidence C. [price](https://www.baculasystems.com/support/subscriptions/)"
    ],
    [
     "Purchase constraints",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Annual subscription: Endpoint count and support-response tiers; no protected-data/front-end-TB charge per published page. HPC tiers may use CPU cores. Current page is not a historical licence-change date. Evidence A. [price](https://www.baculasystems.com/support/subscriptions/)"
    ],
    [
     "Channel and access",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: docs. Training: Partner page names Foundation Course and Expert Series; search index said Admin I but live page says Foundation Course. Launch dates/exam prerequisites unresolved. Evidence A. [partner](https://www.baculasystems.com/si-cloud-msp-partner-program/)"
    ],
    [
     "Owner stability",
     1,
     "2026-10-01 evidence boundary: Bacula Systems; no controlling-owner transaction established in accepted history. Ownership-risk judgement comes from the recorded corporate/financing events; no unrecorded transaction is assumed. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Cost of staying supported",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Two recent-version support rule and coordinated Director/StorageDaemon upgrade dependency documented. Current version policy: Two most recent versions receive support per new-features guide; version-specific EOS list not reconstructed. 18.2 release family;2025-05-19 notes: Director and allStorageDaemons must be upgraded together to18.2 because they are incompatible with earlier versions.18.0 introduced catalog1027; upgrading18.0\u219218.2 does not require catalog-conversion script. Version coupling, not licence termination. Evidence A. [new](https://docs.baculasystems.com/BENewFeatures/EnterpriseNewFeatures/index.html); [rn182](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN18.2/index.html)"
    ]
   ],
   "lock": [
    [
     "Formats",
     2.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Director/StorageDaemon and catalog versions must be coordinated, despite broad storage/hypervisor plugins. Daemon/catalog coupling: 10.0 and18.0 notes require Director and Storage Daemons to be upgraded together; catalog-format migration needed. No generic portability guarantee inferred from shared core. Evidence A. [rn100](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN10.0/index.html); [rn180](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN18.0/index.html)"
    ],
    [
     "Hardware / cloud coupling",
     0.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Software disk/cloud/tape targets reduce own-hardware dependency; specific plugin configuration remains. Observed by 2026-10-01: 18.2 Dedup2 configuration;18.2.5 snapshot accelerator; carry-forward source/global dedupe. Full target matrix pending. Evidence A. [rn182](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN18.2/index.html); [rn122](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN12.2/index.html)"
    ],
    [
     "Skills and tooling coupling",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Training: Partner page names Foundation Course and Expert Series; search index said Admin I but live page says Foundation Course. Launch dates/exam prerequisites unresolved. Evidence A. [partner](https://www.baculasystems.com/si-cloud-msp-partner-program/)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Training: Partner page names Foundation Course and Expert Series; search index said Admin I but live page says Foundation Course. Launch dates/exam prerequisites unresolved. Evidence A. [partner](https://www.baculasystems.com/si-cloud-msp-partner-program/)"
    ],
    [
     "Multi-tenancy and self-service",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Native18.0 multitenancy, with provider entitlement separate. REST/automation: BCloud REST service introduced10.0; JSON console output14.0; native multitenancy18.0. Official Terraform provider audit pending. Evidence A. [rn100](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN10.0/index.html); [rn140](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN14.0/index.html); [rn180](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN18.0/index.html)"
    ],
    [
     "API and infrastructure-as-code",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Official Ansible collection and REST/JSON; download count does not establish support SLA. Official Ansible registry observation2026-10-01: baculasystems.bacula_enterprise: cumulative2617 downloads; collection created2023-05-08, latest2.1.0 updated2026-09-07. Installation guide covers directors/storage/clients/plugins; registry creation is not the product launch date. REST/automation: BCloud REST service introduced10.0; JSON console output14.0; native multitenancy18.0. Official Terraform provider audit pending. Evidence A. [ansibleIndex](https://galaxy.ansible.com/api/v3/plugin/ansible/content/published/collections/index/baculasystems/bacula_enterprise/); [ansibleInstall](https://docs.baculasystems.com/pdf/bsys-installation.pdf); [rn100](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN10.0/index.html); [rn140](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN14.0/index.html); [rn180](https://docs.baculasystems.com/BEReleaseNotes/EnterpriseReleaseNotes/RN18.0/index.html)"
    ],
    [
     "Skills and certification",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named hands-on Foundation certification/Expert Series; Oct2 current fee is not a historical licence price. Training: Partner page names Foundation Course and Expert Series; search index said Admin I but live page says Foundation Course. Launch dates/exam prerequisites unresolved. Foundation Course / observation 2026-10-02: Five live online half-days, maximum eight participants; Linux knowledge and systems-administration skills expected. Vendor says completion leads to Bacula Certified status. Listed fee EUR 3,700 / USD 4,200; this is training, not a software licence price or dated price change. First credential launch and exam standard remain unresolved. Evidence A. [partner](https://www.baculasystems.com/si-cloud-msp-partner-program/); [foundationCurrent](https://www.baculasystems.com/bacula-foundation-course/)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Bacula Enterprise is extending plugin coverage and security controls around its daemon and catalog architecture. Release notes establish database, alternative-hypervisor and immutable-target gains without proving an AI model. Coordinated upgrades, proprietary-plugin rights and product-specific administration remain dependencies.",
   "report": "reports/14-bacula_ent.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "agents": {
     "2016": 0,
     "2017": 0,
     "2018": 1.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    }
   },
   "ai_basis": {
    "infra": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "stack": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "ops": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "agents": "Official Ansible registry observation2026-10-01: baculasystems.bacula_enterprise: cumulative2617 downloads; collection created2023-05-08, latest2.1.0 updated2026-09-07. Installation guide covers directors/storage/clients/plugins; registry creation is not the product launch date. Official Ansible plus REST; not an AI model or MCP. Evidence A. [ansibleIndex](https://galaxy.ansible.com/api/v3/plugin/ansible/content/published/collections/index/baculasystems/bacula_enterprise/); [ansibleInstall](https://docs.baculasystems.com/pdf/bsys-installation.pdf)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 1 recorded announcement rows; 1 GA/shipped matches, 0 preview/early/limited at announcement, 0 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "storware",
   "name": "Storware Backup and Recovery",
   "short": "Storware",
   "kind": "product",
   "group": "specialist",
   "since": 2016,
   "archetype": "Alternative hypervisor specialist",
   "grade": "C",
   "driver": "M",
   "mix": {
    "V": 7,
    "C": 20,
    "M": 73,
    "U": 0,
    "P": 0
   },
   "idx": 0.07,
   "domains": {
    "virtual": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 2.5,
     "2023": 3,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "apps": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 1.5,
     "2026": 2
    },
    "recovery": {
     "2016": 1,
     "2017": 2,
     "2018": 2,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 3.5
    },
    "cyber": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 0.5,
     "2022": 2.5,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "storage": {
     "2016": 2,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    },
    "retention": {
     "2016": 0.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 2.5,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "dr": {
     "2016": 0.5,
     "2017": 0.5,
     "2018": 0.5,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "security": {
     "2016": 1,
     "2017": 1,
     "2018": 1,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "platforms": {
     "2016": 2.5,
     "2017": 2.5,
     "2018": 2.5,
     "2019": 4,
     "2020": 4,
     "2021": 4,
     "2022": 4.5,
     "2023": 4.5,
     "2024": 4.5,
     "2025": 4.5,
     "2026": 4.5
    },
    "scale": {
     "2016": 1.5,
     "2017": 1.5,
     "2018": 1.5,
     "2019": 3,
     "2020": 3,
     "2021": 3,
     "2022": 3.5,
     "2023": 3.5,
     "2024": 3.5,
     "2025": 3.5,
     "2026": 4
    }
   },
   "cred": [
    [
     "Cadence",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. 50 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. 6.1 (2023-10-25): Released: OpenStack Instant Restore; multi-Ceph; multiple tape drives; Keycloak MFA Evidence A. [r61](https://storware.eu/wp-content/uploads/2023/10/Storware-Backup-and-Recovery-6.1-Press-Release.pdf)"
    ],
    [
     "Roadmap transparency",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: 8.0 now available at cutoff; earlier Q3 replication promise needs exact feature comparison rather than assumed completion. No open-roadmap-tracker reference score is awarded. 6.1 (2023-10-25): Released: OpenStack Instant Restore; multi-Ceph; multiple tape drives; Keycloak MFA Evidence A. [r61](https://storware.eu/wp-content/uploads/2023/10/Storware-Backup-and-Recovery-6.1-Press-Release.pdf)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 6 items; 5 shipped, 1 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 0; 0 documented within 12 calendar months, 0 later than 12 months, 0 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. Storware/vProtect 7.5 (2026-03-31 changelog; July22 release blog conflicts): Platform9; Citrix/XCP-ng to OpenStack; AHV APIv4; Proxmox Ceph19 and synthetic SSH strategy. Conflicting dates remain unresolved. Evidence A. [changelog](https://docs.storware.eu/whatsnew/changelog)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: Primary search snippet: development focused on latest major/minor; current lifecycle body and exact7.x EOS not retrieved.. Grade C where current contract/EOS boundaries remain unresolved. 2022-09-27\u201328 announced training session: Free technician certification is explicitly linked to higher partner status and additional discounts. Exact first programme launch and historical discount schedule are not supplied by this event notice. Evidence C. [certSession22](https://storware.eu/news/storware-certification-september-27-28-2022/)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Subscription added6.1 while host/VM/TB metrics persist; no unsupported numeric price jump. 2023-10-25: 6.1 adds subscription licence model; exact contract transition terms not found 7.0 versioned licensing: Per-front-end TB; per-host (two sockets); per-VM; server OS Agent and integration-module licence options Evidence A. [r61](https://storware.eu/wp-content/uploads/2023/10/Storware-Backup-and-Recovery-6.1-Press-Release.pdf); [lic](https://docs.storware.eu/70/overview/licensing)"
    ],
    [
     "Purchase constraints",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Multiple metrics and universal-license claim; contract equivalence and exact minimums unverified. 7.0 versioned licensing: Per-front-end TB; per-host (two sockets); per-VM; server OS Agent and integration-module licence options Current marketing: Universal licence/no feature tiers claimed in FAQ; do not assume identical to historical7.0 licence contract Evidence A. [lic](https://docs.storware.eu/70/overview/licensing); [faq](https://storware.eu/faq/)"
    ],
    [
     "Channel and access",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: lic. Certification structure; launch year unverified: Level I Storware Technical Presales:4-hour course and1-hour exam,75% pass. Level II Storware Technical Expert:one-week course/labs, Level I/Linux prerequisites. Free, valid2 years; certification required for higher partner levels. Evidence A. [certDetail](https://storware.eu/certification/)"
    ],
    [
     "Owner stability",
     1,
     "2026-10-01 evidence boundary: Storware; no controlling-owner transaction established in accepted history. Ownership-risk judgement comes from the recorded corporate/financing events; no unrecorded transaction is assumed. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Cost of staying supported",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Legacy source/config retirements and active-support upgrade condition; archive rights not said to end. 2026-10-01: 8.0 RHV deprecation: existing upgraded environments continue, Zadara new configurations no longer allowed. 7.0 changelog2024-09-25 /press2024-09-30: Deprecates Keep-last-backup flag, CentOS7, RHVSSHtransfer, Xen, OracleVirtualizationManager and old nodeCLI. Network-share OS-agent protection requires front-endTB licence. These are versioned lifecycle/entitlement facts, not proof archive-restoration rights cease. Evidence A. [r80](https://storware.eu/news/storware-backup-and-recovery-8-0/); [press70](https://storware.eu/wp-content/uploads/2024/09/Storware-Backup-and-Recovery-7.0-Press-Release.pdf); [changelog](https://docs.storware.eu/whatsnew/changelog)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Supported third-party backup destinations/hypervisors; licensed integration constraints remain. Destination integration: Licensed integration module can use supported third-party backup system as destination; independent extraction conditions not found Observed by 2026-10-01: 8.0 OpenStack2026.1, Everpure CBT under disk attachment; AHVAPIv4 with PrismCentral7.5+; HarvesterVM workflow. RHV deprecated with existing upgrades retained; new Zadara configs disallowed. Evidence A. [lic](https://docs.storware.eu/70/overview/licensing); [r80](https://storware.eu/news/storware-backup-and-recovery-8-0/)"
    ],
    [
     "Hardware / cloud coupling",
     0.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Software targets and integrations, no own-appliance requirement evidenced. Observed by 2026-10-01: 8.0 9lives filesystem target with dedupe/synthetic backups; native Everpure CBT for OpenStack volumes. Tape and other targets require corresponding versioned guides. Evidence A. [r80](https://storware.eu/news/storware-backup-and-recovery-8-0/); [r61](https://storware.eu/wp-content/uploads/2023/10/Storware-Backup-and-Recovery-6.1-Press-Release.pdf)"
    ],
    [
     "Skills and tooling coupling",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Certification structure; launch year unverified: Level I Storware Technical Presales:4-hour course and1-hour exam,75% pass. Level II Storware Technical Expert:one-week course/labs, Level I/Linux prerequisites. Free, valid2 years; certification required for higher partner levels. Evidence A. [certDetail](https://storware.eu/certification/)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Silver/Gold/Platinum engineering/deal requirements and deal discounts documented. Partner tiers / September2024 brochure path; launch date unresolved: Silver/Gold/Platinum; Gold requires one certified engineer/one deal per12months; Platinum two engineers/two deals. Deal-registration additional discounts15/20/25%; training free and NFR conditions vary. Evidence A. [partnerBrochure24](https://storware.eu/wp-content/uploads/2024/09/09_2024_Business-Partner-Brochure-1.pdf)"
    ],
    [
     "Multi-tenancy and self-service",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: Central6.1 notifications/job history and agent reports; current IaC/API download counts unverified Evidence C. [r61](https://storware.eu/wp-content/uploads/2023/10/Storware-Backup-and-Recovery-6.1-Press-Release.pdf)"
    ],
    [
     "API and infrastructure-as-code",
     3.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: Central6.1 notifications/job history and agent reports; current IaC/API download counts unverified Evidence C. [r61](https://storware.eu/wp-content/uploads/2023/10/Storware-Backup-and-Recovery-6.1-Press-Release.pdf)"
    ],
    [
     "Skills and certification",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Free LevelI/II curricula and exams; existence by2022, not a proven first-launch year. Certification structure; launch year unverified: Level I Storware Technical Presales:4-hour course and1-hour exam,75% pass. Level II Storware Technical Expert:one-week course/labs, Level I/Linux prerequisites. Free, valid2 years; certification required for higher partner levels. Certification existed by September 2022: Vendor advertises a free technical certification session for September 27\u201328, 2022: two four-hour sessions with theory, installation/administration workshops and an exam. Certification enables higher partner levels and discounts. This proves a dated session, not the first-ever launch year or today\u2019s Level I/II exam structure. Evidence A. [certDetail](https://storware.eu/certification/); [certSession22](https://storware.eu/news/storware-certification-september-27-28-2022/)"
    ]
   ],
   "alt": null,
   "ranked": true,
   "reading": "Storware is expanding alternative-hypervisor coverage and restore paths with a channel-led delivery model. Release evidence shows early KVM and Proxmox coverage, later physical agents and an 8.0 release at the cutoff. Database depth, current tape limits and lifecycle changes constrain confidence outside virtualization.",
   "report": "reports/15-storware.md",
   "ai": {
    "infra": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "stack": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "ops": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "agents": {
     "2016": 0,
     "2017": 0,
     "2018": 0,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 1.5,
     "2026": 1.5
    }
   },
   "ai_basis": {
    "infra": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "stack": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "ops": "2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.",
    "agents": "End-2019 checkpoint: 3.1 central multiple nodes/REST;3.1.4 tag/regex auto-assignment;3.9 Ansible installer. REST3.1 and Ansible installer3.9; no official MCP. Evidence A. [changelog](https://docs.storware.eu/whatsnew/changelog)"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 0 recorded announcement rows; 0 GA/shipped matches, 0 preview/early/limited at announcement, 0 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "huawei",
   "name": "Huawei OceanProtect DataBackup (software)",
   "short": "Huawei",
   "kind": "product",
   "group": "regional",
   "since": 2023,
   "archetype": "Software eligibility unresolved",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 0,
    "C": 90,
    "M": 0,
    "U": 0,
    "P": 10
   },
   "idx": 0.0,
   "domains": {
    "virtual": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 2.5
    },
    "apps": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 1,
     "2024": 1,
     "2025": 2.5,
     "2026": 2.5
    },
    "recovery": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 3,
     "2024": 3,
     "2025": 3,
     "2026": 3
    },
    "cyber": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 1,
     "2024": 1,
     "2025": 1.5,
     "2026": 1.5
    },
    "storage": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 2,
     "2024": 2,
     "2025": 3,
     "2026": 3
    },
    "retention": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "dr": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 2.5
    },
    "security": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "platforms": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 0.5,
     "2024": 0.5,
     "2025": 1,
     "2026": 1
    },
    "scale": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    }
   },
   "cred": [
    [
     "Cadence",
     1,
     "Scored 2026-10-03 from the accepted cutoff fact base. 12 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. OceanProtect DataBackup1.6.0 security target (not found): Public security-target document identifies software1.6.0/V200R001C10; version identity is not GA-date proof Evidence A. [st](https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_huawei_oceanprotect160_v1.10.pdf)"
    ],
    [
     "Roadmap transparency",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. OceanProtect DataBackup1.6.0 security target (not found): Public security-target document identifies software1.6.0/V200R001C10; version identity is not GA-date proof Evidence A. [st](https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_huawei_oceanprotect160_v1.10.pdf)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 0 items; 0 shipped, 0 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 0; 0 documented within 12 calendar months, 0 later than 12 months, 0 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. V200R001C32 (2026-04-30 DOCUMENT publication): Release-note/version-mapping publication; feature body entitlement gated. Evidence A. [releasecatalog](https://support.huawei.com/enterprise/en/data-protection/oceanprotect-databackup-pid-258115661?category=release-documents)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: not found. Grade C where current contract/EOS boundaries remain unresolved. 2023-12-20: Huawei announces future open-eBackup open-source project alongsideOceanProtect hardware launches. open-eBackup is excluded under user scope; announcement does not establish separate commercialDataBackup softwareGA or say all commercialsoftware licences became open-source. Evidence C. [opensource23](https://www.huawei.com/cn/news/2023/12/oceanprotect-2023launch)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2023-12-20: Huawei announces future open-eBackup open-source project alongsideOceanProtect hardware launches. open-eBackup is excluded under user scope; announcement does not establish separate commercialDataBackup softwareGA or say all commercialsoftware licences became open-source. Evidence C. [opensource23](https://www.huawei.com/cn/news/2023/12/oceanprotect-2023launch)"
    ],
    [
     "Purchase constraints",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Software scope: Separately documented DataBackup software; OceanProtect X/E appliance announcements excluded from software-release ledger Evidence A. [product](https://e.huawei.com/en/products/storage/oceanprotect/databackup)"
    ],
    [
     "Channel and access",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: st. OceanClub2026: Twelve elite-expert certificates awarded to Latam customer/partner experts; certification launch/requirements/download counts not established. Evidence A. [latam26](https://e.huawei.com/de/news/2026/solutions/storage/data-storage-products-solutions)"
    ],
    [
     "Owner stability",
     2.5,
     "2026-10-01 evidence boundary: Huawei; corporate-control detail not researched for this backup-software candidate. Ownership-risk judgement comes from the recorded corporate/financing events; no unrecorded transaction is assumed. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Cost of staying supported",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Support/upgrade constraints, distinct from licence-expiry restoration: not found. 2023-12-20: Huawei announces future open-eBackup open-source project alongsideOceanProtect hardware launches. open-eBackup is excluded under user scope; announcement does not establish separate commercialDataBackup softwareGA or say all commercialsoftware licences became open-source. Evidence C. [opensource23](https://www.huawei.com/cn/news/2023/12/oceanprotect-2023launch)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     2.5,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Software/control plane: Software security target specifies TOE components, roles and evaluated configuration; not portability or all-deployment certification Evidence C. [st](https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_huawei_oceanprotect160_v1.10.pdf)"
    ],
    [
     "Hardware / cloud coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Software/control plane: Software security target specifies TOE components, roles and evaluated configuration; not portability or all-deployment certification Evidence C. [st](https://www.commoncriteriaportal.org/nfs/ccpfiles/files/epfiles/st_huawei_oceanprotect160_v1.10.pdf)"
    ],
    [
     "Skills and tooling coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. OceanClub2026: Twelve elite-expert certificates awarded to Latam customer/partner experts; certification launch/requirements/download counts not established. Evidence A. [latam26](https://e.huawei.com/de/news/2026/solutions/storage/data-storage-products-solutions)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. OceanClub2026: Twelve elite-expert certificates awarded to Latam customer/partner experts; certification launch/requirements/download counts not established. Evidence A. [latam26](https://e.huawei.com/de/news/2026/solutions/storage/data-storage-products-solutions)"
    ],
    [
     "Multi-tenancy and self-service",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: Software data sheetp3 advertises unified GUI/wizard cluster management, AI assistant/intelligent scheduling, alarms/SNMP/email and PDF/Excel reports. Management plane marketed as software; assistant read/recommend/act permissions and exact GA not documented. Evidence C. [softwareSheet25](https://e-file.huawei.com/marketingcloud/pep/asset/20000001/Material/794c96cf9ef24590951eaba61222b6c7/M3T1A590N1244332150078193852/Huawei%20OceanProtect%20DataBackup%20-%20Data%20Sheet%20V2.pdf)"
    ],
    [
     "API and infrastructure-as-code",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: Software data sheetp3 advertises unified GUI/wizard cluster management, AI assistant/intelligent scheduling, alarms/SNMP/email and PDF/Excel reports. Management plane marketed as software; assistant read/recommend/act permissions and exact GA not documented. Evidence C. [softwareSheet25](https://e-file.huawei.com/marketingcloud/pep/asset/20000001/Material/794c96cf9ef24590951eaba61222b6c7/M3T1A590N1244332150078193852/Huawei%20OceanProtect%20DataBackup%20-%20Data%20Sheet%20V2.pdf)"
    ],
    [
     "Skills and certification",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named certification and hands-on curricula earn credit; first-launch or current credential gaps are retained. OceanClub2026: Twelve elite-expert certificates awarded to Latam customer/partner experts; certification launch/requirements/download counts not established. Evidence A. [latam26](https://e.huawei.com/de/news/2026/solutions/storage/data-storage-products-solutions)"
    ]
   ],
   "alt": null,
   "ranked": false,
   "reading": "Huawei documents backup software alongside a larger appliance portfolio. The software guide establishes VM recovery paths, while current claims lack complete version and availability evidence. The resulting reference scores remain outside rankings because eligibility and delivery cannot be established with confidence.",
   "report": "reports/16a-huawei.md",
   "ai": {
    "infra": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 0,
     "2024": 0,
     "2025": 0.5,
     "2026": 0.5
    },
    "stack": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "ops": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 0,
     "2024": 0,
     "2025": 0.5,
     "2026": 0.5
    },
    "agents": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": null,
     "2020": null,
     "2021": null,
     "2022": null,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    }
   },
   "ai_basis": {
    "infra": "2026-10-01 observation; vendor marketing; GA unverified: Product page mentions AI/emerging workloads; vector/model consistency, restore granularity and GA date not found. AI protection claim without verified software GA: half-step only. Evidence C. [product](https://e.huawei.com/en/products/storage/oceanprotect/databackup)",
    "stack": "none",
    "ops": "2026-10-01 observation; vendor marketing; GA unverified: Product page mentions AI/emerging workloads; vector/model consistency, restore granularity and GA date not found. Software assistant claim without documented GA/tool scope: half-step only. Evidence C. [product](https://e.huawei.com/en/products/storage/oceanprotect/databackup)",
    "agents": "none"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 0 recorded announcement rows; 0 GA/shipped matches, 0 preview/early/limited at announcement, 0 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  },
  {
   "key": "sangfor",
   "name": "Sangfor backup / DR software candidate",
   "short": "Sangfor",
   "kind": "product",
   "group": "regional",
   "since": 2019,
   "archetype": "Integrated platform candidate",
   "grade": "C",
   "driver": "C",
   "mix": {
    "V": 0,
    "C": 100,
    "M": 0,
    "U": 0,
    "P": 0
   },
   "idx": 0.0,
   "domains": {
    "virtual": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 1.5,
     "2026": 2.5
    },
    "apps": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 0.5,
     "2022": 0.5,
     "2023": 0.5,
     "2024": 0.5,
     "2025": 0.5,
     "2026": 1
    },
    "recovery": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 2,
     "2020": 2,
     "2021": 2,
     "2022": 2,
     "2023": 2,
     "2024": 2,
     "2025": 2,
     "2026": 2
    },
    "cyber": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 0.5,
     "2022": 0.5,
     "2023": 0.5,
     "2024": 0.5,
     "2025": 0.5,
     "2026": 2
    },
    "storage": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 1.5,
     "2026": 2.5
    },
    "retention": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 1,
     "2020": 1,
     "2021": 1,
     "2022": 1,
     "2023": 1,
     "2024": 1,
     "2025": 1,
     "2026": 1
    },
    "dr": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 2.5,
     "2020": 2.5,
     "2021": 2.5,
     "2022": 2.5,
     "2023": 2.5,
     "2024": 2.5,
     "2025": 2.5,
     "2026": 3.5
    },
    "security": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 1,
     "2020": 1,
     "2021": 1,
     "2022": 1,
     "2023": 1,
     "2024": 1,
     "2025": 1,
     "2026": 2
    },
    "platforms": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 0.5,
     "2020": 0.5,
     "2021": 0.5,
     "2022": 0.5,
     "2023": 0.5,
     "2024": 0.5,
     "2025": 0.5,
     "2026": 0.5
    },
    "scale": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 1.5,
     "2020": 1.5,
     "2021": 1.5,
     "2022": 1.5,
     "2023": 1.5,
     "2024": 1.5,
     "2025": 1.5,
     "2026": 2.5
    }
   },
   "cred": [
    [
     "Cadence",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. 17 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. HCI brochure (2025-10 document identity): Backup/CDP/DR modules described; brochure identifier20251014 is not software-release/GA date Evidence A. [brochure](https://www.sangfor.com/sites/default/files/2025-10/Sangfor_HCI_Brochure.pdf)"
    ],
    [
     "Roadmap transparency",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. HCI brochure (2025-10 document identity): Backup/CDP/DR modules described; brochure identifier20251014 is not software-release/GA date Evidence A. [brochure](https://www.sangfor.com/sites/default/files/2025-10/Sangfor_HCI_Brochure.pdf)"
    ],
    [
     "Say-do",
     2.5,
     "Recorded ledger: 0 items; 0 shipped, 0 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 0; 0 documented within 12 calendar months, 0 later than 12 months, 0 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F."
    ],
    [
     "Velocity",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. SCP/HCI6.12.0 (Feature documentation updated2026-09-15): Automatic successful-backup email within1 hour and backup report export; rolling upgrades migrate VMs back; operator-IP audit logs. Linked-clone VDI recovery and GPU passthrough are adjacent features, not coordinated AI workload backup. Evidence A. [scp612](https://support.sangfor.com/productDocument/read?product_id=45&version_id=1388&category_id=2655896)"
    ],
    [
     "Lifecycle stability",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Accepted lifecycle finding: not found. Grade C where current contract/EOS boundaries remain unresolved. 6.8 version; GA day unresolved: Offline licence changes no longer require returning/reapplying USB key; virtual licence scope remains HCI. Evidence C. [archive680](https://support.sangfor.com/productDocument/read?product_id=10&version_id=1065&category_id=2645718)"
    ]
   ],
   "comm": [
    [
     "Price and licence volatility",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. 2023\u2013cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. Current undated CBR offer observed2026-10-01: Cloud backup offer lists5TB storage,50M full/10M incremental bandwidth and one validation service; no price or first launch date disclosed. Evidence C. [cbr](https://www.sangfor.com.cn/sangfor-cloud/cbr)"
    ],
    [
     "Purchase constraints",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Integrated HCI modules: Brochure lists different CPU/VM/capacity module metrics; exact standalone backup SKU/price and entitlement not verified Evidence A. [brochure](https://www.sangfor.com/sites/default/files/2025-10/Sangfor_HCI_Brochure.pdf)"
    ],
    [
     "Channel and access",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Partner entry and public documentation access are both considered. Research documentation finding: brochure. Official API observation2026-10-01: Guest SCP6.12 API page updated2026-09-02 lists67.96MB ZIP,12 downloads. This is vendor-document downloads, not Terraform/Ansible registry usage. Direct file retrieval returned HTML, not the API ZIP. Evidence A. [scpapi](https://support.sangfor.com/productDocument/read?product_id=45&version_id=1388&category_id=2656904)"
    ],
    [
     "Owner stability",
     2.5,
     "2026-10-01 evidence boundary: Sangfor; current control/ownership history not established for the standalone backup candidate. Ownership-risk judgement comes from the recorded corporate/financing events; no unrecorded transaction is assumed. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Cost of staying supported",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Support/upgrade constraints, distinct from licence-expiry restoration: not found. 6.8 version; GA day unresolved: Offline licence changes no longer require returning/reapplying USB key; virtual licence scope remains HCI. Evidence C. [archive680](https://support.sangfor.com/productDocument/read?product_id=10&version_id=1065&category_id=2645718)"
    ]
   ],
   "lock": [
    [
     "Formats",
     3.5,
     "2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Export path",
     3,
     "2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C."
    ],
    [
     "Stack coupling",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Built-in HCI management and service dependencies; no independent backup-engine eligibility established. Stack coupling: Chinese product page presents built-in Sangfor HCI backup/CDP. Brochure describes VMware integration and heterogeneous DR; standalone management-plane eligibility not demonstrated. Evidence A. [product](https://www.sangfor.com.cn/sangfor-cloud/data-backup); [brochure](https://www.sangfor.com/sites/default/files/2025-10/Sangfor_HCI_Brochure.pdf)"
    ],
    [
     "Hardware / cloud coupling",
     4,
     "Scored 2026-10-03 from the accepted cutoff fact base. Heterogeneous agent recovery targets Sangfor hosted-cloud resources; not arbitrary portable export. Recovery destination: Chinese heterogeneous DRaaS recovers agent-protected workloads into Sangfor hosted-cloud resources; do not treat this as portable native backup export. Evidence A. [draas](https://www.sangfor.com.cn/sangfor-cloud/draas)"
    ],
    [
     "Skills and tooling coupling",
     3,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Official API observation2026-10-01: Guest SCP6.12 API page updated2026-09-02 lists67.96MB ZIP,12 downloads. This is vendor-document downloads, not Terraform/Ansible registry usage. Direct file retrieval returned HTML, not the API ZIP. Evidence A. [scpapi](https://support.sangfor.com/productDocument/read?product_id=45&version_id=1388&category_id=2656904)"
    ]
   ],
   "integ": [
    [
     "Partner programme openness",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Official API observation2026-10-01: Guest SCP6.12 API page updated2026-09-02 lists67.96MB ZIP,12 downloads. This is vendor-document downloads, not Terraform/Ansible registry usage. Direct file retrieval returned HTML, not the API ZIP. Evidence A. [scpapi](https://support.sangfor.com/productDocument/read?product_id=45&version_id=1388&category_id=2656904)"
    ],
    [
     "Multi-tenancy and self-service",
     2.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 6.12 backup report exports and successful-backup email within1 hour;6.11.2 NetBackup integration job-ID traceability; API documentation still requires inspection. Evidence C. [scp612](https://support.sangfor.com/productDocument/read?product_id=45&version_id=1388&category_id=2655896)"
    ],
    [
     "API and infrastructure-as-code",
     1.5,
     "Scored 2026-10-03 from the accepted cutoff fact base. Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: 6.12 backup report exports and successful-backup email within1 hour;6.11.2 NetBackup integration job-ID traceability; API documentation still requires inspection. Evidence C. [scp612](https://support.sangfor.com/productDocument/read?product_id=45&version_id=1388&category_id=2655896)"
    ],
    [
     "Skills and certification",
     2,
     "Scored 2026-10-03 from the accepted cutoff fact base. Named certification and hands-on curricula earn credit; first-launch or current credential gaps are retained. Official API observation2026-10-01: Guest SCP6.12 API page updated2026-09-02 lists67.96MB ZIP,12 downloads. This is vendor-document downloads, not Terraform/Ansible registry usage. Direct file retrieval returned HTML, not the API ZIP. Evidence A. [scpapi](https://support.sangfor.com/productDocument/read?product_id=45&version_id=1388&category_id=2656904)"
    ]
   ],
   "alt": null,
   "ranked": false,
   "reading": "Sangfor presents backup and DR capabilities across HCI and cloud services. Public platform notes and service pages describe CDP, WORM and recovery paths with workload restrictions. Standalone backup-software eligibility remains unresolved, so these reference scores are excluded from rankings.",
   "report": "reports/16b-sangfor.md",
   "ai": {
    "infra": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "stack": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "ops": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    },
    "agents": {
     "2016": null,
     "2017": null,
     "2018": null,
     "2019": 0,
     "2020": 0,
     "2021": 0,
     "2022": 0,
     "2023": 0,
     "2024": 0,
     "2025": 0,
     "2026": 0
    }
   },
   "ai_basis": {
    "infra": "none",
    "stack": "none",
    "ops": "none",
    "agents": "none"
   },
   "ai_ledger": null,
   "ai_reading": "AI say-do sample: 0 recorded announcement rows; 0 GA/shipped matches, 0 preview/early/limited at announcement, 0 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. \"Shipped\" may be a vendor availability assertion rather than an independently verified first-GA day. "
  }
 ]
}