Mr.PlanB Logo
    Enterprise Backup Ledger 2026
    Ledger
    Enterprise Backup Ledger 2026

    Rubrik Security Cloud: Enterprise Backup Ledger 2026

    Rubrik is extending backup security into identity and AI-agent resilience.

    Edition October 3, 20266 min read

    Part of the Enterprise Backup Ledger (edition 2026-10-03). How the scores work: methodology.

    Snapshot

    • Tier: Leader incumbent
    • Owner: Rubrik; April 2024 IPO recorded, with Laminar/Predibase/Strata acquisitions separately dated.
    • Licence model: Current CDM/RSC tier entitlements and list prices incomplete; MSP PayGo zero minimums announced March 2026.
    • Products scored: CDM/RSC data-centre protection; Agent Cloud is separate and contributes only explicitly labelled AI strand observations.
    • Latest release: CDM latest GA/build not found; RSC MCP private preview, separate clock
    • Next signal: MCP GA: 2026-10 per 2026-09-15 press release; Japanese page snippet targets 2026-09-30, failed opening
    • Archetype: Backup security expansion
    • Evidence grade: B. History rebuilt from a reviewer fact pass with mostly grade-A dates (rubrik.com read via Wayback); some CDM 6.0 items grade B.

    Scope of the scores: Product capability cutoff 2026-10-01; scoring edition 2026-10-03. Combined portfolio scores do not imply one SKU or uniform feature parity. History is evidence-bounded; freezes and first-feature GA dates can be incomplete. AI services named in the AI section do not broaden the ten core domains.

    Scorecard

    DimensionScoreDirection
    Capability today85.4 / 100higher is better
    Momentum since end of 2022+6.2 pointshigher is better
    Credibility13.5 / 25higher is better
    Commercial risk12.5 / 25lower is better
    Technical lock-in14.0 / 25lower is better
    Integrator fit15.0 / 20higher is better
    AI leverage8.0 / 20higher is better
    Ledger Index63.1 / 100balanced weights

    Capability by domain

    Scores 0 to 5 against fixed anchors; total is weighted to 100.

    Domain (weight)201620192022Today
    Virtual and physical servers (12)3444.5
    Databases and applications (12)3444.5
    Recovery (14)3.544.54.5
    Cyber resilience (14)1.5344.5
    Storage efficiency and targets (10)3.5444
    Long-term retention and tape (6)22.533
    Replication and DR (10)3444
    Security and compliance (8)3.53.544.5
    New-platform support (VMware exit) (8)0334
    Management at scale and automation (6)344.54.5
    Total / 10053.073.079.285.4

    Year by year: 2016: 53.0 · 2017: 67.0 · 2018: 70.2 · 2019: 73.0 · 2020: 73.6 · 2021: 77.2 · 2022: 79.2 · 2023: 81.8 · 2024: 82.6 · 2025: 83.4 · 2026: 85.4

    What moved the score

    YearDomainChangePointsTrigger
    2017Cyber resilience1.5 → 2.5+2.8Alta 4.0/4.1 (2017): explicitly immutable backups; Glacier Vault Lock archive. Source: Ledger review fact pass, 2026-10-03
    2017Databases and applications3 → 3.5+1.2Alta 4.0: Oracle RMAN/ASM, SQL Server Live Mount. Source: Ledger review fact pass, 2026-10-03
    2017Long-term retention and tape2 → 2.5+0.6Tape only through the QStar partner product (4.0); Glacier archive. Source: Ledger review fact pass, 2026-10-03
    2017New-platform support (VMware exit)0 → 3+4.8Alta 4.0: Nutanix AHV agentless. Source: Ledger review fact pass, 2026-10-03
    2017Recovery3.5 → 4+1.4Alta 4.0/4.1: CloudOn cross-platform restore VMware to AWS (2017-06) and Azure (2017-09). Source: Ledger review fact pass, 2026-10-03
    2017Replication and DR3 → 3.5+1.0CloudOn DR to AWS (2017-06) and Azure (2017-09). Source: Ledger review fact pass, 2026-10-03
    2017Storage efficiency and targets3.5 → 4+1.0Alta 4.1: GCP and Glacier archive; tape through QStar from 4.0. Source: Ledger review fact pass, 2026-10-03
    2017Virtual and physical servers3 → 3.5+1.2Alta 4.0 (2017-06): Hyper-V and Nutanix AHV agentless; Windows physical (3.1, 2017-02). Source: Ledger review fact pass, 2026-10-03
    2018Cyber resilience2.5 → 3+1.4Polaris Radar ML anomaly / ransomware detection GA 2018-07-25. Source: Ledger review fact pass, 2026-10-03
    2018Management at scale and automation3 → 3.5+0.6Polaris SaaS control plane (2018-04). Source: Ledger review fact pass, 2026-10-03
    2018Virtual and physical servers3.5 → 4+1.2Alta 4.2 (2018-06): AIX and Solaris. Source: Ledger review fact pass, 2026-10-03
    2019Databases and applications3.5 → 4+1.2Andes 5.0 (GA 2019-01-31): Oracle Live Mount, SAP-certified HANA; Exchange since 4.2 (2018). Source: Ledger review fact pass, 2026-10-03
    2019Management at scale and automation3.5 → 4+0.6Terraform provider v1.0 (2019-01); Ansible modules. Source: Ledger review fact pass, 2026-10-03
    2019Replication and DR3.5 → 4+1.0Andes 5.1 (2019-08): VMware CDP; Polaris AppFlows DR orchestration to AWS. Source: Ledger review fact pass, 2026-10-03
    2020Long-term retention and tape2.5 → 3+0.6Andes 5.3 (2020-11): smart tiering to cold archive. Source: Ledger review fact pass, 2026-10-03
    2021Cyber resilience3 → 3.5+1.4S3 Object Lock 2021-11; mass ransomware recovery. Source: Ledger review fact pass, 2026-10-03
    2021Recovery4 → 4.5+1.4CDM 6.0 (2021-07): mass/bulk ransomware recovery, in-place reverse-CBT VMware recovery; Windows bare metal since Andes 5.0. Source: Ledger review fact pass, 2026-10-03
    2021Security and compliance3.5 → 4+0.8CDM 6.0: TOTP MFA; global MFA enforcement. Source: Ledger review fact pass, 2026-10-03
    2022Cyber resilience3.5 → 4+1.4Threat hunting (announced 2021-12), threat containment (2022-05), Rubrik Cloud Vault isolated vault (early 2022). Source: Ledger review fact pass, 2026-10-03
    2022Management at scale and automation4 → 4.5+0.6Rubrik Security Cloud (2022-05) central management with multi-tenancy. Source: Ledger review fact pass, 2026-10-03
    2023Cyber resilience4 → 4.5+1.4Rubrik Cyber Recovery: isolated clean-room recovery and recovery-plan testing, GA early 2023. Source: Ledger review fact pass, 2026-10-03
    2023Databases and applications4 → 4.5+1.2CDM 8.x: Db2 incl. HA/DR (8.1, 2023). Source: Ledger review fact pass, 2026-10-03
    2024Security and compliance4 → 4.5+0.8RSC quorum (multi-person) authorization by 2024-05; FedRAMP RSC Government 2024. Source: Ledger review fact pass, 2026-10-03
    2025New-platform support (VMware exit)3 → 3.5+0.8OpenShift Virtualization supported (2025-02); OpenStack announced 2025-06. Source: Ledger review fact pass, 2026-10-03
    2026New-platform support (VMware exit)3.5 → 4+0.8Oracle Linux Virtualization Manager GA 2026-01; Proxmox VE GA 2026-04; no XCP-ng or proven cross-hypervisor restore. Source: Ledger review fact pass, 2026-10-03
    2026Virtual and physical servers4 → 4.5+1.2RSC: Oracle Linux Virtualization Manager GA 2026-01, Proxmox VE GA 2026-04. Source: Ledger review fact pass, 2026-10-03

    Direction, 2023 to 2026

    Each item carries one theme and one driver (V vision, C customer need, M market window, U upstream, P portfolio).

    DateItemThemeDriver
    2023-04Zscaler DLP integration: partial; By2024-04-10 Government launch; first GA unresolved. Later Government press lists integration; developer instructions remain login-gated. Deadline fulfillment not established.D10 Scale and automationC
    2023-05User Intelligence time-series access risk: partial; Original first GA unresolved. EPE2024 documents access-policy/data activity insight; feature identity/first deadline still uncertain.D10 Scale and automationC
    2023-08VMware AI-guided cyber recovery: pending; First GA unverified. Azure OpenAI task recommendations; layered clean-file recovery over gold-master VM described in future tense. Demo is not GA.D4 Cyber resilienceC
    2023-11Ruby assistant: pending; not found. Initial promise specifies coming months and opt-in; first matching rollout/build remains unverified.D7 AI-assisted operationsV
    2024-03EPE DSPM cloud/on-prem: shipped; 2024-03-12 assertion. Primary GA press; entitlement edition specified, exact RSC rollout/build not exposed.D10 Scale and automationC
    2024-08Mandiant threat feeds and Google clean room: partial; By2024-08-07; original GA unresolved. Threat-intelligence integration/clean-room collaboration; native on-prem release cross-check unresolved.D4 Cyber resilienceC
    2024-12Cloud Vault on AWS: shipped; By2025-03-04 release announcement; first day unresolved. March release and availability blog corroborate managed immutable AWS archive; not on-prem CDM GA.D4 Cyber resilienceC
    2025-04Identity Resilience: partial; First GA unresolved. June2026 adds Identity Continuity and Roll Forward; this does not date original suite GA.D9 SecurityC
    2025-09Agent Rewind: partial; Included in Agent Cloud GA2026-02-18; first stand-alone GA unresolved. Announcement referred to August2025 Rewind; September 9 results are later, not original launch. February GA blog describes restore of affected assets from snapshots; workload coverage and first independent GA remain unresolved.D10 Scale and automationC
    2025-09Amazon DynamoDB protection: partial; First release unresolved. Separate cloud service; release-by-release first availability still needs verification.D10 Scale and automationC
    2025-09Amazon RDS PostgreSQL immutability: partial; First release unresolved. Separate AWS database service capability; no inference of on-prem PostgreSQL delivery.D2 Databases and applicationsC
    2026-06Autonomous Business Recovery for Cloud Applications: pending; GA not established. Dependencies across code/configuration/identity/data; automated network then compute then data restoration. Explicit Private Preview prevents recording launch as GA.D3 RecoveryC
    2026-06Identity Continuity / Roll Forward: partial; Versioned GA unresolved. August 27 results reiterate capabilities; backup and identity components have distinct clocks.D9 SecurityC
    2026-06Rubrik AI agentic recovery: partial; Customer-use claim by 2026-09-15; first GA unresolved. June 9 claim compared with September 15 customer-use statement; release-note and permissions audit incomplete.D7 AI-assisted operationsV
    2026-09Official MCP: pending; not found. Target dates conflict; installable docs do not prove GAD11 Ecosystem opennessV
    • Centre of gravity: Scale and automation (5), Cyber resilience (3), AI-assisted operations (2)
    • Driver mix: Vision 20%, Customer need 80%, Market window 0%, Upstream 0%, Portfolio 0%

    Credibility: 13.5 / 25

    CriterionScoreBasis
    Cadence313 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Ruby (2023-11-07): Announced; earliest GA not found Evidence A. ruby
    Roadmap transparency2Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; press and developer documentation used. No open-roadmap-tracker reference score is awarded. Ruby (2023-11-07): Announced; earliest GA not found Evidence A. ruby
    Say-do2.5Recorded ledger: 34 items; 6 shipped, 14 partial, 0 slipped, 14 pending, 0 dropped. Mature dated prospective cohort: 17; 2 documented within 12 calendar months, 0 later than 12 months, 15 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F.
    Velocity3.5Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. RSC shared-cluster MSP capabilities (2026-09-24 early access; GA later 2026 target): Tenant accounts, network connectors, cross-cluster replication. Per-tenant cryptographic isolation/customer keys still roadmap. Evidence A. mspSep26
    Lifecycle stability2.5Major CDM releases generally 18 months; minor releases inherit major EOS per accepted lifecycle example. 2021-07-20: CDM 6.0.0: GA date from lifecycle example; feature reconstruction not found Evidence A. life

    Say-do record, 2023 to 2026: Recorded ledger: 34 items; 6 shipped, 14 partial, 0 slipped, 14 pending, 0 dropped. Mature dated prospective cohort: 17; 2 documented within 12 calendar months, 0 later than 12 months, 15 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample.

    Commercial risk: 12.5 / 25 (lower is better)

    CriterionScoreBasis
    Price and licence volatility2.52023 to cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2024-04-24: IPO priced 23.5m ClassA shares at 32USD; April 25 trading/April 29 closing targets are prospective Evidence C. ipo
    Purchase constraints2.5MSP zero-minimum PayGo is documented, but universal enterprise minimums and tier contracts remain unknown. 2026-03-18: MSP PayGo starts with zero minimums then contractual scale; new MSP benefit tiers and 24/7 incident response live. Rubrik Verified separately planned for summer. No unit price stated. Evidence C. mspMarch26
    Channel and access3Partner entry and public documentation access are both considered. Research documentation finding: table. Official automation: Python and PowerShell tools; GraphQL/REST; Task-Based REST Beta Evidence A. dev; tools
    Owner stability1IPO is not an acquisition or forced ownership merger; low owner-change risk relative to recently merged portfolios. 2024-04: SEC filing confirms IPO completed during April; exact closing day not established Evidence A. sec
    Cost of staying supported3.5Support/upgrade constraints, distinct from licence-expiry restoration: CDM major releases: 18 months from GA; minor/patch releases inherit major EOS. Lifecycle example 6.0 EOS 2023-01-19.. 2021-09-01 settlement announcement: Commvault reports an amicable agreement resolving all outstanding patent litigation with Rubrik. Public blog does not disclose payments or licensing terms; no court finding of infringement or corresponding Cohesity outcome is inferred. Evidence C. rubrikSettlement21

    Security record of the product itself: No in-scope match located in the accepted security-record.md manual product-name filter of the CISA 2026-09-30 catalogue; no deduction. This is not an exhaustive advisory audit or a claim of no exploitation. Arcserve CVE-2015-4068 was added to KEV in 2022, outside the adjustment window. Adjacent array/infrastructure/hosting-plugin CVEs are excluded. Security record: CISA Known Exploited Vulnerabilities catalogue and vendor advisories.

    Technical lock-in: 14.0 / 25 (lower is better)

    CriterionScoreBasis
    Formats3.52026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C.
    Export path2.52026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C.
    Stack coupling2.5The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. API access: RSC GraphQL and CDM REST differ. Product RBAC and entitlements still apply. Evidence C. dev
    Hardware / cloud coupling3Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. API access: RSC GraphQL and CDM REST differ. Product RBAC and entitlements still apply. Evidence C. dev
    Skills and tooling coupling2.5Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Official automation: Python and PowerShell tools; GraphQL/REST; Task-Based REST Beta Evidence A. dev; tools

    Integrator fit: 15.0 / 20

    CriterionScoreBasis
    Partner programme openness4Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Official automation: Python and PowerShell tools; GraphQL/REST; Task-Based REST Beta Evidence A. dev; tools
    Multi-tenancy and self-service3.5Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: RSC GraphQL / CDM REST; Task-Based REST explicitly Beta Evidence C. r52; ruby; dev
    API and infrastructure-as-code4Official Terraform and GraphQL/CDM REST; support entitlements remain separate. Terraform registry observation 2026-10-01: rubrikinc/rubrik: 50,978 total downloads; current version 1.10.0, published 2026-09-07. Publisher source repository: https://github.com/rubrikinc/terraform-provider-rubrik. Counts are registry requests/downloads, not distinct installations; vendor support obligations are separate. Evidence A. regapi
    Skills and certification3.5Partner credentials/Academy evidence exists, but complete named exam structure is incomplete. Official automation: Python and PowerShell tools; GraphQL/REST; Task-Based REST Beta Evidence C. dev; tools

    AI leverage: 8.0 / 20

    StrandTodayLatest step
    AI for protection / protecting AI3.52026: 2025-10-22 early access →2026-02-18 GA; Separate Agent Cloud service GA: Agent Rewind relates destructive changes to healthy backup snapshots; asset recovery described. This is agent-action resilience, not proved vector/model-registry backup. Agent Rewind GA adds agent-action recovery; no vector/model-consistency assertion. Evidence A. rac; racga
    AI platform stack0.52026: 2025-07 acquisition /2026-08-27 availability claim; Restricted availability: Predibase model customization/serving acquisition plus Annapurna enterprise data layer; Annapurna available to qualified enterprise partners. Not blanket GA of the complete AI stack. Annapurna restricted partners; only half-step for non-GA availability. Evidence A. sec26; results26
    AI-assisted operations12026: 2026-06-09 /2026-09-15; Launch plus customer-use claim: Rubrik AI reasons/acts across RSC and RAC, orchestrates recovery; auditable/attributable/reversible guardrails claimed. Concrete tool scopes, consent workflow and audit-retention details remain unverified. Customer-use/launch claim without explicit first-GA or tool approval contract; at most half-step over prior preview. Evidence A. agent26; mcp
    Agent openness32026: 2026-09-15; private preview: Official MCP. Python tool provides policy gates for write actions; no GA confirmation found. Specific AI openness anchor: official MCP private preview is 3; no GA4/5. Evidence A. mcp; mcpdocs

    AI say-do sample: 6 recorded announcement rows; 0 GA/shipped matches, 1 preview/early/limited at announcement, 3 partial, 3 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. "Shipped" may be a vendor availability assertion rather than an independently verified first-GA day.

    Reading

    Rubrik is extending backup security into identity and AI-agent resilience. The record establishes Radar, database integrations and Agent Cloud delivery, with several recovery-agent and MCP announcements still outside confirmed GA. Restricted release documentation and unresolved CDM exit terms limit confidence in the broader portfolio scores.

    Open questions and evidence caveats

    • Unchanged annual values carry the last scored release; they do not certify a frozen compatibility matrix or exact first-feature GA. Some checkpoint-derived jumps may lag the true first shipment.
    • Unverified AI strands receive zero credited evidence; this is a conservative estimate rather than a vendor-wide absence claim. Preview/limited capabilities add at most half a point beyond the preceding established score.
    • Say-do counts are a bounded research sample. Same-day/release-note announcements and post-release blogs are not promises delivered instantly. Missing outcome dates do not prove non-delivery.
    • Commercial/exit terms not reconstructed use explicit provisional midpoint estimates; executed regional contracts may differ.
    • cyber: 2016 baseline is provisional; no frozen checkpoint fact.
    • retention: 2016 baseline is provisional; no frozen checkpoint fact.
    • platforms: 2016 baseline is provisional; no frozen checkpoint fact.
    • Historical 2022 cells often carry Alta/Andes facts; no later feature is backdated. No core mass/BMR/cleanroom reference score is earned solely from Agent Cloud announcements. Official MCP remains private preview at cutoff.
    • Review 2026-10-03: capability history rebuilt from a dated fact pass (Rubrik first-GA dates for 40 items); tier restored to leader as in the topic sheet.

    Related reading

    More from Enterprise Backup Ledger 2026