The Landscape
What’s changed in how vulnerabilities are found and disclosed?
Discovery is faster
Close to 48,000 CVEs were published in 2025, roughly 130 a day.
The old signal is thinning
The National Vulnerability Database has moved to selective, risk-based processing.
The window is closing
Working exploit code can now appear before a patch is widely deployed.
Trust & Compliance
Backed by independent certification
Our compliance posture is documented and independently audited. View our full certifications and assurance documentation in the Trust Center.
Frequently Asked Questions
What is Commvault doing around AI-assisted security testing?
We actively evaluate our products using AI-assisted methods as part of our structured security engineering program, in Commvault-controlled environments, under the same governance as every other form of testing.
How is Commvault preparing for AI-driven vulnerability discovery?
Our program is model-agnostic and tool-agnostic by design, so we can incorporate new methods inside one consistent governance framework.
Is Commvault using these models safely?
Yes. All evaluation happens on isolated hardware or Commvault-managed cloud infrastructure. Source code never leaves our boundaries, and every AI-generated finding requires human confirmation before action.
How is Commvault scaling vulnerability management for the AI era?
We’re investing in risk-based triage and remediation infrastructure so the response process can scales with discovery volume, not just the discovery itself.