Loading
September 22 2026

Cohesity FortKnox integrates clean room recovery

Recover vaulted snapshots and Digital Jump Bag™ assets into an isolated clean room—so you can validate before you restore.

Fortknox Clean Room

Cohesity FortKnox, our cyber vaulting solution, helps organizations maintain a trusted recovery copy even if production environments and backup infrastructure have been compromised. FortKnox delivers the essential controls organizations need for effective cyber vaulting:

  • An isolated, immutable copy that stays out of reach of attackers.
  • Quorum-based approvals that prevent any single user from taking critical recovery actions.
  • Operational separation between the vault and the protected environment.
  • A self-managed deployment option.

We’ve released a new clean room recovery capability in FortKnox to accelerate incident response and recovery. This new feature extends the FortKnox recovery workflow by securely recovering Digital Jump Bag™ assets and vaulted snapshots into an isolated clean room environment where investigation, validation, and recovery activities can occur before production systems are restored. 

Some organizations still think about vaulting and recovery as separate activities. The reality is that they are becoming part of a single cyber recovery workflow. FortKnox provides a trusted, isolated foundation. The new clean room recovery feature provides a safe environment to validate before restoring. Together, they help organizations move beyond securing recovery data to confidently using it when it matters most.

This feature is now generally available for both FortKnox SaaS and self-managed environments.

Solving a key part of cyber response and recovery

Most organizations maintain multiple recovery points. During normal operations, that is a strength. During a cyber incident, it can become a decision point filled with pressure. Restoring directly into production without validation can introduce risk. If a recovery point contains remnants of an attack, vulnerabilities, or compromised credentials, teams may unintentionally re-introduce the problem. That is why the recovery process requires investigation and remediation of threats. 

Traditional recovery models often looked like this:  

Protect → Vault → Restore

Cyber vaulting ensures the recovery copy is isolated and protected.  

In the age of destructive cyberattacks, organizations need a safer way to examine and validate that copy before returning systems to production. The logical evolution is a more deliberate response and recovery workflow: 

Protect → Vault → Recover to clean room → Investigate → Validate → Restore

Additional enhancements for FortKnox self-managed deployments

FortKnox administrators can now manage physical air-gap settings directly from the paired clusters page. When enabled, recovery or replication operations that use the interface group configured for vaulting are not permitted outside the vaulting window. This gives teams more direct control over separation between production and vault environments.

FortKnox self-managed also gives teams more flexibility over vaulted copy retention periods. You can now set vault retention to the value that fits your recovery, compliance, and storage requirements, including cases where vaulted copies need a shorter retention period than primary backups.

Additional improvements, including multiple-node IP entry during cluster pairing and safeguards against duplicate pairing and configuration errors, help simplify day-to-day vault administration.

Take the next step: Add Cohesity FortKnox to your deployment

Cyber resilience is never a one-time project. You must continuously strengthen the people, processes, and technology that support recovery. A cyber vault remains a critical part of that strategy. 

Register and watch this video to see how to strengthen your cyber resilience with Cohesity FortKnox.

Written By