Skip to content

AWS · Managed Relational Database

Amazon RDS / Aurora Backup and Recovery

Built for cloud teams

SecureVault Standard, SecureVault Archive, managed AWS automated backups, and granular record retrieval. One policy and three backup types covering operational recovery, ransomware recovery, and long-term archival across all your relational databases.

Storage tier

SecureVault Standard
Archive
Managed AWS PITR

Restore type

Granular (record)
Full (instance / cluster)

Cross-region

Supported (out-of-region)

Cross-account

Supported

Why Clumio for Amazon RDS / Aurora

Why pick Clumio for Amazon RDS / Aurora

AWS automated backups cap retention at 35 days, live inside your account, and don’t help if the account itself is compromised. One Clumio policy handles operational recovery, ransomware recovery, and long-term archival, across both RDS instances and Aurora clusters. 

RECORD-LEVEL QUERY

Granular Record Retrieval

Query a SecureVault Archive backup for individual records and get a downloadable CSV. No full instance restore required. Files stay available for 24 hours. Useful for audits and selective compliance lookups against deep archives.

LONG-TERM TIER

Up to 90% cheaper for archival

SecureVault Archive holds weekly, monthly, or yearly backups for years of retention at up to 90% lower cost than Standard tier (source: https://www.commvault.com/clumio/workloads/amazon-rds). Use when retention is > 3 months. Includes built-in compliance reporting; thaw period of up to 48 hours before record retrieval.

AIR-GAPPED VAULT

Survives account compromise

SecureVault backups sit in Clumio’s immutable, off-account vault. If the source AWS account is compromised, or an admin deletes the RDS instance, the backup is still there and still restorable into any account.

SNAPSHOT CONVERSION

Convert existing AWS snapshots

If you’re sitting on years of manual or automated AWS RDS snapshots, Clumio can convert them into SecureVault backups, so you don’t have to start from scratch. Useful for orgs migrating off snapshot-only strategies that have already accumulated history.

ONE POLICY

Unified across RDS and Aurora

One policy covers MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, and Aurora (MySQL and PostgreSQL clusters), across accounts and regions. Tag-based protection rules attach to new databases automatically, so there’s no per-engine drift.

MANAGED PITR

Continuous PITR, past 35 days

Add AWS automated backups to your Clumio policy and Clumio manages the AWS-side PITR configuration. Continuous PITR alongside SecureVault gives you AWS-native recovery for the near term and air-gapped retention beyond the AWS 35-day cap. 

New to Clumio?

Set up your AWS account first 

This page assumes a connected AWS account and at least one protection group. If you haven’t done that yet, the Getting Started guide walks you through sign-up, account connection, and your first backup in under 15 minutes.  

02 · Backup

How to back up Amazon RDS / Aurora

Apply one Clumio policy to your RDS instances and Aurora clusters. The policy can drive SecureVault Standard, SecureVault Archive, and Clumio-managed AWS automated backups (for PITR) simultaneously.

01

 Create a backup policy

A Clumio RDS policy defines frequency and retention for each enabled backup type. Add the RDS asset type to a new or existing policy, then configure SecureVault frequency, retention, and tier. AWS automated backups (PITR) are toggled separately and Clumio takes over their AWS-side configuration once enabled.

 Protect → Backup policies →

02

 Pick the right RPO across the three backup types

Different backup types satisfy different RPO needs. AWS automated backups deliver continuous PITR within their retention window, useful for any-second-recovery against operational mistakes. SecureVault Standard supports frequencies from hourly through yearly for air-gapped operational coverage. SecureVault Archive runs weekly, monthly, or yearly for compliance retention.

 If you enable AWS automated backups inside a Clumio policy, Clumio resynchronizes daily with AWS and will alert if the PITR configuration is changed directly in the AWS console. Manage the schedule from one place to avoid the alert.

03

Choose your tiers (Standard, Archive, or both)

SecureVault Standard

Air-gapped backup optimized for operational recovery. Best for retention windows under 3 months. Fast restore directly to a new instance or cluster, same account or cross-account / cross-region. 

SecureVault Archive

Lower-cost long-term tier for compliance and archival use. Best for retention > 3 months. Unlocks Granular Record Retrieval (query individual records via CSV). Requires up to a 48-hour thaw before records can be retrieved. 

Protect → RDS policies → Backup tier →

AWS automated backups are a third option in the same policy, with Clumio managing the AWS-side PITR config. A common setup is PITR plus one or both SecureVault tiers, depending on the retention horizon.

04

 Choose a region (in-region or out-of-region)

By default Clumio stores SecureVault backups in the same region as the source database. You can target a different region for cross-region durability, which adds AWS data-transfer cost. The destination is set on the policy. 

 N/A — no Heads up callout in current HTML for RDS step 04.

05

 Apply the policy with protection rules

Once the policy is saved, use protection rules to apply it to RDS resources. Rules can target databases by AWS tag, by account, or by region, so newly-created RDS instances and Aurora clusters get protected automatically without manual assignment. The seed backup runs first; subsequent backups are incremental.

Set up → Protection rules →

03 · Restore

How to restore Amazon RDS / Aurora

An RDS restore comes down to three choices: when to recover from, what to recover, and where it lands.

 WHENPick the recovery point

Three sources of recovery points, chosen from the protection-history calendar.

AWS automated backup (PITR)

Pick any timestamp within the AWS PITR window for continuous, second-granular recovery. Best for operational mistakes caught quickly. Requires AWS automated backups enabled in the Clumio policy. 

Restore → Instance → PITR

 SecureVault Standard backup

Air-gapped point-in-time copy outside your AWS account. Fast restore directly to a new instance or cluster. Best for ransomware and account-compromise scenarios. 

Restore → Instance → SecureVault 

SecureVault Archive backup

Pick an Archive dot for long-retention compliance restores or record-level queries. Requires a thaw period of up to 48 hours; Clumio emails you when the data is ready to retrieve.

Restore → Instance → Archive 

 WHATPick the granularity

 From individual records up to the entire instance or cluster.

RECORD (Granular Record Retrieval):

Query a SecureVault Archive backup with SQL-style filters, preview matched rows, and download the result as a CSV. Files are available for 24 hours after retrieval. No full instance restore required. 

FULL INSTANCE OR CLUSTER:

Restore the entire RDS instance or Aurora cluster from any unexpired backup. Configure target subnet group, parameter group, KMS key, and other instance settings before confirming. 

N/A — RDS restores either use Granular Record Retrieval (record-level) or full instance/cluster restore. No intermediate granularity. 

 WHEREPick the destination

RDS restores always create a new instance; there is no in-place rollback.

Same account, same or different region

Restore to a new RDS instance or Aurora cluster in the source account. Pick the target region (defaults to the source), modify the instance name and configuration as needed, then confirm. 

Restore → Same-account 

 Cross-account (any region)

Restore to a target AWS account, useful for ransomware recovery, environment promotion, or staging refreshes. The target account must have a Clumio connector installed and at least one prior RDS instance in the destination region. No dependency on the source account being healthy. 

Restore → Cross-account

05 · Common questions

Frequently asked questions

Questions from engineers setting up Amazon RDS / Aurora protection or troubleshooting restores.

How does Clumio compare to AWS automated backups or AWS Backup for RDS?

AWS automated backups cap retention at 35 days and live inside the source account, so they don’t help during account compromise. Clumio closes both gaps — SecureVault stores backups in an immutable, air-gapped vault outside your AWS account, and the Archive tier holds multi-year retention at up to 90% lower cost than Standard.

How long does the initial seed backup take for an RDS instance?

Yes. Cross-account restore is supported for Amazon S3. Pick the target account during restore setup — the account must have a Clumio connector installed and trust established. No dependency on the source account being healthy. 

Can I restore an RDS instance to a different AWS account?

Seed time depends on database size and instance class. Typical production RDS instances seed in hours. Subsequent backups are incremental-forever, finishing in minutes at typical change rates.

What is the RPO for Amazon RDS / Aurora with Clumio?

RPO is set by your policy schedule. Clumio supports frequent snapshots to minimize data loss; confirm the available schedule frequency for your engine and instance type with the engineering team. 

Does Clumio support Aurora Serverless?

Confirm Aurora Serverless support with the engineering team before relying on Clumio for protection. Standard Aurora provisioned clusters are supported; Serverless v2 compatibility should be verified for your specific configuration. 

Will a Clumio restore create a new RDS instance or restore into the existing one?

Clumio restores are out-of-place — a new RDS instance or Aurora cluster is created at the destination you specify. This avoids disrupting the running database. You redirect application traffic or swap endpoints as part of your runbook. 

Are RDS Multi-AZ deployments backed up differently?

No. Clumio protects the primary database regardless of Multi-AZ configuration. The Multi-AZ standby provides high availability, not backup isolation — Clumio’s air-gapped backup remains outside your account in both cases. 

06 · Related resources

Go deeper

Blog posts and reference material for teams building on Clumio Amazon DynamoDB protection. 

Ebook

Removing Data Protection Roadblocks for Amazon RDS

Where native RDS protection falls short (35-day cap, shared security sphere, compliance gaps), and the architecture Clumio uses to fill those gaps.

datesheet

Clumio Backup as a Service for Amazon RDS

Amazon RDS liberates organizations from setting up and managing what is arguably the most complex and difficult to manage layer of enterprise applications – the database.

Analyst Report

The Total Economic Impact™ of Clumio

Forrester Consulting’s commissioned TEI study on the quantified cost savings and business benefits of moving AWS backup workloads to Clumio. Includes a composite-customer financial model.