Commvault logo

How Commvault cut review cycle time with a reviewer that has already seen the attack

Commvault team photo

CodeAnt AI transformed our code reviews, reducing cycle time and helping us quickly fix quality and security issues.

Portrait of Bhavyan Mehta

Bhavyan Mehta

VP - Engineering, Commvault (NASDAQ:CVLT, $8B+ Market Cap)

Commvault is the global gold standard in cyber resilience and data protection, keeping data secure and operations resilient for more than 100,000 organizations. Their engineering organization runs to over 800 developers distributed across continents.

CHALLENGE

Merge volume scaled. Review capacity did not.

Commvault's developers were writing and merging code faster than they ever had. The number of people available to review it stayed where it was. That gap is the whole problem of the AI era stated plainly, and it does not resolve itself by asking engineers to try harder.

Rule-based static analysis was no longer meeting the depth and intelligence standard Commvault demanded of its own code. A rule pack can tell you a pattern matched. It cannot tell you whether the pattern matters in this codebase, in this service, given what this code is actually for. At Commvault's complexity, that distinction is the entire value of a review.

The requirement was uncompromising on three fronts at once: code security, code quality, and developer velocity. Most tools make you trade the third for the first two.

WHY CODEANT

They needed a reviewer that understood context, intent, and their own internal standards.

Commvault went looking for an AI-native system that could give instant contextual insight into new code changes across millions of lines, offer one-click fixes for both quality and security issues, and keep learning with every commit, all while holding strict data privacy and compliance standards.

The reason ours escalates differently is the offensive side. The engine has already proven which of these patterns is genuinely exploitable in the wild, so it knows what to raise and what to leave alone. For a company whose customers buy them for resilience, a reviewer that has seen real attacks is a different instrument than one running a rule pack.


WHAT WE RAN

CodeAnt integrated into the workflows Commvault already had, at every stage code passes through:

In the IDE. Real-time suggestions and one-click fixes for bugs, vulnerabilities, and code smells, so issues get resolved before code ever reaches review.

At the pull request. The engine learned from past reviews to apply Commvault's own internal best practices automatically, with contextual feedback and one-click remediation attached.

In CI/CD. Builds blocked automatically on quality or security violations, with audit-ready reports generated for every release.

In the dashboards. Real-time visibility for engineering leadership into code health, security posture, and review velocity across all repositories.

Deployed inside the air gap.

This is the part most AI platforms cannot do. Commvault required the entire system to run within an air-gapped, on-premises environment. Not the data pipeline, not a subset of the features. The whole stack.

CodeAnt deployed in full inside Commvault's isolated infrastructure, achieving true air-gap compliance, absolute data sovereignty, and complete governance and control. A self-contained AI code health platform with enterprise-grade resilience, and no data leaving the perimeter.

WHAT CHANGED

Metric

Result

Merge requests reviewed

17,000+

AI-only reviews, zero human input

25% of all MRs

Time to first comment

3.5 days to 1 minute, 98% faster

High-severity issues resolved

38


Review cycles went from days to minutes. A 98% reduction in time to first comment gave developer hours back to higher-impact work. Leadership got complete visibility into code health across the codebase, high-severity vulnerabilities were caught and resolved early rather than late, and on-prem audit logs and dashboards made internal traceability straightforward instead of a project.

COMPANY

Commvault (NASDAQ: CVLT)

INDUSTRY

Security & Infrastructure

SERVES

Large enterprises worldwide

ENGAGEMENT

Defensive platform, code review at the pull request

See what CodeAnt finds in your code

See what CodeAnt finds in your code