Upwind logo

Upwind Review

Visit

Agentless scanning and eBPF runtime sensors in one CNAPP

Upwind is a cloud-native application protection platform (CNAPP) for security, DevOps and platform teams running workloads in public cloud.

Upwind Security·Founded 2022·Contact for pricingFree TrialAI SecurityAI DevOps

AI Panel Score

8.1/10

6 AI reviews

Reviewed

AI Editor Approved

What is Upwind?

Upwind is a cloud-native application protection platform that pairs agentless cloud scanners with eBPF runtime sensors, so posture findings carry evidence of what is actually running, reachable and exposed. It targets security, DevOps and platform engineering teams operating production workloads on AWS, Azure, Google Cloud or Oracle Cloud Infrastructure. Pricing is quote-based: upwind.io publishes no price list and routes buyers to a demo, while the vendor's AWS Marketplace listing offers a free trial plus 12-, 24- and 36-month contracts. Core capabilities include function-level reachability that confirms whether a vulnerable package is actually called, attack-path analysis across identities and workloads, discovery and schema mapping of REST, GraphQL, gRPC and SOAP APIs with PII, PHI and PCI classification, and an Agentic Pack whose Blue, Red and Green agents investigate, validate and remediate findings under a conversational control plane called ChoppyAI. It best fits teams consolidating posture, workload protection and detection and response into one platform.

About Upwind

Getting started means connecting a cloud account - AWS, Azure, Google Cloud or Oracle Cloud Infrastructure - and installing the eBPF sensor on the workloads you want covered. Cloud Scanners either run in Upwind's own tenancy (the SaaS model) or inside your accounts (the Outpost model), and sensors ship for Kubernetes, Linux and Windows Server hosts, Amazon ECS on EC2 and Fargate, AWS Lambda, Azure Container Apps and Google Cloud Run. From there the Management Console shows a live inventory and asset graph, with work organized into Code, Configurations, Attack Surface, Identities, Vulnerabilities, Threats, API Security, Data Security and AI sections.

The runtime layer is what separates findings that matter from the rest. Function-level reachability checks whether a vulnerable package is actually called before a CVE is escalated, attack-path analysis chains individually minor findings into the routes an attacker could take, and the platform baselines normal cloud and workload behavior so privilege escalation, lateral movement and unusual API use surface as deviations. API security discovers managed, unmanaged and shadow APIs across REST, GraphQL, gRPC and SOAP, maps schemas from live traffic, and classifies PII, PHI, PCI and secrets moving through them. The Agentic Pack adds four named AI agents: Blue investigates incidents from first signal to verdict, Red probes the live environment to prove which risks are reachable, Green groups findings into single high-impact fixes, and ChoppyAI answers plain-language questions across the whole data model.

It is aimed at security, DevOps and platform engineering teams already running production workloads in public cloud who want posture management, workload protection, identity entitlements, data security and detection and response in one platform rather than five. Pricing is quote-based: upwind.io lists no prices and routes buyers to a demo request, while the AWS Marketplace listing offers a free trial alongside 12-, 24- and 36-month contracts and private offers. A 24/7 Managed Detection and Response service is sold as a separate line.

The integration surface is wide. There is a documented REST API (v1 and v2), a Terraform provider that manages detection policies and access scopes declaratively, an upwindctl CLI for scanning files, images and machine images, a hosted MCP server at mcp.upwind.io for MCP-capable AI clients, and SAML single sign-on with Okta, Microsoft Entra ID, Google Workspace, Duo, JumpCloud, OneLogin and PingOne. Outbound integrations cover Jira, Slack, Microsoft Teams, ServiceNow, Linear, PagerDuty, Splunk, Datadog, Tines and custom webhooks, and CI/CD connectors cover GitHub Actions, GitLab, CircleCI, Argo CD, Bitbucket and Harbor.

Features

AI Agents

  • Agentic Pack AI Agents

    Blue investigates incidents from first signal to verdict, Red probes the live environment to prove which risks are reachable, Green consolidates findings into single high-impact fixes, and ChoppyAI answers plain-language questions and dispatches the other three.

API Security

  • API Discovery and Schema Cataloging

    Auto-discovers managed, unmanaged and shadow APIs across REST, GraphQL, gRPC and SOAP and builds their schemas from observed runtime traffic rather than from source annotations.

Automation

  • Terraform Provider and REST API

    A Terraform provider manages detection policies, custom rules, access scopes and malware indicators declaratively through the Management REST API v2, alongside a documented v1 and v2 REST surface and ten published onboarding and cloud-scanner modules for AWS, GCP, Azure and OCI. The provider is early — v0.1.x, community tier — so the modules carry the mature onboarding path.

Data Security

  • Sensitive Data Discovery and Classification

    Finds and classifies PII, PHI, PCI data and secrets in cloud data stores and in traffic moving through APIs, and flags when regulated data crosses an unsafe boundary.

Discovery

  • Agentless Cloud Scanners

    Cloud Scanners inventory AWS, Azure, Google Cloud and Oracle Cloud Infrastructure accounts without an agent, running either in Upwind's tenancy (SaaS model) or inside your own accounts (Outpost model).

Identity Security

  • CIEM for Human and Non-Human Identities

    Maps permissions from identity providers through to cloud resources, tiers privilege levels, and surfaces dormant roles, unused access and exposed secrets.

Integration

  • Upwind MCP Server

    A hosted Model Context Protocol server at mcp.upwind.io lets Claude, Cursor and other MCP clients query Upwind security data over OAuth 2.1, with regional endpoints such as mcp.eu.upwind.io.

Kubernetes

  • Container Admission Controller

    A Kubernetes admission controller blocks deployments carrying exploitable vulnerabilities, malware or exposed secrets, with policy scoped by namespace, cluster and workload type.

Posture

  • Cloud Security Posture Management

    Continuously evaluates cloud configuration against built-in and custom rules written in Rego, maps findings to compliance frameworks and produces audit-ready reporting.

Risk Prioritization

  • Attack Path Analysis

    Chains individually minor findings into the routes an attacker could take across workloads, identities and data, and shows the blast radius of each path.

Runtime

  • eBPF Runtime Sensor

    A lightweight eBPF sensor installs on Linux and Windows Server hosts, Kubernetes nodes, Amazon ECS on EC2 and Fargate, AWS Lambda, Azure Container Apps and Google Cloud Run to stream live process, network and syscall telemetry.

Supply Chain

  • Runtime-Powered SBOM and SCA

    Builds SBOMs at both build time and runtime across container images, machine images, IaC templates and repositories, with an SBOM Explorer for tracing a package to the workloads that run it.

Threat Detection

  • Cloud Detection and Response

    Baselines normal cloud and workload activity, then flags deviations such as privilege escalation, lateral movement and unusual API calls and correlates them with audit logs into a single incident timeline.

Vulnerability Management

  • Function-Level Vulnerability Reachability

    Runtime call-graph mapping checks whether a vulnerable function is actually invoked in production, so unreachable CVEs are ranked below ones an attacker can use.

Preview

Upwind desktop previewUpwind mobile preview

Pricing Plans

Upwind Cloud Security Platform

$30,000/yearly

Core CNAPP platform. Listed at $30,000 per unit for a 12-month contract on Upwind Security's own AWS Marketplace listing. Longer commitments are advertised only as ceilings — "save up to 8%" on 24 months and "save up to 11%" on 36 months — with no dollar figure published. upwind.io itself publishes no price list.

  • Agentless cloud scanners plus eBPF runtime sensors
  • CSPM, CIEM, DSPM and AI-SPM posture coverage
  • Vulnerability management with function-level reachability
  • API security, attack-path analysis and cloud detection and response

Upwind Managed Detection & Response

$6,000/yearly

24/7 managed detection and response, billed as a separate line. Listed at $6,000 per unit for a 12-month contract on Upwind Security's own AWS Marketplace listing. Longer commitments are advertised only as ceilings — "save up to 8%" on 24 months and "save up to 11%" on 36 months — with no dollar figure published.

  • 24/7 threat detection, investigation and containment
  • Live incident war rooms for zero-day events
  • Attack-path reconstruction by Upwind researchers
  • Continuous monitoring for follow-up attacker attempts

Private Offer (Custom Quote)

Contact sales

Custom-quoted terms. upwind.io routes all buyers to a demo request and publishes no prices; AWS Marketplace offers a private-offer path for negotiated volume and contract length. A free trial is available through the marketplace listing.

  • Negotiated volume and contract length
  • Private offer through AWS Marketplace
  • Free trial available before purchase
  • Demo-led evaluation via upwind.io

AI Panel Reviews

The Decision Maker

The Decision Maker

Strategic bet, vendor viability, timing, adoption approval
8.3/10

The runtime layer earns the $30,000, but you'll only find that number on AWS Marketplace.

Upwind pairs agentless cloud scanners with an eBPF sensor, so findings carry proof of what is actually running. The platform is deep, but the price you can look up sits on a marketplace listing, not on upwind.io.

Upwind won't quote you on its own site. Every path ends at Get a Demo, and the only rate card I could find is its own AWS Marketplace listing — $30,000 for twelve months of the platform, $6,000 more for the 24/7 MDR line.

What you're buying is runtime evidence. Function-Level Vulnerability Reachability checks whether a vulnerable function is actually called in production before a CVE gets escalated; the obvious posture-only alternative can only tell you the package is installed. That changes which tickets your engineers work on, not just what you pay.

The catch is the term ladder. The discount for committing shows up at 24 and 36 months — up to 8% and 11% off — so you'd sign years before knowing the eBPF sensor covers your ECS, Lambda and Windows Server workloads. Take the free trial, instrument one production cluster, and sign twelve months before anything longer.

Competitive Positioning8.5

Function-level reachability and API schemas built from observed runtime traffic rather than source annotations are things a posture-only scanner cannot produce.

Reputation Risk7.6

SAML single sign-on across seven identity providers, RBAC, audit logs and an Outpost model that keeps scanners inside your own accounts all cut lock-in, though I couldn't find published cancellation terms.

Speed to Value7.8

Connecting an AWS, Azure, Google Cloud or Oracle account gives inventory quickly, but full value waits on rolling the eBPF sensor across Kubernetes, ECS, Lambda and Windows Server.

Strategic Fit8.3

Posture, workload runtime, identity entitlements, data security and detection land in one console, so it replaces a stack rather than shaving cost off one tool.

Vendor Viability8.7

Release notes for the sensor, operator and Helm charts, a documented REST API v1 and v2, a Terraform provider and the upwindctl CLI all read as a platform under active build.

Pros

  • Agentless Cloud Scanners inventory AWS, Azure, Google Cloud and Oracle Cloud accounts before any sensor is installed.
  • Function-level reachability ranks a CVE by whether the vulnerable code actually runs, which shortens the remediation queue.
  • The Outpost model runs scanners inside your own cloud accounts instead of the vendor's tenancy.
  • A Terraform provider and REST API v2 keep detection policies and access scopes in version control.
  • The AWS Marketplace listing puts the platform at $30,000 for twelve months, which is enough to size a budget before a sales call.

Cons

  • upwind.io routes every visitor to a demo request rather than a published price list.
  • The 24/7 Managed Detection and Response service bills as a separate $6,000 line on top of the platform.
  • Marketplace contract terms run 12 to 36 months, and I couldn't find published cancellation terms.
  • Full coverage depends on rolling the eBPF sensor across every workload type you run, which is a project in itself.

Right for

Security teams who run production workloads across more than one public cloud.

Avoid if

Small teams who cannot commit five figures a year to cloud security.

The Domain Strategist

The Domain Strategist

Craft and strategy in the product's domain — adapts identity per category, same lens
8.6/10

Runtime telemetry is where the lock-in lives; scanner placement and Rego policy stay yours.

Upwind pairs agentless Cloud Scanners with an eBPF runtime sensor, and it will run those scanners inside your own cloud accounts if you want them there. The posture layer is portable policy-as-code; the runtime intelligence that justifies the platform is not.

Ask what you'd take with you on the way out. Custom posture rules go in as Rego through Upwind Explorer, so that logic stays legible outside their console. The runtime graph doesn't travel: function-level reachability and attack-path chaining come from the eBPF sensor's telemetry model, and that stays with the vendor.

The other decision worth architecture time is where the Cloud Scanners execute. Outpost runs them inside your own AWS Organization, under your SCPs and logging; the SaaS model runs them in Upwind's tenancy. That's a residency decision made at onboarding, and unwinding it later is a re-onboarding project.

Their own People.ai case study sells the switch off Wiz as a coverage story. But upwind.io publishes no prices, and the one rate card they publish themselves — an AWS Marketplace listing at $30,000 per unit for twelve months — never defines the unit. A three-year commit gets negotiated, not modeled.

Category Positioning8.4

A runtime-first consolidation play against agentless-first platforms, and their own customer case study names the incumbent they are displacing.

Domain Fit8.7

Onboarding runs through Terraform and CloudFormation, custom posture rules accept raw Rego, and detections route into Jira and PagerDuty.

Integration Surface9.0

SAML across seven identity providers, six CI/CD connectors, a hosted MCP server at mcp.upwind.io, a documented REST API and the upwindctl CLI.

Long-term Implications7.8

The Outpost model keeps scanner workloads inside your own AWS Organization, but I couldn't find an export path for the runtime telemetry the platform is built on.

Strategic Depth8.8

Function-level reachability, attack-path chaining and SBOMs built at both build time and runtime are hard things to do well, and all three are documented.

Pros

  • Under the Outpost model the Cloud Scanners run inside your own AWS Organization, subject to your SCPs, tagging and logging.
  • Custom posture rules accept raw Rego, so detection logic is reviewable like any other policy-as-code rather than locked in a GUI.
  • The eBPF sensor covers Kubernetes, Linux and Windows Server hosts, ECS on EC2 and Fargate, Lambda, Azure Container Apps and Cloud Run.
  • Function-level reachability ranks a CVE by whether the vulnerable code actually runs, which cuts triage volume instead of adding to it.
  • Findings route outward into Jira, ServiceNow, Splunk, Datadog, PagerDuty and Slack, so nobody has to live in another console.

Cons

  • Choosing Outpost or SaaS scanner placement happens at onboarding, and reversing it is a re-onboarding project.
  • The $30,000 marketplace rate is per unit for twelve months, and the unit is not defined publicly.
  • The reachability and attack-path work is derived from a proprietary sensor model, so that analysis does not come with you if you leave.
  • 24/7 Managed Detection and Response is sold as a separate line rather than included in the platform.

Right for

Security and platform teams who run production workloads across multiple public clouds.

Avoid if

Teams who need a published price list to plan a budget.

The Finance Lead

The Finance Lead

Money, total cost of ownership, contracts, procurement math
7.9/10

Upwind publishes $30,000 for twelve months, per unit — and I couldn't find what a unit counts.

Upwind's own AWS Marketplace listing prices a 12-month platform contract at $30,000 and the 24/7 MDR line at $6,000. Both are per-unit figures, and I couldn't find what a unit counts, so the published number anchors a budget rather than building one.

Upwind sells by the unit. I couldn't find what a unit counts. Its own AWS Marketplace listing puts $30,000 on a 12-month platform contract and $6,000 on the 24/7 MDR line. Two numbers, no denominator — two more than the category usually publishes.

At quantity one: platform plus MDR is $36,000 for twelve months. Three annual renewals at list: $108,000 by my arithmetic, before any private-offer discount. The 24- and 36-month terms advertise a discount ceiling but no dollar figure, so twelve months is the only term you can budget.

The $6,000 MDR line is 20% of the platform price — cheap against staffing a 24/7 rotation, and optional. The Agentic Pack pushes the same way: Blue works an incident to a verdict, Green collapses findings into single fixes. Procurement is light. It bills on AWS paper, against commitment you've signed.

Billing & Procurement8.5

Marketplace purchase means existing AWS paper, a free trial before commitment and a documented private-offer route.

Contract Flexibility7.6

Three contract lengths and a private-offer path give real negotiating structure, though only the 12-month figures are published.

Pricing Transparency7.2

Upwind's own AWS Marketplace listing publishes $30,000 for a 12-month contract, but upwind.io publishes nothing and I couldn't find what a unit counts.

ROI Clarity8.2

The Agentic Pack and Attack Path Analysis produce countable outputs, and one $30,000 line replaces CSPM, CIEM, DSPM and vulnerability-management renewals you can diff against.

Total Cost of Ownership7.4

Platform plus MDR runs $36,000 a year at quantity one, though Outpost-model scanners put scanning compute on your own cloud bill.

Pros

  • Upwind's own AWS Marketplace listing puts a hard $30,000 on a 12-month platform contract.
  • 24/7 Managed Detection & Response is priced separately at $6,000, so the platform can be bought alone.
  • Buying through the marketplace runs on existing AWS paper and can draw down an AWS commitment.
  • SAML single sign-on is documented across seven identity providers, with no separate SSO line I could find.
  • I couldn't find a separate charge for the Terraform provider, the REST API or the hosted MCP server.

Cons

  • The published figures are per unit, and I couldn't find what one unit covers.
  • upwind.io itself quotes nothing — every route to a number runs through a demo request.
  • Only the 12-month prices are published; longer terms advertise a discount ceiling with no dollar figure.
  • Outpost-model scanners run inside your own accounts, so that compute lands on your cloud bill.

Right for

AWS Marketplace buyers who want cloud security on existing cloud paper.

Avoid if

Budget owners who need a modelable unit price before a sales call.

The Domain Practitioner

The Domain Practitioner

Daily hands-on reality in the product's domain — adapts identity per category, same lens
8.4/10

Runtime proof a vulnerable function actually ran — once you turn the JVM and Go hooks on

Function In-Use uses eBPF uprobes to confirm a vulnerable function was actually executed, which is the difference between a CVE list and a work queue. The per-language hooks on hosts ship mostly off, so the first week is a config pass, not a dashboard tour.

The CLI flag table has a column headed "If you omit it." Small thing, tells you who wrote the page. shiftleft scans an image, a directory or an AMI, takes --max-severity to fail a build step, and writes GitLab vulnerability JSON or GitHub job-summary markdown.

Function In-Use does the real work — eBPF uprobes on interpreter internals confirm a vulnerable function actually executed, and Findings has a filter for exactly that. Agentless-only scanners can say a package is present; this says it ran. But on hosts the per-language hooks in agent.yaml default off. Python and native binaries are on; Java, Go, Node.js and PHP are not.

Overhead is governed, not promised: attachment pauses above 15% CPU, capped at 750 processes and 100 hunted functions. Sensor release notes land every couple of weeks. JVM and Go shops should budget a config pass before that signal shows up in triage.

Day-3 Reality7.8

The sensor is eBPF on Linux and ETW on Windows Server 2016 or later, and a Health Center lists unhealthy sensors with 24-hour CPU and memory per host.

Documentation Practitioner-Fit9.2

The docs run to 643 pages including 22 troubleshooting pages, a flag table with an If you omit it column, and Cluster Manager sizing in CPU cores.

Friction Surface7.2

Per-language in-use hooks default off in agent.yaml, and leaving --upwind-uri at its default fails authentication outside the US.

Power-User Depth8.8

REST API v2 exposes bulk policy create, edit and delete, SBOM Explorer traces a package to the resources running it, and a hosted MCP server sits at mcp.upwind.io.

Workflow Integration8.6

shiftleft returns GitLab vulnerability JSON and GitHub job-summary markdown, and a Terraform provider manages threat policies and access scopes declaratively.

Pros

  • Function In-Use confirms a vulnerable function was actually invoked, so triage starts from execution rather than presence.
  • The shiftleft binary runs in any CI that can execute a binary and fails a step at the severity you pick with --max-severity.
  • Documentation covers the unglamorous parts: 22 troubleshooting pages, release notes per component, and Cluster Manager sizing guidance in CPU cores.
  • A Terraform provider manages threat policies and access scopes, and REST API v2 supports bulk policy edits.
  • Sensor overhead is bounded in public: attachment pauses above 15% CPU and caps at 750 processes.

Cons

  • Per-language in-use hooks ship off on hosts, so Java, Go, Node.js and PHP need an agent.yaml change before reachability data appears.
  • Leaving --upwind-uri at its default sends a non-US scan to the wrong region and authentication fails.
  • Runtime signal only covers workloads carrying the sensor, so coverage stays an ongoing rollout job.
  • upwind.io publishes no price list and routes buyers to a demo, so the only public rate card sits on their AWS Marketplace listing.

Right for

Platform engineers who triage cloud CVE backlogs every week.

Avoid if

Teams who cannot install a runtime sensor on production hosts.

The Power User

The Power User

Daily human experience, onboarding, polish, learning curve, reliability
8.0/10

Sensor installs in one curl line; the console you'll still be learning in month three.

Connecting a cloud account is a CloudFormation stack and one curl line, and the install docs read like somebody watched people do it. The console behind that door is wide, nine sections deep, and I couldn't find a mobile app for any of it.

They tell you the client secret shows once and then never again. Small thing, but somebody wrote that line after watching people fumble it. Drop a CloudFormation stack in, run one curl line on your Linux hosts, validate, and you're collecting — as long as the kernel is 4.14 or newer.

The docs keep that up. Release notes are split per component — sensor, operator, Helm charts, upwindctl and six more — and the deprecated three-stack AWS onboarding is still written down instead of quietly deleted. That's a team that expects you to be here next year.

Month three is the wide part. Nine console sections, Code through AI, and ChoppyAI is the escape hatch — plain-language questions instead of hunting menus like the incumbent consoles make you. But I couldn't find a mobile app, and for a product about catching attacks live, the alert wakes you and the laptop answers it.

Daily Polish8.3

The install guide flags that the client secret appears only once and keeps the deprecated AWS onboarding path documented rather than deleted.

Learning Curve7.6

Nine console sections and a documentation site in the hundreds of pages take time, though ChoppyAI shortens the hunt.

Mobile Parity7.5

I couldn't find a mobile app, though this is cloud infrastructure tooling where a phone was never really the point.

Onboarding Experience7.9

Connect a cloud account, generate credentials, run one curl line, validate — four steps, though the way in still starts with a demo request.

Reliability Feel7.2

Spinners, error states and autosave are not things I can judge without sitting in the console, so this one stays neutral.

Pros

  • One curl line installs the host sensor, with a Helm chart and an EKS add-on covering Kubernetes.
  • The install guide warns that the client secret is shown only once, which is the kind of detail people usually learn the hard way.
  • ChoppyAI answers plain-language questions, so you don't have to know which of the nine console sections holds the answer.
  • Release notes are published per component — sensor, operator, Helm charts, upwindctl and six more.
  • A Terraform provider and the Management REST API v2 let detection policies live in code rather than in clicks.

Cons

  • The host sensor needs Linux kernel 4.14 or newer, which leaves older fleet stragglers uncovered.
  • I couldn't find a mobile app, so alerts land on a screen you have to go sit down at.
  • Nine console sections is a lot of room to learn before the tool feels like second nature.
  • I couldn't find a way to start on your own — upwind.io routes everything through a demo request.

Right for

Platform engineers who need runtime visibility on Kubernetes and Linux hosts.

Avoid if

Teams whose Linux fleet still runs kernels older than 4.14.

The Skeptic

The Skeptic

Contrarian. Watch-outs, deal-breakers, broken promises, category patterns
7.4/10

93% noise reduction and detection in 15 seconds, with no method published behind either number.

What Upwind actually ships is unusually concrete — Rego posture rules, a Kubernetes admission controller, API discovery from live traffic. The proof points on the homepage are not.

The Agentic Pack ships AI agents with names and jobs. Blue investigates, Green consolidates, ChoppyAI answers plain-language questions. Red is the one to think about — it probes your live environment to prove which risks are reachable. Autonomous probing in production is a real capability and a real blast radius.

The homepage leads with 93% noise reduction, detection in 15 seconds, live inventory every 30 seconds. I couldn't find a method behind any of them. Category norm.

Exit is better than I expected. Posture rules are written in Rego, an open policy language, and a Terraform provider keeps detection policy in your repository rather than their console. But the catch is what you cannot take: detection baselines and API schemas are learned from your live traffic, and none of that learned state follows you to another vendor.

Competitive Differentiation7.2

Pairing agentless Cloud Scanners with eBPF runtime sensors is a real architectural choice, though every platform in this category now markets runtime context.

Exit Portability6.8

Rego policy and a Terraform provider travel with you, but eBPF sensors across every workload and a learned detection baseline do not.

Long-term Viability8.3

Product posts dated through mid-September 2026, a documented REST API at v1 and v2, a Terraform provider, upwindctl and a hosted MCP server all point to active work.

Marketing Honesty6.2

The site publishes no price and routes every buyer to a demo, while 93% noise reduction and 15-second detection carry no published method.

Track Record Match8.0

Named capabilities are concrete — Rego posture rules, function-level reachability, API discovery across REST, GraphQL, gRPC and SOAP — and the documentation backs them.

Pros

  • Posture rules are written in Rego, an open policy language, so custom rules are not trapped in a proprietary format.
  • A Terraform provider manages detection policies and access scopes declaratively, keeping configuration in your repository.
  • The Container Admission Controller can block deployments carrying exploitable vulnerabilities or exposed secrets before they reach a cluster.
  • Sensor coverage extends to AWS Lambda, Fargate, Azure Container Apps and Google Cloud Run, not only Kubernetes nodes.
  • A hosted MCP server at mcp.upwind.io exposes security data to MCP clients over OAuth 2.1, with regional endpoints.

Cons

  • Headline figures of 93% noise reduction and 15-second detection come with no published methodology.
  • upwind.io publishes no price at all and routes every buyer to a demo request.
  • Detection baselines and API schemas are learned from live traffic, so that accumulated state does not transfer to another vendor.
  • The Red agent probes live production to prove exploitability, which is worth scoping carefully before enabling.

Right for

Platform teams who want runtime proof before escalating a CVE.

Avoid if

Teams who cannot let an AI agent probe production.

Buyer Questions

Common questions answered by our AI research team

Pricing

How much does Upwind cost?

Upwind's AWS Marketplace listing prices the core platform at $30,000 per unit for a 12-month contract and its 24/7 MDR service at $6,000. The upwind.io site publishes no price list and sells through a demo request, with private offers for negotiated terms.

Features

Does Upwind use agents or agentless scanning?

Both. Agentless Cloud Scanners inventory AWS, Azure, Google Cloud and Oracle Cloud accounts, while a lightweight eBPF sensor runs on hosts, Kubernetes nodes, ECS tasks, Lambda and container apps for runtime telemetry.

Integration

Does Upwind integrate with Jira and Slack?

Yes. Upwind creates and updates Jira tickets from its findings and pushes detections into Slack channels. Other integrations include Microsoft Teams, ServiceNow, Linear, PagerDuty, Splunk, Datadog, Tines and custom webhooks.

Setup

Which clouds does Upwind support?

Upwind connects AWS, Azure, Google Cloud and Oracle Cloud Infrastructure accounts. Cloud Scanners run either in Upwind's own tenancy under the SaaS model or inside your accounts under the Outpost model, onboarded with Terraform or CloudFormation.

Security

Does Upwind support SAML single sign-on?

Yes. Upwind documents SAML single sign-on for Okta, Microsoft Entra ID, Google Workspace, Duo, JumpCloud, OneLogin and PingOne, plus a generic SAML option. Role-based access control and audit logs are built into the Management Console.

Also in AI Security