Upwind is a runtime-powered Cloud Native Application Protection Platform (CNAPP) that utilizes real-time data to enhance security across multi-cloud environments, including VMs, containers, and serverless functions. It reduces alert fatigue and prioritizes critical vulnerabilities, enabling security teams to respond effectively to real risks while streamlining compliance and remediation efforts.
Funding
$100M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.



Founders
Product
Problem
Cloud environments are increasingly complex and dynamic, making it difficult for security teams to gain comprehensive visibility and accurately prioritize risks. Traditional security tools often rely on static configurations and external scans, leading to alert fatigue and slow response times to emerging threats.
Solution
Upwind offers a runtime-powered Cloud Native Application Protection Platform (CNAPP) that leverages real-time data to provide enhanced security across multi-cloud environments, including VMs, containers, and serverless functions. By taking an "inside-out" approach, Upwind analyzes actual API usage, network activity, and data flows to identify critical risks with clear root causes. The platform consolidates multiple security tools, enabling security, DevOps, and engineering teams to collaborate effectively, reduce alert noise, and accelerate remediation efforts.
Target Audience
Upwind is designed for security, DevOps, and engineering teams responsible for securing cloud-native applications and infrastructure in multi-cloud environments.
Features
- Runtime sensors that provide real-time visibility into cloud workloads, including network, APIs, and data flows
- Graph-based inventory and vulnerability management for comprehensive asset discovery
- Cloud Detection and Response (CDR) capabilities for detecting and preventing threats in real-time
- eBPF-powered workload protection for securing hosts, containers, VMs, and serverless functions
- API security features for effortless API discovery, dynamic API testing, and shift-left security with runtime context
- Integration with CI/CD pipelines for continuous security monitoring and vulnerability assessment
- Automated compliance checks and reporting to streamline audit processes
- Customizable rules and policies to enforce security best practices