Upwind CNAPP Platform logo

Upwind CNAPP Platform

Cloud SecurityCloud-Native Application Protection Platform (CNAPP)

Runtime-first CNAPP using eBPF sensors for real-time cloud threat detection and prioritization.

Vendor Information

Upwind logo

Upwind

San Francisco, CA, United States

Upwind CNAPP Platform Overview

Upwind was founded in 2022 by Amiram Shachar and the founding team behind Spot.io, which sold to NetApp for $450 million in 2020 (co-founders: Liran Polak, Lavi Ferdman, Tal Zuri). The company has raised $180 million across three rounds: $28M seed (September 2022), $50M (August 2023), and $100M Series A (December 2024) led by Craft Ventures, with participation from TCV, Alta Park Capital, Greylock, Cyberstarts, Leaders Fund, Cerca Partners, and Sheva (founded by NBA player Omri Casspi). Upwind reached a $900 million valuation in December 2024 (tripling in 15 months) and is in advanced talks for a $1 billion acquisition by Datadog (July 2025). The company employs approximately 150 people across offices in San Francisco, Tel Aviv, UK, and Iceland, with plans to double to 300 employees by end of 2025.

Upwind delivers a runtime-powered CNAPP that uses eBPF sensors to provide deep visibility into cloud workloads at the process, network, and system call level. Unlike traditional CNAPPs that rely on static configuration scanning, Upwind's inside-out security approach analyzes real traffic, API calls, and runtime behavior to detect threats as they happen and prioritize risks based on actual exploitability rather than theoretical vulnerabilities. Customers report 95% alert noise reduction and 7x faster time to remediation through Upwind's contextualized threat detection. In December 2024, Upwind launched its integrated AI Security Suite, introducing AI Detection & Response (AI-DR), AI Security Posture Management (AI-SPM), AI Bill of Materials (AI-BOM), and GenAI Security capabilities that leverage the same runtime intelligence powering its core CNAPP platform. The platform consolidates CSPM, CWPP, CDR, CIEM, DSPM, vulnerability management, container security, identity security, and API security into a unified solution.

Upwind serves over 700 customers including Fortune 500 companies and notable clients such as Wix, Bill.com, Ping Identity, Booking.com, Yotpo, and Abnormal AI. The company achieved FedRAMP Moderate Equivalency designation through a strategic partnership with Coalfire to enable federal agency adoption. In April 2025, Upwind completed its first acquisition of Nyx Security, an embedded cybersecurity startup, further expanding its platform capabilities. Gartner recognizes Upwind as a representative CNAPP vendor, and the company has been featured in industry reports highlighting the convergence of cloud security and observability. With 80% of business in North America and growing European presence, Upwind is positioning itself as a next-generation alternative to legacy cloud security tools and acquisition-heavy platforms.

Key Capabilities

Standardized capabilities mapped to this product's security niche

Analyzes IAM policies across AWS, Azure, and GCP to surface over-permissioned roles, unused permissions, and cross-account trust relationships that create lateral movement opportunities.

Monitors running pod and container behavior against policy, detecting unexpected process execution, network connections, and privilege escalation at runtime rather than at image scan time.

Reads cloud volume snapshots out-of-band to assess workloads without deploying agents or sending traffic to running instances. Enables coverage of systems that cannot run agents (mid-migration, locked-down, or legacy.

Enforces a single policy definition across AWS, Azure, and GCP resource types, translating to provider-native configurations rather than requiring separate policy sets per cloud.

Correlates individual misconfigurations and CVEs into chained attack scenarios showing lateral movement paths from exposed entry point to a target asset. Produces a prioritized list of attack paths rather than a flat CVE inventory.

Delivers scan results inside developer IDEs and pipeline stages so developers receive findings before code merges, reducing the cost and cycle time of remediation.

Exports compliance evidence pre-mapped to framework control requirements (SOC 2, ISO 27001, PCI DSS), in formats auditors can consume directly: not raw CSV exports requiring manual assembly.

Populates exercise technique selection from current threat intelligence about adversaries relevant to the organization, focusing exercise scope on realistic threats rather than theoretical coverage.

Instruments workload behavior at the kernel level via eBPF without a traditional user-space agent. Provides syscall-level visibility into process execution, network connections, and file access in running containers and VMs.

Integrations

Compatible tools and platforms

AWSAzureCI/CD ToolsContainer RegistriesDockerGitGitHub ActionsGitLabGoogle CloudJenkinsKubernetesSIEM Systems

Solution Details

Compliance & Certifications

Regulatory frameworks and security certifications

GDPRISO/IEC 27001:2022SOC 2 Type II

Deployment Options

Where and how this solution can be deployed

CloudSaaS

Support Channels

Available support and communication options

24/7 SupportEmail SupportKnowledge Base

Pricing Model

How this solution is priced

Subscription

How to buy

This profile hasn’t been claimed yet. Contact the vendor directly for pricing and purchasing options.

Is this your company?

Claim Your Profile