Upwind is the next-generation cloud security platform, focusing on runtime context to reveal the most critical risks and important insights from your cloud infrastructure.
Run faster and more securely with Upwind's next-generation cloud security platform. Combine the power of cloud security posture with runtime context and realtime protection, enabling your security team to prioritize accurately and respond fast to your most critical risks.
Highlights
Upwind is the next-generation cloud security platform that helps you simplify and solve cloud security's biggest challenges.
Upwind consolidates tools and brings security, DevOps and engineering
teams together with its comprehensive CNAPP.
Upwind brings together the best of all worlds to fit your unique cloud environment - so you can start fast and scale even faster.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy this platform on a contract basis, priced in units. Two products anchor the pricing. The Upwind Cloud Security Platform covers cloud security across your environment. The Upwind Managed Detection & Response 24/7 Service adds around-the-clock threat detection, investigation, and response support. You choose the units you need for each product, and your cost scales with that quantity. You can commit to either product on its own or combine both. Pricing rises as you add more units under your contract term.
Top-of-mind questions for buyers
What does the Upwind Managed Detection & Response 24/7 Service actually cover?
This service adds around-the-clock threat detection, investigation, and containment support. Senior researchers join your team on-demand to guide action during active breaches and zero-day incidents. It includes live incident war rooms, attack path reconstruction, and continuous monitoring for follow-up attacker attempts after initial containment.
What does the Upwind Cloud Security Platform product include beyond the detection and response service?
The platform unifies application security, security posture, and real-time protection on one system. It covers cloud misconfiguration detection, vulnerability management, container and serverless security, and identity entitlement management. It combines agentless scanners with runtime sensors to map assets and prioritize risks across your cloud lifecycle.
Which product drives my cost, and can I buy them separately?
Both products bill independently by unit quantity. Your total combines the units chosen for each. The Cloud Security Platform typically scales with the size of your cloud environment. The Managed Detection & Response service scales with the coverage you need. You can commit to either product alone or combine both.
www.upwind.io+1
Helpful?
Vendor refund policy
Please contact the Upwind Sales team via email at sales@upwind.io.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Included in your contract, Upwind provides 24/7 live chat support, onboarding, and continuous enablement. Onboarding includes integration setup, assistance configuring the platform, and guidance on utilizing it to serve you in your cloud security journey. You can also contact our support team via email at support@upwind.io.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Combines cloud security posture assessment with runtime context to identify and prioritize critical risks in cloud infrastructure.
Runtime Context Analysis
Leverages runtime context to reveal the most critical risks and provide important insights from cloud infrastructure operations.
Real-time Protection
Delivers real-time protection capabilities enabling security teams to respond quickly to identified critical risks.
Unified Security Platform
Consolidates multiple security tools into a comprehensive Cloud Native Application Protection Platform (CNAPP) for integrated security management.
Cross-team Collaboration
Brings together security, DevOps, and engineering teams through a unified platform to streamline cloud security operations.
Multi-Cloud and Workload Coverage
Supports deployment across more than 40 AWS services including compute, containers, storage, databases, networking, developer tools, management and governance, analytics, security, application integration, end user computing, machine learning, and migration services with coverage for public and private cloud, Kubernetes, rare Linux distros, IBM LinuxONE, and developer endpoints.
Agentless and Agent-Based Detection
Provides instant-on agentless coverage with optional osquery-based agent utilizing eBPF technology for runtime protection, advanced remediation, and forensics with minimal memory, CPU, and disk I/O footprint.
Full Lifecycle Application Security
Detects malware and suspicious behavior on developer endpoints, identifies vulnerabilities in build processes, verifies secure configurations, performs exposure scanning, full attack path analysis, and continuous production monitoring across hybrid cloud workloads and infrastructure.
Identity and Access Management Security
Includes Identity Threat Detection and Response (ITDR) capabilities with full visibility into IAM policies, users, and roles to simplify least privilege access maintenance and detect identity-specific threats.
Compliance and Forensic Analysis
Supports CIS benchmarks, HIPAA, ISO 27001, NIST, PCI, and SOC 2 compliance with 13-month data lookback for compliance and forensic analysis capabilities.
Uses identity-first approach to correlate risks across vulnerabilities, misconfigurations, and excessive privileges with Just-in-Time (JIT) Access and least-privilege remediation
AI and Data Security
Detects unauthorized AI software and vulnerabilities in AI workloads through AI Security Posture Management (AI-SPM) and protects sensitive data through Data Security Posture Management (DSPM)
Agentless Infrastructure Assessment
Provides agentless assessment of EC2 instances with native AWS integration for instant visibility into vulnerabilities across traditional IT and cloud-native environments
Infrastructure as Code Security
Implements shift-left security in CI/CD pipelines through Infrastructure as Code (IaC) scanning to identify and prevent misconfigurations before deployment
Runtime context has transformed how we prioritize exploitable cloud risks and protect workloads
Reviewed on Aug 21, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for Upwind is cloud security and workload protection. I primarily use it to gain visibility into cloud assets, vulnerabilities, and runtime risks, and I mainly use it to prioritize the risks that actually matter and help the team focus remediation efforts instead of treating every finding equally.
A specific example would be using Upwind to investigate a vulnerable cloud workload and determine if it was actually exposed or active at runtime. The runtime context helped us prioritize the issue based on real traffic and workload behavior instead of treating every vulnerability as equally urgent.
What is most valuable?
I appreciate runtime context, which helps connect vulnerabilities and misconfigurations with actual workload behavior and network relationships, making it easier to prioritize remediation based on real exposure rather than simply working through a long list of security findings.
The best features that stand out to me are contextual vulnerability prioritization, cloud workload visibility, and runtime security. I especially value how Upwind connects vulnerabilities with actual runtime behavior, which helps focus on exploitable risk rather than working through a long list of findings.
It has helped us focus on actual exploitable risk instead of treating every vulnerability equally. By considering runtime activity, exposure, reachability, and sensitive data context, the team can prioritize remediation much faster and reduce unnecessary alert noise.
I also value the runtime visibility and attack path context because it connects security findings with network behavior and actual workload. This makes investigations more actionable and helps the team move from simply detecting issues to understanding their real impact.
The biggest positive impact has been the prioritization of cloud security risk and improved visibility. Instead of chasing every vulnerability, we can focus on issues that are actually exposed or active at runtime, which makes the security team more efficient and remediation more targeted.
What needs improvement?
I would appreciate more customizable dashboards and reporting for different teams, such as security operations, engineering, and leadership. The runtime context is excellent, but tailoring those views for each audience would make day-to-day use even smoother.
I would appreciate more flexibility in the filtering capabilities and reporting for different security teams. I would also appreciate customizing dashboards. As environments grow larger, making it easier to surface role-specific risk and trends would make an already strong platform even more efficient.
For how long have I used the solution?
I have been using Upwind for around a year, approximately ten months.
What other advice do I have?
Upwind's AI governance and security are strong because they combine AI posture controls with real-time runtime visibility, which gives the security team better context around data flows, identities, AI workloads, and potential threats rather than relying on static configuration checks.
I have found the AI-related security insights to be generally accurate and useful, especially when they are backed by runtime telemetry and actual workload behavior. I also appreciate that the platform provides context and evidence around findings, which makes it easier to validate whether an alert is genuinely actionable.
I would recommend Upwind to teams that need strong cloud visibility with runtime context rather than relying on static vulnerability scans. I would start with a focused set of cloud workloads, validate the risk prioritization, and then expand it across the environment as the team becomes comfortable with the workflows.
Overall, my experience is very positive with Upwind. The combination of runtime visibility, security insights, and contextual risk prioritization makes it much easier to focus on the risks that actually matter. I gave this review a rating of ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Anton Paolo d.
Fast, High-Fidelity Cloud Risk Visibility with Upwind
Reviewed on Mar 03, 2026
Review provided by G2
What do you like best about the product?
Upwind gives us fast, high‑fidelity visibility into cloud risk with minimal implementation friction. It correlates posture, workload, and identity data into a prioritized view so my team can focus on issues that are actually exploitable instead of wading through generic CSPM noise.
What do you dislike about the product?
Some features still feel early‑stage: reporting and exec‑friendly dashboards are limited, and a few detections/integrations require vendor help to tune. The core signal is strong, but I’d like more polish and self‑service customization around views and workflows.
What problems is the product solving and how is that benefiting you?
It’s consolidating fragmented cloud security (CSPM, CDR, CNAPP) into one view and reducing alert fatigue. We get clearer prioritization, faster remediation cycles with engineering, and a more defensible narrative to leadership about how we’re managing cloud risk.
Marketing and Advertising
Outstanding Support and Customization—A Joy to Work With
Reviewed on Oct 28, 2025
Review provided by G2
What do you like best about the product?
Upwind has been a joy to work with from initial contact through deployment and beyond. Their sales and CS staff is on top of any issues and they work diligently to get the right solution in place. Their technical staff has been super responsive to any questions we have and are always willing to consider adding new functionality to meet the needs of their customers. Awesome tool and staff.
What do you dislike about the product?
None so far! If anything there is work to be done on the compliance front for reporting NIST or GDPR compliance checks.
What problems is the product solving and how is that benefiting you?
Providing visibility into our cloud environment and making discovery of gaps easy to identify.
Jessica S.
Outstanding Visibility, But Overwhelming Volume of Findings
Reviewed on Oct 28, 2025
Review provided by G2
What do you like best about the product?
Upwind has given us excellent visibility and has greatly enhanced our risk posture.
What do you dislike about the product?
The level of visibility we have leads to a large number of vulnerability findings, which can quickly become overwhelming.
What problems is the product solving and how is that benefiting you?
Before using upwind, we lacked any insight into our container run times, so adopting it brought significant value to our operations. Additionally, we now benefit from greater visibility throughout our environment, along with comprehensive data that aids in both identifying and addressing issues.