Upwind Cloud Security Platform
Runtime context has transformed how we prioritize exploitable cloud risks and protect workloads
What is our primary use case?
My main use case for Upwind is cloud security and workload protection. I primarily use it to gain visibility into cloud assets, vulnerabilities, and runtime risks, and I mainly use it to prioritize the risks that actually matter and help the team focus remediation efforts instead of treating every finding equally.
A specific example would be using Upwind to investigate a vulnerable cloud workload and determine if it was actually exposed or active at runtime. The runtime context helped us prioritize the issue based on real traffic and workload behavior instead of treating every vulnerability as equally urgent.
What is most valuable?
I appreciate runtime context, which helps connect vulnerabilities and misconfigurations with actual workload behavior and network relationships, making it easier to prioritize remediation based on real exposure rather than simply working through a long list of security findings.
The best features that stand out to me are contextual vulnerability prioritization, cloud workload visibility, and runtime security. I especially value how Upwind connects vulnerabilities with actual runtime behavior, which helps focus on exploitable risk rather than working through a long list of findings.
It has helped us focus on actual exploitable risk instead of treating every vulnerability equally. By considering runtime activity, exposure, reachability, and sensitive data context, the team can prioritize remediation much faster and reduce unnecessary alert noise.
I also value the runtime visibility and attack path context because it connects security findings with network behavior and actual workload. This makes investigations more actionable and helps the team move from simply detecting issues to understanding their real impact.
The biggest positive impact has been the prioritization of cloud security risk and improved visibility. Instead of chasing every vulnerability, we can focus on issues that are actually exposed or active at runtime, which makes the security team more efficient and remediation more targeted.
What needs improvement?
I would appreciate more customizable dashboards and reporting for different teams, such as security operations, engineering, and leadership. The runtime context is excellent, but tailoring those views for each audience would make day-to-day use even smoother.
I would appreciate more flexibility in the filtering capabilities and reporting for different security teams. I would also appreciate customizing dashboards. As environments grow larger, making it easier to surface role-specific risk and trends would make an already strong platform even more efficient.
For how long have I used the solution?
I have been using Upwind for around a year, approximately ten months.
What other advice do I have?
Upwind's AI governance and security are strong because they combine AI posture controls with real-time runtime visibility, which gives the security team better context around data flows, identities, AI workloads, and potential threats rather than relying on static configuration checks.
I have found the AI-related security insights to be generally accurate and useful, especially when they are backed by runtime telemetry and actual workload behavior. I also appreciate that the platform provides context and evidence around findings, which makes it easier to validate whether an alert is genuinely actionable.
I would recommend Upwind to teams that need strong cloud visibility with runtime context rather than relying on static vulnerability scans. I would start with a focused set of cloud workloads, validate the risk prioritization, and then expand it across the environment as the team becomes comfortable with the workflows.
Overall, my experience is very positive with Upwind. The combination of runtime visibility, security insights, and contextual risk prioritization makes it much easier to focus on the risks that actually matter. I gave this review a rating of ten out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Fast, High-Fidelity Cloud Risk Visibility with Upwind
Outstanding Support and Customization—A Joy to Work With
Outstanding Visibility, But Overwhelming Volume of Findings
Lightning-Fast Detections, Needs Bulk Alert Management
Effortless AWS Integration That Delivers as Promised
Stunning Graphics and Easy Resource Management
The support is qvery quick to respond.
Powerful runtime visibility and root-cause tracing
Gaining Confidence in Cloud Security with Improved Vulnerability Management
What is our primary use case?
I have several use cases for Upwind. I will start with our private cloud that is based on Kubernetes, so we're using it also for Cloud Detection and Response and also for vulnerability scanning. We're also using it on our cloud provider as a CSPM.
For Cloud Detection and Response, one of the biggest challenges is to have detection around containers, which we were missing visibility on, and with Upwind, we get it. Related to the vulnerability, because of the strong runtime sensor Upwind developed, it helps us to reduce many of the vulnerabilities that were classified by the shift left product that we used.
What is most valuable?
In general, I think that Upwind as a product makes a disruption in the concept of shift left; they come with a new approach by the runtime sensor that they made, making life for the AppSec team much easier.
It's a good question about the best features Upwind offers, but in general, they build a great product. One feature I can think about is their very strong API, allowing us to export most of the data to crunch and work with it. To me, having a wide API to interact with the data is very important.
In general, we use the API to export the asset and then compare it with our findings to improve triage, ensuring we are not missing anything. This is one of the main use cases for the API.
Having access to this API changes our team's efficiency dramatically; programmability makes everyone's life much easier. The operation reduces because of the time that analysts need to spend on triaging, and it also minimizes friction with developers, which is something Upwind helps us with.
Upwind positively impacts our organization overall by helping with the CIS benchmark for Kubernetes, which is definitely one of the strongest parts. Second, by reducing the number of vulnerabilities, we automatically reduce the number of tickets opened with the dev team, which is a big win. It also helps us to tune our vulnerability program better regarding classification and priority.
What needs improvement?
Currently, we are working with Upwind on API security, which is something we want them to keep pushing. We also want them to be able to record SSH sessions; it's a tough request.
For how long have I used the solution?
We have been using Upwind for over a year now.
What was my experience with deployment of the solution?
The deployment of Upwind was easy peasy.
The configuration process was pretty straightforward with no challenges.
What do I think about the stability of the solution?
Upwind is stable in my experience; I haven't faced any downtime or reliability issues.
What do I think about the scalability of the solution?
Upwind's scalability is transparent for me; I haven't faced any workload issues.
How are customer service and support?
From my experience, Upwind has the best support as a vendor; their response time is less than 2 minutes from the moment you slack them.
I would rate the customer support a 10.
Which solution did I use previously and why did I switch?
We currently also work with customers, but I can't really disclose the names of previous solutions we used before Upwind.
How was the initial setup?
In terms of proof of value, we see results very fast after implementing Upwind; the deployment is quite simple and doesn't require a lot of time. We start a POC for 2 months, and then we roll out to production in 2 to 2 and a half months in our huge production environment. Related to the vulnerability feature, again, with a strong runtime sensor, you can see the value pretty fast.
In terms of the daily day-to-day operation, Upwind has helped us a lot; even at the beginning, we needed to build a process around it because it's something new, but I would say that we feel much more confident knowing what is running in our Kubernetes environment. Related to the critical vulnerabilities, it has helped us to reduce about 70% of the critical vulnerabilities.
What was our ROI?
Both the licensing process and ROI were very simple, making sense overall.
We compare the return on investment with Upwind versus other companies, but I cannot disclose the specifics.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing process were pretty reasonable.
Which other solutions did I evaluate?
Before choosing Upwind, I evaluated Twistlock.
What other advice do I have?
My company does not have a business relationship with this vendor other than being a customer.
What I would change right now is nothing; I'm okay.
The work with Upwind is very collaborative; analysts work closely with them to make things easier for us as a company and for other companies using Upwind. In terms of time saving, it definitely saves many hours. I struggle to quantify it in numbers.
We did not purchase Upwind through the AWS Marketplace.
Currently, there is no integration with other AWS services, so I cannot comment.
The procurement process was pretty easy and straightforward.
I haven't encountered any surprises regarding the metering and billing experience; everything is clear with our 2-year contract, so we are good to go.
It's hard to dig into it, but I estimate that the number of tickets opened with our dev team drops by probably 30 to 40% after using Upwind.
My advice for others looking into using Upwind is that if you are seeking a strong CNAPP with an advanced runtime and strong CDR capabilities, this is the product.
On a scale of 1-10, I rate Upwind a 10.
Increased compliance and visibility boost cloud security posture
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Positive