Upwind is a private cloud and AI security company. Its Blue, Red, and Green agents use runtime context to investigate incidents, validate exploitable attack paths, and prepare remediations.
Upwind operates a cloud-native application protection platform that combines agentless scanning with runtime sensors. Its platform covers cloud posture, workloads, applications, identities, data, code, APIs, AI systems, and real-time threat detection. The Agentic Pack adds specialized agents for investigation, exploit validation, and remediation workflows.
Upwind was founded in San Francisco in October 2022 by members of the team behind Spot.io. Its public company snapshot reports more than 300 employees and 150 customers. Upwind remains privately held and venture-backed; it announced a $250 million financing in January 2026, which TechCrunch reported valued the company at $1.5 billion.
Documented from public materials · these are the products the AMS scores
Blue Agent
Shipping since 2026
Blue investigates cloud threat stories by gathering and correlating runtime telemetry, cloud events, process activity, network data, Kubernetes events, threat intelligence, and inventory context. It produces a true-positive, false-positive, or inconclusive verdict with supporting evidence and a confidence level. Upwind announced the Agentic Pack as generally available in May 2026 and released Blue's automatic Threat Story investigation experience in beta on August 20, 2026. Analysts can inspect the evidence, question the agent, and decide how to respond. Source
Red Agent
Shipping since 2026
Red validates whether cloud and AI security findings are reachable and exploitable. Upwind documents coverage across cloud misconfigurations, attack surfaces, APIs, identities, runtime behavior, models, MCP servers, and autonomous agents. Its output includes evidence about reachability, blast radius, and remediation priority. Source
Green Agent
Green Agent
Green converts prioritized findings into implementation-ready remediation for cloud infrastructure, applications, and identities. Upwind documents its use for grouping related issues and preparing changes that engineering teams can review and implement. Source
2024 - 2026 ·gold = a monetization move· grey = product or capital
Upwind released Blue's automatic Threat Story investigation experience in beta. The agent can automatically investigate eligible stories, correlate evidence, generate a verdict, and expose its reasoning for analyst review. Source
Upwind announced general availability of its Agentic Pack and packaged Blue, Red, Green, and Choppy inside the existing Cloud and AI Security Platform. The company stated that AI Security was part of the same platform and SKU, with no separate AI Security line item or new procurement requirement for existing customers. Source
Direct-sales pricing is not published as a standard price card. AWS Marketplace lists contract dimensions of $30,000 for the Upwind Cloud Security Platform and $6,000 for Upwind Managed Detection & Response for a 12-month term. The listing offers a free trial and private offers, with discounts of up to 8% for 24 months and up to 11% for 36 months. Contract entitlements are purchased in specified quantities, while Upwind's terms refer to additional capacity as Upwind Units.
Upwind's May 2026 packaging announcement placed AI Security and the Agentic Pack inside the main platform SKU. Public evidence does not document a separate consumption meter or separate charge for Blue, Red, or Green. Managed Detection & Response remains a separately listed marketplace dimension.
Upwind's public terms describe a subscription governed by an order form. Unless the order form states otherwise, fees are paid annually in advance within 30 days, are non-cancelable and non-refundable, and exclude taxes. Additional units, features, or subscription time require an amendment or new order form, with midterm purchases prorated to the existing subscription end date.
Analyst layer · placement follows the documented capability above
Independence, M. This is a provisional assessment as of September 21, 2026. Blue can automatically investigate an eligible Threat Story and issue an evidence-backed verdict, while Red validates exploitability and Green prepares remediations. Analysts still inspect evidence, resolve uncertainty, authorize or implement changes, and manage incident response. That places documented human involvement in the 20% to 50% range.
Job width, M. The Agentic Pack covers an end-to-end cloud defense workflow inside the security function: incident investigation, attack-path validation, prioritization, and remediation preparation. The agents can work across code, cloud infrastructure, workloads, identities, APIs, and AI systems, but the documented workflow remains centered on cloud security rather than broad cross-functional business operations.
Output versus cost, Inflecting. This is a provisional estimate based on public capability evidence available by September 21, 2026. Blue can trigger investigations automatically and run specialized evidence-gathering work in parallel across eligible incidents. An attributed customer statement on Upwind's agentic security page describes investigation work falling from hours to minutes. The evidence supports a 10 to 100 times output range, but not an Exponential classification.
Monetization pattern. Upwind monetizes the agents as capability expansion within a unit-based enterprise platform subscription rather than as separately metered agent products. Revenue scales through contracted platform quantities, subscription duration, private offers, additional Upwind Units, and the separately listed Managed Detection & Response service. The one-SKU approach makes agent adoption a platform packaging change rather than a new standalone budget line.
| Edition | AMS score | Metric on record | Change |
|---|---|---|---|
| Aug 2026 | M · M · Infl | Provisional AMS | Baseline, first edition |
Future editions add a row whenever the score or the metric moves, with the evidence that moved it.
About this data
Everything on this page is a synthesis of public information: published reporting, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.