Upwind is a cloud security vendor that installs a lightweight eBPF-based sensor across cloud workloads and uses the resulting runtime telemetry to find, prioritize, and respond to cloud risks. Its automation acts as a detection and triage layer that correlates runtime activity with cloud configuration data, with response steps still routed to security teams.
Upwind sells a cloud-native application protection platform built around runtime telemetry. A sensor deployed in customer cloud accounts and Kubernetes clusters collects process, network, and file activity using eBPF, and the platform correlates that signal with cloud configuration, identity, and workload inventory data to rank risks and detect active threats. Public product material and documentation describe modules spanning cloud security posture management, vulnerability management, workload and container protection, identity analysis, and API security, all presented through one console rather than as separate scanners (upwind.io, docs.upwind.io).
The company was founded in 2022 by Amiram Shachar, who previously founded and led Spot.io, and it operates from Israel with a United States commercial presence. Upwind remains a privately held, venture-backed business and has not published revenue, customer counts, or headcount in audited form; company profile pages are the only public reference points for scale (Crunchbase, LinkedIn).
Documented from public materials · these are the products the AMS scores
Upwind Cloud Security Platform
Shipping since 2023
The core platform deploys an eBPF sensor alongside cloud API integrations and combines runtime execution data with configuration and inventory context. Documented capability includes asset inventory, misconfiguration findings, vulnerability prioritization based on whether a package is actually loaded at runtime, and identity and permission analysis. The stated purpose of the runtime layer is to reduce the volume of findings that reach analysts rather than to act without them (docs.upwind.io).
Upwind Threat Detection and Response
Shipping since 2023
Threat detection uses the same sensor telemetry to flag suspicious process, network, and container behavior, then assembles related events into incident timelines with workload and cloud account context. Documentation describes alert routing to messaging and ticketing tools and support for investigation workflows, with containment and remediation decisions remaining with the customer security team (docs.upwind.io).
Upwind API Security
Upwind API Security
API security uses passive observation of runtime traffic to discover internal and external API endpoints, classify sensitive data flows, and highlight exposed or unauthenticated paths without requiring proxies or code changes. It is packaged as a module on the same sensor and console as the rest of the platform (upwind.io, docs.upwind.io).
2024 - 2026 ·gold = a monetization move· grey = product or capital
Upwind announced a growth financing round reported at roughly 100 million dollars, positioning the company as one of the larger privately funded runtime cloud security vendors. The round was capital and ownership related rather than a change to pricing or packaging (Crunchbase company profile).
Upwind expanded the platform into API security and additional runtime coverage areas, adding modules that reuse the existing sensor instead of introducing separate agents. The change broadened the product surface sold under the platform without any published change to the commercial model (upwind.io, docs.upwind.io).
Pricing not public. Upwind does not publish list prices, rate cards, or tier prices on its website, and the commercial route is a sales conversation or demo request. There is no published per-seat price, per-workload price, or published minimum commitment that can be verified from primary sources (upwind.io).
Packaging is described publicly in module terms rather than price terms. Product and documentation material presents posture management, vulnerability management, workload and container protection, identity analysis, threat detection and response, and API security as parts of one platform served by a single sensor deployment, which suggests a platform subscription with module scope rather than separately metered point products. Contract length, discount schedules, and ramp terms are not disclosed in any public document reviewed for this edition (docs.upwind.io).
There is no public evidence that Upwind operates a separate meter for automated or agentic activity. Detection, correlation, and prioritization are presented as platform functions included with the subscription, not as consumption units priced per action, per investigation, or per remediation. Any customer-specific pricing structure would need to be confirmed from a quote or order form, which is not public.
Analyst layer · placement follows the documented capability above
Independence. Documented behavior places Upwind in the middle band. The sensor collects and correlates continuously without human effort, and the platform reduces raw findings into ranked issues and incident timelines automatically. However, public documentation describes alerting, investigation support, and integration with ticketing and messaging tools rather than unattended containment or remediation of production workloads. A security engineer still decides and executes most outcomes, which supports an M rather than an L.
Job width. The platform covers an end-to-end workflow inside one function. Discovery, configuration analysis, vulnerability prioritization, identity review, runtime detection, and API exposure findings are handled in one console, which is more than a single task. It does not span functions outside security operations and cloud engineering, so the width is M rather than L.
Output versus cost. The runtime approach scales telemetry collection and correlation across large cloud estates with a fixed sensor footprint, producing a material multiple on what a manual review cycle could cover. Public evidence supports a meaningful but bounded multiplier of roughly ten to one hundred times on analysis throughput, so the position is Inflecting. There is no published customer metric that would justify an exponential position.
Monetization pattern. Upwind monetizes as a private-quote platform subscription. The documented pattern is to add modules onto one sensor and one console and to sell the combined platform to security and cloud teams, rather than to publish prices or expose automation as a separately billed meter. Because no list pricing, per-action pricing, or contract terms are public, the monetization design cannot be assessed beyond the module-based platform structure described in vendor documentation (upwind.io, docs.upwind.io).
| Edition | AMS score | Metric on record | Change |
|---|---|---|---|
| Aug 2026 | M · M · Infl | Pricing not public | Baseline, first edition |
Future editions add a row whenever the score or the metric moves, with the evidence that moved it.
About this data
Everything on this page is a synthesis of public information: published reporting, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.