Company breakdown · 2026-09-21

Upwind

Upwind is a cloud security vendor that installs a lightweight eBPF-based sensor across cloud workloads and uses the resulting runtime telemetry to find, prioritize, and respond to cloud risks. Its automation acts as a detection and triage layer that correlates runtime activity with cloud configuration data, with response steps still routed to security teams.

Emerging tierCloud Defense AgentsPublic data only
2022
Founded
Not verified
Employees
Tel Aviv, Israel
Headquarters
Private, venture backed
Ownership

What Upwind does

Upwind sells a cloud-native application protection platform built around runtime telemetry. A sensor deployed in customer cloud accounts and Kubernetes clusters collects process, network, and file activity using eBPF, and the platform correlates that signal with cloud configuration, identity, and workload inventory data to rank risks and detect active threats. Public product material and documentation describe modules spanning cloud security posture management, vulnerability management, workload and container protection, identity analysis, and API security, all presented through one console rather than as separate scanners (upwind.io, docs.upwind.io).

The company was founded in 2022 by Amiram Shachar, who previously founded and led Spot.io, and it operates from Israel with a United States commercial presence. Upwind remains a privately held, venture-backed business and has not published revenue, customer counts, or headcount in audited form; company profile pages are the only public reference points for scale (Crunchbase, LinkedIn).

The agentic products

Documented from public materials · these are the products the AMS scores

Upwind Cloud Security Platform

Shipping since 2023

The core platform deploys an eBPF sensor alongside cloud API integrations and combines runtime execution data with configuration and inventory context. Documented capability includes asset inventory, misconfiguration findings, vulnerability prioritization based on whether a package is actually loaded at runtime, and identity and permission analysis. The stated purpose of the runtime layer is to reduce the volume of findings that reach analysts rather than to act without them (docs.upwind.io).

Upwind Threat Detection and Response

Shipping since 2023

Threat detection uses the same sensor telemetry to flag suspicious process, network, and container behavior, then assembles related events into incident timelines with workload and cloud account context. Documentation describes alert routing to messaging and ticketing tools and support for investigation workflows, with containment and remediation decisions remaining with the customer security team (docs.upwind.io).

Upwind API Security

Upwind API Security

API security uses passive observation of runtime traffic to discover internal and external API endpoints, classify sensitive data flows, and highlight exposed or unauthenticated paths without requiring proxies or code changes. It is packaged as a module on the same sensor and console as the rest of the platform (upwind.io, docs.upwind.io).

Recent moves

2024 - 2026 ·gold = a monetization move· grey = product or capital

Funding2024-11-01

Upwind announced a growth financing round reported at roughly 100 million dollars, positioning the company as one of the larger privately funded runtime cloud security vendors. The round was capital and ownership related rather than a change to pricing or packaging (Crunchbase company profile).

Product expansion2024-01-01

Upwind expanded the platform into API security and additional runtime coverage areas, adding modules that reuse the existing sensor instead of introducing separate agents. The change broadened the product surface sold under the platform without any published change to the commercial model (upwind.io, docs.upwind.io).

How Upwind charges today

Pricing not public. Upwind does not publish list prices, rate cards, or tier prices on its website, and the commercial route is a sales conversation or demo request. There is no published per-seat price, per-workload price, or published minimum commitment that can be verified from primary sources (upwind.io).

Packaging is described publicly in module terms rather than price terms. Product and documentation material presents posture management, vulnerability management, workload and container protection, identity analysis, threat detection and response, and API security as parts of one platform served by a single sensor deployment, which suggests a platform subscription with module scope rather than separately metered point products. Contract length, discount schedules, and ramp terms are not disclosed in any public document reviewed for this edition (docs.upwind.io).

There is no public evidence that Upwind operates a separate meter for automated or agentic activity. Detection, correlation, and prioritization are presented as platform functions included with the subscription, not as consumption units priced per action, per investigation, or per remediation. Any customer-specific pricing structure would need to be confirmed from a quote or order form, which is not public.

Our monetization breakdown

Analyst layer · placement follows the documented capability above

Independence. Documented behavior places Upwind in the middle band. The sensor collects and correlates continuously without human effort, and the platform reduces raw findings into ranked issues and incident timelines automatically. However, public documentation describes alerting, investigation support, and integration with ticketing and messaging tools rather than unattended containment or remediation of production workloads. A security engineer still decides and executes most outcomes, which supports an M rather than an L.

Job width. The platform covers an end-to-end workflow inside one function. Discovery, configuration analysis, vulnerability prioritization, identity review, runtime detection, and API exposure findings are handled in one console, which is more than a single task. It does not span functions outside security operations and cloud engineering, so the width is M rather than L.

Output versus cost. The runtime approach scales telemetry collection and correlation across large cloud estates with a fixed sensor footprint, producing a material multiple on what a manual review cycle could cover. Public evidence supports a meaningful but bounded multiplier of roughly ten to one hundred times on analysis throughput, so the position is Inflecting. There is no published customer metric that would justify an exponential position.

Monetization pattern. Upwind monetizes as a private-quote platform subscription. The documented pattern is to add modules onto one sensor and one console and to sell the combined platform to security and cloud teams, rather than to publish prices or expose automation as a separately billed meter. Because no list pricing, per-action pricing, or contract terms are public, the monetization design cannot be assessed beyond the module-based platform structure described in vendor documentation (upwind.io, docs.upwind.io).

Score and metric history

EditionAMS scoreMetric on recordChange
Aug 2026M · M · InflPricing not publicBaseline, first edition

Future editions add a row whenever the score or the metric moves, with the evidence that moved it.

Sources

About this data

Everything on this page is a synthesis of public information: published reporting, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.