Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk correlation.
Visit Website ↗Overview
Upwind Security was founded in October 2022 in San Francisco by Amiram Shachar, Tal Zur, and Lavi Ferdman, a founding team previously behind Spot.io, acquired by NetApp. Upwind has raised capital unusually fast: $80 million within its first twelve months, a $100 million round in December 2024, and a $250 million round in January 2026, backed by Bessemer Venture Partners, Greylock Partners, TCV, and Salesforce Ventures.
Technically, Upwind combines agentless cloud-resource scanning with lightweight eBPF-based runtime sensors, correlating static posture findings with live runtime behavior. The company reports 300+ employees and 150+ customers, including Roku, Siemens, Wix, and Peloton.
Innovation Matrix Assessment
Three funding rounds and rapid platform expansion within roughly three years of founding indicate an unusually fast product-development pace.
The agentless-plus-eBPF-runtime combination is designed specifically to cut alert noise by correlating static posture with live exploitability.
Raised roughly $430M+ across three rounds in about three years from top-tier investors — an exceptional funding trajectory for a company this young.
Runtime-first, eBPF-based detection paired with agentless posture scanning is a genuinely different architecture from traditional periodic-scan CSPM tools.
Analyst recognition is real third-party validation, but headline claims like 15-second detection time are vendor-stated and not independently verified; no named incident case study was found.
eBPF-based runtime detection for cloud and AI workloads is precisely the direction the category is moving.
Why CISOs Should Care
Upwind's runtime correlation is designed to cut through the alert fatigue of static CSPM findings by showing which misconfigurations are actually reachable and exploitable right now.
What Makes It Different
Rather than periodic agentless scans alone, Upwind pairs that posture data with always-on eBPF runtime sensors.
The Matrix Verdict
73/100 — MEANINGFUL INNOVATOR
Upwind is the most architecturally disruptive and fastest-moving company in this cloud-security comparison set, backed by exceptional funding momentum, but as a three-year-old company its real-world efficacy evidence is still thin.
Editorial Note: Claims vs. Verified Findings
Detection-time and 'hundreds of enterprises' claims are vendor-stated and unverified by independent sources found in this research.
Sources
Alternatives to Upwind Security
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Tenable Cloud Security
An agentless, graph-based cloud identity and posture platform, born as Israeli startup Ermetic, now folded into Tenable's exposure-management…
CrowdStrike Falcon Cloud Security
Hybrid agent/agentless cloud security module inside CrowdStrike's Falcon platform, pairing posture management with endpoint-grade runtime detection.