Listing Thumbnail

    Upwind for AWS Security Hub Extended

     Info
    Upwind secures your entire cloud from deployments, configurations, and applications through a runtime fabric that transforms every layer in cloud security. When you understand what actually runs, you can cut through the noise and protect what really matters, prioritize security risks based on real usage, and detect threats in real time.
    4.8

    Overview

    Play video

    Upwind secures your entire cloud, from configurations and deployments to applications and runtime, through a runtime fabric that transforms cloud security from the inside out.

    Upwind combines agentless and sensor based scanning to secure your cloud deployments, configurations, and applications through a runtime fabric that provides real-time visibility from the inside out. You get a live map of your network and application topology, can prioritize fixes based on real usage, and detect threats as they happen across cloud configurations (CSPM), vulnerabilities,

    With Upwind, security, dev, and ops teams move faster, stay focused, and fix risks that matter most.

    Highlights

    • Upwind combines agentless scanning with real-time sensors to give you complete coverage without tradeoffs. That means CSPM, vulnerability management, container security, runtime protection, and attack surface management, across multi-cloud and on-prem, all in one platform.
    • By pairing runtime context with agentless scanning, Upwind reduces cloud risk noise by 95%. Risk prioritization improves by 10x.
    • Mean time to detect drops. Mean time to resolution drops. And every fix your team makes is grounded in what's actually running, not what might theoretically be at risk.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Upwind for AWS Security Hub Extended

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (1)

     Info
    Dimension
    Description
    Cost/unit
    Units protected by Upwind
    Count of assets scanned by Upwind
    $3.75

    Vendor refund policy

    Please contact the Upwind Sales team via email at sales@upwind.io  .

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Included in your contract, Upwind provides 24/7 live chat support, onboarding, and continuous enablement. Onboarding includes integration setup, assistance configuring the platform, and guidance on utilizing it to serve you in your cloud security journey. You can also contact our support team via email at support@upwind.io  .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.8
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    100%
    0%
    0%
    0%
    0%
    2 AWS reviews
    Guy Fridman

    Gaining Confidence in Cloud Security with Improved Vulnerability Management

    Reviewed on May 09, 2025
    Review from a verified AWS customer

    What is our primary use case?

    I have several use cases for Upwind . I will start with our private cloud that is based on Kubernetes , so we're using it also for Cloud Detection and Response and also for vulnerability scanning. We're also using it on our cloud provider as a CSPM.

    For Cloud Detection and Response, one of the biggest challenges is to have detection around containers, which we were missing visibility on, and with Upwind , we get it. Related to the vulnerability, because of the strong runtime sensor Upwind developed, it helps us to reduce many of the vulnerabilities that were classified by the shift left product that we used.

    What is most valuable?

    In general, I think that Upwind as a product makes a disruption in the concept of shift left; they come with a new approach by the runtime sensor that they made, making life for the AppSec team much easier.

    It's a good question about the best features Upwind offers, but in general, they build a great product. One feature I can think about is their very strong API, allowing us to export most of the data to crunch and work with it. To me, having a wide API to interact with the data is very important.

    In general, we use the API to export the asset and then compare it with our findings to improve triage, ensuring we are not missing anything. This is one of the main use cases for the API.

    Having access to this API changes our team's efficiency dramatically; programmability makes everyone's life much easier. The operation reduces because of the time that analysts need to spend on triaging, and it also minimizes friction with developers, which is something Upwind helps us with.

    Upwind positively impacts our organization overall by helping with the CIS benchmark for Kubernetes , which is definitely one of the strongest parts. Second, by reducing the number of vulnerabilities, we automatically reduce the number of tickets opened with the dev team, which is a big win. It also helps us to tune our vulnerability program better regarding classification and priority.

    What needs improvement?

    Currently, we are working with Upwind on API security, which is something we want them to keep pushing. We also want them to be able to record SSH sessions; it's a tough request.

    For how long have I used the solution?

    We have been using Upwind for over a year now.

    What was my experience with deployment of the solution?

    The deployment of Upwind was easy peasy.

    The configuration process was pretty straightforward with no challenges.

    What do I think about the stability of the solution?

    Upwind is stable in my experience; I haven't faced any downtime or reliability issues.

    What do I think about the scalability of the solution?

    Upwind's scalability is transparent for me; I haven't faced any workload issues.

    How are customer service and support?

    From my experience, Upwind has the best support as a vendor; their response time is less than 2 minutes from the moment you slack them.

    I would rate the customer support a 10.

    Which solution did I use previously and why did I switch?

    We currently also work with customers, but I can't really disclose the names of previous solutions we used before Upwind.

    How was the initial setup?

    In terms of proof of value, we see results very fast after implementing Upwind; the deployment is quite simple and doesn't require a lot of time. We start a POC for 2 months, and then we roll out to production in 2 to 2 and a half months in our huge production environment. Related to the vulnerability feature, again, with a strong runtime sensor, you can see the value pretty fast.

    In terms of the daily day-to-day operation, Upwind has helped us a lot; even at the beginning, we needed to build a process around it because it's something new, but I would say that we feel much more confident knowing what is running in our Kubernetes environment. Related to the critical vulnerabilities, it has helped us to reduce about 70% of the critical vulnerabilities.

    What was our ROI?

    Both the licensing process and ROI were very simple, making sense overall.

    We compare the return on investment with Upwind versus other companies, but I cannot disclose the specifics.

    What's my experience with pricing, setup cost, and licensing?

    The pricing, setup cost, and licensing process were pretty reasonable.

    Which other solutions did I evaluate?

    Before choosing Upwind, I evaluated Twistlock .

    What other advice do I have?

    My company does not have a business relationship with this vendor other than being a customer.

    What I would change right now is nothing; I'm okay.

    The work with Upwind is very collaborative; analysts work closely with them to make things easier for us as a company and for other companies using Upwind. In terms of time saving, it definitely saves many hours. I struggle to quantify it in numbers.

    We did not purchase Upwind through the AWS Marketplace .

    Currently, there is no integration with other AWS  services, so I cannot comment.

    The procurement process was pretty easy and straightforward.

    I haven't encountered any surprises regarding the metering and billing experience; everything is clear with our 2-year contract, so we are good to go.

    It's hard to dig into it, but I estimate that the number of tickets opened with our dev team drops by probably 30 to 40% after using Upwind.

    My advice for others looking into using Upwind is that if you are seeking a strong CNAPP  with an advanced runtime and strong CDR capabilities, this is the product.

    On a scale of 1-10, I rate Upwind a 10.

    reviewer2702562

    Increased compliance and visibility boost cloud security posture

    Reviewed on May 05, 2025
    Review from a verified AWS customer

    What is our primary use case?

    We use Upwind  for runtime security in our cloud environments. We also use Upwind  for cloud security posture management, API security, and cloud vulnerability management.

    What is most valuable?

    Upwind has great runtime detection and response capabilities for our cloud workloads. It provides great context for vulnerability management, allowing us to see what our most important vulnerabilities are. Upwind gives us insight into API security threats and helps us identify misconfigurations in our cloud environments to align with security frameworks like CIS or NIST. With Upwind, we have greatly increased our cloud security posture. Our compliance rates have improved significantly, and they have helped us automate vulnerability management and gain insights into API endpoint security.

    What needs improvement?

    Upwind just needs to continue on the path they are on. They have some really great ideas and need to keep refining their different tool sets and add to their reporting and automation. However, they have a strong platform as it is.

    For how long have I used the solution?

    I started using Upwind a couple of years ago.

    What was my experience with deployment of the solution?

    It was very easy for us to deploy. Their deployment is much more modern and automated than others that we have seen.

    What do I think about the stability of the solution?

    Absolutely, Upwind is stable.

    What do I think about the scalability of the solution?

    Upwind scales great for us. It is deployed in such a way that whenever we build something new, it automatically deploys to those new resources, and we really don't have to touch it much. So, it scales really well.

    How are customer service and support?

    Customer support is fantastic. We have a very good relationship with the Upwind team. They are always timely in their response and provide direct integration with us via Slack . Whenever we have issues, they are right there to support us.

    Which solution did I use previously and why did I switch?

    Yes, we did. We used another cloud security provider. We switched because they were a more legacy provider and their integrations were not as modern or capable. Their runtime alerting did not surface the same amount of detail or events, and we felt Upwind was cloud-first, which aligns with our company's cloud-first direction.

    How was the initial setup?

    The initial setup was fairly straightforward. Pretty much everything was done via infrastructure as code, using either Terraform  or CloudFormation . It was as easy as applying those templates to our environment.

    What was our ROI?

    Upwind has definitely saved us a lot of time in reviewing the findings with the posture findings. It also saved us time in vulnerability management by significantly lowering the number of vulnerabilities we need to focus on, reducing the time required to address critical issues.

    What's my experience with pricing, setup cost, and licensing?

    Pricing, setup costs, and licensing were very fair.

    What other advice do I have?

    I would just say it's a great product. They have greatly improved our visibility. They are great to work with. They are a great overall cloud security platform and they continue innovating and adding new features. I would rate the overall solution a 10 out of 10.
    View all reviews