Vestiaire Collective Strengthens Cloud Security with Upwind's CNAPP

"Upwind's real-time insights and support have enhanced our cloud security operations."

f69ddd666f6ea04612d9ffed41435f703ce120f3
Sardorbek Pulatov
|
VP Engineering (Security), Vestiaire Collective
vestiairecollective_logo 1

About

Co-founded in 2009, Vestiaire Collective is the leading global platform for pre-loved luxury and designer fashion. Its mission is to transform the fashion industry for a more sustainable future, through empowering its community to shop more consciously. The Certified B Corporation® offers a trusted space for its global community to prolong the life of its most-loved fashion pieces by simplifying the selling and buying process, as well as giving its members access to one-of-a-kind wardrobes on the platform.

Vestiaire Collective uses Upwind to increase visibility, reduce alert noise, and enhance vulnerability prioritization in their cloud environment.

Challenges

  • Vestiaire Collective’s security team experienced a significant increase in alert volume, with many notifications lacking the contextual information necessary for effective prioritization, leading to growing remediation backlogs.
  • The current system presented opportunities for enhancement in delivering comprehensive risk assessment guidance, causing inefficiencies in remediation efforts.
  • Understanding how services interacted within their cloud environment was challenging, hindering the team’s ability to assess potential impact areas.

Solutions

  • Upwind delivers runtime-powered security intelligence, allowing Vestiaire Collective’s team to eliminate unnecessary backlog and focus resources on genuine risks.
  • By correlating vulnerabilities with actual workload behavior and exposure, Upwind enables Vestiaire Collective’s security engineers to quickly identify which issues affect live services, improving response times and reducing the noise-to-signal ratio.
  • Upwind’s real-time topology map enables Vestiaire Collective to understand potential blast radius of risks, pinpoint upstream/downstream dependencies, and assess risk across their cloud environment.

Reduced Alert Noise and Fatigue

One of the most immediate improvements Vestiaire Collective experienced with Upwind was a significant reduction in alert noise. By leveraging runtime context and environment-aware intelligence, Upwind filters out non-actionable findings and surfaces only those threats and vulnerabilities that are exploitable and relevant. This shift allowed the security engineers to move away from manual triaging of endless alerts and focus on critical incidents that demanded their attention.

Upwind saves us a significant amount of time, helping our team focus on the truly critical alerts while disregarding low-priority findings.”

f69ddd666f6ea04612d9ffed41435f703ce120f3
Sardorbek Pulatov
|
VP Engineering (Security), Vestiaire Collective

Improved Vulnerability Prioritization

Upwind’s ability to tie vulnerabilities to actual running services provided Vestiaire Collective with newfound clarity in their risk landscape. Instead of being overwhelmed by a long list of CVEs, the team could see which vulnerabilities were present in running workloads, internet-exposed services, or had active exploit paths. This real-time prioritization helped the team focus their efforts on remediating vulnerabilities that actually mattered, significantly improving operational efficiency.

With Upwind, we are able to identify any vulnerabilities and can prioritize them for remediation — helping us operate more efficiently and securely.”

f69ddd666f6ea04612d9ffed41435f703ce120f3
Sardorbek Pulatov
|
VP Engineering (Security), Vestiaire Collective

Enhancing Security with Runtime Visibility

Upwind’s topology map and runtime insights provided a comprehensive, real-time view of how services connected and communicated within Vestiaire Collective’s cloud environment. This visibility proved critical not only for threat response but also for architectural planning and operational awareness.

Proactive Discovery Through API Insights

Upwind’s API discovery and behavioral analysis have also enhanced Vestiaire Collective’s ability to proactively identify potential risks in their environment. These findings allow their security team to proactively remediate potential risks across both cloud infrastructure and APIs while enhancing internal systems and configurations. What could have been missed or delayed was now proactively addressed thanks to Upwind’s deep contextual visibility into cloud workloads.

Upwind’s ability to provide detailed API insights shined the light on areas where we could proactively reduce our attack surface, that previously we had no visibility into. Doing so not only allowed us to harden our security, but to also act with increased precision and speed to reduce potential risks.”

f69ddd666f6ea04612d9ffed41435f703ce120f3
Sardorbek Pulatov
|
VP Engineering (Security), Vestiaire Collective

Expert Support as a Force Multiplier

Throughout the onboarding and expansion phases, Vestiaire Collective emphasized the strength of Upwind’s customer success and support team. More than just answering tickets, Upwind acted as a security partner — advising on best practices, helping with threat assessments, and providing real-time assistance when new issues emerged.

Summary

Today, Upwind provides Vestiaire Collective with real-time runtime visibility, contextual risk prioritization, proactive API security insights, and expert support, resulting in a dramatically streamlined and more effective cloud security posture.

Uplift Your Cloud
Security Today

Schedule a meeting with a cloud security experts today to secure your cloud, reduce friction between your teams and proactively protect your cloud infrastructure and applications.

Further Reading

How EX.CO Elevated Their Cloud Security with a Smarter UI and Unmatched Customer Care from Upwind Security

Spacelift is a modern infrastructure-as-code (IaC) platform that helps DevOps teams manage complex cloud deployments securely and collaboratively.

Ada is an AI-powered customer service automation platform on a mission to make customer service extraordinary for everyone.