Get a Demo
Under Attack?
Severless framework

A New Standard for Serverless Security: The Upwind Serverless Framework

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Chris Lentricchia September 12, 2025

Today, we’re introducing the Upwind Serverless Framework, a new runtime-first compliance framework purpose-built for serverless environments. Upwind has long provided runtime visibility into serverless workloads; this framework builds on that foundation by aligning real-time behavior with compliance controls, making it easier to detect misconfigurations, enforce least privilege, and surface risks that matter. It helps security teams and platform engineers bring structure and clarity to the dynamic nature of serverless applications without relying on static analysis or manual auditing.

In this blog, we’ll walk through what makes serverless environments challenging to secure, how the framework addresses those challenges, and the benefits it offers to engineering and security teams.

What Are Serverless Environments and Why Are They Hard to Secure?

Serverless computing has become a key enabler of modern cloud-native development. Platforms like AWS Lambda and Google Cloud Functions allow teams to run isolated units of code without managing servers or infrastructure. These functions are ephemeral, event-driven, and highly scalable, offering clear operational advantages.

But the characteristics that make serverless appealing also make it difficult to secure. Functions are short-lived, which limits the effectiveness of traditional monitoring tools. They often rely on broad permissions, and they scale horizontally, sometimes creating hundreds or thousands of points of exposure. Visibility gaps are common, and misconfigurations are difficult to detect, especially when runtime behavior is not fully understood. This creates a situation where even simple serverless applications can introduce meaningful security risk.

CleanShot-2025-08-28-at-10.48.09@2x
The Upwind Platform observes an ECS Fargate instance via its Real Time Topology Map

How Upwind Addresses These Challenges with the Upwind Serverless Framework

The Upwind Serverless Framework is part of our broader family of Upwind Frameworks: pre-built, customizable, and continually evolving collections of policy checks based on real runtime behavior. These frameworks are designed to move beyond static posture assessments by surfacing actual exploitability and aligning security controls with live activity across cloud environments.

Applied to serverless, this model provides real-time visibility into how each function behaves during execution. The framework monitors access patterns, resource calls, permission usage, and network interactions without requiring agents or code modifications. With this data, it builds a behavioral profile of each function and automatically detects deviations from expected patterns.

This approach enables security teams to identify and prioritize real risks, such as over-permissioned roles, unnecessary public exposure, or dormant functions with embedded secrets, based not just on configuration, but on how those functions actually operate in production. Policy recommendations are context-aware and tied directly to runtime evidence, which means teams can remediate issues with high confidence and minimal disruption.

CleanShot-2025-08-28-at-11.17.46@2x

Benefits of the Upwind Serverless Framework

By extending Upwind’s runtime-first model to serverless workloads, the Serverless Framework helps teams gain clarity and control over environments that are otherwise difficult to observe. It surfaces the risks that matter, connects them to actual behavior, and makes it easy to take action.

CleanShot-2025-09-02-at-18.16.38@2x
The Upwind Platform identifies a public AWS Lambda function vulnerable to a critical CVE and storing Google Cloud secrets, then provides additional context and remediation options.

With the Upwind Serverless framework, teams can:

  • Understand what functions are doing in real time, including what data they access, what permissions they use, and whether they deviate from expected behavior
  • Reduce the attack surface by identifying and eliminating excessive or unused permissions through automated, least-privilege policy recommendations
  • Detect issues that static checks miss such as dormant functions with publicly exposed endpoints or embedded secrets – by looking at runtime activity and historical trends
  • Demonstrate compliance with auditable evidence that ties policies to function behavior, not just theoretical intent

These capabilities turn serverless environments into manageable and secure components of your infrastructure, without compromising the agility they’re meant to deliver.

CleanShot-2025-08-28-at-10.59.15@2x
The Upwind Platform checks for public serverless functions with crital CVEs that store CI/CD secrets

Conclusion

Serverless architectures are foundational to how modern applications are built, but their speed and scale come with new challenges. Traditional security models were not designed for workloads that spin up in milliseconds and disappear just as quickly. The Upwind Serverless Framework brings a purpose-built, runtime-aware solution to this space, combining visibility, enforcement, and automation into a framework that meets the moment.

Discover how the Upwind Serverless Framework can help your team secure cloud-native functions with runtime-first visibility and control. Schedule a customized demo with us.

Contents

Further Reading

upwind-identities

Introducing the Upwind Identity Graph: End-to-End Identity Security

Identity used to be treated as a directory problem: find the user, inspect the groups, review the assigned roles, and decide whether the account has too much access. That model no longer matches the cloud. A single person may authenticate through Okta, inherit permissions from multiple groups, receive role assignments in more than one cloud,…
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers: Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths,…
ChatGPT Image Aug 4, 2026, 08_46_20 AM

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract

Executive Summary On August 4, 2026 at 09:35 UTC, [email protected] was published to npm carrying a credential stealer, an npm worm, and a persistence mechanism designed to detonate during incident response.  Keyv ranks #274 by npm reach and is present in 84,759 customer environments, and the release shipped with valid GitHub OIDC provenance and a…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS