Get a Demo
Under Attack?
AWS Well-Architected Framework

AWS Well-Architected Framework Available in Upwind

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Sam Langrock June 12, 2026

Continuous Compliance for Cloud Security Teams

The AWS Well-Architected Framework is now available in Upwind. The framework helps organizations evaluate architectural decisions and align workloads with AWS best practices across 6 pillars: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability.

The Well-Architected Framework was designed by AWS as a consistent way for teams to evaluate their cloud workloads against proven architectural best practices. Organizations use it to identify risks early, reduce technical debt, and make more informed decisions about how their infrastructure is built and maintained.

By bringing this framework into Upwind, customers can continuously assess cloud environments against architectural best practices, better understand architectural gaps, and prioritize improvements directly within their security posture workflows.

aws-well-architected-framework-mock-a-scaled

What’s Included in Upwind?

You get full visibility into AWS Well-Architected categories, controls, compliance status, finding severity, and impacted assets, all inside Upwind’s Configurations module. 

Compliance scores per control. View the percentage of scanned resources compliant with a control, the number of compliant vs. non-compliant assets, and a breakdown of the severity of findings generated by the controls (e.g., High, Critical, and Other). 

aws-well-architected-framework-mock-b-scaled

Control-level detail. To learn more about a specific control or investigate specific issues you can click into any control to access greater detail, such as when a violation was last detected, its severity, and its risk category.

Compliance trends over time. The statistics tab shows whether you’re improving or drifting on any given control. Users can select a time frame and toggle compliance types to better match requirements. 

Violating controls. View related controls from the AWS Well-Architected Framework or others, such as NIST CSF, DORA, PCI-DSS and more, along with their respective compliance status.

aws-well-architected-framework-mock-e-scaled

Control status. Analyze your compliance status for a specific control. View counts and percentages of compliant vs non-compliant assets, and filter on non-compliant assets to investigate further. 

Finding Details. Evaluate the risk of specific security aspects for a given resource type. Findings explain why a resource is non-compliant by identifying the specific configuration leading to a security risk. 

aws-well-architected-framework-mock-d

Remediation guidance. Learn how to resolve your security issues and bring your environment into compliance with the control. Step-by-step guidance per asset type is provided. Pick the remediation method that works for your environment.

Who Benefits from Access to this Framework?

Security and platform teams get a continuously updated view of where their AWS environment stands against an AWS-authored benchmark, without waiting for a manual review cycle.

For security engineers, it means architectural gaps and security findings live in the same place. No switching tools to cross-reference a Well-Architected violation with an active misconfiguration.

For CISOs and security leaders, the framework provides a credible, structured way to report on architectural risk to leadership. Here’s where we stand, here’s what we’ve fixed, here’s what’s still open.

Upwind and AWS

Upwind is an AWS Security Competency partner, supports 100+ integrations with AWS services, and is one of a select few vendors on AWS Security Hub Extended, meaning your Well-Architected findings sit inside a broader AWS security ecosystem that’s deeply integrated with how Upwind works.

To learn more about our AWS partnership, visit our AWS partner page

Or read about how Upwind is one of the select few vendors that’s integrated into AWS Security Hub Extended.

Contents

Further Reading

The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
API Custom Threat Detection

Upwind brings Custom Detection Policies for APIs

Every API has a different risk profile. An internal billing endpoint and a public-facing authorization endpoint don't fail the same way. They don't get attacked the same way either. A generic ruleset can't account for that. Custom rules can, and now those rules can see sensitive data too. This new release brings two things together…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS