Get a Demo
Under Attack?
Focus-Mode

Focus Mode for AI Security: A Dedicated Workspace for Identifying and Securing Your AI Stack 

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Sam Langrock July 23, 2026

When we launched Focus Mode, we built it around the way security teams actually work: Vulnerability Management, Cloud Security Posture, Attack Surface Management, Threat Detection & Response, Administration. Each one strips away everything unrelated to the job at hand.

AI Security is the next domain in the Focus Mode lineup, and it’s built for a problem that’s grown more complex by the day. Now security teams can quickly view all their AI stack, AI models, agents, and guardrails that are actually running in their environment, and whether they present a potential security issue.

AIFocus1

The Challenge: AI risk gets buried in general noise 

GenAI adoption inside cloud environments didn’t wait for security teams to catch up. Engineering teams are spinning up SageMaker endpoints, wiring apps to Bedrock, and pulling in LangChain and PyTorch faster than security teams are able to inventory everything. 

Without a dedicated view, that risk gets lost in the shuffle. A public SageMaker endpoint shows up as just another misconfiguration, indistinguishable from a stray S3 bucket, until someone manually connects it to a model in production. A workload running a vulnerable AI package looks like any other CVE, with no signal on whether it’s actually reachable or exploitable.

Security teams need direct answers: What AI frameworks are actually deployed? Which GenAI services are misconfigured? What’s talking to OpenAI or Anthropic right now? Are we seeing abnormal tool usage by an agent? Digging through dashboards to answer AI-specific questions costs valuable time.

focus-mode-mock-a-scaled

What Focus Mode for AI Security gives you

Activating Focus Mode for AI Security reshapes the Upwind console around a single dashboard for AI Security. It pulls together a number of key findings: all filterable by cloud provider or cloud account and exportable as a PDF for reporting.

GenAI Technologies Breakdown. A full inventory of AI frameworks running across your workloads: OpenAI, Anthropic, LangChain, Vercel, and more. Know what’s actually deployed in your environment instead of guessing.

AIFocusMode3

Summary of AI Risks Across Your Environment. View your AI-specific configuration findings by severity and how they’re trending over time on a weekly or monthly time horizon. This view can be used to spot spikes and track remediation progress. Easily drill into findings to identify impacted resources, view remediation steps, and create tickets. 

Configuration Findings on AI Services. Identify misconfigurations, and the number of resources impacted, across SageMaker, Bedrock, and AI workloads on GKE and AKS. Public endpoints, missing IAM restrictions, shore up gaps that can turn a model into an open door for threat actors.

focus-mode-mock-b-scaled

Resources Communicating with Public GenAI Services. View every outbound call to OpenAI, Anthropic, Bedrock, and similar services, with port, throughput, and encryption status attached. 

Top 10 AI Applications Usage. Your highest-throughput AI applications, ranked, each with risk indicators attached: CVEs, public exposure, compliance violations. 

Runtime Exploit Risk on GenAI Packages. Active workloads running AI packages with known critical or high-severity CVEs, scored by exploit probability. Quickly understand the application, account, package, and technology that are introducing security risks into your environment.

Beyond the main dashboard: every tab scoped to AI Security

The AI Security Dashboard is the centerpiece, but Focus Mode scopes the rest of the platform’s navigation too. The tabs you can already use for other domains stay in place, just filtered down to key AI Security use cases.

Inventory. Pull up an inventory of every AI agent, model, guardrail, datastore, pipeline, and workload running in your environment. Each list is automatically filtered down to the AI resources running in your environment, and can be shared and exported via CSV.

AIFocusMode2-1

Issues & Findings. Configuration findings and compliance violations specific to AI services, the same ones surfaced on the AI Dashboard, but browsable and actionable in the standard findings workflow.

Threats. Runtime detections scoped to AI workloads: anomalous outbound calls, unexpected process executions on GenAI containers. The same threat detection engine, pointed specifically at where your models and agents run.

What this means for security teams

One inventory, no guessing. Every AI framework and package in production, in a single list.

Misconfigurations caught early. SageMaker, Bedrock, and AI workload configurations get checked continuously instead of during the next audit cycle.

Visibility into Shadow AI. View every resource talking to a public GenAI service.

Operate within one tool. No new tool to deploy, no new access to request. Just a workspace scoped to AI.

Built on the same Focus Mode foundation

AI Security Focus works exactly like the other focus areas. Switch into it whenever AI risk is the question you’re answering, switch out when it’s not. Nothing about your permissions changes, and nothing about your visibility into the rest of the platform goes away. Under the hood, it’s drawing on the same correlated runtime, identity, and vulnerability context that powers every area of the Upwind platform, just pointed at your AI stack specifically.

Contents

Further Reading

ArgoCD repoURL XSS

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover (CVE-2026-62341)

Executive Summary  CVE-2026-62341 is a stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.6] that lets an attacker who can create or modify an Application persist a malicious repoURL, which then executes in an administrator's browser inside the ArgoCD origin. Because the payload rides the admin's authenticated session, and because ArgoCD's controller typically runs…
The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS