AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

Omri Limor August 05, 2026

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers:

  • Cloud Providers & Managed AI Services: Cloud-native AI platforms and hosted API services.
  • Self-Hosted AI Workloads: AI agents running on workloads, custom models, and self-managed GPU clusters.
  • AI Providers: External enterprise AI SaaS services and API endpoints.
  • Endpoints & Developer Environments: Developer environments, workstations, and local tools.

Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths, active configurations, and data moving across provider perimeters. This creates a critical blind spot in the modern AI security stack.

Introducing Upwind Graph Support for AI Providers

To close this gap, Upwind is expanding the Upwind AI Graph beyond cloud provider boundaries to ingest external AI Providers.

Upwind ingests administrative configurations, workspace boundaries, user memberships, and active identity paths directly into Upwind’s runtime graph database. Instead of managing fragmented inventories across isolated platforms, security teams gain a continuous, unified graph inventory of their entire AI footprint in a single operational view.

image-10-scaled

Unified Identity Across Cloud Providers, AI Providers, and IdP

While workloads run inside cloud providers and AI operations run across external AI Providers, identity is the unifying thread across your entire environment.

Upwind bridges these identity silos by connecting relationships between your Identity Provider (IdP), cloud provider accounts, and AI Provider workspaces. With Upwind, security teams gain complete traceability to follow a single corporate identity from your central IdP, through cloud workloads, and out to external AI Provider environments within a single visual model.

Detecting Sensitive Data Risks via Threats (AI-DR)

Extending inventory visibility to external AI Providers directly addresses the primary risk vector in enterprise AI usage: sensitive data exposure.

When users and automated workflows interact with AI Providers, confidential information can easily slip past traditional defenses through two main vectors:

  • Direct Prompts & Chat Messages: PII, proprietary source code, or internal credentials pasted directly into model interactions.
  • Input Files & Attachments: Document uploads, CSVs, or codebases attached directly to chat sessions.

Upwind operationalizes this inventory through Threats (AI-DR). By capturing real-time runtime events, Upwind alerts security teams immediately when sensitive data or unauthorized files are transmitted into external AI Provider workflows, ensuring rapid detection and response across the full AI lifecycle.

Ready to eliminate your AI visibility blind spots? Book a demo with the Upwind team today.

image-11-scaled
Contents

Further Reading

behind-the-curtain-part-02

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part II

Recap In Part I, we explored the AgentCore Runtime microVM from the inside and discovered we weren't alone - four platform binaries were running alongside our code, and one of them was quietly shipping logs to an AWS-internal S3 bucket. We left off with a question: what can we learn from these internal components, and…
behind-the-curtain-part-01

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part I

Introduction When you deploy an AI agent to AWS Bedrock AgentCore Runtime, your code runs inside a Firecracker microVM - but it doesn't run alone. In this three-part series, we tear down the platform internals, document what we found, and assess how well the isolation holds up. Setting the Stage AWS Bedrock AgentCore Runtime is…
upwind-code

Upwind Code Expands Enterprise Coverage to Azure DevOps and Bitbucket Cloud

Modern development organizations rarely keep all their code in one place. Teams may use different version control platforms because of acquisitions, business-unit preferences, regional requirements, or existing development workflows. But when code is spread across multiple providers, application security coverage can become fragmented too. Today, Upwind Code adds support for Azure DevOps and Bitbucket Cloud.…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS