Get a Demo
Under Attack?
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Omri Limor August 05, 2026

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers:

  • Cloud Providers & Managed AI Services: Cloud-native AI platforms and hosted API services.
  • Self-Hosted AI Workloads: AI agents running on workloads, custom models, and self-managed GPU clusters.
  • AI Providers: External enterprise AI SaaS services and API endpoints.
  • Endpoints & Developer Environments: Developer environments, workstations, and local tools.

Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths, active configurations, and data moving across provider perimeters. This creates a critical blind spot in the modern AI security stack.

Introducing Upwind Graph Support for AI Providers

To close this gap, Upwind is expanding the Upwind AI Graph beyond cloud provider boundaries to ingest external AI Providers.

Upwind ingests administrative configurations, workspace boundaries, user memberships, and active identity paths directly into Upwind’s runtime graph database. Instead of managing fragmented inventories across isolated platforms, security teams gain a continuous, unified graph inventory of their entire AI footprint in a single operational view.

image-10-scaled

Unified Identity Across Cloud Providers, AI Providers, and IdP

While workloads run inside cloud providers and AI operations run across external AI Providers, identity is the unifying thread across your entire environment.

Upwind bridges these identity silos by connecting relationships between your Identity Provider (IdP), cloud provider accounts, and AI Provider workspaces. With Upwind, security teams gain complete traceability to follow a single corporate identity from your central IdP, through cloud workloads, and out to external AI Provider environments within a single visual model.

Detecting Sensitive Data Risks via Threats (AI-DR)

Extending inventory visibility to external AI Providers directly addresses the primary risk vector in enterprise AI usage: sensitive data exposure.

When users and automated workflows interact with AI Providers, confidential information can easily slip past traditional defenses through two main vectors:

  • Direct Prompts & Chat Messages: PII, proprietary source code, or internal credentials pasted directly into model interactions.
  • Input Files & Attachments: Document uploads, CSVs, or codebases attached directly to chat sessions.

Upwind operationalizes this inventory through Threats (AI-DR). By capturing real-time runtime events, Upwind alerts security teams immediately when sensitive data or unauthorized files are transmitted into external AI Provider workflows, ensuring rapid detection and response across the full AI lifecycle.

Ready to eliminate your AI visibility blind spots? Book a demo with the Upwind team today.

image-11-scaled
Contents

Further Reading

ChatGPT Image Aug 4, 2026, 08_46_20 AM

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract

Executive Summary On August 4, 2026 at 09:35 UTC, [email protected] was published to npm carrying a credential stealer, an npm worm, and a persistence mechanism designed to detonate during incident response.  Keyv ranks #274 by npm reach and is present in 84,759 customer environments, and the release shipped with valid GitHub OIDC provenance and a…
upwind-code

Upwind Code Brings Cloud Security Into the Development Control Plane

Cloud applications begin long before they reach the cloud. Source code, open-source dependencies, infrastructure definitions, container images and pull requests all shape what will eventually run in production. Yet these layers are often secured separately. Software Composition Analysis (SCA) tools inspect dependencies, Infrastructure as Code (IaC) scanners inspect configuration files, container scanners inspect artifacts and…
Red-agent-deep-dive

Building Autonomous Cloud & AI Security

How Upwind’s Agentic Pack uses NVIDIA Nemotron 3 Super and NVIDIA garak agent breaker probe to continuously validate cloud posture, attack surfaces, and AI applications. By: Avital Harel, Alon Saban, Yuval Elarat (Upwind). Eliya Cohen, Shiri Hochhauser, Orel Hazai (NVIDIA) Executive Summary AI-generated code, autonomous agents, MCP servers, and cloud-native architectures are transforming how software is…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS