Get a Demo
Under Attack?
Configuration Reporting

Upwind Simplifies Compliance with Real-Time Configuration Reporting

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
Joshua Burgin June 11, 2025

Upwind Simplifies Compliance with Real-Time Configuration Reporting

We are excited to announce a new enhancement to Upwind’s posture capabilities, with Upwind now providing comprehensive executive-level Configuration Reports.

Users can now generate and download configuration reports, powered by live runtime data, directly from the UI. These reports deliver clear, actionable summaries of posture risk and misconfiguration findings, making it easier for security leaders to support compliance reviews, communicate with stakeholders, and make informed decisions. 

Configuration-dashboard-1024x574

By providing easy-to-understand high-level dashboards and seamless report creation, Upwind saves teams time while improving accuracy, visibility, and operational transparency.

What are Configuration Reports?

Configuration reports are readouts that provide a comprehensive view of cloud infrastructure security by collecting and synthesizing critical configuration details across diverse resources like containers, Kubernetes, cloud services, or workloads.

These configuration reports empower teams by:

  • Identifying specific configuration elements that could lead to vulnerabilities or compliance deviations
  • Offering actionable intelligence for security, DevOps teams, and executive leadership
  • Facilitating communication of security posture to stakeholders
  • Supporting audits
  • Demonstrating regulatory compliance
  • Enabling continuous monitoring. 

By highlighting risks, configuration reports empower organizations to proactively address misconfigurations, strengthen security, and reduce the likelihood of breaches or violations. Regular generation of configuration reports is crucial for a strong cloud security program.

Configuration Reporting within the Upwind Platform

The Upwind Platform has the ability to generate reports on specific frameworks, based on runtime data, with a few UI clicks.

AD_4nXdNZzKr8d9gd6ac3oocshlwqJ0Y5qL4AbEIRVAUpNNiQ4KfSFSkh9UefbQ8Nt4FZLW7-pXgN7qjy80-PyBRZIOsqKaCTZK3D2GaiuzSbBXEKc-d06UfM-xFNFCqgbg1V9Zn8T2Fcw?key=rMgKz4rPslm0WIqzR4hRgA
To generate a report, head to your framework and then click “share”

Configuration reports offer comprehensive compliance status overviews, providing detailed insights into the adherence of your environments to established and customized standards. Like all features, our configuration reports are rooted in runtime data and context. This ensures you’re reporting on what’s happening right now, not outdated snapshots from hours or days ago.

Upwind Configuration Reports can be generated in a variety of formats, including easily shareable and archivable PDF documents or directly through email, facilitating both local storage and distribution. 

unnamed-1024x588
An example Configuration Report generated on CIS AWS Foundations

To further streamline compliance monitoring and reporting, Upwind supports automated report generation on a pre-defined schedule through the settings section and workflows subheader of the Upwind Platform, eliminating the need for manual intervention and ensuring regular updates are provided to stakeholders. Our scheduling feature allows for the proactive identification of potential compliance gaps and facilitates timely remediation efforts, contributing to a consistently compliant operational environment.

AD_4nXfKkPFACqVFCZw6WMEkskdCgiwWZtS2obNXIn2M9GIUpxHBfzDmWtVPqz2t1eM4909xl96Nh6l5oZt_JOWRzVo-xR6qPP6o27RhgnvwDl5Bk6hXWUd24ua6V4VoxY0Px-XYMJyCiw?key=rMgKz4rPslm0WIqzR4hRgA

To schedule automatic configuration reports:

  1. Go to the Settings section of the Upwind Platform.
  2. Click on the Workflows subheader.
  3. Select Create Workflow.
  4. Follow the prompts to set your desired report type and schedule.

Why It Matters

Upwind’s UI-driven configuration reporting streamlines compliance audits and security monitoring. Reports can be generated in just a few clicks, with automated scheduling to ensure teams stay prepared without the manual scramble.

Whether for internal reviews or external certification, stakeholders get accurate, real-time insights grounded in what’s actually running, not outdated snapshots. These reports help teams maintain continuous compliance, reduce overhead, and improve overall security posture through clear, actionable intelligence based on runtime context.

Want to make configuration reporting faster and more accurate with real-time data?  Schedule a demo or reach out at [email protected].

Contents

Further Reading

KSPM-Agentless-Scanning

Complete KSPM: From Pull Request to Production Runtime

Kubernetes environments move fast. Workloads appear and disappear, container images change continuously, services are exposed, permissions evolve, and development teams deploy updates throughout the day. But most cloud security platforms force practitioners to investigate Kubernetes risk through interfaces designed for the broader cloud, leaving teams to manually filter the noise before they can begin investigating…
Upwind MCP Server

Revolutionizing Security Investigations with the Upwind MCP Server

Frontier AI models combined with a rampant rate of new critical vulnerabilities mean speed and context are everything. When a critical production service starts behaving suspiciously, every second spent jumping between different tools and dashboards is a second lost to a potential attacker. At Upwind, we are excited to introduce a game-changer for security teams:…
Security Feed - Threat

No npm Token Required: Inside the AsyncAPI Supply Chain Attack

Executive Summary Upwind identified a critical supply chain compromise across five npm packages in the @asyncapi scope, published on July 14, 2026 via two separate branch compromises in two GitHub repositories. The attacker never touched an npm token. They abused each project's own CI pipeline through GitHub Actions OIDC to publish the malicious packages. The…