Get a Demo
Under Attack?
FEED-UpwindxSVP

Welcoming Salesforce Ventures to the Upwind Family

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Amiram Shachar March 18, 2026

Welcoming Salesforce Ventures to the Upwind Family


What started as a visibility problem has become something much more dynamic and urgent: understanding what is actually happening inside modern cloud environments, in real time. As infrastructure becomes more distributed, ephemeral, and increasingly shaped by AI, security teams need more than snapshots. They need context. They need precision. And they need answers that move at the speed of their applications.

That’s why we’re excited to share that Salesforce Ventures is joining Upwind’s $250 million Series B.

This is more than a milestone for our business. It’s a strong signal that the market is entering a new phase — one where runtime context is becoming foundational to cloud security, and where the ability to separate theoretical risk from real-world exposure matters more than ever.

The Evolution

The history of modern cloud security has been defined by three distinct eras.

  • The Visibility Era (2018–2020): As enterprises lifted and shifted workloads to the cloud, the primary challenge was simply seeing what was out there. This era gave rise to the first generation of Cloud Security Posture Management (CSPM) tools — scanners that inventoried assets and checked for basic misconfigurations.
  • The Shift-Left and Agentless Era (2021–2023): As cloud adoption matured, friction became the enemy. DevOps teams rejected heavy agents that slowed down deployments. The market swung toward agentless scanning — taking snapshots of disk volumes via APIs to find vulnerabilities without installing software. While this solved the friction problem, it created a new one: noise. These tools flagged every theoretical vulnerability, leading to massive alert fatigue.
  • The Runtime and AI Era (2024–Present): In the current third phase, near real-time visibility is no longer sufficient. Modern cloud-native environments are ephemeral, complex, and increasingly driven by AI. In this era, security must move from outside-in observation to inside-out understanding.

Against this backdrop, strategic value is consolidating in the Cloud-Native Application Protection Platform (CNAPP) category — and we believe that the future belongs to platforms that can bring real runtime intelligence into every security decision.

The Opportunity

At Upwind, we’re redefining the CNAPP market with a runtime-first approach.

Instead of relying solely on static API scans, Upwind leverages its runtime fabric technology to gain deep, unmatched visibility into running workloads without the heavy performance penalty of legacy agents.


This inside-out architecture allows us to do something static scanners cannot: determine reachability. Drastically Prioritize cloud security risks. Build bridges between security and devops and save enormous amount of precious time.

By correlating build-time data with real-time runtime context, Upwind can mathematically prove which vulnerabilities are actually exploitable in a production environment. If a vulnerable library is present on a disk but never loaded into memory, Upwind knows it is not an immediate threat. That context allows our platform to filter out approximately 95% of alert noise, empowering security teams to focus on the risks that actually matter.

Beyond vulnerability prioritization, Upwind unifies critical security pillars — CSPM, Cloud Workload Protection, Cloud Detection and Response, API Security, and Identity — into a single, coherent platform. It provides a real-time map of network topology and data flows, enabling organizations to secure everything from containers and serverless functions to the rapidly expanding attack surface of AI models and pipelines.

What’s Ahead


This new chapter is about more than capital. It’s about momentum, direction, alignment, and continuing to build for what matters to customers in an ever changing cloud infrastructure world.

Contents

Further Reading

upwind-identities

Introducing the Upwind Identity Graph: End-to-End Identity Security

Identity used to be treated as a directory problem: find the user, inspect the groups, review the assigned roles, and decide whether the account has too much access. That model no longer matches the cloud. A single person may authenticate through Okta, inherit permissions from multiple groups, receive role assignments in more than one cloud,…
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers: Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths,…
ChatGPT Image Aug 4, 2026, 08_46_20 AM

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract

Executive Summary On August 4, 2026 at 09:35 UTC, [email protected] was published to npm carrying a credential stealer, an npm worm, and a persistence mechanism designed to detonate during incident response.  Keyv ranks #274 by npm reach and is present in 84,759 customer environments, and the release shipped with valid GitHub OIDC provenance and a…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS