3 min Security

Upwind raises $300M at a valuation of $3.8B

Upwind raises $300M at a valuation of $3.8B

Cloud security company Upwind has raised approximately $300 million in new capital. The Israeli provider is valued at approximately $3.8 billion in this funding round. Earlier this year, that valuation stood at $1.5 billion.

Bessemer Venture Partners and TCV are leading the new round. In addition, Craft Ventures, Salesforce Ventures, Greylock, Cyberstarts, Leaders Fund, and Alta Park Capital are investing in the company. Penny Jar Capital, the investment firm backed by NBA player Steph Curry, is also among the existing investors, according to CTech.

The capital injection comes less than eight months after a $250 million Series B round. In January, Upwind was valued at approximately $1.5 billion. Shortly thereafter, Salesforce Ventures invested tens of millions of dollars at a valuation of $1.6 billion. At the end of 2024, Upwind’s estimated value was still between $800 million and $900 million.

Runtime security

Upwind was founded in 2022 by Amiram Shachar, Liran Polak, Lavi Ferdman, and Tal Zuri. The founders were previously involved with Spot.io, which was acquired by NetApp in 2020 for $450 million.

Upwind’s technology focuses on securing cloud environments while workloads are actually running. The company refers to this as a “runtime-first” approach. It uses information from the operational environment to determine which identified vulnerabilities actually pose a risk.

According to SiliconANGLE, the platform automatically maps the assets within a cloud environment and refreshes that information every thirty seconds. Upwind uses eBPF, among other technologies, to collect telemetry from the Linux kernel. This allows observability code to be executed in isolation without making significant changes to the kernel.

The platform collects data on instances, encryption keys, and configuration scripts, among other things. It also reveals relationships between different components of the cloud environment. This makes it possible to determine which data or other resources are accessible from a particular application.

AI helps identify risks

Upwind also applies the technology to AI workloads. The platform can automatically generate so-called AI-BOMs: inventories of the components that make up AI applications. Administrators can use this information to identify components with potential security risks.

In addition, Upwind uses AI to examine identified assets for vulnerabilities. Configurations are compared against security policies and legal requirements. The platform can also carry out simulated attacks to determine whether critical components of the environment are actually accessible or vulnerable.

Two AI agents play a role in this process. Red is designed to filter vulnerabilities with a low practical risk out of the stream of alerts. Blue focuses on detecting attack attempts. In this way, Upwind aims to reduce the number of alerts that security teams must assess manually.

Upwind has not disclosed exactly how the new $300 million will be used. However, the company has recently added several integrations with third-party cloud services. Further expansion of the number of environments and services the platform can secure therefore seems likely.