# Upwind Security

**Canonical:** https://apis.io/providers/upwind-security/  
**Website:** https://www.upwind.io/  
**APIs profiled:** 12

Upwind is a cloud security (CNAPP) platform that pairs cloud security posture with eBPF-based runtime protection across AWS, Azure, Google Cloud, and Oracle Cloud, spanning vulnerability management, threat detection, configuration and compliance, API security, identity security, and shift-left CI/CD scanning. Its Management REST API (v1 and v2) exposes threats, vulnerabilities, configurations, inventory, SBOM packages, workflows, and access management using OAuth 2.0 client credentials, and the company ships a hosted MCP server plus an official Agent Skill for AI coding assistants.

## Kin Score — 55.7 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 55.7).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 63.7 |
| Governance | 20.8 |
| Operational Transparency | 44.7 |
| Developer Ergonomics | 60.9 |
| Commercial Clarity | 50.0 |

## Agent readiness — 56.3 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (12)

- **Upwind Security access-management API** — The Access Management resource offers methods for managing groups, members, roles, and scopes.
- **Upwind Security api-security API** — The API Security resource offers methods for retrieving API catalog endpoints and their security information.
- **Upwind Security cloud-accounts API** — The Cloud Accounts resource offers methods for creating, updating, and deleting cloud accounts for monitoring and security analysis.
- **Upwind Security configurations API** — The Configurations resource offers a range of methods for listing, retrieving, and deleting configuration findings and rules.
- **Upwind Security events API** — The Events resource offers a range of methods for listing, retrieving, and deleting events.
- **Upwind Security integrations API** — The Integrations resource offers methods for managing various integrations with external systems, including integration webhooks.
- **Upwind Security inventory API** — The Inventory resource offers a range of methods for listing and retrieving inventory assets.
- **Upwind Security packages API** — The Packages resource offers methods for retrieving Software Bill of Materials (SBOM) package details.
- **Upwind Security shiftleft API** — The ShiftLeft resource offers methods for retrieving ShiftLeft related information
- **Upwind Security threats API** — The Threats resource offers a range of methods for listing, retrieving, and deleting threat detections.
- **Upwind Security vulnerabilities API** — The Vulnerabilities resource offers a range of methods for listing, retrieving, and deleting vulnerability findings.
- **Upwind Security workflows API** — The Workflows resource offers a range of methods for listing, retrieving, and deleting workflows.

## MCP servers (1)

- **upwind-security-mcp.yml**

## Security (3)

- **Upwind Security Authentication** — oauth2 · 1 scheme
- **Upwind Security Domain Security** — TLSv1.3 · HSTS · DMARC
- **Upwind Security Trust Center** — SOC 2, ISO 27001, GDPR

## Tags

Company, Cybersecurity, Cloud Security, CNAPP, Runtime Security, Vulnerability Management, API Security, Kubernetes

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/upwind-security/). Scores are computed from the provider's own public artifacts under a published rubric.
