# Upwind

**Canonical:** https://apis.io/providers/upwind/  
**Website:** https://upwind.io  
**APIs profiled:** 12

Upwind is a cloud and AI security platform (CNAPP) that secures cloud infrastructure, workloads, and applications in real time — spanning cloud security posture management (CSPM), vulnerability management, container and Kubernetes security, API security, data security posture management (DSPM), identity and entitlements (CIEM), and incident response. Its Management REST API (v1 and v2) exposes threats, vulnerabilities, configurations, cloud accounts, inventory graph search, access management, and webhook integrations, secured with OAuth 2.0 client credentials and served from US, EU, and ME regional endpoints. Backed by Craft Ventures and Greylock.

## Kin Score — 61.1 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 61.1).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 69.7 |
| Governance | 20.8 |
| Operational Transparency | 65.8 |
| Developer Ergonomics | 66.8 |
| Commercial Clarity | 50.0 |

## Agent readiness — 47.5 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (12)

- **Upwind access-management API** — The access-management API from Upwind — 10 operation(s) for access-management.
- **Upwind api-security API** — The api-security API from Upwind — 2 operation(s) for api-security.
- **Upwind cloud-accounts API** — The cloud-accounts API from Upwind — 2 operation(s) for cloud-accounts.
- **Upwind configurations API** — The configurations API from Upwind — 14 operation(s) for configurations.
- **Upwind events API** — The events API from Upwind — 3 operation(s) for events.
- **Upwind integrations API** — The integrations API from Upwind — 2 operation(s) for integrations.
- **Upwind Inventory API** — The Inventory API from Upwind — 6 operation(s) for inventory.
- **Upwind packages API** — The packages API from Upwind — 2 operation(s) for packages.
- **Upwind shiftleft API** — The shiftleft API from Upwind — 1 operation(s) for shiftleft.
- **Upwind threats API** — The threats API from Upwind — 18 operation(s) for threats.
- **Upwind vulnerabilities API** — The vulnerabilities API from Upwind — 2 operation(s) for vulnerabilities.
- **Upwind workflows API** — The workflows API from Upwind — 2 operation(s) for workflows.

## MCP servers (1)

- **upwind-mcp.yml**

## Security (3)

- **Upwind Authentication** — oauth2 · 1 scheme
- **Upwind Domain Security** — TLSv1.3 · HSTS · DMARC
- **Upwind Trust Center** — SOC 2 Type 2, ISO/IEC 27001:2022, GDPR

## Tags

Security, Cloud Security, CNAPP, Vulnerability Management, Container Security, Kubernetes, API Security, Threat Detection, Data Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/upwind/). Scores are computed from the provider's own public artifacts under a published rubric.
