Upwind Security and Surf AI

Close confirmed runtime CVEs in minutes.

Upwind confirms which vulnerabilities are actively running. Surf AI turns those confirmed findings into owned, approved, closed remediations — in minutes, not days.

  • Runtime-confirmed findings
  • Ownership in seconds
  • Closed-loop write-back
Surf AI
Upwind logo

The Problem

Cloud security teams carry a growing remediation backlog.

A typical enterprise environment generates thousands of CVE alerts per week from static analysis alone, many of them theoretical. Cutting through that noise to identify what is genuinely dangerous right now is the first unsolved problem. The second is what happens after you find it.

Upwind separates signal from noise with eBPF-powered runtime sensors that confirm which vulnerable libraries are actively loaded in memory. Surf AI solves everything that comes after detection — ownership, blast radius, compliance, and remediation — so teams work through their backlog instead of just managing it.

What changes

From noisy backlog to closed finding.

Signal

Separate real exposures from theoretical alerts

Static scanners flag what's present in an image. Upwind confirms what's loaded in memory on live workloads — the difference between a 10,000-finding backlog and a focused list of what needs to be fixed today.

Context

Stop hunting for ownership and approvals

Who owns this service? What breaks on redeploy? Is it PCI-scoped? Those answers live across a dozen systems. Surf's Context Graph resolves them in seconds so engineers remediate instead of escalate.

Throughput

Close 50+ confirmed findings in a day

Without Surf, teams spend 8–20 hours closing a single runtime CVE. With Surf, detection-to-closure drops to 12–20 minutes — human time under 30 seconds — so backlog becomes throughput.

The Scenario

A critical CVE is live in production.

UpwindCVE-2024-XXXX
Active at runtimeCVSS 9.1

Critical exposure in payments-api

Vulnerable library confirmed loaded in memory on a live production workload.

Container
payments-service:v2.3.1
Deployment
payments-api
Namespace
prod-payments
Cluster
prod-us-east-1
Library
libssl.so.1.1
Process
PID 1842

Two paths

Same finding. Two outcomes.

Without Surf AI

8–20 hours

50 findings takes weeks — before new ones arrive.

Runtime detail is there. Ownership, blast radius, and change policy still aren't.

  1. Find the owner30–120 min
  2. Assess blast radius1–4 hrs
  3. Clear compliance1–2 hrs
  4. Escalate and approve2–8 hrs
  5. Remediate and close1–2 hrs

With Surf AI

12–20 minutes

Human time: under 30 seconds. 50 findings in a day.

Upwind's webhook fires. The Context Graph fills in the rest in parallel.

  1. Resolve ownershipSeconds
  2. Model blast radiusSeconds
  3. Apply change policySeconds
  4. Route and remediate< 1 min

Critical CVE — payments-api

Critical

CVE-2024-XXXX · CVSS 9.1 · active at runtime

Surf AI via Upwind · Approve & Redeploy

How it works

Detection precision becomes remediation speed.

Confirm at runtime

Signal

Upwind emits a webhook with full runtime context — container, namespace, cluster, loaded library, and confirmed active status — so Surf can trust the signal immediately.

Enrich in parallel

Context

The Context Graph resolves ownership, models blast radius, applies compliance policy, and drafts the change record across GitHub, Okta, Workday, PagerDuty, AWS, and ServiceNow.

Route, approve, write back

Execution

The owner gets a Slack action with the recommended fix. One approval triggers redeploy; Upwind confirms the CVE is gone; Surf writes REMEDIATED back with a full audit trail.

All of it runs inside the Context Graph, a continuously updated knowledge graph that links identity, cloud, code, HR, and IT systems.

How the Context Graph makes this possible

Five capabilities that turn Upwind findings into closed remediations.

Subject defragmentation

A stale Kubernetes label still resolves to the humans responsible today — by correlating GitHub commits, Okta groups, Slack activity, and HR records.

Ripple-effect modeling

Before recommending action, Surf simulates downstream impact across service call graphs and retry logic so teams know what will and won't break.

Compliance embedding

PCI scope, change approval rules, and SLAs are properties of every node — resolved alongside ownership, not as a separate chase.

Availability awareness

Workday leave, PagerDuty on-call, and Okta activity determine who can act right now — not just who owns the resource on paper.

Bidirectional lifecycle closure

Surf writes remediation outcomes back to Upwind with timestamp, action, and approver — so the audit trail is complete on both sides.

Partners

Built together for runtime remediation.

Surf AI

About Surf AI

Surf AI is an agentic operations platform that helps enterprises operationalize security programs with AI. By connecting context across identity, cloud, data, HR, and IT systems, Surf closes the gap between understanding risk and acting on it. Surf's AI-native platform uses specialized agents to drive action with human oversight, guardrails, and auditability built in. Surf is backed by Accel, Cyberstarts and Boldstart Ventures, and trusted by global companies including Fortune 500 enterprises.

www.surf.ai
Upwind

About Upwind Security

Upwind is the next-generation cloud security platform built to lead the runtime revolution. With rapid momentum and a bold vision to unify cloud and application-layer protection, Upwind helps organizations run faster, detect threats earlier, and secure their environments with unmatched precision. Upwind was founded by Amiram Shachar and his founding partners from Spot.io and is backed by Greylock, Cyberstarts, Leaders Fund, Craft Ventures, Cerca Partners, and Sheva. The company has secured $180 million in funding since its founding in 2022.

www.upwind.io

Upwind Security and Surf AI

Turn Upwind precision into remediation speed.

See how Surf operationalizes runtime-confirmed findings with ownership, guardrails, and a closed-loop audit trail.