Upwind Security and Surf AI

Close confirmed runtime CVEs in minutes.

Upwind confirms which vulnerabilities are actively running. Surf AI turns those confirmed findings into owned, approved, closed remediations — in minutes, not days.

  • Runtime-confirmed findings
  • Ownership in seconds
  • Closed-loop write-back
Upwind remediation workflow from detection to fix

The Problem

Cloud security teams carry a growing remediation backlog.

A typical enterprise environment generates thousands of CVE alerts per week from static analysis alone, many of them theoretical. Cutting through that noise to identify what is genuinely dangerous right now is the first unsolved problem. The second is what happens after you find it.

Upwind separates signal from noise with eBPF-powered runtime sensors that confirm which vulnerable libraries are actively loaded in memory. Surf AI solves everything that comes after detection — ownership, blast radius, compliance, and remediation — so teams work through their backlog instead of just managing it.

What changes

From noisy backlog to closed finding.

Signal

Separate real exposures from theoretical alerts

Static scanners flag what's present in an image. Upwind confirms what's loaded in memory on live workloads — the difference between a 10,000-finding backlog and a focused list of what needs to be fixed today.

Context

Stop hunting for ownership and approvals

Who owns this service? What breaks on redeploy? Is it PCI-scoped? Those answers live across a dozen systems. Surf's Context Graph resolves them in seconds so engineers remediate instead of escalate.

Throughput

Close 50+ confirmed findings in a day

Without Surf, teams spend 8–20 hours closing a single runtime CVE. With Surf, detection-to-closure drops to 12–20 minutes — human time under 30 seconds — so backlog becomes throughput.

The Scenario

A critical CVE is live in production.

UpwindRuntime finding
Active at runtime

CVE-2024-XXXX

Critical exposure in payments-api

CVSS

9.1

Vulnerable library confirmed loaded in memory on a live production workload.

Container
payments-service:v2.3.1
Deployment
payments-api
Namespace
prod-payments
Cluster
prod-us-east-1
Library
libssl.so.1.1
Process
PID 1842

Two paths

Same finding. Two outcomes.

Without Surf AI

Runtime detail is there. Ownership, blast radius, and change policy still aren't.

  1. 1

    Find the owner

    30–120 min

    Stale CMDB, Slack hunt, timezone miss.

  2. 2

    Assess blast radius

    1–4 hrs

    War room. Outdated maps. No redeploy confidence.

  3. 3

    Clear compliance

    1–2 hrs

    PCI scope confirmed. Next CAB is Friday.

  4. 4

    Escalate and approve

    2–8 hrs

    Manager chain, then a manual ServiceNow ticket.

  5. 5

    Remediate and close

    1–2 hrs

    Manual redeploy. Finding closed by hand — if remembered.

Total time from detection to closure

8–20 hours

50 findings takes weeks — before new ones arrive.

With Surf AI

Upwind's webhook fires. The Context Graph fills in the rest in parallel.

  1. 1

    Resolve ownership

    Seconds

    @rrao identified at 94% confidence. Escalation path ready.

  2. 2

    Model blast radius

    Seconds

    3 downstream services. Retry logic confirmed. Redeploy is safe.

  3. 3

    Apply change policy

    Seconds

    PCI tier-1 emergency change auto-drafted for @dchen.

  4. 4

    Route and remediate

    < 1 min

    One Slack approval. Redeploy runs. Upwind marked REMEDIATED.

Critical CVE — payments-api

CVE-2024-XXXX · CVSS 9.1 · active at runtime

  • Fix: rolling redeploy → payments-service:v2.3.2
  • Blast radius: 3 services · <5% for ~45s
  • Change #CHG0042891 approved by @dchen
Approve & RedeployReviewEscalate

Total time from detection to closure

12–20 minutes

Human time: under 30 seconds. 50 findings in a day.

Side by side

Same Upwind finding. Completely different throughput.

StepWithout Surf AIWith Surf AI
Find the owner30–120 min, manualSeconds, automated
Confirm blast radius1–4 hrsSeconds, graph simulation
Determine compliance path1–2 hrs, multiple teamsSeconds, policy engine
Route to the right person2–8 hrs, escalation chain< 1 min, direct Slack
Model ripple effectsDays, if possibleSeconds, from Context Graph
Execute remediation1–2 hrs, manualMinutes, one-click approval
Close the findingManual, often forgottenAutomated write-back to Upwind
Findings closed per day1 to 350+

How it works

Detection precision becomes remediation speed.

Confirm at runtime

Signal

Upwind emits a webhook with full runtime context — container, namespace, cluster, loaded library, and confirmed active status — so Surf can trust the signal immediately.

Enrich in parallel

Context

The Context Graph resolves ownership, models blast radius, applies compliance policy, and drafts the change record across GitHub, Okta, Workday, PagerDuty, AWS, and ServiceNow.

Route, approve, write back

Execution

The owner gets a Slack action with the recommended fix. One approval triggers redeploy; Upwind confirms the CVE is gone; Surf writes REMEDIATED back with a full audit trail.

All of it runs inside the Context Graph, a continuously updated knowledge graph that links identity, cloud, code, HR, and IT systems.

How the Context Graph makes this possible

Five capabilities that turn Upwind findings into closed remediations.

Subject defragmentation

A stale Kubernetes label still resolves to the humans responsible today — by correlating GitHub commits, Okta groups, Slack activity, and HR records.

Ripple-effect modeling

Before recommending action, Surf simulates downstream impact across service call graphs and retry logic so teams know what will and won't break.

Compliance embedding

PCI scope, change approval rules, and SLAs are properties of every node — resolved alongside ownership, not as a separate chase.

Availability awareness

Workday leave, PagerDuty on-call, and Okta activity determine who can act right now — not just who owns the resource on paper.

Bidirectional lifecycle closure

Surf writes remediation outcomes back to Upwind with timestamp, action, and approver — so the audit trail is complete on both sides.

Partners

Built together for runtime remediation.

About Surf AI

Surf AI is an agentic operations platform that helps enterprises operationalize security programs with AI. By connecting context across identity, cloud, data, HR, and IT systems, Surf closes the gap between understanding risk and acting on it. Surf's AI-native platform uses specialized agents to drive action with human oversight, guardrails, and auditability built in. Surf is backed by Accel, Cyberstarts and Boldstart Ventures, and trusted by global companies including Fortune 500 enterprises.

www.surf.ai

About Upwind Security

Upwind is the next-generation cloud security platform built to lead the runtime revolution. With rapid momentum and a bold vision to unify cloud and application-layer protection, Upwind helps organizations run faster, detect threats earlier, and secure their environments with unmatched precision. Upwind was founded by Amiram Shachar and his founding partners from Spot.io and is backed by Greylock, Cyberstarts, Leaders Fund, Craft Ventures, Cerca Partners, and Sheva. The company has secured $180 million in funding since its founding in 2022.

www.upwind.io

Upwind Security and Surf AI

Turn Upwind precision into remediation speed.

See how Surf operationalizes runtime-confirmed findings with ownership, guardrails, and a closed-loop audit trail.