Upwind AI agent scanner launches as AI DR reaches general availability
Upwind added context scanning for AI agents and made AI DR generally available, extending its cloud security platform into runtime AI workflows.
By Dominic Okoye · Staff Writer
· 3 min read
Upwind Security today launched the Upwind AI agent scanner, a new capability that examines the instructions, tools and connections available to AI agents before those agents act. The cloud security startup also made AI Detection & Response, or AI DR, generally available, moving a product first introduced in December into broader production release.
The release is aimed at a security gap created by agentic systems that operate inside cloud environments, use enterprise credentials and interact with tools, APIs and data stores. Upwind’s position is that securing the underlying model is not enough when an agent’s behavior can be shaped at runtime by active instructions, skills, stored memory, tool access and Model Context Protocol connections.
The company said the new AI Agent Context Scanner reviews those inputs continuously across employee endpoints, cloud infrastructure and managed AI providers. Upwind said it is designed to identify malicious, vulnerable or unclear instructions before an agent uses them, then compare findings with other runtime signals in its platform so security teams can prioritize issues by operational risk rather than by scanner output alone.
What does Upwind AI DR do?
Upwind AI DR monitors how AI agents behave once they are running. The company said it builds a baseline for each agent, including tool calls, API access, data-store access and normal session behavior, then flags deviations from that pattern as they occur.
The detection system correlates those deviations with workload identity, network topology, API traffic, data sensitivity, permissions, posture and exposure, according to Upwind. The goal is to give security teams a record of which agent was affected, what it did, what systems or data it touched and how the activity unfolded.
Upwind said AI DR can also identify data that may have been exposed and recommend responses. Examples the company gave include revoking a session or credential, reducing permissions or auditing downstream systems. Those are response suggestions rather than proof of automated containment in every case, and Upwind did not disclose customer adoption, revenue or headcount tied to the release.
Why context scanning matters for AI agents
AI agents assemble their operating context at runtime. That context can include instructions, tools, memory and external connections, meaning two agents that appear similar in an inventory can behave differently once they are active.
Upwind argues that an AI inventory, a live catalog of models, agents, tools, skills and MCP connections, is only a starting point for security teams. The company’s broader claim is that runtime behavior and context need to be evaluated together because an instruction introduced through any connected component can redirect an agent’s actions while using permissions the agent already holds.
AI DR was introduced in December as part of a wider AI security suite inside Upwind’s cloud-native application protection platform. That suite also included posture management, an AI bill of materials, network visibility and MCP tracing, according to the company.
Upwind is venture-backed and last raised $250 million in January in a round led by Bessemer Venture Partners at a $1.5 billion valuation. Total funding is about $430 million, putting the company among the better-capitalized startups trying to extend cloud security tooling to AI workloads. For a refresher on how firms take these high-risk startup bets, see Venture Post’s guide to how venture capital works.
This story draws on original reporting from SiliconANGLE.