NextFin

Upwind Raises $300 Million at $3.8 Billion Valuation as Runtime Security Becomes the AI Control Plane

Summarized by NextFin AI
  • Upwind Security is raising $300 million at a $3.8 billion valuation, roughly 2.5x its $1.5 billion price tag from seven months ago, led by Bessemer Venture Partners.
  • The startup's runtime-first cloud security approach is being repriced as an AI-infrastructure bet, with 900% year-over-year revenue growth and 200% logo growth since its Series A.
  • The global cloud security market is projected to reach $75.26 billion by 2030 (13.3% CAGR), while AI-specific cybersecurity spending is expected to hit $182.9 billion by 2033 (24.7% CAGR).
  • Cybersecurity M&A hit $96 billion across 400 deals in 2025, with anchor transactions like Google's $32 billion Wiz acquisition and Palo Alto Networks' $25 billion CyberArk deal reshaping the market.

NextFin News - Upwind Security is raising $300 million at a $3.8 billion valuation, roughly 2.5 times the $1.5 billion price tag it carried seven months ago, as investors bet that the startup's runtime-first approach to cloud security will become the control plane for AI workloads. Bessemer Venture Partners is leading the round, with participation from some existing investors, according to people familiar with the matter who asked not to be identified because the financing is not yet public. The San Francisco-based company has not yet made a public announcement.

The deal lands at a moment when cloud security has stopped being a back-office compliance function and become the gatekeeper of the AI build-out. Every agentic workflow, every model call, every container that spins up to serve an inference request is a new attack surface - and Upwind's thesis is that only a platform sitting inside the running workload, watching what actually executes, can tell enterprises which of those surfaces is genuinely exposed. That is the bet behind a valuation that has more than quadrupled since the company's $900 million Series A in December 2024.

The Valuation Ladder: From $900 Million to $3.8 Billion in Under Three Years

Upwind was founded in 2022 by the former leadership team of Spot.io, the cloud-cost optimization company acquired by NetApp in 2020 for $450 million. CEO Amiram Shachar, who spent six years as an officer in the Israeli military's Mamram unit managing data-center infrastructure, founded Spot.io in 2015 on the back of his college final project. After the NetApp exit he served as a vice president and general manager there, then returned to build Upwind with CTO Tal Zur and SVP of Growth Lavi Ferdman - a team that had worked together for a decade before the first startup.

The funding ladder has been steep and fast. After a seed round in late 2022, Upwind raised $100 million at an approximately $900 million valuation in December 2024, led by Craft Ventures with participation from TCV, Alta Park Capital, and its earlier backers. On January 26, 2026, the company announced a $250 million Series B led by Bessemer Venture Partners that lifted the valuation to about $1.5 billion and brought total funding to $430 million. Shachar called Upwind "the first unicorn in modern cloud security" and said the capital would go toward "expanding our cloud security platform across AI, data, code, and whatever comes next."

The new $300 million round at $3.8 billion represents a 153% increase in valuation in roughly seven months. The prior step - $900 million to $1.5 billion - took about 13 months and was a 67% gain. The acceleration is the story: Upwind is being repriced not as a cloud-security vendor riding a steady market, but as an AI-infrastructure name riding a structural shift in where security budgets are going.

The company has the growth numbers to justify investor attention. Since the Series A, Upwind reported 900% year-over-year revenue growth and 200% logo growth, with enterprise customers including Siemens, Peloton, Roku, and NuBank. In April 2025 it acquired Nyx Security, which specialized in real-time application security, and it has doubled its workforce while expanding from offices in Israel, San Francisco, the UK, and Iceland into Australia, India, Singapore, and Japan.

"Cloud infrastructures have evolved far faster than the security models designed to protect them. The next generation of cloud security requires a fundamentally different approach, a runtime-first method, which is the only way to protect the cloud during the AI era."

Shachar said in the January 2026 announcement. Elliott Robinson, a partner at Bessemer, added that the firm was "proud to partner with Upwind as they build the runtime-first cloud security platform for the next generation of enterprises."

Why Runtime Is the Choke Point: The Mechanism Behind the Multiple

To understand why investors are willing to pay $3.8 billion for a four-year-old private company, start with what broke in cloud security. The first generation of tools - cloud security posture management, vulnerability scanners, configuration checkers - took periodic snapshots of an environment and produced a list of findings. The problem is that a snapshot cannot tell you whether a vulnerability is reachable. A dormant flaw in an unused service, sitting behind a firewall with no route to the internet, is not the same risk as an exploitable flaw in a public-facing container. Yet legacy tools treated them identically, flooding security and DevOps teams with alerts they could not triage.

Upwind's answer is to start inside the workload. Its sensors, built on eBPF, capture the actual execution graph of an environment: which processes talk to which services, which identities are in play, which dependencies are actually loaded at runtime. A correlation engine then reconstructs attack paths and ranks only the vulnerabilities that are genuinely exploitable in a specific container or service. The mechanism is simple to state but hard to replicate at scale: visibility plus context equals signal over noise.

This matters because the cost of a false positive in cloud security is not just an annoying ticket. It is engineering time diverted from shipping, remediation applied to the wrong thing while the real exposure sits unpatched, and alert fatigue that causes teams to miss the one finding that matters. Runtime-first security reduces ticket volume and, more importantly, changes the unit of analysis from "asset" to "attack path."

Bessemer, which led both the Series B and the new round, framed the thesis in exactly these terms in January 2026: runtime visibility is becoming a requirement for every CISO now that containers and Kubernetes are the standard architecture, and the winners will be platforms built with runtime at the core rather than bolting it onto a legacy posture-management stack. The new valuation is the market's verdict on that framing.

The AI Multiplier: Why This Is Priced as an AI Bet, Not Just a Cloud-Security Bet

The second-order question is why a cloud-security company is commanding an AI multiple. The answer lies in what AI does to the attack surface. Agentic workflows - autonomous AI systems that call tools, read data, and take actions - explode the number of non-human identities in an environment. Each agent is a service account with permissions. Each model inference can run in a freshly spawned container. Each retrieval-augmented generation pipeline touches data stores that may or may not be appropriate to expose to the model.

Static posture tools cannot see this. They can tell you what permissions an identity has; they cannot tell you what that identity actually did at 3:17 a.m. while serving an agent request. Runtime telemetry is the only layer that captures behavior as it happens, which is why Upwind's positioning has shifted from "cloud security" to "cloud and AI security." In May 2026 the company launched an AI Agentic Pack - specialized agents for investigation, risk validation, and remediation - explicitly targeting the new threat class that AI introduces.

The market numbers justify the repricing. The global cloud security market was worth $35.84 billion in 2024 and is projected to reach $75.26 billion by 2030, a 13.3% compound annual growth rate, according to Grand View Research. The CNAPP sub-segment - the category Upwind competes in - is growing faster, from $10.90 billion in 2025 to a projected $28.03 billion by 2030, a 20.8% CAGR per Mordor Intelligence. AI-specific cybersecurity spending is faster still: $31.5 billion in 2025, projected to reach $39.1 billion in 2026 and $182.9 billion by 2033, a 24.7% CAGR.

Put differently, Upwind is not being valued on the 13% growth of legacy cloud security. It is being valued on the 20-25% growth of the AI-security and CNAPP wedge, where the marginal dollar of enterprise security spend is going. That is the mechanism behind the 2.5x valuation step-up in seven months: investors are paying for the category the company is growing into, not the category it grew up in.

The Consolidation Squeeze: Who Wins and Who Gets Bought

The backdrop to Upwind's raise is a cybersecurity M&A market that has become a race to assemble platform scale. Disclosed cybersecurity deal value hit $96 billion across 400 transactions in 2025, a 270% increase over 2024, and 2026 has already crossed $65 billion in disclosed value by mid-year, according to industry data compiled by Windsor Drake. The anchor deals define the shape of the market: Google's $32 billion acquisition of Wiz, cleared by the Justice Department in November 2025 and closed in March 2026; Palo Alto Networks' $25 billion acquisition of CyberArk, closed in February 2026; and ServiceNow's pending $7.75 billion purchase of Armis.

This consolidation creates a fork for independent players. On one path, a runtime-first platform with a defensible data graph becomes a must-have layer that the hyperscalers and platform vendors cannot replicate in-house - and therefore a prime acquisition target or a standalone public company. On the other path, point tools get bundled into the Microsoft Defender, AWS Security, and Google Cloud security stacks and lose their pricing power. Upwind is betting on the first path: runtime telemetry is too close to the customer's actual execution environment to be a checkbox feature in a broader bundle.

The public-market bar, however, remains high. Conventional wisdom in the sector holds that public cybersecurity vendors need roughly a $5 billion valuation and around $500 million in annual sales. Upwind's $3.8 billion private valuation puts it within striking distance of that threshold on the valuation side; the revenue side is the variable the market will test next. A funding round at this size is as much about giving the company the runway to reach public-market scale on its own terms as it is about funding product development.

The Counter-Thesis: Bubble Multiple or Structural Repricing?

The strongest case against Upwind's valuation is that it is a liquidity-driven AI bubble multiple, not a structural repricing. Interest rates have come down, AI infrastructure budgets are at a cyclical peak, and private-market investors are competing aggressively for a limited set of AI-adjacent names. In that reading, a 153% valuation increase in seven months reflects capital chasing a narrative rather than a durable change in the company's fundamentals. If AI infrastructure spending slows, or if the market begins to discount AI-security revenue at the same multiple as legacy security revenue, the $3.8 billion mark could prove to be the local top.

There is also the bundling risk. Microsoft, Amazon, and Google are all moving security down the stack, embedding it in the cloud platforms that enterprises already buy from them. If the market decides that runtime protection is a feature of the hyperscaler stack rather than a standalone platform, independent valuations compress regardless of how good the technology is. The Google-Wiz and Palo Alto-CyberArk deals are evidence both ways: they show the premium buyers will pay for scale, but they also show how much of the market is being pulled inside a few platforms.

The answer to the counter-thesis rests on one question: is runtime telemetry a defensible data asset, or a commodity? If Upwind's execution graph becomes the system of record for what actually runs in a customer's cloud - the thing that security, DevOps, and incident response all depend on - then the valuation is a structural repricing and will hold. If it is merely a better alerting engine, the multiple will revert.

The falsifying signal is concrete: if Upwind's next disclosed financing or secondary transaction clears below $3.8 billion, or if independent CNAPP deal multiples compress below roughly 15 times annual recurring revenue while AI-security spending growth decelerates below 20% year over year, the structural thesis is wrong and the round was a cyclical top.

What Comes Next: Scenarios and What to Watch

Base case. Upwind uses the $300 million to scale sales and product, reaches the revenue scale needed for a public listing or a strategic sale, and the $3.8 billion valuation holds as AI-security budgets continue to grow. Runtime-first security becomes a standard line item in enterprise cloud budgets, and Upwind remains an independent leader in the category.

Upside case. Agentic AI adoption accelerates faster than expected, non-human identity risk becomes the dominant security concern for enterprises, and Upwind's runtime data graph becomes the control plane for AI workloads. In this scenario the company could command a premium well above $3.8 billion, either in a later round or in a strategic transaction with a hyperscaler or platform vendor that needs the runtime layer.

Downside case. AI infrastructure spending slows, CNAPP consolidation favors the bundled offerings from Microsoft, AWS, and Google, and independent valuations compress. Upwind still has a strong product and $430 million in total funding, but growth slows and the next round prices flat or down.

What to watch: Upwind's next disclosed customer or revenue milestone; the pace of AI-agent adoption in enterprise environments; whether hyperscalers announce native runtime-protection capabilities that directly compete with Upwind's core offering; and the multiple paid in the next large independent CNAPP transaction.

The central judgment: this is the market pricing runtime security as the control plane for AI workloads, not a cyclical up-round in a crowded cloud-security category. The $3.8 billion valuation is a bet that the execution graph - knowing what actually runs, not what should run - is the scarcest asset in AI-era security. If that is right, the round will look cheap in retrospect. If runtime telemetry turns out to be a feature rather than a platform, $3.8 billion is the high-water mark.

Data as of September 2, 2026. The new financing is based on people familiar with the matter, as the company has not yet made a public announcement.

Explore more exclusive insights at nextfin.ai.

Search
NextFinNextFin
NextFin.Al
No Noise, only Signal.
Open App