Overview
Upwind is a runtime-powered cloud-native application protection platform (CNAPP) that secures AWS, Azure, and GCP environments. The integration ingests Upwind's posture results and asset inventory into Cye Platform, where they are assessed by Exposure, Maturity, and remediation priority in the context of your business.
Collect Configuration & Vulnerability Findings: Configuration findings are the results of Upwind's cloud security posture checks on your cloud resources. Vulnerability findings are the CVEs Upwind identifies on your cloud resources and container images, with the vulnerable package.
Import Cloud Assets: Cye Platform imports the cloud assets in Upwind's inventory.
Connect with Read-Only Access: Cye Platform only reads data from Upwind. The Upwind Global Reader role is enough.
Stay Current Automatically: Data refreshes daily, and the integration supports Auto-fix.
Before You Start
Cye Platform: You must be an administrator to add the integration.
Upwind: You need an Upwind user that can generate API credentials.
Collect these four values from Upwind. The next section shows where to find each one:
Client ID and Client Secret: The API credentials you create for Cye Platform.
Organization ID: Your Upwind organization identifier, in the format
org_<id>.Region: Where your Upwind account is hosted:
US,EU, orME.
Getting Your Credentials from Upwind
Generate API Credentials
In the Upwind Console, click Settings in the side menu.
Under Access management, open the Credentials tab and click Generate Credentials.
Under I want to use these credentials for, select API.
Under Set permission, select one of the following:
Global Scope: Full access to all your Upwind data, with all of Upwind's admin roles.
Custom: Read-only access to all your Upwind data. Keep Scope set to Global Scope and select the Global Reader role. This is all Cye Platform needs.
Under Credentials details, click the pencil icon and rename the credentials, for example
Cye Platform.Click Generate new client credentials.
Copy the Client ID and Client Secret.
Note: Upwind displays the credentials only once. If you did not record them, reset the credentials in Upwind. Resetting invalidates the previous Client Secret.
Find Your Organization ID and Region
In the Upwind Console, click your company name at the top right.
Copy the Organization ID (
org_<id>) from the panel that opens.Read the Data residency value. It is your region. For example, Data residency: USA means you select US in Cye Platform.
Connecting Upwind in Cye Platform
In the side menu, click Integrations and open Data Integrations.
In the Cloud Security section, click Add on the Upwind tile.
Enter an integration name, for example
Upwind integration - <your company name>.Enter the Client ID and Client Secret from Upwind.
Enter the Organization ID and select the Region.
Click Verify Connection to test the connection to Upwind.
Click Save.
Reviewing Your Upwind Data
When Data Appears
Cye Platform starts collecting your data as soon as you save the integration.
The data is processed overnight, and your Upwind findings appear on the Findings page the following morning.
From then on, the data refreshes daily.
Find Upwind Findings
In the side menu, go to Operations and open Findings.
In the Filters panel, under Sources, select Upwind.
Read the Extended Data on a Remediation Asset
Failing Upwind configuration checks are mapped to the Cye Platform findings taxonomy and consolidated into findings, each with its remediation assets. On each remediation asset, the Extended Data Related To The Asset section shows:
Number of failing Upwind rules: The count of rules the asset fails.
Each failing rule: The rule name, its severity, and the compliance frameworks it maps to.
How Upwind rules become findings:
Related rules, one finding: Several related Upwind rules can map to the same finding, so one weakness appears once.
Frameworks merged: Upwind reports a rule once for each compliance framework that cites it. Cye Platform merges these into one remediation asset and lists the frameworks on it.
Vulnerable software: Upwind rules about vulnerable software map to the Usage of Outdated and Vulnerable Technologies finding. Its Extended Data shows a vulnerability summary instead of a list of rules.
Auto-Fix Statuses
Auto-fix updates the status of a remediation asset automatically when it is fixed in the source system.
The status of each finding is determined by its remediation assets.
This integration supports Auto-fix: when Upwind reports a failing check as passing, Cye Platform marks the remediation asset as Fixed.
Collected Endpoints
Cye Platform collects data from these Upwind API endpoints:
configurations/findings: The results of Upwind's security and compliance checks. Each result shows whether a cloud resource meets a specific rule.vulnerability-findings: The CVEs Upwind identifies on your cloud resources and container images, with the vulnerable package and its runtime context.inventory/catalog/assets: The catalog of cloud assets Upwind tracks across your cloud accounts.
Editing or Deleting the Integration
Edit: Click Edit Integration, make your changes, and click Save.
Delete: Click Delete Integration and confirm. The connection ends immediately, no new data is ingested, and existing data remains in Cye Platform.
After you delete the integration, also revoke the credentials in Upwind. In the Upwind Console, go to Settings > Access management > Credentials and delete the credentials you created for Cye Platform.
Wrap-up
Check your data: Go to Operations > Findings the morning after setup and filter Sources by Upwind.
Review a failing asset: Open a finding and read Extended Data Related To The Asset on its remediation asset.
Compare other cloud sources: Read Integrating with WIZ – Full Guide and Integrating with Microsoft Defender for Cloud – Full Guide.









