Build1 distinct publisher3 min readPublished
The ranking arrives with no deal count and no partner roster, so the part a buyer can actually check is the plumbing under it, which is pay-as-you-go billing on an account you already own and findings normalised to OCSF.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Two mechanisms carry this, and they have little to do with each other.
The commercial one is a meter. Upwind brought its full portfolio into Extended with aggressive pay-as-you-go pricing from day one and aligned its field organisation on joint deal flow [3], and Upwind co-founder and CEO Amiram Shachar describes the customer-side payoff as billing, support and operations that match what customers already know from AWS [8]. Pay-as-you-go against an account you already own changes what you are approving: a meter, sitting on top of billing you already have. The post does not say who owns the ticket when a sensor misbehaves, and "same support path" can mean AWS triages it, or it can mean AWS routes you to Upwind with an account manager attached. Those are different operational models, and the difference is worth pinning down before the meter starts.
The technical one is a schema. Findings arrive in Security Hub as OCSF records and are correlated and prioritised there before routing to downstream tools [6], and that is the entire basis for AWS saying these solutions work together without you building the integrations [7]. For that to hold in your environment, the fields your downstream rules key on have to survive normalisation. Runtime evidence is the awkward case, because process ancestry and container identity are the parts most likely to land in an extension the receiving rule never reads. One finding and one query settles it, and I would settle it before believing the build-to-runtime-to-triage example the post walks through with Chainguard, Upwind and Splunk [5].
Then the ranking. AWS says Upwind has driven more customer activity and closed deals than any other partner [2], engaged faster than any other partner in the program [4], and that the joint deals are multi-million dollar, with one enterprise customer recently replacing its incumbent CNAPP with Upwind [9]. There is no deal count and no partner list [10]. Counting the vendors the post itself places inside Extended gets to four: Upwind, Chainguard, Splunk and 7AI [11][12]. First place in a field you cannot enumerate is a softer number than it looks.
The two products also do not adopt the same way. Security Hub Essentials covers posture management and vulnerability scanning [13]; Upwind's stated differentiator is an eBPF sensor in the Linux kernel that watches process behaviour, network connections, API calls and container interactions continuously [14]. Posture reads APIs and lands per account. A kernel sensor lands per host, so the unit of work is node coverage and kernel compatibility. Pay-as-you-go removes the purchase order. The rollout still has to happen. AWS also says the runtime view cuts alert noise dramatically [15]. That is a claim about someone else's alert volume, and it transfers only if your noise comes from vulnerabilities in code that never gets loaded, rather than from misconfiguration you have already decided to live with.
What I take at face value is the invitation. A vendor that overlaps AWS's own capabilities brought its own pricing and its own pipeline into the program [1][3], and AWS published that it out-closed everyone else [2]. That is an expensive thing to write down if the channel is not working.
Ranked by verification strength, evidence, and original report placement.
AWS says it invited Upwind into Security Hub Extended even though Upwind's solution overlaps parts of AWS's own offering, because customers kept naming Upwind as something that was working for them.
According to AWS, Upwind brought its full solution portfolio into Security Hub Extended with aggressive pay-as-you-go pricing from day one and got its field organisation fully aligned on joint deal flow.
AWS says partner findings flow into Security Hub in OCSF (Open Cybersecurity Schema Framework), get correlated and prioritised together, and route to the downstream tools the team already uses.
Amiram Shachar, Co-Founder and CEO of Upwind, is quoted saying that being inside Security Hub means customers get Upwind's cloud workload protection with the same billing, the same support path and the same operational model they already know.
The AWS post gives no count of deals closed through Security Hub Extended and no roster of the partners participating in the program, describing deal size only as multi-million dollar.
AWS describes the split as customer choice: some will choose Security Hub Essentials for cloud security posture management and vulnerability scanning, some will choose Upwind for runtime-first protection, and some will run both.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
AWS gives software supply chain its own Security Hub category, with two vendors in it1 distinct publisher
build
AWS says GuardDuty catches the universal attacks. The rest is your detection engineering.1 distinct publisher
security
The AsyncAPI backdoor shipped with valid provenance, because the official pipeline built it1 distinct publisher
build
Force the tool call, then hand Lightsail a long-lived key1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One interested party, mostly unquantified
Everything in this story comes from a single document written by one of the two companies that profit from it. The parts that survive outside the post are structural: OCSF as the finding format, an eBPF sensor in the Linux kernel, pay-as-you-go on an AWS account a buyer already holds. The parts carrying the headline — most activity, fastest engagement, multi-million dollar deals — arrive as adjectives with no counts, no named customer and no field of competitors to be first in.
Real channel traffic, none of it audited
This is further along than a signed logo slide: the portfolio is live in the program at pay-as-you-go, and AWS describes an enterprise actually tearing out an incumbent CNAPP through a Private Offer. It is also as far as the disclosure goes. The buyer is anonymous, the number of deals is missing, and the Siemens-Peloton-Roku-Nubank list belongs to Upwind's business at large rather than to anything bought through Security Hub Extended.
Superlatives outrunning the arithmetic
The framing is flattering to both signatories by construction — we opened the door to our competitor, and it is outselling everyone — and the ranking depends on a partner list AWS declines to publish. 'Cuts alert noise dramatically' does the same work without a single before-and-after figure. Strip the ordinals and something durable remains: billing that lands on an existing account, findings normalised to a public schema, and an entry point with no term commitment.
Co-sell marketing signed by both beneficiaries
AWS bills the consumption, banks the channel credit, and gets to look like an open platform while pointing generously at a rival product. Upwind gets Amazon's field organisation and a CEO quote published in Amazon's own voice. Chainguard, Splunk and 7AI appear as proof that the program has a network effect. Nobody inside this document is positioned to publish a number that would disappoint.
Firm on the sourcing, loose on the magnitudes
What kind of evidence this is, we can say precisely: one issuer post, no corroborating account, no test behind either the ranking or the noise-reduction claim. That makes the read on the story easy and the underlying quantities hard. Direction — Upwind is genuinely selling through AWS and displacing at least one incumbent — is well founded; every size attached to it is not.