Uptycs is the top Cloud-Native Application Protection Platform (CNAPP) choice for security teams collaborating with developers to safeguard critical application pipelines, mitigate risks, and defend runtime environments in the hybrid cloud.
Uptycs consolidates cloud security silos into a unified platform, providing a single security console, policy framework, and data lake. This unification enables greater automation, simplifies policy enforcement, and extends security coverage, all while
reducing costs.
DATA IS YOUR POWER, NOT A HEADACHE
Uptycs tackled the cybersecurity data challenge first to give you deeper context so you can prioritize what truly matters. Our modern architecture normalizes security telemetry close to its collection point, and then streams it into your detection cloud, so you can query your attack surface like a database. No black boxes, no ETL, and no need to put in a support ticket to get new insights.
FULL LIFECYCLE CLOUD-NATIVE APPLICATION PROTECTION
Detect malware or suspicious behavior on developer endpoints, identify vulnerabilities early in the build process, verify secure configurations, and continuously monitor in production.
:: Prioritize security findings across your hybrid cloud workloads (VMs, containers, clusters, and serverless), and cloud infrastructure (databases, data stores, object storage) through exposure scanning, full attack path analysis, and correlation of security signals
:: Detect active threats to workloads with anomaly and behavior-based detections. Identify, prioritize, and fix misconfigurations and policy violations in Infrastructure as Code (IaC)
:: Simplify the maintenance of least privilege access and reduce IAM risks with full visibility into policies, users, and roles. Detect identity-specific threats through Identity Threat Detection and Response (ITDR) capabilities
:: Get deep support for AWS and start with instant-on, agentless coverage, then add the Uptycs Sensor for runtime protection, advanced remediation, and forensics
:: Gain full visibility into your software development pipeline posture and apply guardrails throughout your software development lifecycle (SDLC)
:: Fully protect your cloud with visibility of all cloud-connected assets, empowering you to understand your blast radius should a developer laptop be compromised
:: Meet compliance mandates with support for CIS benchmarks, HIPAA, ISO 27001, NIST, PCI, and SOC 2 across your cloud infrastructure and workloads running within the cloud
PROTECT YOUR CRITICAL WORKLOADS, WHEREVER THEY RUN
Replace multiple agents and tools with Uptycs for unified threat detection and response, vulnerability scanning, security hygiene, compliance, cyber asset management, file integrity monitoring (FIM), and ad hoc investigation and threat hunting.
:: Enjoy deep support for rare Linux distros, IBM LinuxONE, Linux on Z, IBM Power, AIX, HPC environments, and more
:: Enjoy blazing-fast response times with the Uptycs osquery-based agent with eBPF, designed to minimize its memory, CPU, and disk I/O footprint
:: Leverage rich security telemetry that goes beyond basic events to include file system files, Augeas lens, DNS lookups, sudoers list, and disk encryption
Reach out directly to learn more about how we can tailor solutions to your unique needs.
Uptycs provides custom pricing for customers via Private Offer. Please contact
aws@uptycs.com for a better understanding of our pricing model and products.
Highlights
Complete, consistent coverage. Secure public and private cloud, Kubernetes, rare Linux distros, IBM LinuxONE, developer endpoints, and the software pipeline. Scales from hundreds to millions of workloads with proven reliability. Learn more at https://www.uptycs.com/products/cnapp.
Deeper data delivers better insights. Correlate real-time insights with historical data to prioritize the threats and vulnerabilities that matter. Get 13-month lookback for compliance and forensic analysis, and Ask Uptycs for on-the-fly investigations.
Remediation requires cloud speed. Slash MTTR by 50% with real-time ATT&CK-mapped detections and blast radius visibility from laptop to code to cloud.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy this product as a contract priced per unit of 100 cloud workloads. Two options build on each other. Uptycs Cloud Audit covers inventory, compliance, vulnerability management, risk, infrastructure-as-code, and identity analytics. Uptycs Cloud Secure includes everything in Cloud Audit and adds workload protection, forensics, and threat detection. You choose one based on whether you need posture assessment alone or posture plus active runtime protection. Pricing scales with the number of cloud workloads you protect, so you add units as your environment grows. A cloud workload unit covers up to eight processing cores.
Top-of-mind questions for buyers
What counts as one cloud workload for billing purposes?
A cloud workload is a non-containerized cloud workload or a container node in the public cloud. A non-containerized workload is a VM or physical machine running a host OS. A container node is a VM or machine running containers, or a node in a Kubernetes cluster. Each unit supports up to eight processing cores.
What happens to my cost as I add more cloud workloads?
Pricing is unit-based, with each unit covering 100 cloud workloads. As your environment grows past a purchased unit, you add more units to cover the extra workloads. Each unit supports up to eight processing cores per workload. You pay for the units you purchase under your annual contract.
What is the practical difference between the Cloud Audit and Cloud Secure options?
Cloud Audit gives you posture assessment: inventory, compliance, vulnerability management, risk, infrastructure-as-code, and identity analytics. Cloud Secure adds active runtime protection on top: workload protection, threat detection, and forensics for real-time investigations. Choose Cloud Audit for visibility and posture alone, or Cloud Secure to also stop threats as they occur.
www.uptycs.com
Helpful?
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Supports deployment across more than 40 AWS services including compute, containers, storage, databases, networking, developer tools, management and governance, analytics, security, application integration, end user computing, machine learning, and migration services. Extends coverage to public and private cloud, Kubernetes, rare Linux distros, IBM LinuxONE, Linux on Z, IBM Power, AIX, and HPC environments.
Unified Security Data Platform
Consolidates cloud security into a single console with unified policy framework and data lake. Normalizes security telemetry close to collection point and streams into detection cloud for queryable attack surface analysis without ETL requirements.
Full Lifecycle Application Protection
Provides end-to-end protection including malware and suspicious behavior detection on developer endpoints, vulnerability identification in build process, secure configuration verification, runtime monitoring, exposure scanning, full attack path analysis, anomaly and behavior-based threat detection, Infrastructure as Code misconfigurations identification, and Identity Threat Detection and Response (ITDR) capabilities.
Agentless and Agent-Based Detection
Offers instant-on agentless coverage with optional osquery-based agent utilizing eBPF technology for runtime protection, advanced remediation, and forensics. Agent designed to minimize memory, CPU, and disk I/O footprint while providing rich security telemetry including file system files, Augeas lens, DNS lookups, sudoers list, and disk encryption data.
Compliance and Security Standards Support
Supports CIS benchmarks, HIPAA, ISO 27001, NIST, PCI, and SOC 2 compliance requirements. Includes file integrity monitoring (FIM), vulnerability scanning, security hygiene assessment, cyber asset management, and 13-month historical data lookback for compliance and forensic analysis.
Agentless Cloud Security Architecture
Agentless-first approach using patented SideScanning technology that provides deep visibility into cloud environments without requiring agent deployment
Risk Prioritization and Attack Path Analysis
Granular risk scoring applied to each alert with capability to identify and correlate seemingly unrelated issues into dangerous attack paths
Unified Cloud Security Platform
Single platform consolidating multiple security functions including CSPM, CWPP, CIEM, DSPM, Container security, and API security
CI/CD Integration for Application Security
Seamless integration into CI/CD process to secure applications from code to cloud deployment
AI-Powered Investigation and Remediation
Generative AI capabilities for simplified security investigations and accelerated remediation workflows
Offensive Security Engine
Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are reachable by outside attackers and reducing cloud attack surface.
Cloud Security Posture Management
Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
Secrets Scanning
Identifies more than 750 types of secrets across public and private repositories.
Cloud Infrastructure Entitlements Management
Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
Real-Time Malware Detection
Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.
Centralized visibility has improved risk-based vulnerability management but onboarding still needs simplification
Reviewed on Jun 04, 2026
Review provided by PeerSpot
What is our primary use case?
I use Uptycs as part of cloud security threat detection, vulnerability management, and security operations initiatives in my organization.
One use case demonstrates how I used Uptycs for the vulnerability management solution with a project where Uptycs is already deployed. I can simply check what vulnerabilities are available in the organization, determine the critical vulnerabilities and the high-severity vulnerabilities to prioritize and remediate them based on priority.
From my perspective, I can identify two areas regarding Uptycs: one is vulnerability management and the other is cloud workload, and it also provides endpoint visibility. In vulnerability management, I need to know about the overall asset inventory, and while it is difficult to know which assets are working properly, this centralized solution helps me obtain all the endpoint details and endpoint visibility. I can check what vulnerabilities are present, the high-severity vulnerabilities, and whether vulnerabilities are mitigated, and I can also review if the vulnerability is actually mitigated, which helps reduce the risks for the overall organization.
As a subject matter expert in vulnerability management or TVM, I mostly use vulnerability management because it helps significantly to detect vulnerabilities and prioritize vulnerabilities, risk-based matrices, and mitigate the vulnerabilities with the remediation team. That is my primary area, and it has been really helpful.
Regarding Uptycs's impact on my organization, I can add two points regarding vulnerability management. First, in asset inventory management, I can obtain all the inventory details and check what my overall scope is, including whether any asset is dead, not working, or if it is not connected to the cloud or VM solution. This centralized solution provides the complete asset inventory in a single place. Secondly, vulnerability management provides vulnerability prioritization, which is impactful and helps reduce risks for the overall organization because I can prioritize vulnerabilities and mitigate those risks as soon as possible after prioritizing.
What is most valuable?
From my perspective, the features of Uptycs that stand out more for my projects and organization are the vulnerability management, endpoint visibility, and asset inventory management features.
I can share two specific outcomes that show this positive impact using Uptycs. First, it reduces significant time and effort from the asset inventory point of view because previously I needed to scan all of the assets which were in scope, but now I only scan those assets that are currently active and in scope, and the CMDB and asset inventory receive proper updates of those assets. Secondly, in vulnerability prioritization, I receive all the prioritized vulnerabilities so I can prioritize and mitigate or remediate them as soon as possible, which reduces the overall time of remediation as well.
What needs improvement?
Regarding improvements for Uptycs, I suggest simplified onboarding for complex cloud environments because the current onboarding method is complex and requires checks with the support team. Another area for improvement is the visualization of asset relationships. It should provide overall mapping of the assets, risk scores, matrices, and vulnerability prioritization so I can map all the assets and vulnerabilities.
For how long have I used the solution?
I have used Uptycs for one year.
What do I think about the stability of the solution?
In my experience, Uptycs is stable with no downtime or reliability issues.
What do I think about the scalability of the solution?
Uptycs handles growth and increased workload well. I have extensive data for vulnerability and asset data in the solution, and as of now, there have been no issues regarding scalability.
How are customer service and support?
The customer support team is helpful, knowledgeable, and cooperative based on my interactions with them.
Which solution did I use previously and why did I switch?
I have used multiple solutions for VM, including Rapid7, Qualys, and Nessus, because I am a subject matter expert in vulnerability management, and I have not switched from any of them. We started using Uptycs as it was our client's requirement.
What was our ROI?
I have seen a return on investment from using Uptycs, saving almost 25 to 30 percent in terms of asset investigations or asset inventory management and vulnerability prioritization, which is significant.
What other advice do I have?
My advice for others looking into using Uptycs is that if you are looking for a centralized solution for all security practices, including endpoint security, vulnerability management, cloud security, and asset inventory management, then you can implement this solution, and it will be helpful. I would rate this review 7 out of 10.
Rajitha A.
A unified solution to improve IT management and operations – all in one.
Reviewed on Jan 27, 2025
Review provided by G2
What do you like best about the product?
Uptycs is good for its comparitive feature. It can analyse several tools of the same category and assist in making the correct choice at the end. This is particularly helpful for people like me who constantly flip between a few tools when I needed to select the best for cloud security.
What do you dislike about the product?
To facilitate a more rapid decision-making process, I suggest adding more concise and clear recommendations or summaries.
What problems is the product solving and how is that benefiting you?
As a security professional, it is important to me to have relevant non-compliance points and to decrease the risk of those non compliance points to the infrastructure. Uptycs is advantageous to me because I can see the compliance status of the cloud infrastructure and I can also enforce it with automated compliance checks.
Computer & Network Security
Uptycs – an advanced security monitoring tool, albeit expensive.
Reviewed on Jan 26, 2025
Review provided by G2
What do you like best about the product?
Very good tool for monitoring security, compliant with CIS or PCI DSS standards. I like the ability to create your own SQL queries in network security research.
What do you dislike about the product?
It's a pity that the price is high, I would gladly continue using this tool if it weren't for the high fees.
What problems is the product solving and how is that benefiting you?
Uptycs addresses issues with visibility across environments, maintaining compliance, excessive false positives, securing containers, and the lack of flexibility in customizing tools to meet individual needs.
reviewer2301639
Great features, good support, and lots of functionality
Reviewed on Oct 27, 2023
Review provided by PeerSpot
What is our primary use case?
We are using the solution for configuration and file integrity management. It's a validation tool.
What is most valuable?
They have multiple great features.
It offers most of the functionalities we need.
What needs improvement?
The one thing missing is the IPS part, the blocking part.
We end up facing a lot of issues after upgrades.
For how long have I used the solution?
I've been using the solution for three or more years.
What do I think about the stability of the solution?
The solution is somewhat stable. It depends on how we are integrating it. Apart from the major upgrades and bugs around that, I'd rate the stability six or seven out of ten.
What do I think about the scalability of the solution?
The solution is scalable. It covers multiple functionalities, operating systems, and clouds.
We have around 10,000 users on the solution currently.
How are customer service and support?
Technical support is good. They provide us with valuable assistance.
How was the initial setup?
The initial setup was really hard since the profiles you have to build around certain things. We had a lot of challenges implementing it.
It was a bit time-consuming to set up.
What's my experience with pricing, setup cost, and licensing?
The pricing is moderate compared to other products in the market. However, it is not the cheapest option.
Depending on the requirements and how it is used, it's worth the money spent.
What other advice do I have?
I'm an end-user.
We use the solution on multiple clouds.
I'd advise users to validate which product and metrics will help them the most. The solution has multiple functionalities. Don't go in blindly. Know what you want to get out of the product.
I'd rate the solution eight out of ten based on the scalability potential.
Joseph M.
Excellent lightweight EDR with full Mac support
Reviewed on Aug 03, 2023
Review provided by G2
What do you like best about the product?
It's tought ot find an EDR with decent support for Macs, there's plenty of options for Windows but if you're in a hybrid environment you're likely to notice the difference between endpoint systems. Uptycs supports Windows/Mac/Unix equally with a full set of detections for each. Inplementing Uptycs is a breeze, and the continuous development means you remain on the cutting edge. Systems are easy to use and figure out, tuning is straigtforward
What do you dislike about the product?
Communications around bugs is lacking. The backend is constantly under development which means things will change, and not always in a way you may want them to. Removing Uptycs from a Mac remotely is challenging at best, although this is mostly due to Apple.
What problems is the product solving and how is that benefiting you?
Uptycs isa full suite EDR/XDR and can provide an MDR as well. We use the EDR and MDR capabilities to cover corporate assets for compliance, governance, and security purposes.