# Upwind > Upwind is a cloud and AI security platform (CNAPP) that secures cloud infrastructure and applications in real time — CSPM, vulnerability management, container and Kubernetes security, API security, DSPM, identity security, and incident response — with a Management REST API (v1 and v2) for automating administrative tasks, querying threats, vulnerabilities, configurations, and the inventory asset graph. Generated by the API Evangelist enrichment pipeline (2026-07-21, method: generated) from apis.yml and the artifacts in this repository. Upwind's docs host publishes no llms.txt of its own. ## APIs - [Management REST API v1 introduction](https://docs.upwind.io/restapi/v1/introduction): OAuth 2.0 client credentials, threats, vulnerabilities, configurations, cloud accounts, workflows, webhook integrations, SBOM packages, shift-left events - [Management REST API v2 introduction](https://docs.upwind.io/restapi/v2/introduction): search-first surface — assets, findings, policies, policy rules, rule definitions, stories, shift-left events, access management (groups, members, roles, scopes) - [Inventory API v2 introduction](https://docs.upwind.io/restapi/inventory/v2/inventory-introduction): graph-style asset search with relationship traversal - Base URLs: https://api.upwind.io (US), https://api.eu.upwind.io (EU), https://api.me.upwind.io (ME) - Auth: POST https://auth.upwind.io/oauth/token (client_credentials + audience=), then Authorization: Bearer ; tokens expire after 24 hours ## Specs - [OpenAPI v1 (reconstructed from docs)](openapi/upwind-management-v1-openapi.yml) - [OpenAPI v2 (reconstructed from docs)](openapi/upwind-management-v2-openapi.yml) ## Docs - [Documentation](https://docs.upwind.io/public/) - [Credentials & RBAC](https://docs.upwind.io/settings/credentials) - [Custom Webhook integration](https://docs.upwind.io/integrations/monitoring-and-logging/custom-webhook) - [Release notes (per component)](https://docs.upwind.io/release-notes/sensor) - [Status page](https://status.upwind.io/) - [Trust center (SOC 2 Type 2, ISO/IEC 27001:2022, GDPR)](https://trust.upwind.io/) - [GitHub organization](https://github.com/upwindsecurity) - [upwindctl CLI installer](https://get.upwind.io/upwindctl.sh) ## Artifacts in this repository - [Authentication profile](authentication/upwind-authentication.yml) - [Conventions (pagination, regions, tokens)](conventions/upwind-conventions.yml) - [Error catalog](errors/upwind-problem-types.yml) - [Rate limits](rate-limits/upwind-rate-limits.yml) - [Webhooks](asyncapi/upwind-webhooks.yml) - [Lifecycle (versioning, status page, release notes)](lifecycle/upwind-lifecycle.yml) - [Packages (Terraform modules, GitHub Actions, upwindctl)](packages/upwind-packages.yml) - [CLI (upwindctl)](cli/upwind-cli.yml) - [Conformance](conformance/upwind-conformance.yml) - [Trust center](security/upwind-trust-center.yml)