No more typing reviews! Try our Samantha, our new voice AI agent.

StackHawk vs Upwind comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

StackHawk
Ranking in Dynamic Application Security Testing (DAST)
10th
Average Rating
7.6
Reviews Sentiment
4.6
Number of Reviews
2
Ranking in other categories
No ranking in other categories
Upwind
Ranking in Dynamic Application Security Testing (DAST)
11th
Average Rating
9.6
Reviews Sentiment
6.7
Number of Reviews
4
Ranking in other categories
Vulnerability Management (39th), Container Security (26th), Cloud Workload Protection Platforms (CWPP) (18th), API Security (11th), Cloud Security Posture Management (CSPM) (25th), Cloud-Native Application Protection Platforms (CNAPP) (15th), Attack Surface Management (ASM) (30th), Data Security Posture Management (DSPM) (18th), Cloud Infrastructure Entitlement Management (CIEM) (8th), Cloud Detection and Response (CDR) (7th), AI Security (11th)
 

Mindshare comparison

As of October 2026, in the Dynamic Application Security Testing (DAST) category, the mindshare of StackHawk is 1.9%, up from 0.9% compared to the previous year. The mindshare of Upwind is 0.5%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST) Mindshare Distribution
ProductMindshare (%)
StackHawk1.9%
Upwind0.5%
Other97.6%
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Ney Roman - PeerSpot reviewer
DevOps Engineer at Deuna
Vulnerability visibility has improved across microservices but integration still needs refinement
StackHawk can be improved in the way that it is integrated, as at the very beginning, the idea was to, within the pipeline, mount the different resources that our microservices needed to start to run. For example, if we have a service that needed Redis, maybe Kafka, or a database to initialize, we did need to have a Docker Compose file, get up those services, and after that, do the analysis. It didn't have that; it wasn't reachable at the very beginning and it wasn't that good as we expected. But at some point, we decided to mount it as an agent in the Docker file, and it was waiting for new jobs. It was even better, and when we figured out how to integrate it within our EKS cluster, suddenly we started reaching to the services, knowing what was going on, and everything related to security. As long as we have a P2T to our QA site or cluster, we do not have garbage in our databases, but StackHawk does put a little information, a garbage information, doing their job. That's the main area I'm focusing on right now regarding needed improvements.
Mohammed Mudasser - PeerSpot reviewer
AI/ML Engineer at a educational organization with 501-1,000 employees
Runtime context has transformed how we prioritize exploitable cloud risks and protect workloads
I appreciate runtime context, which helps connect vulnerabilities and misconfigurations with actual workload behavior and network relationships, making it easier to prioritize remediation based on real exposure rather than simply working through a long list of security findings. The best features that stand out to me are contextual vulnerability prioritization, cloud workload visibility, and runtime security. I especially value how Upwind connects vulnerabilities with actual runtime behavior, which helps focus on exploitable risk rather than working through a long list of findings. It has helped us focus on actual exploitable risk instead of treating every vulnerability equally. By considering runtime activity, exposure, reachability, and sensitive data context, the team can prioritize remediation much faster and reduce unnecessary alert noise. I also value the runtime visibility and attack path context because it connects security findings with network behavior and actual workload. This makes investigations more actionable and helps the team move from simply detecting issues to understanding their real impact. The biggest positive impact has been the prioritization of cloud security risk and improved visibility. Instead of chasing every vulnerability, we can focus on issues that are actually exposed or active at runtime, which makes the security team more efficient and remediation more targeted.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"StackHawk has positively impacted my organization by giving us a new vision of how vulnerabilities were seen, as we now have more visibility in that matter."
"StackHawk has positively impacted my organization by introducing an automated process that did not exist previously, and it helped the company achieve PCI certification."
"Upwind has positively impacted my organization by reducing time to action and time to response by half."
"My advice for others looking into using Upwind is that if you are seeking a strong CNAPP with an advanced runtime and strong CDR capabilities, this is the product."
"They are a great overall cloud security platform and they continue innovating and adding new features."
"The combination of runtime visibility, security insights, and contextual risk prioritization makes it much easier to focus on the risks that actually matter."
 

Cons

"StackHawk can be improved in the way that it is integrated, as at the very beginning, the idea was to, within the pipeline, mount the different resources that our microservices needed to start to run."
"On a scale of one to ten, I would rate StackHawk an eight, only because I wish the product was a little less expensive."
"Upwind can be improved because its UI is a bit difficult to navigate."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Outsourcing Company
13%
Financial Services Firm
8%
Comms Service Provider
7%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
 

Questions from the Community

What needs improvement with StackHawk?
StackHawk can be improved in the way that it is integrated, as at the very beginning, the idea was to, within the pipeline, mount the different resources that our microservices needed to start to r...
What is your primary use case for StackHawk?
My main use case for StackHawk is to analyze our application live in our EKS cluster. A specific example of how we use StackHawk in our EKS cluster is that we deployed an agent authenticated to the...
What advice do you have for others considering StackHawk?
I don't actually have a clear perspective on StackHawk's AI capabilities regarding its governance and security. My advice to others looking into using StackHawk is to stay prepared. Document how yo...
What is your experience regarding pricing and costs for Upwind?
The pricing, setup cost, and licensing process were pretty reasonable.
What needs improvement with Upwind?
I would appreciate more customizable dashboards and reporting for different teams, such as security operations, engineering, and leadership. The runtime context is excellent, but tailoring those vi...
What is your primary use case for Upwind?
My main use case for Upwind is cloud security and workload protection. I primarily use it to gain visibility into cloud assets, vulnerabilities, and runtime risks, and I mainly use it to prioritize...
 

Comparisons

 

Also Known As

No data available
Upwind Security Upwind Platform for AWS Security Hub, Upwind Security Upwind for AWS Security Hub Extended
 

Overview

 

Sample Customers

Information Not Available
StockX, Yotpo, bill, Digital Turbine, nanit, CallRail, boomi
Find out what your peers are saying about StackHawk vs. Upwind and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.