LATEST / MARCH 2026 Juno MCP brings investigations into compatible developer toolsTHE STORY Cloud security, with a memoryPRODUCT WATCH Evidence behind the answer

COMPANY / SECURITY ANALYTICS

Uptycs and the art of asking what happened before

An alert tells you something happened. Uptycs sells the missing backstory - joining cloud, container and endpoint evidence so security teams can decide what deserves their afternoon.

At Lumin Digital, the problem was what happened after the alarm. The digital banking software company already had SentinelOne and Jamf on its employees’ Macs. An alert could identify something suspicious. Explaining how it arrived, whether it belonged, and what else a developer had installed was another matter. The security team needed a memory.

  • Uptycs joins evidence from endpoints, cloud infrastructure and containers.
  • Lumin Digital reported saving about 30% per investigation.
  • Its newer Juno AI analyst exposes evidence for human review.

So Lumin added Uptycs as a visibility layer. Its case study describes using historical metrics, package-manager information and browser-extension data to fill out an investigation. The interesting purchase was context. Buying another detector would have answered a question the team could already ask.

≈30%less time per investigation
Lumin Digital’s reported result; not a platform-wide benchmark.

A database walks into a security conference

Uptycs began with a complaint about fragmentation. In Ganesh Pai’s account, a coffee conversation with his co-founders turned toward the proliferation of security products: separate agents, separate stores of overlapping information, separate interfaces. Every booth had an answer. Getting the answers into the same conversation was harder.

The founders borrowed an idea from Salesforce and SAP: put the underlying information into a structured foundation that supports different questions. Facebook’s open-source osquery supplied a way to collect system information and interrogate it through SQL. Uptycs incorporated in April 2016. Pai remembers Sichuan meals and whiteboards along the way. The glamour of a startup occasionally resembles dinner followed by database design.

Today, the company identifies Pai, Uma Reddy and Mike Hluchyj as founders. Pai’s background includes Akamai, Verivue and NetDevices. That history helps explain the emphasis on distributed systems and scale. Collecting a useful observation from one laptop is a different engineering problem from collecting it across a fleet.

Uma Reddy, Uptycs co-founder
Uma Reddy, co-founder and product leader. Behind the new AI interface sits an older obsession: make the evidence inspectable.

The alarm needs a biography

Uptycs now sells a cloud-native application protection platform, usually shortened to CNAPP. In plain English, it helps teams inventory computing assets, examine configurations and vulnerabilities, monitor running workloads, and investigate threats. Its territory includes Kubernetes containers, cloud resources and employee endpoints. Security operations, infrastructure and compliance teams can work from related information.

The company’s hybrid-cloud evolution combines agentless discovery with sensor-based runtime observation. Those approaches answer different questions. A configuration check can expose a risky permission; runtime telemetry can show what a process actually did. Uptycs’s bet is that the relationship between those observations is useful enough to buy.

01ObserveAssets, permissions,
process activity
02ConnectShared context
and history
03InvestigateQueries, evidence,
response
The investigation gets a plot: collect the clues, connect the actors, examine the sequence. A conceptual view of Uptycs’s approach.

The market has several adjacent doors: Wiz for cloud-security evaluations, Sysdig and Aqua for cloud and container use cases, CrowdStrike for endpoint protection. Buyers should compare the coverage their own environment requires. Uptycs’s distinguishing argument is its shared telemetry and queryable history across those environments. Lumin’s deployment also shows that consolidation can mean adding a common view while keeping a useful detector.

“Uptycs ticks the boxes to complete our endpoint security stack.”Sean McElroy, CSO, Lumin Digital

Modern infrastructure keeps its old furniture

Enterprise computing rarely inhabits one technological decade. Uptycs’s IBM work covers LinuxONE, Linux on Z, Power and AIX, alongside public-cloud environments. In October 2025, it announced continuous threat exposure management for IBM Cloud. The pitch suits organizations whose important workloads refuse to fit a tidy cloud-only diagram.

Another connection reaches backward from production into development. The December 2024 Checkmarx partnership combines application-security findings with runtime and exposure information. A running container image can be linked to its source repository. That gives teams a route from an observed risk toward the code that needs attention.

Public customer names include Comcast, PayPal, Nutanix and Lookout. An anonymous financial-services case describes more than 100,000 Linux servers and a six-month production pilot. Uptycs reports that the pilot exceeded its success criteria. The useful detail is the test period: a fleet-scale promise had to survive contact with production.

A small monthly number, a substantial annual decision

Uptycs earns money through software subscriptions and workload-based licensing, supported by channel and managed-security partners. Its published hybrid-cloud pricing starts Discover at $3 per workload per month, or $5 per cloud workload, billed annually. Audit starts at $6 and $10 respectively. Secure adds runtime protection and response capabilities at quoted pricing.

The same page specifies a $12,000 annual minimum. Workload definitions matter too: server and container-node license units cover up to eight processing cores. A sensible evaluation starts with the required capabilities and a counted estate. The appealing monthly figure is only the first line of the calculation.

The company announced $93 million in cumulative funding with its May 2021 Series C. Its 2023 Deloitte ranking followed reported revenue growth of 796% between 2019 and 2022. Those figures suggest commercial traction; neither tells a buyer whether tomorrow’s difficult investigation will get easier.

Now the analyst must show its workings

Juno AI, announced in November 2025, brings natural-language investigation into the platform. Uptycs says its answers expose supporting logs, SQL queries and a reasoning trail. That is the meaningful promise to evaluate: can an analyst inspect the steps behind a conclusion?

Uptycs Juno product demonstration investigating a React Server Components vulnerability
A vulnerability headline becomes a question about your own estate. Still from Uptycs’s Juno demonstration; the detective now has a text box.

In March 2026, Uptycs introduced a Juno MCP server for compatible clients, including development tools. A question can begin where someone is already working, with a route back to the full investigation. It extends the original ambition: make the evidence easier to question.

There is a practical lesson here even for teams that never buy Uptycs. Pick a troublesome alert. Specify the history needed to explain it. Test whether that history is collected, retained and connected to an owner who can act. An agentless inventory alone will not supply every runtime detail; a short retention window will not answer every older question. The purchase works when those gaps are understood before the next alarm rings.