# Stream Security > AI SOC makes your security faster. Stream makes it real. Stream Security is a cloud detection and response platform built on CloudTwin: a live model of your cloud environment that updates the moment anything changes. Your SIEM records what happened. Stream knows what your environment actually looks like right now, and what every change means for your risk. Most security AI runs on logs. Logs are a record of events that already happened. They are not a model of the environment those events are happening in. Stream builds and maintains that model, so detection, investigation, and response run on ground truth instead of log patterns. ## The Core Idea Every AI security platform is reasoning about an environment it cannot see. They have logs. They do not have a map. Stream gives your SOC the map. A live model of cloud, identity, network, SaaS, and ephemeral assets that recalculates attack paths and blast radius as your environment changes. When an attacker changes a security group, modifies a permission, or opens a network path, Stream knows what that just made possible. Faster does not fix blind. Better data changes the outcome, not just the speed. ## CloudTwin A continuously updated model of your environment: workloads, identities, permissions, network paths, risk, and behavior. Built once from an initial map, then kept current from the same cloud, identity, and SaaS logs your other tools already consume. Every change recalculates attack paths, blast radius, and posture. A finding is not a severity score. It is whether something is actually reachable, and what it reaches. ## Products ### Stream Go (free) The full visibility layer at no cost. Unlimited assets. No trial window. No card. - CSPM and CIEM across cloud and Kubernetes - Exposure paths from the internet to your crown jewels - Vulnerability management: CVE prioritization by exploitability, not severity alone - Complete inventory and asset graph - Compliance scoring: SOC 2, CIS, PCI, AWS Well-Architected, out of the box - MCP endpoint to connect your own AI agents - SSO, audit logs, RBAC, ticket management Drop a read-only role. Full posture in minutes. No agents to deploy. ### Agentless Detection and response on top of the live model. - Posture that updates as your environment changes - Cloud threat detection - AI triage and zero-query investigation - AI SOC via StreamForce - Auto-remediation ### Runtime eBPF sensor for full-stack defense. Network, API, process, and file detection. Runtime vulnerability prioritization and containment. ### StreamForce The AI agent orchestration layer. Agents operate on the live environment model, not log patterns, so automation produces outcomes you can trust. Run pre-built workflows, build custom agents in free text, or bring your own agents and give them accurate context. ### AIDR (AI Workload Detection and Response) AI agents are already running in production, making model calls, invoking tools, and accessing data. Most SOCs cannot see any of it. Stream maps AI workloads as nodes in the same environment graph and surfaces risk the moment an agent behaves unexpectedly, accesses something it should not, or opens a path that did not exist before. ## Detection, Investigation, Response **Detect.** Catch attacks at the first move. Layered detection across rules, stateful UEBA, and anomalies, scored against actual current posture. Works across cloud, identity, network, runtime, and SaaS. **Investigate.** Understand why and how without drowning in logs. Attack storylines connect posture, identity, network, and runtime. AI Copilot answers analyst questions from the full model. **Respond.** See blast radius before acting. Response playbooks tied to asset state. Automated blocking or rollback of malicious changes. ## Integrations - Cloud: AWS, Azure, GCP, Kubernetes - Identity: Okta, Microsoft Entra ID, Google Workspace, PingOne - Workload: eBPF sensors for network, process, and file activity across K8s and VMs - Version control: GitHub, GitLab - DBaaS: Snowflake, MongoDB Atlas - Business apps: Salesforce, Microsoft 365 - AI platforms: OpenAI - Vulnerability scanners: Wiz, CrowdStrike, Rapid7 InsightVM, Snyk, Qualys, Tenable Nessus, Oligo, AWS Inspector, Azure Defender - DSPM: Sentra, Cyera - EDR: SentinelOne, CrowdStrike, Palo Alto Cortex - Firewalls: Palo Alto NGFW, Fortinet, cloud WAFs - Cloud-native: AWS GuardDuty, Azure Defender, GCP Security Command Center - SIEM: any SIEM with webhook support - Alerting: Slack, Microsoft Teams, PagerDuty, Opsgenie, Google Chat - Ticketing: Jira, ServiceNow, Azure Boards, JetBrains - SOAR: Torq, Tines ## Proof Points - Used by HiBob, RingCentral, Kaltura, Hunt Energy, Shield, Cross River, 3Commas - Agentless. No sensors to deploy. Read-only role only. - Covers AWS, GCP, Azure, and Kubernetes - Compliance scored out of the box: SOC 2, CIS, PCI, AWS Well-Architected, C5 - 46% of all alerts are false positives (Microsoft/Omdia 2026) - 61% of SOC teams admit to ignoring alerts that later proved critical ## Who Stream Is For Security teams that need to defend a live attack with full knowledge of what their environment looks like right now. CISOs accountable for AI security ROI. Security architects and SOC leaders who build and run detection and response. ## What Stream Is Not - Not a SIEM replacement or log federation platform - Not a periodic-scan hardening tool - Not an AI SOC that enriches logs without a model of the environment - Not a post-breach forensics platform - Not a simulation or red-team lab ## Links - Website: https://stream.security - Stream Go (free): https://stream.security/stream-go - Documentation: https://docs.stream.security