Today, we're releasing the integration of Fortinet FortiGate Next-Generation Firewalls (NGFW) and Stream.Security’s CDR (Cloud Detection and Response) platform.
The goal? To connect what’s happening at the perimeter with what’s actually happening in your cloud.
Security teams are spending far too much time untangling conflicting signals in the cloud, leading to unnecessary escalations, wasted effort, and missed threats. That’s why we built an integration between Fortinet FortiGate Next-Generation Firewalls (NGFW) and Stream.Security’s CDR (Cloud Detection and Response) platform.
The goal? To connect what’s happening at the perimeter with what’s actually happening in your cloud.
Firewalls are designed to keep attackers out. But in the cloud, where resources spin up and down constantly and the perimeter is more of a concept than a location, it’s easy for visibility to fall apart. Security teams are often forced to operate on assumptions, especially when firewall logs and cloud infrastructure tell two different stories.
With this integration, Fortinet’s FortiGate NGFWs feed critical topology and enforcement data into Stream, including:
Stream’s CloudTwin™ engine then maps that data into a real-time model of your cloud environment, creating an accurate, always-updated view of which resources are actually reachable from the outside - and which ones aren’t.
Imagine your team receives an alert from your EDR about a suspicious command executed on an EC2 instance. Typically, determining whether that host is truly exploitable requires manual cross-tooling and coordination across teams—especially when third-party firewalls are involved.
But with FortiGate NGFW data flowing into Stream, your team can instantly see whether the affected instance is reachable from the internet—eliminating guesswork and accelerating response.

This integration is part of our broader mission: to help SOC and SecOps teams investigate, prioritize, and respond to cloud-native threats with real-time precision rather than static alerts or stitched-together logs.
By unifying firewall and cloud context, we give your team the clarity needed to:
Ready to bring perimeter awareness into your cloud response strategy?
Reach out to our team and we’ll show you how Fortinet NGFW + Stream.Security keeps your team one step ahead.
Stream.Security is redefining cloud security for the age of AI. Built around CloudTwin™, our patented live system model, Stream provides security teams with a continuously updated, deterministic view of their entire environment, including cloud infrastructure, identities, Kubernetes, networks, SaaS applications, and AI workloads. Rather than relying on fragmented logs and periodic scans, CloudTwin computes the real-time state of your environment, enabling every detection, investigation, and response to be grounded in complete, accurate context. Trusted by cloud-native enterprises and recognized as a Gartner® Cool Vendor in Modern SecOps, Stream.Security is building the intelligence layer that enables humans and AI agents to defend modern infrastructure with speed, precision, and confidence.