# Stream.Security

**Canonical:** https://apis.io/providers/stream-security/  
**Website:** https://www.stream.security/  
**APIs profiled:** 2

Stream.Security (formerly Lightlytics) is a cloud detection and response (CDR) and real-time CNAPP vendor that builds a live model of a customer's cloud - its "CloudTwin" - by continuously ingesting configuration state and activity from AWS, Azure, GCP, Kubernetes, ECS and VMware vSphere, then correlating posture drift against runtime behaviour to expose exploitable attack paths, excessive privilege, external exposure and active threats. The platform combines cloud-native log ingestion (CloudTrail, VPC Flow Logs, Route53 DNS, ELB/ALB, WAF, Entra ID audit) with eBPF runtime agents on Kubernetes, ECS and standalone VMs, adds canary/trap decoy resources and auto-remediation, and exposes it all through a public REST API and an MCP server so security teams and agents can query inventory, detections, vulnerabilities, attack paths and posture violations programmatically.

## Kin Score — 41.3 / 100 (developing)

Scored 2026-09-01 under rubric 0.17.2. Trend: flat (+0.0 from 41.3).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 61.2 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 10.5 |
| Developer Ergonomics | 45.2 |
| Commercial Clarity | 28.9 |
| Access Clarity | 28.9 |

## Agent readiness — 35.1 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (2)

- **Stream Security API** — REST API over the Stream Security CloudTwin. 34 operations across twelve resource groups - inventory, attack paths, config changes, threat detections, detection rules, posture s...
- **Stream Security MCP Server** — Hosted remote MCP server that lets an agent query the Stream Security CloudTwin in natural language - resource metadata, configuration changes, misconfigurations, external expos...

## MCP servers (1)

- **Stream Security MCP Server** — Lets an agent interact with Stream Security data in natural language - retrieving resource metadata, configuration changes, misconfigurations, external exposures, excessive priv...

## Security (2)

- **Stream Security Authentication** — http · 1 scheme
- **Stream Security Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Stream Security Plans Pricing**

## Tags

Company, Security, Cloud Security, Cloud Detection and Response, CNAPP, Threat Detection, Vulnerability Management, Kubernetes, Observability, DevSecOps, Artificial Intelligence

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/stream-security/). Scores are computed from the provider's own public artifacts under a published rubric.
