Grocery shopping app (previously Groceries), providing reliable sync with multiple users/devices (web/Android/iOS), recipes and integration with Tandoor. ([Source Code](https://github.com/davideshay/groceries)) `MIT` `Docker`
Best alternatives to Tracecat in 2026
When a security team gets an alert at 2am, the response usually follows a repeatable checklist: check the IP against a threat feed, look up the user in the identity system, maybe lock an account. Doing that by hand every time doesn't scale, and the enterprise tools built to automate it (Splunk SOAR, Tines) are priced for teams with six-figure security budgets. Tracecat is an open-source alternative: a drag-and-drop workflow builder for exactly this kind of security automation, that a small or understaffed team can self-host for free. Tracecat is a Y Combinator-backed (W24), AGPL v3.0-licensed SOAR (Security Orchestration, Automation and Response) platform built to be AI-native from the ground up. Beyond the visual playbook canvas — which supports branching, looping, and custom Python actions — it includes an AI agent builder, case management with SLAs, human-in-the-loop approval steps, and an audit log of every prompt, tool call and agent decision (important for compliance). It ships 50+ pre-built MCP server integrations covering tools like CrowdStrike, Wiz, Okta, AWS, Azure, Slack and Gmail, with 500+ tools reachable via broader MCP/custom integrations. It's SOC 2 Type II certified and available self-hosted, on a managed cloud, or via VPC deployment, with adopters including Depop, Neo Financial and Saronic.
Quick comparison of Tracecat alternatives
| # | Tool | Best for | Price |
|---|---|---|---|
| 1 | Grand public | — | |
| 2 | Équipes sécurité et développement de toute taille — du MVP solo aux organisations avec des dizaines de millions de lignes de code | — | |
| 3 | Développeurs et administrateurs système gérant des secrets sensibles (clés SSH, tokens) qui veulent éviter le vendor lock-in | — | |
| 4 | Utilisateurs individuels qui veulent automatiser des tâches de navigation web (gestion réseaux sociaux, veille, recherche, remplissage de formulaires) en langage naturel | — | |
| 5 | Utilisateurs soucieux de leur vie privée qui veulent éviter les gestionnaires de mots de passe cloud et garder un contrôle total sur leurs identifiants chiffrés | — | |
| 6 | Pentesters professionnels, chercheurs en sécurité et équipes DevSecOps qui veulent automatiser une partie d'un engagement de test d'intrusion | — | |
| 7 | Équipes de développement et de sécurité qui gèrent des clés API pour des pipelines CI/CD ou des agents IA et veulent limiter le risque de fuite de credentials | — | |
| 8 | Particuliers soucieux de leur vie privée et entreprises qui partagent des fichiers sensibles (photos, PDF, documents, vidéos, audio) et veulent en retirer les métadonnées cachées | — | |
| 9 | Startups et entreprises SaaS/tech sans équipe conformité interne qui veulent un accompagnement humain en plus du logiciel | — | |
| 10 | Responsables sécurité (CISO, SOC) d'entreprises qui veulent remplacer ou compléter une passerelle email sécurisée traditionnelle (SEG) face aux attaques de phishing générées par IA | — | |
| 11 | Équipes d'ingénierie et entreprises SaaS/Gen AI qui doivent obtenir ou maintenir des certifications (SOC 2, HIPAA, ISO 27001, GDPR, PCI DSS) sans staff conformité dédié | — | |
| 12 | Équipes d'ingénierie qui déploient des agents IA avec accès à des systèmes de production (bases de données, clusters Kubernetes, APIs internes) et veulent un contrôle strict entre l'agent et ces systèmes | — |
A security scanner that doesn't just flag possible bugs like most tools — it tries to actually exploit them first, so you only see the ones that are real.
- ✓ Génère des preuves de concept validées, pas juste des alertes à trier
- ✓ Open source AGPL-3.0, auto-hébergeable sans envoyer le code à un tiers
A tiny command-line tool for backing up SSH keys and other secrets so securely encrypted that you could still recover them in 10 years using nothing but standard Unix tools — even if this tool itself is long gone.
- ✓ Aucun vendor lock-in, récupérable avec des outils Unix standards
- ✓ Chiffrement age reconnu + vérification d'intégrité SHA256
A browser extension you can talk to in plain English to get things done — like "check my email for anything from my accountant" — instead of clicking through the steps yourself, while everything stays inside your own browser.
- ✓ Gratuit, open source (Apache 2.0)
- ✓ Automatisation côté client, pas de serveur tiers
A password manager that never uploads your passwords to any company's servers — instead, your devices talk to each other directly to stay in sync, so there's no central vault that could ever get hacked or breached.
- ✓ Zéro serveur central, rien à breach
- ✓ Chiffrement solide (AES-256-GCM, Argon2id)
A hacking-simulation tool that uses a team of AI agents — each specialized like a real penetration-testing crew member — to automatically probe a system for security weaknesses, from initial scanning all the way to proving an exploit works.
- ✓ Gratuit, open source (GPL-3.0)
- ✓ Pipeline multi-agents complet
Instead of handing your AI agents and scripts your real API keys (which is dangerous if they get compromised), API Stronghold gives them temporary, limited-use tokens that expire in minutes and can't be traced back to your actual credentials.
- ✓ Chiffrement zero-knowledge
- ✓ Tokens à expiration minute
Every photo or document you share online quietly carries hidden data — like the exact GPS location where a photo was taken, or your name buried in a PDF's properties. RemoveMD strips all of that out before you share the file.
- ✓ Traitement en mémoire, zéro stockage
- ✓ Pas de compte requis
Instead of giving you software and leaving you to figure out compliance certifications yourself, Probo assigns a real person who handles the whole SOC 2 / ISO / HIPAA process for you while the software automates the paperwork.
- ✓ Officier de conformité humain inclus
- ✓ Couvre de nombreux frameworks
An email security tool that reads the full context of every incoming email — not just the sender's address — to catch scam emails that look convincingly like they're from your CEO or a real vendor.
- ✓ Analyse d'intention contextuelle par agents IA
- ✓ Bon sur la détection de BEC / ingénierie sociale
A tool that automates the tedious parts of getting your company officially certified as secure (SOC 2, HIPAA, ISO 27001) — collecting proof automatically instead of your team screenshotting settings for weeks before an audit.
- ✓ Multi-frameworks (SOC2, HIPAA, ISO27001, GDPR, PCI DSS)
- ✓ Pentesting automatisé inclus
A checkpoint that sits between your AI agents and your real systems (databases, servers, cloud accounts), reviewing every action the agent tries to take before it's allowed through.
- ✓ Gratuit, open source, MIT license
- ✓ Contrôle au niveau protocole (SQL, Kubernetes, HTTP)
FAQ about Tracecat alternatives
- What is the best alternative to Tracecat in 2026?
- Based on our selection, Specifically Clementines is the best alternative to Tracecat in 2026. Grocery shopping app (previously Groceries), providing reliable sync with multiple users/devices (web/Android/iOS), recipes and integration with Tandoor. ([Source Code](https://github.com/davideshay/groceries)) `MIT` `Docker`. See our full ranking above to compare all options.
- Is Tracecat free?
- Tracecat is a paid tool. Several alternatives in our selection offer free or freemium versions.
- How many alternatives to Tracecat are there?
- mySelectas has listed 12 alternatives to Tracecat in the Security & Privacy category. Our selection is updated regularly to include the best options available.