Tracecat
Open-source software that lets a small security team automate their alert-response playbooks — and now AI agents — without paying enterprise SOAR prices.
🔗 Visit TracecatDescription
When a security team gets an alert at 2am, the response usually follows a repeatable checklist: check the IP against a threat feed, look up the user in the identity system, maybe lock an account. Doing that by hand every time doesn't scale, and the enterprise tools built to automate it (Splunk SOAR, Tines) are priced for teams with six-figure security budgets. Tracecat is an open-source alternative: a drag-and-drop workflow builder for exactly this kind of security automation, that a small or understaffed team can self-host for free.
Tracecat is a Y Combinator-backed (W24), AGPL v3.0-licensed SOAR (Security Orchestration, Automation and Response) platform built to be AI-native from the ground up. Beyond the visual playbook canvas — which supports branching, looping, and custom Python actions — it includes an AI agent builder, case management with SLAs, human-in-the-loop approval steps, and an audit log of every prompt, tool call and agent decision (important for compliance). It ships 50+ pre-built MCP server integrations covering tools like CrowdStrike, Wiz, Okta, AWS, Azure, Slack and Gmail, with 500+ tools reachable via broader MCP/custom integrations. It's SOC 2 Type II certified and available self-hosted, on a managed cloud, or via VPC deployment, with adopters including Depop, Neo Financial and Saronic.
💬 Our review
The short version: Tracecat is for a security team that wants Tines- or Splunk-SOAR-level automation without the enterprise price tag, and is comfortable self-hosting or trusting a younger vendor with their security workflows.
Open-sourcing a genuinely capable SOAR platform under AGPL is the standout move here — Tines and Splunk SOAR are effectively locked to large budgets, so a self-hostable, free alternative with 50+ real integrations changes who can afford real security automation. The AI-native design (agent builder, full audit logging of AI decisions) is also well-timed as teams start letting agents touch production security tooling, and SOC 2 Type II certification is a meaningful trust signal this early. The honest caveat: it's a 2024-founded, YC-backed company — cloud/enterprise pricing isn't public, which makes it hard to budget against Tines or Splunk SOAR without contacting sales, and while the self-hosted tier is genuinely free, running and maintaining a SOAR platform yourself is real operational work that a fully managed Tines subscription avoids. If your team has the engineering capacity to self-host, this is a strong pick; if you want zero-maintenance, factor that cost into the comparison.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Auto-hébergé : gratuit (AGPL v3.0). Cloud et déploiement VPC/entreprise disponibles, tarif non public sur le site.
Pros
Version open source auto-hébergeable réellement gratuite (AGPL v3.0)
50+ intégrations MCP prêtes à l'emploi (CrowdStrike, Wiz, Okta, AWS...)
Certifié SOC 2 Type II, journal d'audit complet des décisions IA
Backé par Y Combinator (W24), adopté par des entreprises réelles (Depop, Neo Financial)
Cons
Tarif cloud/entreprise non public, nécessite de contacter les ventes
Auto-hébergement = charge opérationnelle réelle à assumer
Entreprise jeune (2024) comparée à Splunk
