Tracecat

Tracecat

Open source AI-native SOAR for security automation

95/100Safe BetFree planFreemium

Best open-source SOAR for teams that prefer AI agent-based automation over static playbooks. Recent MCP and skills updates lower the barrier, but it still demands development investment. Not a plug-and-play replacement for traditional SOAR.

Verified 17d ago · liveness 95/100 · cite: rightaichoice.com/tools/tracecat

Best for
  • Security teams wanting custom AI agents for automation
  • Startups and mid-size companies seeking open-source SOAR
  • Teams with engineering talent who prefer self-hosted security automation
  • Cloud-native security operations needing flexible integration via MCP servers
Not ideal for
  • Teams needing plug-and-play SOAR with pre-built playbooks
  • Organizations without in-house development resources for agent building
  • Teams that prefer vendor-supported closed-source solutions with SLAs
Visit Website

IntermediateSelf-hosted: 1-2 hours with Docker or AWS Fargate. Tracecat Cloud: instant provisioning. Building a first agent takes a few hours for a team familiar with workflows. MCP hookups require configuring OAuth 2.1 for hosted servers (e.g., Jira).Web · API · CLIAPI available3.1k viewsVerified 17d ago
Pricing
Free plan
FreemiumFree tier2 plans4 hidden costs
Learning curve
Intermediate
Self-hosted: 1-2 hours with Docker or AWS Fargate. Tracecat Cloud: instant provisioning. Building a first agent takes a few hours for a team familiar with workflows. MCP hookups require configuring OAuth 2.1 for hosted servers (e.g., Jira).
Runs on
WebAPICLI
API available · 15 integrations
Who it's for
SOC analystCloud security engineerDevSecOps engineer
Live sentiment
Is Tracecat actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip Tracecat if you need a plug-and-play SOAR with pre-built playbooks and no custom development work.

The 30-second take
Biggest gripe

You must bring your own LLM API keys (e.g., OpenAI, Anthropic), adding variable cost.

Price reality

Tracecat's Open Source tier is free forever with unlimited workflows and cases, making it extremely cost-effective for startups. The Enterprise tier is custom-priced, likely higher than n8n's Team plan ($50/mo) but cheaper than Tines ($15K+/yr). Best for teams who can self-host.

In short

Tracecat — Open source AI-native SOAR for security automation. Best for Security teams wanting custom AI agents for automation, Startups and mid-size companies seeking open-source SOAR, Teams with engineering talent who prefer self-hosted security automation. Free to use.

What's new in Tracecat

Checked 17 days ago

Across the latest 8 updates: 5 feature updates and 3 launches.

LaunchChangelog·Jun 11Newest

Tracecat automation skill for coding agents

Open source skill lets agents build Tracecat automations: author YAML, design tables, validate definitions, debug executions.

FeatureChangelog·Jun 11Newest

Enterprise edition MCP servers now have their own page

MCP catalog gets dedicated page; new tool picker organizes integrations by capability; chat sessions can carry own tools.

FeatureChangelog·Apr 30

Agent Skills (Enterprise edition)

Agents can load reusable skills for alert enrichment, escalation, and tool use. New skills studio to build and manage them.

FeatureChangelog·Apr 20

Case Metrics, Dropdowns & Closure Requirements (Enterprise edition)

Dropdowns, fields, metrics in case rows; closure requirements; long-text and URL field types; bulk actions for commenting and dropdowns.

FeatureChangelog·Feb 27

Hosted MCP Servers (Open source)

MCP servers now run on Tracecat's infrastructure; Jira first hosted integration secured with OAuth 2.1; more servers coming.

FeatureChangelog·Feb 27

Chat for Workflows, Tables & Agents (Enterprise edition)

Chat panel from cases now available on workflows, tables, agents; each conversation is a full agent session with real tools.

LaunchChangelog·Feb 25

Tracecat MCP (Open source)

Tracecat runs as an MCP server; connect Claude, Codex, or any MCP client to workspace for workflows, cases, tables.

LaunchChangelog·Feb 5

Managed Cloud (Cloud)

Tracecat Cloud is live: multi-tenant service with organizations, workspaces; rebuilt execution engine with Temporal orchestration.

Viability Score

95/100
Safe Bet

How likely is Tracecat to still be operational in 12 months? Based on 4 signals — momentum (how recently it shipped), wrapper dependency, revenue model, and web presence.

momentum
100
funding runway
80
website health
90
wrapper dependency
100

Last calculated: July 2026

How we score →

Key Features

  • Build custom AI agents for security tasks
  • Human-in-the-loop approvals on sensitive actions
  • Replayable workflow runs with full audit logs
  • Hosted MCP servers for 100+ tool integrations
  • Draft workflows from natural language via Tracecat MCP
  • Limitless control flow: loops, conditions, subflows
  • Cloud alert enrichment and triage agents
  • Endpoint isolation and containment agents
  • OAuth app review and vulnerability response agents
  • Case management with agent-assisted summaries and metrics
  • Agent skills studio for reusable instructions
  • Closure requirements and dropdowns in cases
  • Self-host in your VPC or on-premises
  • Deploy on Tracecat Cloud (managed multi-tenant)
  • Open source audit logs of every tool call

About Tracecat

FreemiumIntermediateAPI availableWeb · API · CLI

Tracecat is an open-source security automation platform that lets you replace static playbooks with custom AI agents. It handles phishing triage, cloud alert enrichment, endpoint isolation, OAuth app review, and vulnerability response. Core features include human-in-the-loop approvals, replayable workflow runs with full audit logs, and over 100 tool integrations via hosted MCP servers. You can self-host in your VPC or use Tracecat Cloud (managed multi-tenant). Recent additions include an agent skills studio, case metrics, and the Tracecat MCP server, which lets coding assistants like Claude and Codex manage automations from natural language prompts. Unlike proprietary SOAR platforms, Tracecat gives you full control over data and automations with open-source auditability.

Behind the Verdict

Tracecat is a compelling option if you're building a security automation practice from scratch or migrating off a legacy SOAR. Its agent-first mindset lets you define playbooks in natural language and reuse skills across workflows. The hosted MCP servers with 100+ integrations dramatically reduce the integration coding burden. However, this isn't a tool you hand to a junior analyst and walk away. Building custom agents still requires understanding how to prompt, chain tool calls, and handle edge cases. Teams without a security engineer who can script will find the ramp steep. Compared to Tines or Splunk SOAR, Tracecat offers more flexibility and transparency (open-source AGPL, full audit logs), but less out-of-the-box playbook content. The managed cloud option lowers deployment friction, but for production use you'll likely want the Enterprise plan for RBAC and support. In practice, we'd recommend it for startups and mid-size teams that have one or two automation-savvy engineers who can own the agent library. Larger teams may prefer the guardrails and SLAs of a commercial SOAR.

Researching Tracecat? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas Tracecat actually fits — and what changes day-one when you adopt it.

SOC analyst

Phishing email triage via Gmail

Outcome: Automatically parse headers, detonate links, pull Falcon telemetry, quarantine endpoints, and revoke Okta sessions -- all with human approval gates.

Cloud security engineer

Wiz cloud finding enrichment

Outcome: Correlate Wiz alerts with CloudTrail and CrowdStrike Falcon telemetry, then propose containment actions for approval.

DevSecOps engineer

OAuth grant review automation

Outcome: Schedule weekly scans of OAuth grants across Google Workspace and Entra ID, revoke risky permissions, and notify app owners.

Use Cases

  • Triage Wiz cloud findings by correlating with CloudTrail and EDR, then propose containment actions.
  • Isolate compromised endpoints via CrowdStrike Falcon after an alert, with human approval.
  • Automate OAuth grant review across Google Workspace and Entra ID, revoking risky permissions.
  • Correlate npm package vulnerability alerts with GitHub advisories and rotate affected tokens.
  • Scheduled weekly scans of OAuth grants using the OAuth grant review agent (May 2026).

Models Under the Hood

Claude Opus 4.5

as of 2026-07-14

Limitations

  • Open-source tier is self-managed (Docker/AWS Fargate) and lacks advanced agents, skills registry, RBAC, and SCIM.
  • Enterprise features like AI-powered dashboards are still 'coming soon.' Hosted MCP servers are available in open source.

as of 2026-06-26

12-month cost

Project the real annual outlay, including the implied monthly cost when only an annual tier is published.

Annual total
Free
Over 12 months
Effective monthly
Free
Billed monthly

Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.

Plans compared

For each published Tracecat tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.

Open Source

$0/mo

Ideal for

Solo security engineers or small teams willing to self-host and build custom agents with no budget for commercial SOAR.

What this tier adds

Free entry point with unlimited workflows and cases; includes Tracecat MCP but no advanced agents or skills registry.

Enterprise

Custom

Ideal for

Mid-to-large security teams that need advanced agents, RBAC, SCIM, dedicated support, and managed cloud deployment.

What this tier adds

Adds advanced agents, agent guardrails, skills registry, MCP inventory, RBAC/SCIM, and a dedicated security engineer.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • You must bring your own LLM API keys (e.g., OpenAI, Anthropic), adding variable cost.
  • Self-hosted deployment requires Docker or AWS Fargate — infrastructure costs not included.
  • Managed Cloud pricing is custom — no published per-seat or per-mo rates.
  • Enterprise plan likely requires annual contract — no month-to-month option advertised.

Where the pricing makes sense

The company stage and team size where Tracecat's pricing actually pencils out — and where peers do it cheaper.

Tracecat's Open Source tier is free forever with unlimited workflows and cases, making it extremely cost-effective for startups. The Enterprise tier is custom-priced, likely higher than n8n's Team plan ($50/mo) but cheaper than Tines ($15K+/yr). Best for teams who can self-host.

Setup time & first value

How long it actually takes to get something useful out of Tracecat — broken out by persona, not the marketing-page minute.

Self-hosted: 1-2 hours with Docker or AWS Fargate. Tracecat Cloud: instant provisioning. Building a first agent takes a few hours for a team familiar with workflows. MCP hookups require configuring OAuth 2.1 for hosted servers (e.g., Jira).

Switching to or from Tracecat

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • From Tines: Export playbooks as YAML and adapt to Tracecat workflow DSL (manual).
  • From Splunk SOAR: Rebuild playbooks as agents using Tracecat's agent builder.
  • From n8n: Rewrite general-purpose workflows for security-specific agent logic.
Migrating out
  • To Tines: Rebuild agent logic as no-code playbooks (manual).
  • To n8n: Export workflow definitions and adapt to n8n nodes (manual).
  • To Splunk SOAR: Export run logs and rebuild playbooks in Splunk SOAR format.

Integrations

WizCrowdStrike FalconGmailOktaVirusTotalURLScanSlackSplunkElasticMicrosoft Defender XDRGitHubClaudeCursorMicrosoft CopilotCodex

Resources & Guides

Tutorials & Learning

Popular in Security & Privacy

AudioEye

AudioEye

Automated web accessibility compliance platform for ADA and WCAG.

PaidTry
Push Security

Push Security

Browser security platform for AI-era attacks and AI tool control.

FreemiumTry
Sublime Security

Sublime Security

AI email security platform that stops BEC with transparent, agentic detection.

Contact SalesTry

Frequently Asked Questions

Used Tracecat? Help shape our editorial sentiment research.