Tracecat
Book a demo

Tines vs Tracecat: A side-by-side comparison

Tracecat team

Tracecat vs Tines: A side-by-side comparison

Tines started in security operations. Its next product, Tines 3B, is an internal app builder in the same category as Replit, Lovable, and Claude Code artifacts, marketed to every business team. With that shift, Tines has lost its security focus. Tracecat, by contrast, is purpose-built for AI-native, engineering-minded security teams that want to build their own security agents, workflows, and custom cases.

Pick Tracecat if you want a modern security automation platform that:

  • Treats automation as code, with workflows, agents, and integrations versioned in a Git repository your team owns.
  • Runs agentic security operations in one place, with agents working the same cases, tables, and durable workflows as your analysts.
  • Is built agent-first, with an MCP server that lets you drive the entire platform from Claude Code or ChatGPT Codex.
  • Is designed to scale in the cloud and on-prem, including air-gapped. Tracecat is built on-prem first, with the same features and architecture in every deployment.
  • Has all-in-one enterprise pricing. Agents, workflows, tables, cases, and security features are built and priced as one coherent agentic product. Tines, by contrast, sells cases and AI credits as separate add-ons.

Pick Tines if you:

  • Want one governed app builder for every department, with security as one of several teams using it.
  • Plan to build your security operations yourself on a general-purpose builder, and have the engineers to write and maintain the Python scripts behind it.
  • Already run Tines Stories at scale, do not have the mandate to migrate off, and prefer to follow Tines to 3B as an internal app builder rather than move to a platform purpose-built for modern security operations.

Tines started in security, but its focus has shifted

Tines started as a security automation product. Stories, its no-code workflow builder, shipped with security use cases and integrations, with cases and records sold as add-ons. It is deployed and proven in enterprise security teams. But Stories is no longer where Tines is heading. Today, Tines calls 3B "the next generation of Tines": a code-first builder for every team's apps, agents, and automations. Its Head of Product and Lead Product Designer left their Stories roles to build it.

3B exists to secure what Tines calls "wild code", the apps employees build with AI outside IT and security oversight. That is a governance problem for every department, but it is not security operations. Unlike Tracecat, 3B was not designed for alert queues, collaborative case management across teams and AI agents, durable, fast, deterministic workflows, or long-running security agents.

Tines' answer for security teams is to build your own AI SOC on 3B. But that means writing and maintaining Python scripts inside an internal app builder. In practice, those scripts are harder to maintain and carry no performance guarantees for normalization, deduplication, correlation, and enrichment. These are mixed IO-bound, CPU-bound, and agentic workloads that Tracecat is optimized for out of the box. Security teams that want a purpose-built platform should evaluate whether Tines can still keep up with the growing alert queues and longer-running agents that define modern AI-native security operations.

Tracecat is the agentic automation platform for security teams. Agents, workflows, cases, tables, 500+ integrations, and 50+ hosted MCP servers ship in one platform that teams use as a SOAR replacement. Tracecat works with security teams from startups to Fortune 500 companies and federal agencies, including on-prem and air-gapped deployments.

To see how other platforms compare, read the top Tines alternatives.

What Tracecat does better than Tines

  • Case management is included, not sold as an add-on. Tracecat open source includes cases with comments, attachments, tags, and custom fields. Workflows and agents open and update the same case record your analysts work in. Tines' documentation says "Cases are an add-on feature for paid plans."
  • Durable execution that scales on-prem by default. Tracecat's scheduler is built on Temporal. Every workflow and agent run is persisted step by step. Work that is already scheduled survives bursts, crashes, and restarts, then resumes where it stopped. On Kubernetes, executors autoscale with KEDA. Mixed queues keep fast deterministic actions and long-running agents from affecting each other. Tines Stories, on the other hand, is a Rails application that queues tasks in Redis for Sidekiq workers. Its scaling guidance is to raise Sidekiq concurrency or add Sidekiq pods once queue latency passes one second. Self-hosted Python runs in a separate command runner container.
  • Agents built for security operations. A Tracecat agent is a reusable preset with versioned skills, tools, and MCP servers. It works on Tracecat's own primitives, reading and updating cases and tables. The same preset runs in workflows, chat, and cases. Every case has a copilot. Workspace chat is a separate assistant for the whole workspace. You set each tool to run automatically or to wait for a person's approval. Tines, by comparison, meters its Stories agent action by credits. Agents in 3B are general-purpose.
  • The entire platform, driven from your coding assistant. Tracecat MCP exposes more than 100 tools across workflows, agents, cases, and tables. Your team builds and runs its security automation through prompts in Claude Code or ChatGPT Codex, the assistants it already uses. There is no new builder or new way of prompting to learn. Tracecat MCP is open source, built and optimized for security operations. Tines' MCP server for Stories, by contrast, is for authoring stories.
  • A custom registry for security engineers. A custom Tracecat integration is a Python package or a YAML template in your own Git repository. Tracecat syncs the repository at a pinned commit, once for the whole organization, for every workflow and agent. You promote or roll back a version from the platform. Tines Stories has no shared registry of Python packages. Instead, Python runs inside a Run Script action: Python 3.13 only, a 110 second maximum, and a 6 MB limit on payload and output. Tines' own documentation says, "we are an automation platform, not a code repository."
  • Git sync to a repository your team owns. Tracecat Enterprise syncs workflows, agent presets, skills, table schemas, and case configuration to GitHub, GitLab, or Bitbucket. A push opens a pull request. A pull applies a reviewed commit. Tines Stories, on the other hand, has no native Git sync from the platform. Storing stories in Git means adopting a Terraform provider that Tines labels Enterprise.
  • Open source, with a free tier a security team can run on. Tracecat is open source under AGPL-3.0. The free edition has unlimited workflows, agents, and cases, plus SSO, built-in roles, and organization audit logs. Tines, by contrast, publishes no source code. Its Community Edition allows 3 flows, 1 user, and 25,000 events a month.
  • Better documentation for air-gapped deployments. Tracecat's air-gapped deployment guide covers production Kubernetes with no runtime internet access. It includes a reference architecture, images mirrored to an internal registry, internal dependencies, and self-hosted LLM inference with vLLM or Ollama. Every Tracecat feature works air-gapped. By comparison, Tines' only air-gapped installation guide is for the single-server 3B install. Tines says that install "has no high availability and no redundancy" and lists it for evaluations. The 3B Helm guide has no air-gapped section. Stories has no end-to-end air-gapped deployment guide.

"Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future," says a Principal Threat Researcher at Saronic.

Tines vs Tracecat

CategoryTracecatTines
Built forSecurity operations: alert triage, investigation, and incident response"Every team". Launch examples include procure-to-pay workflows and sales forecast dashboards.
Product directionOne platform for agents, workflows, cases, and tables3B is "the next generation of Tines": a code-first builder for apps, agents, and automations
Case managementIncluded in open source. Enterprise adds tasks, triggers, metrics, dropdowns, and linked table rows."Cases are an add-on feature for paid plans."
AI agentsReusable presets with versioned skills and human-in-the-loop agent approvals. The same agent runs in workflows, chat, and cases.Stories agent action is metered by credits and accepts remote MCP tools only. 3B agents are general-purpose.
Coding assistants and MCPTracecat MCP gives Claude Code and ChatGPT Codex 100+ tools for workflows, agents, cases, and tables.MCP server for authoring stories. 3B has a separate MCP endpoint.
Integrations500+ integrations focused on security tools, plus 50+ hosted MCP servers for agentsCustom integrations are HTTP request templates or Run Script actions
Python and customizationPython packages and YAML templates in your Git repository, synced at a pinned commit with promote and rollbackRun Script actions: Python 3.13 only, 110 second maximum, 6 MB payload and output limit. No shared registry.
Version controlEnterprise Git sync for workflows, agent presets, skills, table schemas, and case configuration. A push opens a pull request.Stories go to Git through a Terraform provider labeled Enterprise. No native Git sync from the platform.
Scale and execution modelDurable execution on Temporal. Runs persist step by step and resume after a crash or restart.Rails application. Tasks are queued in Redis for Sidekiq workers.
Scaling on-premKEDA autoscaling on Kubernetes. Mixed queues keep fast actions and long-running agents apart.Add Sidekiq pods when queue latency passes one second. Runs pause until the next day at the daily event limit.
DeploymentOpen source on Docker Compose or AWS Fargate. Enterprise adds a Kubernetes Helm chart and managed cloud in the US or EU.Stories self-hosting requires a Business or Enterprise edition, a license key, and images from a credentialed registry
Air-gapped deploymentFull guide for production Kubernetes, including self-hosted LLM inferenceAir-gapped guide only for the single-server 3B install, which "has no high availability and no redundancy"
Pricing and packagingOpen source is free to self-host with unlimited workflows, agents, and cases. Enterprise is one custom plan.No public prices for paid plans. The pricing page shows only 3B, metered in "Tines units".
Free tierUnlimited workflows, agents, and cases with SSO, built-in roles, and organization audit logsCommunity Edition: 3 flows, 1 user, 25,000 events a month
Source modelOpen source under AGPL-3.0Closed source. Both products ship as licensed images.
Tracecat team

Back to alternatives

FAQ

Appendix

Methodology

Tracecat publishes this comparison. We reviewed first-party product, deployment, and pricing documentation in October 2026, along with Tines' launch posts, homepage, and its CEO's interview with The New Stack. Quotations are from those sources. The conclusion that Tines has moved its focus away from security operations is our assessment. So is the comparison of Tines 3B to Replit, Lovable, and Claude artifacts. Recommendations reflect our assessment of technical fit for security teams.

Sources

Tracecat. AI agents, Case management, Git sync, Kubernetes and KEDA, Air-gapped deployment, Architecture, Security architecture, Tracecat MCP, Custom registry, Custom model providers, Pricing, License.

Tines. Homepage, Introducing Tines 3B, Making Tines 3B, Tines 3B, 3B product updates, Build your own AI SOC, Newsroom, The New Stack interview, Pricing, Stories architecture, Stories scaling, Events, AI agent action, MCP server, Run script, Case management, Terraform provider.

Book a demo

Talk to a Tracecat expert

Or self-host Tracecat open source today. Read the docs

Loved by security teams building with AI

CNLRER
+3

Security Engineer @ Depop

Tracecat copilot has changed my life. I describe an agentic workflow and it builds it for me. I never had time to build and experiment around my other responsibilities. Now I do.

Senior Security Engineer @ Neo Financial

A genuine thank you to the team. I built an end-to-end IoC enrichment pipeline with Claude and Tracecat MCP and created more value for our SOC in a day than I probably would have in weeks on my own. You're making my one-man SOC assignment possible.

Principal Threat Researcher @ Saronic

Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future.