Tines vs Tracecat: A side-by-side comparison
Tracecat team
Tracecat vs Tines: A side-by-side comparison
Tines started in security operations. Its next product, Tines 3B, is an internal app builder in the same category as Replit, Lovable, and Claude Code artifacts, marketed to every business team. With that shift, Tines has lost its security focus. Tracecat, by contrast, is purpose-built for AI-native, engineering-minded security teams that want to build their own security agents, workflows, and custom cases.
Pick Tracecat if you want a modern security automation platform that:
- Treats automation as code, with workflows, agents, and integrations versioned in a Git repository your team owns.
- Runs agentic security operations in one place, with agents working the same cases, tables, and durable workflows as your analysts.
- Is built agent-first, with an MCP server that lets you drive the entire platform from Claude Code or ChatGPT Codex.
- Is designed to scale in the cloud and on-prem, including air-gapped. Tracecat is built on-prem first, with the same features and architecture in every deployment.
- Has all-in-one enterprise pricing. Agents, workflows, tables, cases, and security features are built and priced as one coherent agentic product. Tines, by contrast, sells cases and AI credits as separate add-ons.
Pick Tines if you:
- Want one governed app builder for every department, with security as one of several teams using it.
- Plan to build your security operations yourself on a general-purpose builder, and have the engineers to write and maintain the Python scripts behind it.
- Already run Tines Stories at scale, do not have the mandate to migrate off, and prefer to follow Tines to 3B as an internal app builder rather than move to a platform purpose-built for modern security operations.
Tines started in security, but its focus has shifted
Tines started as a security automation product. Stories, its no-code workflow builder, shipped with security use cases and integrations, with cases and records sold as add-ons. It is deployed and proven in enterprise security teams. But Stories is no longer where Tines is heading. Today, Tines calls 3B "the next generation of Tines": a code-first builder for every team's apps, agents, and automations. Its Head of Product and Lead Product Designer left their Stories roles to build it.
3B exists to secure what Tines calls "wild code", the apps employees build with AI outside IT and security oversight. That is a governance problem for every department, but it is not security operations. Unlike Tracecat, 3B was not designed for alert queues, collaborative case management across teams and AI agents, durable, fast, deterministic workflows, or long-running security agents.
Tines' answer for security teams is to build your own AI SOC on 3B. But that means writing and maintaining Python scripts inside an internal app builder. In practice, those scripts are harder to maintain and carry no performance guarantees for normalization, deduplication, correlation, and enrichment. These are mixed IO-bound, CPU-bound, and agentic workloads that Tracecat is optimized for out of the box. Security teams that want a purpose-built platform should evaluate whether Tines can still keep up with the growing alert queues and longer-running agents that define modern AI-native security operations.
Tracecat is the agentic automation platform for security teams. Agents, workflows, cases, tables, 500+ integrations, and 50+ hosted MCP servers ship in one platform that teams use as a SOAR replacement. Tracecat works with security teams from startups to Fortune 500 companies and federal agencies, including on-prem and air-gapped deployments.
To see how other platforms compare, read the top Tines alternatives.
What Tracecat does better than Tines
- Case management is included, not sold as an add-on. Tracecat open source includes cases with comments, attachments, tags, and custom fields. Workflows and agents open and update the same case record your analysts work in. Tines' documentation says "Cases are an add-on feature for paid plans."
- Durable execution that scales on-prem by default. Tracecat's scheduler is built on Temporal. Every workflow and agent run is persisted step by step. Work that is already scheduled survives bursts, crashes, and restarts, then resumes where it stopped. On Kubernetes, executors autoscale with KEDA. Mixed queues keep fast deterministic actions and long-running agents from affecting each other. Tines Stories, on the other hand, is a Rails application that queues tasks in Redis for Sidekiq workers. Its scaling guidance is to raise Sidekiq concurrency or add Sidekiq pods once queue latency passes one second. Self-hosted Python runs in a separate command runner container.
- Agents built for security operations. A Tracecat agent is a reusable preset with versioned skills, tools, and MCP servers. It works on Tracecat's own primitives, reading and updating cases and tables. The same preset runs in workflows, chat, and cases. Every case has a copilot. Workspace chat is a separate assistant for the whole workspace. You set each tool to run automatically or to wait for a person's approval. Tines, by comparison, meters its Stories agent action by credits. Agents in 3B are general-purpose.
- The entire platform, driven from your coding assistant. Tracecat MCP exposes more than 100 tools across workflows, agents, cases, and tables. Your team builds and runs its security automation through prompts in Claude Code or ChatGPT Codex, the assistants it already uses. There is no new builder or new way of prompting to learn. Tracecat MCP is open source, built and optimized for security operations. Tines' MCP server for Stories, by contrast, is for authoring stories.
- A custom registry for security engineers. A custom Tracecat integration is a Python package or a YAML template in your own Git repository. Tracecat syncs the repository at a pinned commit, once for the whole organization, for every workflow and agent. You promote or roll back a version from the platform. Tines Stories has no shared registry of Python packages. Instead, Python runs inside a Run Script action: Python 3.13 only, a 110 second maximum, and a 6 MB limit on payload and output. Tines' own documentation says, "we are an automation platform, not a code repository."
- Git sync to a repository your team owns. Tracecat Enterprise syncs workflows, agent presets, skills, table schemas, and case configuration to GitHub, GitLab, or Bitbucket. A push opens a pull request. A pull applies a reviewed commit. Tines Stories, on the other hand, has no native Git sync from the platform. Storing stories in Git means adopting a Terraform provider that Tines labels Enterprise.
- Open source, with a free tier a security team can run on. Tracecat is open source under AGPL-3.0. The free edition has unlimited workflows, agents, and cases, plus SSO, built-in roles, and organization audit logs. Tines, by contrast, publishes no source code. Its Community Edition allows 3 flows, 1 user, and 25,000 events a month.
- Better documentation for air-gapped deployments. Tracecat's air-gapped deployment guide covers production Kubernetes with no runtime internet access. It includes a reference architecture, images mirrored to an internal registry, internal dependencies, and self-hosted LLM inference with vLLM or Ollama. Every Tracecat feature works air-gapped. By comparison, Tines' only air-gapped installation guide is for the single-server 3B install. Tines says that install "has no high availability and no redundancy" and lists it for evaluations. The 3B Helm guide has no air-gapped section. Stories has no end-to-end air-gapped deployment guide.
"Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future," says a Principal Threat Researcher at Saronic.
Tines vs Tracecat
| Category | Tracecat | Tines |
|---|---|---|
| Built for | Security operations: alert triage, investigation, and incident response | "Every team". Launch examples include procure-to-pay workflows and sales forecast dashboards. |
| Product direction | One platform for agents, workflows, cases, and tables | 3B is "the next generation of Tines": a code-first builder for apps, agents, and automations |
| Case management | Included in open source. Enterprise adds tasks, triggers, metrics, dropdowns, and linked table rows. | "Cases are an add-on feature for paid plans." |
| AI agents | Reusable presets with versioned skills and human-in-the-loop agent approvals. The same agent runs in workflows, chat, and cases. | Stories agent action is metered by credits and accepts remote MCP tools only. 3B agents are general-purpose. |
| Coding assistants and MCP | Tracecat MCP gives Claude Code and ChatGPT Codex 100+ tools for workflows, agents, cases, and tables. | MCP server for authoring stories. 3B has a separate MCP endpoint. |
| Integrations | 500+ integrations focused on security tools, plus 50+ hosted MCP servers for agents | Custom integrations are HTTP request templates or Run Script actions |
| Python and customization | Python packages and YAML templates in your Git repository, synced at a pinned commit with promote and rollback | Run Script actions: Python 3.13 only, 110 second maximum, 6 MB payload and output limit. No shared registry. |
| Version control | Enterprise Git sync for workflows, agent presets, skills, table schemas, and case configuration. A push opens a pull request. | Stories go to Git through a Terraform provider labeled Enterprise. No native Git sync from the platform. |
| Scale and execution model | Durable execution on Temporal. Runs persist step by step and resume after a crash or restart. | Rails application. Tasks are queued in Redis for Sidekiq workers. |
| Scaling on-prem | KEDA autoscaling on Kubernetes. Mixed queues keep fast actions and long-running agents apart. | Add Sidekiq pods when queue latency passes one second. Runs pause until the next day at the daily event limit. |
| Deployment | Open source on Docker Compose or AWS Fargate. Enterprise adds a Kubernetes Helm chart and managed cloud in the US or EU. | Stories self-hosting requires a Business or Enterprise edition, a license key, and images from a credentialed registry |
| Air-gapped deployment | Full guide for production Kubernetes, including self-hosted LLM inference | Air-gapped guide only for the single-server 3B install, which "has no high availability and no redundancy" |
| Pricing and packaging | Open source is free to self-host with unlimited workflows, agents, and cases. Enterprise is one custom plan. | No public prices for paid plans. The pricing page shows only 3B, metered in "Tines units". |
| Free tier | Unlimited workflows, agents, and cases with SSO, built-in roles, and organization audit logs | Community Edition: 3 flows, 1 user, 25,000 events a month |
| Source model | Open source under AGPL-3.0 | Closed source. Both products ship as licensed images. |