Tracecat
Book a demo

Introducing Tracecat 1.0

The Tracecat cat spins as light-mode beta becomes dark-mode 1.0. The preview loops; the article settles into dark mode with occasional bounces and continuous bouncing on hover. beta 1.0

Chris (Co-founder / CEO)

Tracecat 1.0 is now generally available.

This milestone marks 2.5 years of lessons learned helping security teams run mission-critical workflows, manage incidents, and build agents for cyber defense.

Our mission is to enable security teams to build and own their agentic workflows. We saw open source as the best way to make that happen:

  • Works with any LLM provider: closed and open source models
  • Works with any coding assistant: turn prompts-to-automations via Tracecat MCP
  • Open integrations: Python and YAML templates
  • Open standards: agent skills, MCP, and plugins
  • Open infrastructure: Temporal-backed engine and nsjail agent sandboxes
  • Unlimited agents, workflows, and cases
  • Zero security tax: free SSO, audit logs, and IP allowlisting

But most importantly, we believe self-hosting is back. Tracecat runs without any 3rd party licenses, Cloud vendors, or internet access. The best defense against offensive agents is a locked down network.

With Tracecat, users can securely evaluate and build agentic use-cases without gated demos or vendor lock-in. Over 90% of customers had production use-cases fully automated on open source before upgrading to enterprise.

What 1.0 means

Today, Tracecat Cloud executes over 20 million automations per month. You'll find Tracecat running, fully air-gapped, within the world's most regulated industries and high stakes environments. Tracecat open source has been downloaded over 50,000 times in the past 12 months. Up in minutes in a home lab. Built to run at enterprise scale.

1.0 means Tracecat has consistently proven itself as stable, easy-to-use, and secure. The core engine is battle-tested and APIs stable.

Agents and skills
Case management
Workflows
Tables
Tracecat MCP
Integrations

The full agent experience, now open source

1.0 open sources multiple agentic features with one trade-off:

FeatureBefore 1.01.0
Reusable agent presetsEnterpriseOpen source
Agent skillsEnterpriseOpen source
Secrets in agent presetsEnterpriseOpen source
Pre-built MCP serversEnterpriseOpen source
WorkspacesUnlimitedSingle-tenant

You can continue to build as many agents and workflows as you need. However, multi-tenancy via workspaces is now enterprise only. For pre-1.0 users, your existing workspaces remain usable, but new workspaces will require an enterprise license.

Designed for enterprise security teams

  • Workspace git sync: Push and pull workspace configuration to your own Git repository. Review, version, and roll back changes as code.
  • SCIM: Provision and deprovision users through your identity provider.
  • BYO secrets manager: Keep credentials in your own secrets manager and retrieve them at runtime.

Coming soon

  • Agent memory: Search past conversations and learn from past cases. Agents will review previous work and suggest improvements.
  • Custom agent harness: Custom Pi harness optimized for security work running in firecracker MicroVMs.
  • Pre-built agent skills: Give agents reusable skills from Tracecat and official third-party vendors.
  • Open source agentic SOC: A technical guide to building an agentic security operations center with Tracecat.

This roadmap lays the foundation for a customizable self-improving agentic security operations center. A future where analysts become builders and builders become architects.


Build security agents

Self-host Tracecat 1.0 today: github.com/TracecatHQ/tracecat


Special thanks to our top open source contributors and GHSA security reporters.

Contributors

Security reporters

Chris (Co-founder / CEO)

Back to blog