Pricing

Start open source. Scale with one fee for the whole platform. Unlimited workflows, workspaces, and cases on every plan.

Open Source

Self-hosted automations with full control

Free forever

  • Unlimited workflows, workspaces, and cases
  • Tracecat MCP (prompt-to-automation)
  • Prebuilt integrations
  • Lookup tables
  • Deploy with Docker or AWS Fargate
  • SSO and audit trails included
  • Discord community and GitHub issues
  • -Advanced agents
  • -Advanced cases
  • -Skills registry
  • -RBAC
  • -Enterprise support
Deploy now

Enterprise

Build your agentic security team

Custom

Everything in open source, plus:

  • Cloud (US / EU) or self-hosted
  • Advanced agents
  • Forward deployed security engineer
  • Agent guardrails
  • Skills registry
  • MCP inventory
  • Advanced cases (triggers, metrics)
  • AI-powered dashboards (coming soon)
  • Git-native version control
  • Kubernetes Helm chart
  • RBAC and SCIM
  • 24/7 Slack and email support
  • Custom SLAs
Book a demo

Trusted by AI-native security teams

Included with Enterprise

A forward deployed security engineer for your agent rollout.

Connect your alert queues, device findings, cloud findings, and runbooks. Tracecat helps your team turn real investigation patterns into production agents, deployed with the controls security teams need.

Compare plans

Compare open source with the enterprise edition.

FeaturesOpen SourceEnterprise
Workflows
Webhooks
Schedules
Git sync-
Agents
AI action
AI agent action
Tracecat MCP (prompt-to-automation)
Agent builder-
Agent guardrails-
Skills registry-
Preset agents-
Versioned prompts-
Subagents-
Memory-
Sandboxed MCP-
Tool HiTL approvals-
Agent monitoring-
Cases
Case management
Comments
Attachments
Linked tables
Custom fields
Case metrics-
Case triggers-
AI-powered dashboards-Coming soon
Custom dropdowns-
Integrations
Prebuilt integrations
Lookup tables
Custom registry
Deployment
Managed cloud-
Self-hosted
Docker
AWS Fargate
Kubernetes-
Security
SSO
Audit logs
RBAC-
SCIM-
Usage
Unlimited workflows
Unlimited workspaces
Unlimited cases
Monthly executionsSelf-managedCustom pricing
Support
Discord community
GitHub issues
24/7 Slack-
Priority email-
Forward deployed security engineer-
Custom training-
Custom SLAs-

First 3 weeks

From security backlog to production agents

Week 1

Connect your tools

  • Connect SIEM, EDR, MDM, CSPM, CNAPP, ticketing, email, and cloud systems.
  • Map real alerts, device findings, cloud findings, and runbooks into Tracecat.
  • Set tool policies for read actions, write actions, and sensitive actions.

Week 2

Build your first security agents

  • Build agents around your alert queues, findings, and runbooks.
  • Use agents to collect evidence, summarize findings, and prepare next actions.
  • Add approval gates where a human needs to decide.

Week 3+

Grow your agents in production

  • Trigger agents from schedules, webhooks, and cases.
  • Review tool calls, approvals, decisions, and run history.
  • Tune prompts, tool use, and policies from analyst feedback.

FAQ

Open Source is self-managed with no execution limits. Enterprise is all-in-one pricing for the full platform and scales with usage, deployment model, and support needs. Book a demo for a custom quote.

Book a demo

Talk to a Tracecat expert

Or self-host Tracecat open source today. Read the docs

Loved by security teams building with AI

CNLRER
+3

Security Engineer @ Depop

Tracecat copilot has changed my life. I describe an agentic workflow and it builds it for me. I never had time to build and experiment around my other responsibilities. Now I do.

Senior Security Engineer @ Neo Financial

A genuine thank you to the team. I built an end-to-end IoC enrichment pipeline with Claude and Tracecat MCP and created more value for our SOC in a day than I probably would have in weeks on my own. You're making my one-man SOC assignment possible.

Principal Threat Researcher @ Saronic

Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future.