Open source SOAR and agent builder for AI-native security teams
We made the SOAR free and open source for builders.
So enterprise security teams can focus on scaling with agents.
We've got 3 newly-consented apps with sensitive scopes — triage them.
• Found 3 grants in last 24h via Google Admin SDK
• Cross-checking app reputation and publisher verification
Two of three grants request gmail.readonly from unverified publishers. Recommend revoking and notifying the owners.
Flagged grants
Ready to revoke slack-notes-export and meeting-mate. Approve to proceed.
New OAuth grant
google.directory.consent
OAuth analyst agent
google.directory · entra.graph
Revoke grant
google.revoke_token
Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future.
Trusted by security builders replacing legacy SOAR

Workflows can't keep up. Agents can.
Self-host the SOAR primitives for free. Upgrade to Enterprise for the agent stack, hosted MCP servers, and AI governance features.
Trigger
OAuth grant
Scatter
Per user
Run subflow
Quarantine
Workflows
Visual playbook canvas. Branch, scatter, loop, and run Python actions.
Tables
Lookup tables for IoCs, assets, and allowlists. Query from workflows and agents.
Shai-Hulud npm worm across 3 endpoints
Cases
Triage alerts with custom fields, SLAs, comments, and two-way ticket sync.
Agents with skills
Compose agents from reusable skills your team ships to Git.
Hosted MCP servers
50+ pre-built MCP servers for security and IT tools.
Chat in Slack and Teams
Deploy agents where your team works.
Replace click-and-drag with prompt to workflows.
Define playbooks in natural language. Give everyone the power to automate security work through Tracecat MCP.
Works with your favorite coding assistant
Everything you need to make security agents work.
Automate security work with prompts
Draft workflows, cases, tables, agent skills, and tool integrations from Claude, Cursor, or your AI workspace.
Skills built by your team
Reusable agent capabilities your engineers ship to GitHub. Analysts compose them into runbooks.
Hosted MCP servers
Connect agents to over 100 pre-built MCP servers without writing integration code.
Self-host anywhere
Deploy in your own VPC, on-prem, or on Tracecat's cloud. Your prompts and detections stay yours.
Human approvals on sensitive actions
Pause workflows for explicit approval before sensitive actions. Every approval is logged.
Audit every tool call
Open source audit logs of every prompt, tool call, and decision your agents make. In your Git, in your VPC.
Code when it matters.
Build integrations through prompts and code for any internal or third-party API.
Prompt versioning
Diff, review, and roll back every change to agent prompts and skills, with full audit history.
Sync everything to Git
Push and pull prompts, workflows, and skills between Tracecat and your Git repo.
Custom Python and dependencies
Write Python actions and pin dependencies, then sync the package directly into Tracecat for agents and workflows.