Tracecat vs Tines: Which is best for AI security automation?
Tines now has two products. Stories remains its visual, no-code designer for security and IT operations. Tines 3B is a code-first, general-purpose AI building platform for apps, agents, and automations. For AI-native security teams, Tracecat is the better choice.
Tines 3B is a general-purpose AI building platform. Tracecat is built for security operations.
Compare the top Tines alternatives →Tines says Stories has a no-code foundation and continues as its visual designer for security and IT operations. Tines calls 3B its next generation. It is a code-first, general-purpose AI building platform for apps, agents, and automations.
Tracecat was built for AI agents and security engineers from day one. The same preset agent works across workflows, cases, and chat. Tracecat MCP works with coding assistants. Git sync keeps security automation in repositories your team owns.
What Tracecat does better than Tines
One agent across workflows, cases, and chat
Tracecat preset agents run across workflows, cases, and chat. Define one with skills and tools, then reuse it everywhere.
A Tines AI agent is configured as an action inside a story. It supports task and chat modes.
Build with coding assistants
Coding agents connected to Tracecat MCP can build and run workflows, agents, tables, and cases.
Tines Stories supports remote MCP tools and MCP-assisted story authoring.
Integrations and MCP servers
Tracecat ships 500+ integrations and 65+ hosted MCP servers curated and maintained for agents and workflows.
Tines connects agents to remote MCP servers. It does not provide a comparable out-of-the-box catalog.
Custom integrations from Git
Tracecat pulls your Python functions and template integrations from Git in one click. Registered once, they run in every workflow and agent.
Tines executes repository code through run script actions inside stories. It does not provide a shared custom registry.
Customizable case management for AI-native teams
Tracecat case management includes custom fields. Enterprise lets analysts mention preset agents in case comments and approve sensitive tool calls.
Tines cases and tables are paid add-ons. Its AI-assisted case experience is separate from the AI agent configured inside a story.
Sync to Git
Tracecat Enterprise syncs workflows, preset agents, skills, table schemas, and case configuration to GitHub, GitLab, or Bitbucket.
Tines keeps story versions and change control inside the product. External version control requires exporting and importing story files.
Secure, scalable infrastructure for agent workloads
Tracecat runs on Temporal durable execution with retries, timeouts, and long-running state. Enterprise adds Kubernetes Helm deployment with KEDA scaling per queue.
Tines runs on Rails, Postgres, Redis queues, and Sidekiq workers. Self-hosted scaling means sizing worker capacity and pod counts yourself.
Unlimited workflows, workspaces, and cases
Tracecat includes unlimited workflows, workspaces, and cases on every plan. Build small, modular automations without a pricing decision per workflow.
Tines pricing is modular. Depending on the plan, workflows, events, cases, tables, AI usage, API access, and version control are separate line items.
Open source vs. closed source
Tracecat is open source under AGPL-3.0. Inspect the code, review integrations, and let coding assistants reason over the real platform.
Tines is closed source and proprietary. Customers cannot inspect or modify the platform code they run.
Support and enablement
Enterprise customers get a forward deployed security engineer. Support is founder led, and feedback goes straight into the roadmap.
Tines provides support through account teams. Services and support use add-on credits.
Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future.
Trusted by security teams replacing traditional SOAR

Tines vs Tracecat
| Category | Tracecat | Tines |
|---|---|---|
| AI agents | The open source edition includes AI and agent actions inside workflows plus Tracecat MCP. Enterprise adds an agent builder with preset agents, skills, subagents, and sandboxed execution. Preset agents combine reusable skills, tools, tables, resources, and MCP servers. The same preset agent runs across workflows, cases, and chat. | An AI agent is configured as an action inside a story. It supports task and chat modes, agent skills, tools, code analysis, and remote MCP servers. |
| Case management | Case management with custom fields is included in the open source edition. Enterprise adds preset agents in cases, case triggers, approval gates, tasks, metrics, and Git sync for case configuration. | Tines cases and tables are paid add-ons. The AI-assisted case experience is separate from the AI agent action configured inside a story. |
| Git and automation-as-code | Enterprise customer-owned Git sync to GitHub, GitLab, or Bitbucket for workflows, preset agents, skills, table schemas, and case configuration. Exports open pull requests. Imports target one reviewed commit. Teams reuse the review, rollback, branching, and change-management practices they already apply to infrastructure and application code. | In-product story versions and change control, plus story file export and import. This does not replace external version control for teams that keep automation with their other engineering assets. |
| Infrastructure and scaling | Temporal durable execution with event history, retries, timeouts, and long-running state. Enterprise adds Kubernetes Helm deployment with KEDA scaling for separate workflow, action, and agent queues. | Rails, Postgres, Redis queues, and Sidekiq workers. Self-hosted guidance scales from worker capacity, queue latency, traces, and pod counts. |
| Custom Python integrations | The custom registry brings Python functions and template integrations from Git into Tracecat. Once registered, actions are reusable across workflows and agents. Git-synced integrations stay versioned with your code for review and rollback. | Run script actions pull code from an external repository and execute it within stories. Custom runtimes are also supported. That works for script execution inside a workflow, not for shared functions reused across the platform. |
| MCP | Coding assistants connected to Tracecat MCP can build and run workflows, agents, tables, and cases. Enterprise includes 65+ hosted MCP servers for agents and workflows. Tracecat curates and maintains the catalog. | Tines Stories supports remote MCP tools, story-built MCP servers, and MCP-assisted story authoring. AI agent actions can call remote MCP servers. Tines does not provide a comparable out-of-the-box MCP server catalog. |
| Sandboxed execution | Enterprise nsjail sandboxing on Kubernetes for isolated agent tool calls and Python actions. | AWS Lambda in Tines Cloud. Command runner for self-hosted or Cloud-over-Tunnel execution. |
| Self-hosting | The open source edition supports Docker or Fargate self-hosting. Enterprise adds Kubernetes Helm deployment. | Commercial self-hosting with proprietary images across Docker and Kubernetes environments. |
| Source model | Tracecat is open source under AGPL-3.0 with commercial Enterprise modules. Users can inspect the code, review integrations, contribute improvements, and let coding assistants work from the real platform code. | Closed source and proprietary. Customers cannot inspect or modify the underlying platform code. |
| Model choice | Tracecat supports any LLM provider or gateway, cloud or self-hosted. | Tines credits or a configured model provider. |
| Pricing | Unlimited workflows, workspaces, and cases on every plan. The open source edition is free to self-host. Teams can build smaller workflows and reuse them without paying per workflow. | Commercial editions with modular packaging. Workflows, events, AI usage, API access, and version control vary by plan. Cases and tables are paid add-ons. |
| Support | Enterprise includes a forward deployed security engineer. Support is founder led, and customer feedback goes directly into the product roadmap. | Documented onboarding, customer success, customer success engineering, and technical support. Services and support use add-on credits. |
Sources and methodology
We reviewed first-party product, deployment, and pricing documentation in September 2026. Recommendations reflect our assessment of technical fit for AI-native security teams.