Tracecat
Book a demo
TracecatvsTines

Tracecat vs Tines: Which is best for AI security automation?

Tines now has two products. Stories remains its visual, no-code designer for security and IT operations. Tines 3B is a code-first, general-purpose AI building platform for apps, agents, and automations. For AI-native security teams, Tracecat is the better choice.

Tines 3B is a general-purpose AI building platform. Tracecat is built for security operations.

Compare the top Tines alternatives →

Tines says Stories has a no-code foundation and continues as its visual designer for security and IT operations. Tines calls 3B its next generation. It is a code-first, general-purpose AI building platform for apps, agents, and automations.

Tracecat was built for AI agents and security engineers from day one. The same preset agent works across workflows, cases, and chat. Tracecat MCP works with coding assistants. Git sync keeps security automation in repositories your team owns.

What Tracecat does better than Tines

One agent across workflows, cases, and chat

Tracecat

Tracecat preset agents run across workflows, cases, and chat. Define one with skills and tools, then reuse it everywhere.

Tines

A Tines AI agent is configured as an action inside a story. It supports task and chat modes.

Build with coding assistants

Tracecat

Coding agents connected to Tracecat MCP can build and run workflows, agents, tables, and cases.

Tines

Tines Stories supports remote MCP tools and MCP-assisted story authoring.

Integrations and MCP servers

Tracecat

Tracecat ships 500+ integrations and 65+ hosted MCP servers curated and maintained for agents and workflows.

Tines

Tines connects agents to remote MCP servers. It does not provide a comparable out-of-the-box catalog.

Custom integrations from Git

Tracecat

Tracecat pulls your Python functions and template integrations from Git in one click. Registered once, they run in every workflow and agent.

Tines

Tines executes repository code through run script actions inside stories. It does not provide a shared custom registry.

Customizable case management for AI-native teams

Tracecat

Tracecat case management includes custom fields. Enterprise lets analysts mention preset agents in case comments and approve sensitive tool calls.

Tines

Tines cases and tables are paid add-ons. Its AI-assisted case experience is separate from the AI agent configured inside a story.

Sync to Git

Tracecat

Tracecat Enterprise syncs workflows, preset agents, skills, table schemas, and case configuration to GitHub, GitLab, or Bitbucket.

Tines

Tines keeps story versions and change control inside the product. External version control requires exporting and importing story files.

Secure, scalable infrastructure for agent workloads

Tracecat

Tracecat runs on Temporal durable execution with retries, timeouts, and long-running state. Enterprise adds Kubernetes Helm deployment with KEDA scaling per queue.

Tines

Tines runs on Rails, Postgres, Redis queues, and Sidekiq workers. Self-hosted scaling means sizing worker capacity and pod counts yourself.

Unlimited workflows, workspaces, and cases

Tracecat

Tracecat includes unlimited workflows, workspaces, and cases on every plan. Build small, modular automations without a pricing decision per workflow.

Tines

Tines pricing is modular. Depending on the plan, workflows, events, cases, tables, AI usage, API access, and version control are separate line items.

Open source vs. closed source

Tracecat

Tracecat is open source under AGPL-3.0. Inspect the code, review integrations, and let coding assistants reason over the real platform.

Tines

Tines is closed source and proprietary. Customers cannot inspect or modify the platform code they run.

Support and enablement

Tracecat

Enterprise customers get a forward deployed security engineer. Support is founder led, and feedback goes straight into the roadmap.

Tines

Tines provides support through account teams. Services and support use add-on credits.

Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future.
Principal Threat Researcher, Saronic

Trusted by security teams replacing traditional SOAR

Tines vs Tracecat

CategoryTracecatTines
AI agentsThe open source edition includes AI and agent actions inside workflows plus Tracecat MCP. Enterprise adds an agent builder with preset agents, skills, subagents, and sandboxed execution. Preset agents combine reusable skills, tools, tables, resources, and MCP servers. The same preset agent runs across workflows, cases, and chat.An AI agent is configured as an action inside a story. It supports task and chat modes, agent skills, tools, code analysis, and remote MCP servers.
Case managementCase management with custom fields is included in the open source edition. Enterprise adds preset agents in cases, case triggers, approval gates, tasks, metrics, and Git sync for case configuration.Tines cases and tables are paid add-ons. The AI-assisted case experience is separate from the AI agent action configured inside a story.
Git and automation-as-codeEnterprise customer-owned Git sync to GitHub, GitLab, or Bitbucket for workflows, preset agents, skills, table schemas, and case configuration. Exports open pull requests. Imports target one reviewed commit. Teams reuse the review, rollback, branching, and change-management practices they already apply to infrastructure and application code.In-product story versions and change control, plus story file export and import. This does not replace external version control for teams that keep automation with their other engineering assets.
Infrastructure and scalingTemporal durable execution with event history, retries, timeouts, and long-running state. Enterprise adds Kubernetes Helm deployment with KEDA scaling for separate workflow, action, and agent queues.Rails, Postgres, Redis queues, and Sidekiq workers. Self-hosted guidance scales from worker capacity, queue latency, traces, and pod counts.
Custom Python integrationsThe custom registry brings Python functions and template integrations from Git into Tracecat. Once registered, actions are reusable across workflows and agents. Git-synced integrations stay versioned with your code for review and rollback.Run script actions pull code from an external repository and execute it within stories. Custom runtimes are also supported. That works for script execution inside a workflow, not for shared functions reused across the platform.
MCPCoding assistants connected to Tracecat MCP can build and run workflows, agents, tables, and cases. Enterprise includes 65+ hosted MCP servers for agents and workflows. Tracecat curates and maintains the catalog.Tines Stories supports remote MCP tools, story-built MCP servers, and MCP-assisted story authoring. AI agent actions can call remote MCP servers. Tines does not provide a comparable out-of-the-box MCP server catalog.
Sandboxed executionEnterprise nsjail sandboxing on Kubernetes for isolated agent tool calls and Python actions.AWS Lambda in Tines Cloud. Command runner for self-hosted or Cloud-over-Tunnel execution.
Self-hostingThe open source edition supports Docker or Fargate self-hosting. Enterprise adds Kubernetes Helm deployment.Commercial self-hosting with proprietary images across Docker and Kubernetes environments.
Source modelTracecat is open source under AGPL-3.0 with commercial Enterprise modules. Users can inspect the code, review integrations, contribute improvements, and let coding assistants work from the real platform code.Closed source and proprietary. Customers cannot inspect or modify the underlying platform code.
Model choiceTracecat supports any LLM provider or gateway, cloud or self-hosted.Tines credits or a configured model provider.
PricingUnlimited workflows, workspaces, and cases on every plan. The open source edition is free to self-host. Teams can build smaller workflows and reuse them without paying per workflow.Commercial editions with modular packaging. Workflows, events, AI usage, API access, and version control vary by plan. Cases and tables are paid add-ons.
SupportEnterprise includes a forward deployed security engineer. Support is founder led, and customer feedback goes directly into the product roadmap.Documented onboarding, customer success, customer success engineering, and technical support. Services and support use add-on credits.

FAQ

Book a demo

Talk to a Tracecat expert

Or self-host Tracecat open source today. Read the docs

Loved by security teams building with AI

CNLRER
+3

Security Engineer @ Depop

Tracecat copilot has changed my life. I describe an agentic workflow and it builds it for me. I never had time to build and experiment around my other responsibilities. Now I do.

Senior Security Engineer @ Neo Financial

A genuine thank you to the team. I built an end-to-end IoC enrichment pipeline with Claude and Tracecat MCP and created more value for our SOC in a day than I probably would have in weeks on my own. You're making my one-man SOC assignment possible.

Principal Threat Researcher @ Saronic

Tracecat is a cheat code for corporate security teams that want to build and own their own agentic future.