Skip to content
aicoolies logo
Tracecat logo

Tracecat

Open-source SOAR platform with AI-powered playbooks

Tracecat is a YC S24-backed open-source SOAR (Security Orchestration, Automation and Response) platform that lets security teams build AI-powered playbooks for automated incident response. It provides visual workflow builders for creating response procedures, integrates with common security tools, and handles alert triage, enrichment, and remediation — positioned as an open-source alternative to Tines and Splunk SOAR.

About Tracecat

Tracecat is an open-source security automation platform that brings SOAR (Security Orchestration, Automation and Response) capabilities to teams that cannot afford or justify the cost of enterprise solutions like Tines, Splunk SOAR, or Palo Alto XSOAR. Backed by Y Combinator's Summer 2024 batch and carrying over 3,500 GitHub stars, Tracecat provides a visual workflow builder for creating automated response playbooks that handle the full lifecycle of security incidents — from initial alert triage through enrichment, investigation, and remediation.

The platform's AI capabilities go beyond simple automation. LLM-powered playbook steps can reason about alert context, correlate events across multiple data sources, generate investigation summaries, and suggest remediation actions based on the specific characteristics of each incident. This transforms security operations from reactive, manual processes into proactive, semi-automated workflows where analysts focus on decision-making rather than repetitive data gathering. Integrations with common security tools — SIEMs, EDR platforms, ticketing systems, communication channels — ensure Tracecat fits into existing security stacks.

Self-hosting is free under the Apache-2.0 license, with Tracecat Cloud available as a managed option for teams that prefer not to maintain infrastructure. The SOAR category represents a genuine gap in the aicoolies catalog: while security scanning and code review tools are well represented, security automation and incident response tooling is entirely absent. For DevSecOps engineers and security teams in developer-heavy organizations, Tracecat provides the automation layer that connects security alerts to actual response actions.

Pricing & Platform Specs

Pricing Summary

Freemium open-source AI-native SOAR platform. Self-hosting the core engine (via Docker Compose, Kubernetes Helm, or AWS Fargate) is 100% free under open-source licensing with no per-seat or event-ingestion fees. Tracecat Enterprise provides dedicated security engineering support, SCIM provisioning, advanced agent skill registries, and enterprise-grade human-in-the-loop governance controls.

full pricing breakdown →

Supported Platforms

Self-hosted via Docker on Linux. Cloud hosted option. Web-based visual workflow builder.

Explore categories, tags & use cases

Slack-native incident management with AI SRE agent

Incident.io is a Slack- and Microsoft Teams-native incident management platform with AI SRE investigation, on-call scheduling, status pages, and post-incident learning in one product. Vendor case studies cite Buffer reducing critical incidents by 70% and Favor reducing MTTR by 37%. It integrates with PagerDuty, Datadog, GitHub, Jira, and 100+ tools for incident response and operational workflows.

freemium

Industry-standard incident management and on-call alerting platform

PagerDuty is an enterprise incident management platform for on-call scheduling, alert routing, escalation policies, and incident response orchestration. It integrates with 750+ monitoring, ticketing, cloud, and collaboration tools, including Datadog, Slack, Jira, AWS, and Microsoft Teams. Current pricing lists a Free tier for up to 5 users, Professional from $21/user/mo annually ($25 monthly), Business from $41/user/mo annually ($49 monthly), and Enterprise custom.

freemium

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is Tracecat?

Tracecat is a YC S24-backed open-source SOAR (Security Orchestration, Automation and Response) platform that lets security teams build AI-powered playbooks for automated incident response. It provides visual workflow builders for creating response procedures, integrates with common security tools, and handles alert triage, enrichment, and remediation — positioned as an open-source alternative to Tines and Splunk SOAR.

Is Tracecat free?

Tracecat offers a free tier alongside paid plans. Freemium open-source AI-native SOAR platform. Self-hosting the core engine (via Docker Compose, Kubernetes Helm, or AWS Fargate) is 100% free under open-source licensing with no per-seat or event-ingestion fees. Tracecat Enterprise provides dedicated security engineering support, SCIM provisioning, advanced agent skill registries, and enterprise-grade human-in-the-loop governance controls.

Is Tracecat open source?

Yes — Tracecat is open source.

Is Tracecat still maintained?

Yes — Tracecat is active. Its listing was last verified on September 6, 2026.

What are the best Tracecat alternatives?

The first editor-selected Tracecat alternatives are Incident.io, PagerDuty.