Skip to main content
T

Tracecat

Tracecat is an open‑source, AI‑native security automation platform that lets SOC teams build custom agents and prompt‑to‑automation workflows across 200+ integrations such as SIEM, EDR, MDM, and IdP systems. It provides case management, human‑in‑the‑loop approvals, and enterprise controls like RBAC and audit logs, while allowing self‑hosted deployment for full data control.

San Francisco, United StatesFounded 202471K+ followers
Updated 2 months ago

Funding

$500K raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

Security operations teams often rely on fragmented tools and manual processes to triage alerts, coordinate investigations, and execute remediation, leading to slow response times and inconsistent handling of incidents.

Solution

Tracecat provides an open‑source, AI‑native security automation platform that lets teams build custom agents, workflows, and case management processes. Users can define prompt‑to‑automation (MCP) pipelines that translate natural‑language instructions into orchestrated actions across over 200 integrations, including SIEM, EDR, MDM, and IdP systems. The platform supports human‑in‑the‑loop approvals, enabling analysts to review and authorize tool calls from the UI, Slack, or Teams. Advanced features such as versioned prompts, agent guardrails, and a skills registry allow organizations to scale secure agent deployments while maintaining auditability and role‑based access control. Tracecat can be self‑hosted via Docker, AWS Fargate, or Kubernetes, giving full control over data and execution.

Target Audience

Primary users are security operations teams, SOC analysts, and incident response engineers who need programmable automation and AI assistance to streamline alert triage and remediation.

Features

  • Open‑source, self‑hosted deployment with unlimited workflows, cases, and integrations
  • AI‑driven MCP (prompt‑to‑automation) that converts natural language into executable security workflows
  • Built‑in agent framework supporting custom LLMs and sandboxed MCP servers for secure tool execution
  • Human‑in‑the‑loop approvals and tool call monitoring to enforce policy and prevent misuse
  • Rich case management with comments, attachments, custom fields, and AI copilot assistance
  • Extensive integration library (200+ connectors) and support for custom actions via Git sync
  • Advanced enterprise controls: RBAC, SCIM, agent guardrails, versioned prompts, and monitoring dashboards
This profile is AI-generated and may contain inaccuracies.