# TracecatHQ/tracecat

Open-source security automation platform for teams and AI agents

Repository: https://github.com/TracecatHQ/tracecat
Canonical: https://ross.abutalabs.com/products/tracecat
Homepage: https://tracecat.com
Language: Python
License: AGPL-3.0
License Family: copyleft
Topics: automation, openapi, fastapi, monitoring, nextjs, pydantic, workflow-engine, event-driven, temporalio, orchestration, llm, low-code, agents, security
Last push: 2026-08-26T22:53:12+00:00

## Health v2 (maintenance only)
Score: 87/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 85, longevity 65
- inputs: {"age_days": 918, "days_push": 7, "days_rel": 23, "gap_med": 1, "n_releases_24m": 266}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3780, forks 407 (observed 2026-08-28T04:08:18.417045+00:00)

## What it is
Tracecat is an open-source, AI-native security automation (SOAR) platform that combines low-code workflows, tool-calling agents, case management, and MCP server integrations. It runs on Temporal for durable execution, sandboxes untrusted code with nsjail, and can be self-hosted via Docker, AWS Fargate, or Kubernetes.

## Use cases
- automate security alert triage and incident response
- build AI agents that call security tools like CrowdStrike and Wiz
- replace legacy SOAR with an open-source alternative
- turn prompts into automations from Claude Code or Codex via MCP
- manage security cases with human-in-the-loop approvals
- orchestrate phishing triage and endpoint isolation workflows

## When to choose
- your security team wants agentic automation with durable, sandboxed workflows
- you need self-hosted SOAR with case management and 100+ integrations
- you want coding agents to build and run automations via MCP

## When to avoid
- you need a lightweight cron-style scheduler without security focus
- you require a permissive license - Tracecat is AGPL-3.0
- you want a fully managed turnkey product without self-hosting or enterprise plans

## Facets
- artifact type: application
- maturity: active
- function: workflow-automation, agent-framework, mcp, chatbot, webhook, scheduling, security, self-hosted, api-framework
- domain: security, large-language-models, developer-tools, self-hosted
- platform: self-hosted, python, cloud
- tags: soar, security-automation, case-management, temporal, low-code, incident-response, agentic-automation, automation, ai-agents, docker, kubernetes, web-server

## Member repositories
- TracecatHQ/tracecat (main) score 87

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:18.417045+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:27:45.934921+00:00, confidence not recorded.
  - readme: https://github.com/TracecatHQ/tracecat (fetched 2026-08-28T04:08:18.417045+00:00, sha df9bb5c686fa)
  - homepage: https://tracecat.com (fetched 2026-08-29T09:22:35.872284+00:00, sha a94714815cc1)
  - site_page: https://docs.tracecat.com/overview/getting-started (fetched 2026-08-29T09:22:35.880851+00:00, sha 3e78e172ac91)
  - site_page: https://docs.tracecat.com/agents/ai-agent (fetched 2026-08-29T09:22:35.882835+00:00, sha 3429e80c286e)
  - site_page: https://docs.tracecat.com/overview/introduction (fetched 2026-08-29T09:22:35.884703+00:00, sha df57916b4637)
  - site_page: https://docs.tracecat.com/automations/integrations/mcp-integrations (fetched 2026-08-29T09:22:35.886315+00:00, sha 96cb63912f07)
  - site_page: https://www.tracecat.com/mcp (fetched 2026-08-29T09:22:35.878763+00:00, sha 841a3f20e81b)
  - site_page: https://www.tracecat.com/pricing (fetched 2026-08-29T09:22:35.875004+00:00, sha d4285f55d682)
  - site_page: https://www.tracecat.com/changelog (fetched 2026-08-29T09:22:35.876876+00:00, sha 0d16b96bd2f4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
