Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor lock-in to a single security suite.
Visit Website ↗Overview
Tines was founded in Dublin in 2018 by two former DocuSign security engineers who had grown frustrated building one-off automation scripts for their own SOC and wanted a reusable, visual way to chain security tools together. Its core product lets analysts build automated workflows (‘Stories’) via a drag-and-drop canvas rather than writing and maintaining code, and connects to whatever tools a security team already owns rather than requiring them to standardize on one vendor’s ecosystem.
A distinguishing feature is its public library of community-shared Stories, which lets security teams reuse and adapt automation workflows built by other practitioners rather than starting from scratch. Tines reached unicorn status in February 2025 with a $125 million Series C round led by Goldman Sachs Alternatives at roughly a $1.1 billion valuation, and reported around $85 million in 2025 revenue; investors include CrowdStrike’s venture arm.
Innovation Matrix Assessment
Rapid addition of AI-agent capabilities on top of its workflow canvas and continued growth of its public Story library.
Practitioners frequently cite Tines for meaningfully reducing manual, repetitive SOC tasks without requiring dedicated engineering resources to build and maintain automations.
Unicorn valuation, $85M in 2025 revenue, and backing from strategic investors like CrowdStrike are strong, independently reported signals.
A vendor-neutral, no-code automation layer that isn't tied to any single security suite is a genuine structural alternative to SOAR modules bundled inside proprietary SIEM/XDR platforms.
Strong customer adoption and a widely used community Story library are good adoption signals, though efficacy here is about process automation rather than threat-detection accuracy, which is harder to independently benchmark.
As SOC tool sprawl continues, a vendor-agnostic automation layer is likely to remain relevant regardless of which specific SIEM or EDR products an organization uses.
Why CISOs Should Care
SOC teams can automate repetitive triage and enrichment work without needing dedicated software engineers, and the automations keep working even if the underlying security tools change vendors.
What Makes It Different
Rather than bundling automation as a locked-in module of one SIEM/XDR suite, Tines is architected to be the neutral connective layer across whatever tools a security team already runs, with a public library of reusable community workflows as a network effect.
The Matrix Verdict
73/100 — MEANINGFUL INNOVATOR
A genuinely disruptive distribution and architecture model for security automation, with strong independent momentum (unicorn status, real revenue, strategic investors) to back it. Ranks near the top of the Meaningful Innovator tier.
Editorial Note: Claims vs. Verified Findings
Unicorn valuation, Series C amount, and investor list are corroborated across independent trackers. The $85M 2025 revenue figure is drawn from an industry data aggregator rather than an audited public filing, since Tines is privately held.
Sources
Alternatives to Tines
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Google Security Operations
Google's cloud-scale SIEM/SOAR (formerly Chronicle), unifying a petabyte-scale data lake with Mandiant frontline threat intelligence and Gemini-powered investigation.
Microsoft Sentinel
Microsoft's cloud-native SIEM, deeply integrated with Azure and Microsoft 365 telemetry, now layering agentic AI (Security Copilot/Sentinel agents)…
Arctic Wolf
Managed detection and response provider delivering a 24/7 human 'Concierge Security Team' as a de facto outsourced SOC…
Huntress
Managed detection and response platform purpose-built for small and midsize businesses, delivered primarily through managed service providers rather…