Tines vs Dropzone AI: Workflows vs an Autonomous Analyst
An alert has to be investigated, then acted on. These two products usually enter at different points.
A security alert has to be detected, investigated, judged, contained, documented, and routed somewhere.
Tines and Dropzone AI can both show up in that chain. They usually enter at different points. Dropzone focuses on the investigation: it queries the SIEM, EDR, identity, and email tools you already run, via API, and returns a verdict with an evidence trail. Tines focuses on the workflow around it: Stories you author with webhooks, HTTP actions, pages, and AI steps, so the next response actually happens.
That is why they get bought as if they were the same AI SOC platform. They are not. One is a storyboard. The other is an investigation agent.
| Job | Human-designed Stories for security and IT operations: you author the path | Autonomous SOC analyst that investigates alerts already in your stack |
|---|---|---|
| What actually closes/triages an alert | A Story you built, triggered by webhook, email, page, or another system | An AI SOC Analyst run that returns a verdict plus the queries it made |
| Playbooks vs agents | You design the storyboard. AI Agent actions are steps you place | No playbook-first model. The agent follows evidence across connected APIs |
| Deploy | Cloud tenant. Business and Enterprise can self-host, per their knowledge base | SaaS agent. Queries SIEM/EDR/identity/email via API. No data lift on the public docs |
| License/price | Community Edition is free with documented limits. Business and Enterprise are sales-quoted | Public unit is investigation capacity (4,000 full investigations per year per AI analyst). Dollar price is request-quote |
| Who operates it | Whoever builds and owns the Stories, often SOC or IT automation | SOC sets scope and authorization. Analysts review finished investigations |
Recent launches have not collapsed that split. On 28 July 2026 Tines launched 3B, a separate AI-native environment. The product this comparison is about continues in parallel as Tines Stories, still a visual designer for security and IT operations. On 8 April 2026 Dropzone announced an Agentic SOC: the AI SOC Analyst plus Threat Hunter and a Threat Intel Analyst planned later. That is still an agent team investigating your stack. It is not a storyboard you maintain. For Dropzone among other AI SOC products see AI SOC tools.
neochris, launching an open-source alert automation project on Hacker News in March 2024, put the buyer problem in numbers: an average analyst facing about 100 alerts a day, roughly 30 minutes each, with work that gets dropped and breaches traced to week-old alerts. That queue is why these two products get shortlisted together. It is not proof they do the same job.
We reviewed first-party documentation, public pricing, release notes, and license pages. We did not test the products in paid production environments, so this is not a hands-on benchmark.
Tines

Dropzone AI

Editions and pricing
Tines publishes a forever-free Community Edition and two paid editions. Dropzone publishes investigation capacity and asks you to request a price. Community Edition details belong in this section because they do not change the job each product is built for.
| Public free line | Community Edition: 3 flows, 1 licensed team, 1 builder user, 25,000 monthly events, 50 monthly AI credits (knowledge base, feature sets dated 1 May 2026) | No forever-free SKU on the pricing page. Public docs describe a structured proof-of-concept |
|---|---|---|
| Paid line | Business and Enterprise. List dollars are not on a public price table. Self-hosting is offered on both paid editions | Request pricing. Enterprise is a dedicated single-tenant environment. MSSP is multi-tenant, contact them |
| What you are buying | Flows, teams, users, events, and add-ons such as Cases and extra AI credits on paid plans | Investigation capacity: up to 4,000 full investigations per year per AI analyst, unlimited users, pre-built integrations |
| Where it can run | Community Edition is the cloud tenant they give you. Paid editions can self-host | Their SaaS. The agent reaches your tools over API. Public docs describe no data lift |
That 2022 comment still maps to the packaging they publish: Community Edition is the limited cloud line, and self-host sits on paid editions. Dropzone’s public number is capacity. There is no published dollar SKU, so a spreadsheet that needs a monthly seat price will stall until sales answers.
How investigations start
| Trigger | Webhook, incoming email, a Tines page, or another Story sending work in | An alert from SIEM, EDR, or another connected source handed to the AI SOC Analyst |
|---|---|---|
| First move | The actions you placed: HTTP request, transform, AI Agent, page, notification | The agent queries the connected stack the way an analyst would, via API |
| If the alert is new | Someone authors or forks a Story. A path you did not build does not run | Public docs describe investigation without a new playbook for that alert type |
| Human in the loop | Pages and confirmations you designed. You decide where the Story pauses | You set which alert types run, what systems the agent may query, and when containment is allowed |
That is the Tines start: you have an API, you put it on the board. Dropzone’s start is the opposite direction. The alert already exists in Sentinel, Splunk, CrowdStrike, or kin. The agent pulls context from those same APIs. Between these two, Tines is the product that waits on a Story you own. Dropzone is the product that starts when the detection tool fires.
Investigation output and response
| Primary artifact | Story run events, optional Pages, and Cases on paid editions (Cases is an add-on; Community Edition does not include it) | A finished investigation: verdict, evidence, and recommended next step |
|---|---|---|
| Evidence trail | Whatever the Story logged: HTTP responses, transforms, operator clicks on a page | Every tool queried and every reasoning step, which public docs describe as visible to analysts |
| Taking action | The Story can call the same APIs to contain, ticket, or page, if you built that | They position response with your SOAR and your analysts. Public docs describe a complement rather than a rip-and-replace of playbooks |
| Talking to the other tool | HTTP out to whatever case system you already run | Tines is on their integration list, next to other SOAR products. The case can land in a Story if you wire it |
If the argument is “who queries Okta and the EDR for this impossible-travel alert,” Dropzone is selling that as the product. If the argument is “when it is confirmed, disable the account and open the ticket,” between these two that is a Story you can write in Tines, including the curl-shaped HTTP Tines was built around.
When to use both
Keep both when Dropzone works the alert queue and Tines owns the actions you already trust: paging, account lock, ticket fields, customer-specific HTTP. Dropzone’s own stack list includes Tines, which is the honest architecture: agent investigates, workflow executes the decision you already encoded.
Skip Dropzone if the problem is not investigation depth but a pile of repeatable processes across IT, HR, and security that need a storyboard and a Community Edition to prove the model. Skip Tines for this pair if nobody on the team will author or maintain Stories, and the only job is “investigate the SIEM alerts we already have.”
Decide the job first. If you need workflows you own, that is Tines Stories. If you need an agent on the alerts you already generate, that is Dropzone. Only then decide whether the handoff between them is worth staffing.
FAQs
Can Dropzone replace Tines Stories?
Not if you need a storyboard for processes you design, including IT ops beyond alert investigation. Dropzone investigates. Response playbooks still live in a SOAR or in Tines if you keep it.
Can Tines replace an autonomous SOC analyst?
Only for the alert types you have actually built Stories for. A novel alert with no Story does not get a Dropzone-style investigation unless a person writes the path.
Is Tines Community Edition enough to run a SOC?
It is the documented learning and proof-of-concept line: 3 flows, one team, one builder, 25,000 monthly events. Production SOC automation is the paid editions, including self-host.
Is this a scored bake-off?
No. Order is editorial.