Tines is a workflow automation platform: your team builds stories, agents, and apps that connect almost any API. Vigilbase is the cybersecurity operating system: it connects the security tools you already pay for, analyzes their events, and has the Vigil agent investigate and respond within the authority you set.
The short answer
Choose Vigilbase when you want a working security operation across your tools, with dashboards, analysis, investigations, and approvals ready to use rather than built workflow by workflow.
Keep Tines when you have engineers who want to design and own their automation, or when your workflows reach well beyond security into IT, HR, and the rest of the business.
Run both when Tines automates cross-team processes and Vigilbase runs security operations across the tools it connects. Vigilbase does not read from Tines, so decide which system owns each action.
How they actually differ
Tines is a canvas: the detections, data stores, and triage logic come from the tools you connect and the stories you build. Vigilbase is where your security events live and get worked.
Each native connector knows its provider’s datasets, so events arrive in a common schema with analysis already switched on. You do not have to build a detection library before the platform is useful.
Native connectors cover edge, identity, endpoint, network, cloud, and email security, including Cloudflare, Akamai, Fastly, Imperva, Microsoft 365 and Entra ID, Google Workspace, Okta, CrowdStrike Falcon, SentinelOne, Microsoft Defender XDR, Palo Alto Networks, Fortinet, Zscaler, AWS, Google Cloud, Proofpoint, and Mimecast. Wiz is coming soon.
Log collection and analysis differ by provider, and a connection does not mean every response action is available. Where the platform cannot act directly, the investigation returns the steps for your team to complete.
What the operating system adds
Every connected tool feeds one auditable record. Each team gets dashboards over that record, and the Vigil agent opens investigations on high-severity incidents without anyone designing the workflow first.
You choose the autonomy: keep actions off, propose them for approval, or allow low-risk, reversible actions to run. Agents work from evidence and remediate in scope. Humans set authority, approve changes when required, and handle exceptions. The record shows the investigation, actions taken, and verification results.
Vigilbase combines native Cloudflare integration with Cloudflare Enterprise licensing and Managed Cloudflare. Confirm the required products, permissions, commercial terms, and operating scope with us.
Tines in depth
Tines lets teams build workflows, AI agents, and internal apps with a no-code builder and natural-language assistance. It connects to any tool with an API and runs its agents within the Tines platform.
Tines is strongest where the workflow is specific to your organization and someone owns keeping it running as tools and APIs change.
Tools without a native connector can send Splunk HTTP Event Collector-compatible logs to a custom source. Those logs are stored alongside your other sources, but they are not analyzed automatically and carry no response actions.
Pricing and scope
Compare written quotes for the same connected systems, data volume, retention, operating responsibilities, and response authority. Cloudflare Enterprise licensing and Managed Cloudflare have their own agreed scope. We do not claim a universal savings percentage or bundled coverage.
Tines offers a free edition with a limited number of live workflows and custom pricing for paid editions. Compare the workflows you need, the people who will build and maintain them, and any SIEM or data store they depend on.
Default retention is set per dataset, typically 30 to 90 days. If you need a long-term archive or compliance retention, decide where that data lives before you consolidate.
How to choose
Start with the tools you already pay for and the security work you need done. On a discovery call, we map that stack onto the platform and show you the operating system live, including a representative investigation, a permitted response, and its verification record.
If your current Tines workflows remain necessary, keep them while validating Vigilbase against the agreed scope. Decide which system owns each response before any cutover so that no action runs twice.