Shuffle
No phone app
in Runbook Automation Software
- Recognised40% of the score89
- Phone app26% of the score0
- Documented20% of the score93
- Free plan14% of the score100
- Free plan
- Yes
- Runs on
- api, Linux, self-hosted, Web
Summary
Shuffle is an open-source automation platform for security teams to build and run workflows. Its visual designer works with a no-code app creator that can generate integrations from Swagger or OpenAPI specifications and API documentation URLs. The public app catalog lists more than 2,500 apps, including Slack, Gmail, MISP, Wazuh, Splunk and Jira. Workflows can start from webhooks, schedules, subflows or user input, with extensions for AWS Lambda, AWS S3, Kafka and Pub/Sub. Shuffle offers self-hosted open-source and licensed options, cloud SaaS and hybrid deployment. Documented runtime setups include Docker Compose, distributed Docker Swarm, a local Orborus runner for cloud hybrid use, and Kubernetes with Helm charts. Its documentation describes bcrypt password hashing and AES-256 encryption for app authentication, protected datastore keys and files. Tenant-controlled SAML/SSO and MFA are also documented. The Scale free plan includes 2,000 app runs per month, three tenants and one location, with a hard app-run limit. Custom Python apps are not yet easy to create for Shuffle Cloud; on-premises instances support local app hotloading.
Who it is for
Shuffle suits security operations teams looking to automate and share processes, automations and detections. Its self-hosted and hybrid options may suit teams with those deployment needs.
What is good
- Free plan includes 2,000 app runs monthly.
- Catalog lists more than 2,500 apps.
- Supports webhooks, schedules and event extensions.
- Self-hosted, cloud and hybrid deployment options.
- Documents encryption and tenant-controlled SSO and MFA.
What to know first
- Free plan has a hard run limit.
- Free plan is limited to three tenants and one location.
- Custom Python apps are not easy to create on cloud.
Samsung Mobile US Press review
Shuffle: the full review
Shuffle combines visual workflow building with a large integration catalog and several deployment models. Check the free plan’s run and tenant limits, and note the cloud limitation for custom Python apps.
Shuffle is an open-source automation platform for security teams building workflows across their tools. It is best suited to security operations centers that need broad integrations and deployment control. Its flexibility is compelling, but the free plan’s hard run cap and cloud custom-app constraint narrow its appeal.
Overview
Built to address automation needs in the CERT/SIRT community, Shuffle aims to help security operations centers share processes, automations, and detections. Its visual workflow designer is paired with a no-code app creator that can generate integrations from Swagger/OpenAPI specifications or API documentation URLs. That gives teams a way to extend workflows beyond the public catalog, though it does not remove the practical distinction between cloud and on-prem app development.
Key features
The public catalog lists more than 2,500 apps, including Slack, Gmail, MISP, Wazuh, Splunk, and Jira. Workflows can start from webhooks, schedules, subflows, or user input; extension triggers include AWS Lambda, AWS S3, Kafka, and Pub/Sub. This range is useful for security teams connecting incident signals to existing tools and communications, rather than relying on one trigger pattern.
Shuffle supports approval steps, scheduled runs, event triggers, incident integrations, and audit logs. It describes its API as API-first and documents Bearer-token authentication for cloud and on-prem installations, which suits teams that need to incorporate workflow operations into software integrations. Passwords are bcrypt-hashed, while app authentication, protected datastore keys, and files are AES-256 encrypted. Tenant-controlled SAML/SSO and MFA are documented, with Okta, Auth0, PingID, and AzureAD supported.
Cloud AI requests are routed to regional model endpoints with tenant contexts isolated; on-prem installations can use local models without external requests. That makes the deployment choice relevant to teams weighing how AI requests are handled. Shuffle documents Docker Compose, distributed Docker Swarm, a cloud-hybrid setup with a local Orborus runner, and Kubernetes via Helm charts. This breadth provides options for different operating environments, but teams should choose an architecture that matches their own deployment capacity.
Pricing
Shuffle’s Scale plan is free at 0.00 USD per free, billed monthly. It includes 2k App Runs, a hard run limit, three tenants, one location, and 98.2% feature coverage. The 2,000 monthly runs make it a reasonable starting point for evaluation or modest workloads, but a hard ceiling and limited tenant and location counts may constrain a growing or multi-tenant operation. No support or onboarding is included.
Business and Enterprise both start at 300k App Runs with a soft limit, unlimited tenants, locations, and branding, and 100% feature coverage; both have custom pricing. Business includes onboarding and setup, SLA and email support, and covers three use cases, making it the more bounded paid fit. Enterprise adds unlimited use cases, professional services, and on-call support with an alert mechanism alongside SLA and email support. Its extra services suit organizations with broader deployment and response needs; those requiring only three use cases may find Business better aligned.
Platforms
Shuffle supports API, Linux, self-hosted, and web environments. The self-hosted open-source and licensed options sit alongside Shuffle Cloud SaaS, with hybrid deployment also documented. On-prem instances support local app hotloading, while custom Python apps cannot yet be created easily for Shuffle Cloud. Teams that depend on custom Python integrations should favor an on-prem deployment; cloud users get SaaS but give up that straightforward app-development path.
Who it's for
Shuffle is a strong candidate for security operations centers and CERT/SIRT teams that want to share and automate security processes across a broad toolset. It also fits organizations that value a choice of cloud, on-prem, or hybrid operation. It is less suited to teams needing more than 2,000 runs on the free tier, or cloud users whose workflows depend on easily creating custom Python apps.
Pros and cons
- Pros: More than 2,500 catalog apps and a no-code app creator provide multiple ways to connect tools and APIs.
- Pros: Cloud, self-hosted, and hybrid deployment options, plus documented runtime architectures, give teams meaningful operational choice.
- Pros: Approval steps, audit logs, SSO, MFA, and documented encryption address workflow governance and security needs.
- Cons: The free plan stops at 2,000 App Runs under a hard limit and includes only three tenants and one location.
- Cons: Custom Python apps are not easy to create for Shuffle Cloud, so teams needing that flexibility should consider on-prem.
- Cons: Paid plans use custom pricing, making their cost harder to assess before engaging with the maker.
Alternatives
For other runbook automation options, browse Runbook Automation Software. Choose Rundeck if its free Community plan for small teams or its broader platform availability better fits your requirements. StackStorm is a straightforward alternative for teams seeking a free, open-source project with no paid products. Tracecat may suit teams prioritizing a self-hosted open-source option with unlimited workflows, cases, and agents and self-managed monthly executions. Tines is worth considering for a web-based option whose free edition allows three live workflows. Tanium Deploy, Palo Alto Networks Cortex Cloud API Security, Torq Case Management, and BlinkOps are alternatives to compare for teams seeking paid products.
Verdict
Choose Shuffle if your security team needs a large integration catalog, workflow-building flexibility, and the option to run cloud, on-prem, or hybrid. Its strongest advantage is that combination of breadth and deployment choice. Look elsewhere if you need a free tier beyond 2,000 runs, or if custom Python apps are central to a cloud deployment.
Shuffle plans and pricing
All plansCompared on runbook automation software
- Free plan
- Yesshuffler.io
- Approval steps
- Yesshuffler.io
- Scheduled runs
- Yesshuffler.io
- Event triggers
- Yesshuffler.io
- Incident integrations
- Yesshuffler.io
- Audit logs
- Yesshuffler.io
- Self-hosted option
- Yesshuffler.io
- Runs included
- $2,000/moshuffler.io
Facts
- Purpose
- Shuffle is an open-source automation platform designed for the security industry, for building and executing automation workflows.shuffler.io · 29 Sept 2026
- Workflow and app builder
- Its visual workflow designer works with a no-code app creator that can generate integrations from Swagger/OpenAPI specifications or API documentation URLs.shuffler.io · 29 Sept 2026
- Integrations
- Shuffle's public app catalog lists more than 2,500 apps, including integrations such as Slack, Gmail, MISP, Wazuh, Splunk, and Jira.shuffler.io · 29 Sept 2026
- Triggers
- Core workflow triggers include webhooks, schedules, subflows, and user input; listed extension triggers include AWS Lambda, AWS S3, Kafka, and Pub/Sub.shuffler.io · 29 Sept 2026
- Deployment options
- Shuffle is offered as self-hosted open source, self-hosted licensed, and Shuffle Cloud SaaS, with hybrid deployment also documented.shuffler.io · 29 Sept 2026
- Runtime deployment
- Documented runtime architectures include Docker Compose, distributed Docker Swarm, cloud hybrid with a local Orborus runner, and Kubernetes using Helm charts.shuffler.io · 29 Sept 2026
- Security
- The architecture documentation says passwords are bcrypt-hashed and app authentication, protected datastore keys, and files are AES-256 encrypted.shuffler.io · 29 Sept 2026
- Authentication
- Shuffle documents tenant-controlled SAML/SSO and MFA, and names Okta, Auth0, PingID, and AzureAD as supported platforms.shuffler.io · 29 Sept 2026
- AI data handling
- Shuffle says cloud AI requests are routed to regional model endpoints and tenant contexts are isolated; on-prem installations can use local models without external requests.shuffler.io · 29 Sept 2026
- API
- Shuffle describes itself as API-first and documents Bearer-token authentication for its API on both cloud and on-prem installations.shuffler.io · 29 Sept 2026
- Integration implementation limit
- The apps documentation says custom Python apps cannot yet be created easily for Shuffle Cloud, while on-prem instances support local app hotloading.shuffler.io · 29 Sept 2026
- Audience
- Shuffle says it was created to address automation problems in the CERT/SIRT community and aims to help security operations centers share processes, automations, and detections.shuffler.io · 29 Sept 2026
- Support
- The pricing page lists Shuffle Support with SLA and email support for Business, with on-call support and an alert mechanism additionally listed for Enterprise.shuffler.io · 29 Sept 2026
Company
- Founded
- 2019shuffler.io · 28 Sept 2026
Best Shuffle alternatives
See all 12Where it ranks on Samsung Mobile US Press
Is Shuffle yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- shuffler.io/docs/getting_started· checked 29 Sept 2026
- shuffler.io/docs/features· checked 29 Sept 2026
- shuffler.io/apps· checked 29 Sept 2026
- shuffler.io/docs/architecture· checked 29 Sept 2026
- shuffler.io/docs/AI· checked 29 Sept 2026
- shuffler.io/docs/API· checked 29 Sept 2026
- shuffler.io/docs/apps· checked 29 Sept 2026
- shuffler.io/docs/about· checked 29 Sept 2026
- shuffler.io/pricing· checked 29 Sept 2026
- shuffler.io· checked 28 Sept 2026



