Shuffle is an open-source automation and SOAR platform (Security Orchestration, Automation, and Response) platform designed to help IT and security teams automate workloads, incident response, and integrate security tools using visual workflows and APIs. It enables faster alert triage, consistent playbook execution, and centralized security automation across cloud and on-premise environments, improving operational efficiency and response reliability.
Shuffle is an open-source automation and Security Orchestration, Automation, and Response (SOAR) platform designed to help organizations automate and streamline IT and security operations. It centralizes alerts, integrates security tools, and executes response actions through visual workflows and APIs. By connecting SIEM, EDR, firewalls, cloud platforms, ticketing systems, and other security solutions, Shuffle enables teams to standardize incident handling and improve operational consistency across cloud, hybrid, and on-premise environments.
The platform provides a visual workflow builder that allows analysts to design automated playbooks without complex scripting. Teams can automate repetitive tasks such as alert enrichment, threat intelligence lookups, case creation, user notifications, and remediation actions. Human approval steps can be included where needed, ensuring controlled decision-making for sensitive operations. Shuffle also supports API-driven integrations, custom apps, and extensible workflows, allowing organizations to adapt automation to their specific processes and compliance requirements.
Shuffle is built to support scalable deployments with role-based access control and multi-tenant capabilities, making it suitable for security teams, managed security service providers (MSSPs), and enterprise SOC environments. Its open-source architecture provides transparency and flexibility while reducing dependency on proprietary systems. By reducing manual effort, minimizing alert fatigue, and shortening mean time to respond (MTTR), Shuffle helps organizations improve efficiency, maintain consistent response procedures, and strengthen overall security operations.
Highlights
Open-Source Automation and SOAR platform that enables agentic workflows, general automation, security orchestration and response through visual workflows and API-driven integrations.
Automate incident response playbooks across SIEM, EDR, cloud services, and ticketing systems to reduce manual effort and improve mean time to respond (MTTR).
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for the software running on your chosen EC2 instance type. All 13 dimensions run the same open-source SOAR automation platform. They differ only by the underlying compute size and family. The general-purpose m5, m5a, m6a, and burstable t3 and t3a families cover a range of CPU and memory profiles. The r5 options add more memory per core. Larger sizes (large, xlarge, 2xlarge, 4xlarge) carry higher hourly rates. Pick the instance that matches your expected workload and scaling needs. Your total cost depends on which instance you select and how many hours it runs.
Top-of-mind questions for buyers
What does the hourly rate cover, since the software itself is free and open source?
The hourly rate covers the software running on your chosen EC2 instance type. The platform is open source and free to self-host. On Marketplace, you pay per hour for the instance size and family you select. Your total depends on the instance chosen and how many hours it runs.
Am I charged when the instance is stopped or powered off?
Software charges apply per running instance-hour. A fully stopped instance does not accrue software charges. Stopped instances may still incur underlying AWS storage fees for attached volumes, but the software license meters running time only.
What is an App Run, and does it affect my hourly cost?
An App Run is an actual automation or execution inside a workflow, used to measure platform usage. On Marketplace, your cost is based on instance-hours, not App Runs. Heavier automation volume may push you toward a bigger instance size, which carries a higher hourly rate.
shuffler.io
Helpful?
Vendor refund policy
Shuffle is offered as a free AMI on AWS Marketplace and does not include any usage or subscription charges. Since the product is provided at no cost, refunds are not applicable. Users can stop using the product or terminate the deployed AWS resources at any time. Any infrastructure costs incurred are billed directly by AWS according to their pricing.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
This delivery option provides the product through an AWS CloudFormation template published in AWS Marketplace, enabling buyers to deploy the solution directly into their own AWS accounts using infrastructure as code. Instead of manually provisioning resources, customers launch the product by creating a CloudFormation stack from the Marketplace listing. The template orchestrates all required AWS resources in a single, repeatable, and auditable deployment workflow.
When a buyer subscribes and selects this delivery option, AWS Marketplace automatically injects the approved Marketplace AMI into the stack at launch time. This ensures that the correct, scanned, and version-approved image is used in every supported AWS Region without requiring customers to manually select AMI IDs. The template remains region-aware and deployable across supported regions while maintaining compliance with Marketplace AMI policies.
This delivery mechanism also integrates with standard AWS stack lifecycle management. Customers can update, monitor, or delete the deployment using native CloudFormation operations. Stack events, rollback behavior, drift detection, and parameter overrides are handled through the AWS CloudFormation service, providing full visibility and governance. This approach allows organizations to deploy the product in a controlled, policy-compliant manner aligned with enterprise DevOps practices.
By using a CloudFormation-based delivery option, the product supports automated provisioning, repeatable deployments across environments, centralized change management, and compatibility with AWS account governance controls such as IAM permissions boundaries and Service Control Policies. This method is recommended for customers who require infrastructure transparency, compliance tracking, and integration with existing AWS automation workflows.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Shuffle provides support for AI agents, workflows, apps, triggers, all features (complete platform functionality), deployment, onboarding, maintenance, and more.
Open Source and Scale License: Community Support
Support for the open-source license is community-based, relying on public channels such as documentation, community forums (discord), and shared troubleshooting resources. Direct support from the Shuffle team is not included in the open-source license.
Business and Enterprise License: Official Shuffle Support
Business and Enterprise Licenses include support from the Shuffle team spanning email with SLAs, onCall support, alert (escalation) mechanism, and professional services; and cover AI agents, workflows, apps, triggers, all features (complete platform functionality), deployment, onboarding, maintenance, and any specific customer needs.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Invinsense XDR+ combines the power of network deception with Automated Moving Target Defense (AMTD) to deliver a proactive, adaptive, and intelligence-driven security layer. By deploying environment-specific decoy assets and constantly shifting attack surfaces such as dynamic IPs, configurations, and runtime elements Invinsense XDR+ misleads, traps, and disrupts adversaries in real time. It captures attacker behaviors through deep behavioral analytics and forensic logging while reducing the attack surface and increasing the complexity of lateral movement. With seamless integration into SIEM, SOAR, and EDR platforms, Invinsense XDR+ enables early detection, rapid response, and continuous threat exposure management across hybrid environments.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.