Skip to content
Tray.ai

Moving from n8n / Risk and patching

n8n keeps shipping patches.
And they keep landing on your team.

Self-hosted, every advisory is your team's upgrade to schedule, test and roll out, inside a short window. Tray takes you off the patch treadmill.

Great — a couple more details

This helps us connect you with the right person. Optional, and you can skip it.

Sleep better at night with Tray

The speed of the fix is not in question here. Where the work of keeping up with it sits, is.

Nothing for you to patch

Patching is automatic. Every advisory and every upgrade lands on a runtime we run and get audited on.

CVE-2026-1183 patched · 4h
runtime v4.18.2 rolled out
CVE-2026-1179 patched · 11h
your patch tickets 0

No version to be behind on

The software you are running is the current one, so running behind is not a liability sitting with you.

you
releases behind 0
runtime v4.18.2 current

Independently audited every year

SOC 1 Type 2 and SOC 2 Type 2, penetration tested annually by independent assessors, with a bug bounty programme alongside.

SOC 1 Type 2
SOC 2 Type 2
pen test annual
bug bounty always on
Q1Q2Q3Q4
independent assessors · every year

Tray produces the evidence

Scoped access, approvals and a record of every run, ready when a reviewer asks. Your team does not assemble it.

run_9f2a11 approved
run_9f2a10 approved
run_9f2a0f held
export · SOC 2 ready

No instance of yours to expose

Nothing of yours sits on the internet to be found, fingerprinted or reached. The runtime is Tray’s to operate, monitor and defend.

0 hosts of yours reachable
tcp/5678 no host
/rest/login no host
webhook host no host

Policy on every agent call

Scope and policy are set on every agent and MCP call, then logged. Not a node somebody remembered to add.

mcp:crm.read allow
mcp:billing.write deny
agent:ticket.create allow
logged · scope set at platform

Why enterprises choose Tray

CiscoAirbnbFedExNotionNetAppApollo.ioYextLife360

What self-hosting puts on your team

n8n discloses properly and patches fast. What follows is not about them, it is about where the work of keeping up lands.

  • Maintenance. n8n’s own docs list maintenance of a self-hosted instance as your responsibility, and their security page scopes their scanning and penetration testing to their own environment.
  • Liability. Their Master Enterprise Terms make the customer solely responsible for the internal cost of implementing updates, and disclaim responsibility where an outdated version is in use.
  • The clock, often. 129 CVE records in n8n’s own code, published between 15 December 2025 and 18 August 2026 (NVD, pulled 18 August 2026). Counted by publication date rather than by affected version. One sits in CISA’s Known Exploited Vulnerabilities catalogue, with a fourteen-day federal deadline.
  • A licence, mid-incident. When a national CERT recommends limiting workflow edit rights to trusted users, that needs a permissions construct the free edition does not have.

Industry recognized

Gartner 3× Visionary Gartner Magic Quadrant for iPaaS, 2024, 2025 and 2026
Nucleus Research 7× Leader Nucleus Research iPaaS Value Matrix, seven consecutive years
Gartner Pioneer Gartner Emerging Market Quadrant for No-Code Agent Builders, 2026
Gartner 14 Hype Cycles Gartner inclusions in 2026, including Agentic AI and Agentic Automation

No patch queue. No exposed instance. No 2am emergency.

Not the existence of vulnerabilities, which no platform can promise away. What changes is who carries the standing work, and stands behind it.

The platform is patched and monitored for you

When an advisory lands, the response is Tray.ai’s operational work. It does not become an unplanned week for whoever on your team understands production best.

Encryption in transit and at rest

A property of the platform rather than something each deployment has to be configured correctly to get, and re-verified every time the infrastructure changes.

Audit logs stream to your SIEM

Your security team keeps the visibility they need without running the platform. Detection stays where it already lives, alongside everything else you monitor.

Access control does not need buying

Access control is operated by Tray, so limiting who can edit a workflow is a setting your team changes rather than infrastructure it maintains.

Audited and certified

The controls are already on

SOC 1

audited annually

SOC 2 Type 2

with penetration testing

HIPAA

PHI handling

GDPR

EU data residency

CCPA

US data residency

700+

connectors managed

across integration, automation, and agents

1T+

processes run per year

on the platform

100%

workflow execution uptime

over the trailing 90 days

US, EU, and APAC data residency · Annual penetration testing · Uptime measured on status.tray.ai and publicly checkable there. As of August 2026.

See the trust center

Contents

01 02
02 04
03 06
04 08
05 10

tray.ai · 12 pages

Five signs you've outgrown n8n — guide cover

The guide · 12 pages

Five signs you've outgrown n8n

Five signs, what each one costs, and where your setup stands.

Get the guide

Why enterprises love Tray

“Since implementing Tray, we've quadrupled our integration delivery speed. More integrations mean happier customers that can respond to cybersecurity vulnerabilities even faster.”

— Martijn Russchen, Senior Project Manager, HackerOne
Read the study →

Frequently asked questions

Who patches a self-hosted n8n instance? +

You do. n8n’s own documentation assigns maintenance of a self-hosted instance to you in as many words, and their Master Enterprise Terms put the internal cost of implementing updates on the customer. Upstream publishes the fix quickly; getting it onto your instance, inside your own window, with evidence, is your team’s work.

Is n8n insecure? +

No. They disclose properly, they patch fast, and 2.0 tightened the defaults. The question is who carries the standing work of keeping up with every advisory, and on a self-hosted install that is your team rather than a vendor under contract.

Has an n8n vulnerability actually been exploited? +

One entry is in CISA’s Known Exploited Vulnerabilities catalogue, added 11 March 2026, which carries a fourteen-day remediation deadline for federal agencies. For scale, that catalogue holds roughly 1,670 entries, so a listing is not evidence that n8n is unusually exposed. What it does show is the shape of the work: a deadline someone has to meet.

Does n8n 2.0 solve the patching problem? +

It reduces how far any single issue can reach, which is genuinely valuable and applied to every operator at once. It does not change who applies the next patch. Hardened defaults and patch ownership are different things, and only one of them moves when you self-host.

What does a managed platform change? +

The clock stops being yours. Tray.ai patches and monitors the platform, encrypts data in transit and at rest, and streams audit logs into your own SIEM so your security team keeps visibility without operating the platform.

Still confident you can stay ahead?

Let's discuss your life without patching.

Great — a couple more details

This helps us connect you with the right person. Optional, and you can skip it.

GARTNER is a registered trademark and service mark, HYPE CYCLE and MAGIC QUADRANT are registered trademarks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.