Echo, a hardened-container startup backed by $50M, acquires technology assets from Minimus following the latter's wind-down, positioning Echo as the sole distro-agnostic secure software platform.
- Echo acquires Minimus's minimal OS technology after the $51M-backed startup enters a 60-day shutdown on Aug. 24, 2026.
- Financial terms were not disclosed; the deal is a technology asset acquisition, not a full company purchase.
- Echo now claims the first distro-agnostic position in hardened software, leaving Chainguard as its principal remaining rival.
Lead
Echo, an Israeli-founded, AI-native hardened software startup, announced on August 27 the acquisition of key technology assets from Minimus, a container security company that raised $51 million before deciding earlier this month to wind down operations. The acquisition expands Echo's library of vulnerability-free software artifacts across Linux distributions it had not previously supported, a gap that limited its enterprise reach. Terms were not disclosed.
What Did Echo Actually Buy?
The acquisition is a technology transfer, not a company purchase. Echo gains Minimus's minimal OS technology - its method for stripping container images down to runtime-only dependencies, eliminating shell access, package managers, and compilers that conventional images carry - along with technical research and proprietary security datasets used to identify and verify CVE-free components across Linux distributions.
The assets fold into Echo's existing software factory, which uses autonomous AI agents to detect newly disclosed vulnerabilities, develop patches, validate fixes, and republish hardened artifacts. Minimus's distro coverage complements that pipeline. Echo can now deliver hardened containers, virtual machines, OS packages, libraries, serverless functions, and Helm charts across distributions it could not previously serve, meeting the stated goal of becoming a distro-agnostic platform.
Why Did Minimus Fail Despite $51 Million?
Minimus launched in 2022 under the name Gutsy before rebranding. Its founders - Ben Bernstein, Dima Stopel, and John Morello - had previously built Twistlock, the container security pioneer acquired by Palo Alto Networks in 2019 for roughly $378 million. That pedigree attracted early conviction: YL Ventures and Mayfield backed the company with a $51 million seed round in May 2025 before it had shipped a commercial product at scale.
The underlying technology worked. Minimus claimed to eliminate more than 95% of vulnerabilities found in standard container images, and its free community catalog drew developer interest. But eliminating vulnerabilities is a building material, not a control plane. Enterprises need more than trusted base images - they need governance over how those images are selected, verified, promoted, and replaced as new CVEs emerge. Minimus supplied the bricks; it never became the architect.
When the company entered a 60-day maintenance period on August 24, it had roughly $10 million of its raised capital remaining, which it returned to investors. The registry is set to go dark on October 22, 2026.
Who Is Echo?
Echo was founded in early 2025 by Eilon Elhadad and Eylam Milner, both veterans of Israeli military intelligence Unit 8200. The pair previously co-founded Argon, a software supply chain security company acquired by Aqua Security for $100 million within a year of its founding.
Echo raised a $15 million seed round, then a $35 million Series A led by N47, with participation from Notable Capital, Hyperwise Ventures, and SentinelOne's S Ventures - all within 10 months of founding. Its customers already include Varonis, EDB, UiPath, Vectra AI, and Port.
The distinction Echo draws against Minimus is durability. Static hardened images age poorly as new CVEs emerge against pinned dependencies; Echo's AI agents continuously monitor, patch, and republish artifacts, theoretically keeping the hardened state current without manual intervention. Adding Minimus's distribution breadth strengthens that value proposition across a wider set of enterprise Linux environments.
What Does the Competitive Field Look Like Now?
The market for secure-by-default software artifacts has narrowed sharply. With Minimus exiting, Chainguard is Echo's primary named rival. Chainguard has taken a similar image-hardening approach and has raised substantially more capital. The consolidation concentrates enterprise evaluation onto two remaining platforms with meaningfully different operational models: one centered on curated static catalogs updated by engineering teams, the other on autonomous agent-driven continuous patching.
For buyers, the question shifts from "which vendor has the cleanest images today" to "which vendor's process keeps images clean six months from now as the CVE landscape shifts."
Outlook
Echo enters the acquisition having already deployed across a growing enterprise customer base and carrying $50 million in backing. The Minimus deal adds technical depth without adding operational complexity from an ongoing company - the assets transfer cleanly because Minimus is winding down rather than being integrated as a going concern. The harder test is execution: building a genuinely distro-agnostic platform from two separate codebases while maintaining the autonomous patching cycle that differentiates Echo's pitch. Whether the combined technical base holds under that load will determine whether this acquisition reads, in retrospect, as a smart fill-in or an expensive distraction.



