Echo is acquiring Minimus
.png)
Key takeaways
- Echo is becoming the first distro-agnostic secure-by-default OS.
- Echo has acquired key Minimus assets as the company winds down, ensuring valuable technology the team built can continue to evolve.
- Minimus technology, integrations, research, and data give Echo new opportunities to broaden distro support, expand security integrations, and strengthen the proprietary agents behind its software factory.
- What began as a market with several competing vendors is increasingly consolidating around two players: Echo and Chainguard – marking a new phase for the category.
Minimus may not have built a sustainable business around its technology, but the team built meaningful technology around an idea we strongly believe in: organizations shouldn’t have to inherit unnecessary security risk simply because they depend on open source software.
We saw an opportunity to give that work a new home, strengthen what we’re building at Echo, and, importantly, give Minimus customers a clear and seamless path forward.
A category entering its next phase
There’s a common trajectory in fast-growing technology markets: A new category emerges, a broad group of companies enters with different approaches to solving the same problem, the market tests those approaches, and eventually, the category begins to consolidate around two key players.
We’ve seen this story play out across technology: mobile operating systems consolidated around iOS and Android, the U.S. ride-hailing market around Uber and Lyft, and the frontier LLM market has increasingly centered around OpenAI and Anthropic.
We believe secure-by-default software is entering a similar phase. What started as a crowded market of companies is now consolidating around two remaining players: Echo and Chainguard.
That consolidation is happening as the category itself matures. Enterprises increasingly recognize that finding vulnerabilities after software enters their environment can only take them so far. The alternative is to change the software supply itself – replacing vulnerable open source artifacts with continuously vetted, hardened, and maintained versions before they ever reach production.
The question is increasingly shifting from whether organizations should adopt this model to how broadly they can apply it. That’s where this acquisition becomes particularly strategic for Echo.
Building a broader hardened software ecosystem
From the beginning, our goal at Echo has been to build a trusted source for the open source software modern organizations depend on – containers, libraries, OS packages, VMs, Helm charts, and beyond. Minimus built technology that can help us accelerate that vision in several important areas.
The first multi-distro OS
Minimus’s OS technology allows us to expand our foundation further across Linux distributions, making us the first truly distro-agnostic, secure-by-default software platform.
Extended integrations
Minimus invested heavily in integrations with established security vendors that complement Echo’s already vast and comprehensive ecosystem. This move means Echo artifacts will be recognizable across an even broader range of vulnerability scanners and security tools.
More robust software factory
Behind every Echo artifact is a software factory powered by proprietary AI agents that help our researchers investigate vulnerabilities, develop and validate patches, and continuously maintain the software we provide. Access to Minimus’s technology, technical research, and relevant data provides us with additional inputs we can explore to enhance those systems over time.
Giving Minimus customers a path forward
There’s another part of this acquisition that matters a lot to us. Minimus customers made the decision to move away from vulnerable upstream software and adopt a secure-by-default model, so the business winding down shouldn’t mean they have to abandon that security.
We are working closely with the Minimus founders and engineering team to create a seamless transition, that doesn't require Minimus customers to take any further action.
As the Minimus founders put it:
“When we made the decision to wind down Minimus, our priority was finding the right home for the technology we built and, most importantly, the right path forward for our customers. Echo shares our belief that software should be secure by default, and has built the platform and engineering capabilities to take that vision even further. We’re confident that our technology and customers are in the right hands.” Ben Bernstein, Co-founder and CEO, Minimus
Carrying the work forward
Minimus and Echo approached this market as competitors, but we started from a shared conviction: the security of open source software needs to improve at the source. The Minimus team contributed meaningful technology toward making that possible. We’re glad that work won’t disappear with the company.
We’re bringing the best of what Minimus built into Echo, helping its customers continue what they started, and using the acquisition to accelerate our broader mission: making secure-by-default software the standard for how organizations consume open source.
FAQ
What did Echo acquire from Minimus?
Echo acquired key Minimus assets, including technology that can help expand Echo’s Linux distro coverage and security integrations, as well as technical research and data that can strengthen the proprietary agents behind Echo’s software factory.
Why did Echo acquire Minimus technology?
Minimus built valuable technology around the same fundamental idea as Echo: software should be secure by default. Its technology can help Echo expand across more Linux distributions and security integrations while providing additional technical data and research to strengthen Echo’s software factory.
What does this mean for Echo customers?
There are no immediate changes for existing Echo customers. Over time, the acquisition allows us to broaden distro support, expand integrations, and strengthen the technology behind Echo’s secure-by-default software platform.
What does this mean for Minimus customers?
No action is needed to continue using Minimus services. The Echo team will be meeting with all Minimus customers over the next week. If you’d like to schedule a call now, you can book some time here to speak directly with Echo’s leadership team.



.avif)
.avif)