How UiPath avoided 100,000+ vulnerability instances with Echo

100,000+

open-source vulnerability instances dodged since adopting Echo

3+

years of supported product versions secured

10,000+

of engineering hours saved across 28+ products

10K

10 k hours of dev time saved each year

100+

integrations secured with 0 added maintenance

$3.2M

in annual savings

“Echo has been one of the few security changes that we’ve pushed into engineering where they’ve come back to ask for more.”
Scott Roberts,
Chief Information Security Officer, UiPath

Meet UiPath

UiPath is a global leader in business orchestration and automation, helping tens of thousands of customers automate complex business processes across highly regulated industries, including healthcare, insurance, and financial services. For these organizations, trust is fundamental, and that means maintaining a high bar for security, governance, and compliance across the software supply chain.

That responsibility sits at significant scale. UiPath ships more than 500 releases each year, with over 28 products and multiple versions remaining in support for three years or more. Its Trust Ops organization spans security, GRC, product security, security engineering, and other functions involved in delivering and protecting UiPath products. Security isn't something added at the end of that process – it’s designed into the software lifecycle from development through build, runtime, and response.

The open-source vulnerability challenge

Maintaining UiPath’s rigorous security standard across the open source software supply chain had become increasingly difficult. The company was triaging roughly 1,000 unique incoming open-source vulnerabilities every week, which each had to be routed to the appropriate engineering teams, fixed, integrated, and verified. And because UiPath supports products and versions over long lifecycles, simply upgrading to the latest available open source package wasn’t always an option. A new version could introduce application compatibility issues and trigger another round of quality assurance testing.

The result was a vulnerability management process that was extremely time-intensive. Across all of its products and supported versions, UiPath estimates that managing vulnerabilities while maintaining its standards for security and product quality consumed tens of thousands of engineering hours.

Even with automation helping accelerate vulnerability triage, developers still had to determine which image contained the appropriate fix, integrate it, and put it through verification. The challenge wasn't simply finding a vulnerability – it was fixing it without creating a new problem somewhere else, which was becoming increasingly difficult to sustain.

Why UiPath chose Echo

UiPath evaluated every vendor available to them, comparing solutions against a demanding set of requirements that included security capabilities, ease of developer adoption, and the length of time packages would remain supported.

“Echo beat all of the competition on every one of the measures that we set for our internal bake-off.”

Compatibility:

UiPath has a large global customer base, and its products remain supported for multiple years, so some alternative approaches would have required the company to migrate to a vendor-specific Linux distribution – a change that simply wasn't feasible across UiPath's existing product footprint. Echo instead allowed UiPath to drop secure images directly into the operating system versions it was already using.

Compliance:

UiPath maintains FedRAMP certification for its public sector cloud product, making FIPS compliance and the ability to meet rigorous federal security requirements essential. Echo could provide hardened, FIPS-compliant images while supporting more than just the newest image versions.

That was particularly important because upgrading to the newest FIPS-compliant open source package could create application compatibility issues and force UiPath to repeat significant amounts of testing. Echo could instead support earlier image versions while bringing vulnerability fixes back to them, reducing the risk of breaking existing applications.

Real results and impact

“In some cases, a single line in a Dockerfile was all that was required” to bring an Echo image into UiPath's environment. Since beginning its work with Echo, UiPath has adopted hundreds of images with minimal upfront engineering effort.

The results appeared almost immediately. Processes that could previously require thousands of hours of compatibility testing could, in some cases, be replaced by a single-line change to adopt the appropriate Echo image.

At UiPath's scale, those improvements compound quickly. A single vulnerability can appear dozens or even hundreds of times across products, language versions, packages, and years of supported releases. Since adopting Echo, UiPath estimates that Echo images have proactively eliminated thousands of unique open-source vulnerabilities that could scale to more than 100,000 individual vulnerability instances across its environment.

And the benefits extend beyond eliminating existing CVEs. Echo's hardened images remove unnecessary components and functionality without compromising application compatibility, reducing the attack surface and helping prevent vulnerabilities from appearing in the first place. For UiPath, that translates into lower ongoing servicing costs rather than simply faster remediation of today's findings.

FedRAMP operations have also become easier. Federal environments impose tight SLAs between vulnerability disclosure and remediation, so by reducing both triage and patching time, Echo makes it easier for UiPath's developers to meet those requirements while spending more of their time building new functionality.

Perhaps the clearest signal, however, has come from engineering.

“Echo has been one of the few security changes that we've pushed into engineering where they've come back to ask for more.” 

Developers quickly recognized the time and quality benefits and began actively requesting additional Echo images. If any of those images weren't readily available, Echo worked as an extension of the development team to quickly provide them.

Takeaway

For UiPath, the decision to rethink vulnerability management ultimately comes down to where engineering talent should spend its time.

“Where do you want your top talent spending their time? Do you want them innovating their products and services for your customers, or do you want them cherry-picking CVEs into binaries?”

With Echo, UiPath is moving that work upstream. Instead of repeatedly asking developers to triage, patch, integrate, and verify vulnerabilities across a sprawling product portfolio, teams can start with hardened software designed to remove much of that work altogether.

The result is more than faster vulnerability remediation. UiPath has proactively reduced vulnerability instances at massive scale, simplified FedRAMP-related remediation, reduced application compatibility risk, and returned thousands of hours to engineering – all without forcing developers onto a new operating system or fundamentally changing how they build software.

That model is becoming even more important as UiPath looks beyond container images to the broader software supply chain. The company is exploring how safe and patched libraries can provide developers and coding agents with a known source of secure software rather than pulling arbitrary packages directly from the internet.

As UiPath's CISO put it, Echo has become “an extended part of our delivery team” – a partnership the company sees expanding alongside its broader secure-by-default strategy.

Related stories

Create your own success story