How Webflow reclaimed 20% of engineering time with Echo

100+

container images migrated to Echo’s CVE-free versions

45,000

vulnerabilities eliminated in five months

> 100

lines of code changed across the migration

10K

10 k hours of dev time saved each year

100+

integrations secured with 0 added maintenance

$3.2M

in annual savings

“Everybody has been a little bit mind-blown by the product itself. I get Slack messages from engineers saying, ‘Mohit, we migrated this image with just one line of code change,’ and they share screenshots of AWS Inspector going from thousands of vulnerabilities to zero.”
Mohit Bansal,
Security Engineering Leader, Webflow

Meet Webflow

Webflow is a web experience platform where brand, growth, and marketing teams come together to build, launch, and optimize web experiences. Its platform serves everyone from freelancers and startups to some of the world's largest enterprises – and today, Webflow powers roughly 1% of the internet.

That scale creates an enormous security responsibility. Webflow handles approximately 10 million API requests every hour, while its security operations team works to ensure that everything the company builds and ships remains both fast and secure.

As development accelerates, that responsibility is only becoming more complex. Webflow's teams are shipping software faster than ever, while scanners continue to identify more vulnerabilities. For its security organization, keeping pace meant finding a way to fundamentally change how vulnerabilities were handled.

The vulnerability challenge

Before Echo, vulnerability management at Webflow was a constant battle. Every new vulnerability required security and engineering teams to triage the finding, identify the appropriate owner, make sure it was patched, and deploy the fix. The work wasn't limited to a handful of security engineers – remediation was distributed across multiple engineering teams throughout the company.

Vulnerability management consumed approximately 20% of every engineer's sprint, meaning that rather than dedicating that time to shipping new products and developing new features, engineers were repeatedly pulled back into vulnerability remediation work.

Vulnerability volume wasn't going down, while AI was enabling engineering teams to produce software at an unprecedented pace. More software meant a growing attack surface – and potentially even more vulnerabilities for security teams to chase. So, instead of continuing with a reactive model, the team wanted to move toward secure-by-default infrastructure where vulnerabilities could be addressed before they ever reached developers.

Why Webflow chose Echo

Webflow approached the decision as a competitive evaluation. The security team initially looked at seven different vendors before narrowing the process to two solutions for a proof of concept. The team evaluated both against a defined set of technical and operational criteria. The difference became apparent early in the POC.

Webflow migrated three images with each approach and compared the amount of work required. According to the team, migrating those images with Echo required approximately 90% fewer lines of code changes than with the alternative. That mattered because Webflow didn't view security as the only stakeholder in the decision.

Unlike traditional security tools where the security organization is the primary user, container images directly affect platform and engineering teams. Any solution therefore needed to fit into developers' existing workflows without requiring significant migration work, retraining, or operational changes. Echo's approach made that possible.

“The level of effort for migration was extremely straightforward and easy to understand for engineers,” said Facundo Orsi, Senior Security Engineer at Webflow.

The partnership was another differentiator. Webflow found Echo's response times to be in alignment with its own, both before and after procurement. In one instance, the team requested API documentation to integrate Echo with an internal AI agent, and by the following morning, the requested documentation was already available. 

For Webflow, Echo offered both sides of what it was looking for: a technically simple migration and a team that could move at the same speed it did.

Real results and impact

Webflow created a simple page of instructions explaining how to use Echo, configured an AWS ECR pull-through cache, and allowed teams to begin migrating. The company even trained an AI agent to perform migrations on behalf of engineers. Within five months, Webflow had migrated more than 45 container images running in production, resulting in 45,000 fewer vulnerabilities across its environment.

The total code change across those migrations? Less than 100 lines.

For the security team, that represented a fundamental change in the vulnerability management equation. The response from engineering was just as significant.

“Since bringing Echo into our environment, we’re generating fewer security tickets and addressing issues much faster. Engineers are proactively asking where else they can implement Echo images, even in places we hadn’t suggested. That’s exactly the kind of security ownership we want to see,” said Mohammad Alam, Security Engineer at Webflow.

Engineers began sending the security team screenshots after migrations: an AWS Inspector scan showing thousands of vulnerabilities, followed by another showing zero – often after changing only a single line of code.

But the biggest impact has been giving engineering teams their time back. Engineers have reclaimed 20% of their sprint time, which they can now dedicate toward shipping new products, building new experiences, and keeping pace with the speed of AI-driven development.

Takeaway

With Echo, security and engineering teams can move away from repetitive remediation and redirect their attention toward the problems that will define the next generation of software security.

“Echo has opened up important conversations about our software supply chain – why we need to be thoughtful about every layer of our environment and how we can reduce risk through minimalism, slimmer containers, and multistage builds. At the end of the day, the best security tools reduce toil instead of creating more of it.” - Andrew Rose, Sr. Staff Security Engineer, Webflow

With AI accelerating software development, Webflow is also exploring Echo's patched libraries as a way to prevent vulnerable or compromised packages from entering the development lifecycle in the first place.

As Webflow puts it: “Echo takes the repetitive work off our plates so we can focus on innovative development.”

Related stories

Create your own success story