Minimus is joining Echo

Minimus is winding down operations, and key Minimus technology and assets have been acquired by Echo.

We chose Echo because we believe they offer the strongest path forward for both the technology we built and, most importantly, our customers. We are working closely with the Echo team and will be meeting with every Minimus customer to provide necessary support during the transition period.

You can learn more about Echo here

Why Echo?

Minimus and Echo were built around the same fundamental idea: security should be built into the software you use, not added after the fact.

With Echo, you’ll get:

  • Hardened software without changing how you build: Drop-in replacements designed to fit into your existing environments and workflows.
  • More than an OS: Hardened container images, libraries, OS packages, VMs, Helm charts, and more from one platform.
  • Continuous security: Echo continuously vets, maintains, and patches its artifacts as new vulnerabilities and threats emerge.
  • Broad ecosystem support: Integrations across the security and registry tools enterprises already use.

A message from Minimus

“When we made the decision to wind down Minimus, our priority was finding the right home for the technology we built and, most importantly, the right path forward for our customers.

Echo shares our belief that software should be secure by default and has built the platform and engineering capabilities to take that vision even further. We’ve spent time working directly with their team, and we’re confident both in their technology and the people behind it.

We believe Echo is the best place for what we built to continue – and the best path forward for our customers.”

Ben Bernstein

CEO, Co-founder, Minimus

Community Edition Done Right

Free minimized container images Pull yours now

The world’s largest selection of free, ~0 CVEs, compliant container images.
No login. No $. Just pull & go.

Everything you need to ship secure software

Minimal images, maximum flexibility, fastest path to deployment.

Security

Zero-CVE images, rebuilt daily

Every image is scanned, hardened, and shipped clean. If a CVE drops at 3am, we're already patching, so you don't have to.

  • 24 hour SLA for critical and high CVEs on KEV; 48 hours for all other critical and high
  • Continuous scanning across thousands of images
  • SBOMs and signatures for every build
Efficiency

A fraction of the size, none of the bloat

Strip everything non-essential. Smaller images mean faster pulls, fewer dependencies, and a dramatically smaller attack surface.

  • Often 95% smaller than standard images
  • Image creator to customize images if you need to, optimized for agents and automation
  • Faster CI/CD and cold starts
Compliance

Audit-ready from the start

FedRAMP, NIST 800-190, SLSA Level 3, SBOM, CIS, and FIPS. Every image, every build the work auditors ask about? Already done.

  • FedRAMP-ready images out of the box
  • SBOM + provenance attestations included
  • Continuous SLSA Level 3 compliance
compliance
Adoption

Change one line. That’s it

Minimus images are API-compatible with what you already run. Update your Dockerfile, rebuild, and ship. No refactoring, no surprises.

  • Drop-in replacements for standard base images
  • Continuously maintained Helm charts to deploy complex apps with multiple images
  • Agent ready with prebuilt skills, prompts, agent config files, and CLI tools so agents can help you migrate and deploy
adoption

Start free. Scale when you're ready

Open access to hardened images for everyone. Upgrade for private builds, SLA-backed support, and the controls enterprise teams need.

Community

For individuals exploring secure container images.

$0

Get Started

What's included:

  • 1,000s of near 0 CVE images built from source
  • FIPS, CIS, NIST, STIG compliant images
  • Agent optimized for rapid adoption
  • All images, Major versions, Minor versions

Enterprise

For teams shipping production at scale.

Custom

Let's Talk

Everything in Community, plus:

  • Best in industry, contractually guaranteed, CVE remediation
  • 24x7 enterprise support with contractually guaranteed SLAs
  • Image creator to define custom images backed by the same SLAs
  • Actions to integrate with the tooling you already use like GitHub, Slack, and webhooks
  • Supply chain protection
  • Enterprise SSO and RBAC for unlimited users
  • Sync images to the registries you already use, even air-gapped ones
  • AI ready with skills and config tools for Claude, Codex, Cursor, and more to migrate to and build on Minimus images