Minimus
Minimus built hardened, minimal container images from scratch directly from upstream open-source sources, aiming to eliminate more than 95% of the software supply-chain vulnerabilities that accumulate in typical container images by stripping out everything not strictly needed to run the application.
Visit Website ↗ + Add to CompareOverview
Minimus built hardened, minimal container images from scratch directly from upstream open-source sources, aiming to eliminate more than 95% of the software supply-chain vulnerabilities that accumulate in typical container images by stripping out everything not strictly needed to run the application. Founded in October 2022 by Ben Bernstein, Dima Stopel, and John Morello — the same team that built and sold Twistlock (container security) to Palo Alto Networks in 2019 for roughly $410 million — Minimus raised $51 million in seed funding co-led by YL Ventures and Mayfield.
In August 2026, Minimus announced it would shut down operations, citing a business and investment climate that left it unable to continue, and returned remaining cash to investors. Echo, a New York-based startup using AI agents to secure container images, acquired Minimus’s assets — intellectual property, technology, customer contracts, and data — shortly after the shutdown announcement, strengthening Echo’s position as the secure-container-image market consolidates around it and rival Chainguard.
Innovation Matrix Assessment
Built a from-scratch, upstream-source hardened container image platform under a credible repeat-founder team, though the company wound down roughly four years after founding.
Designed to slot into existing container build pipelines with minimal images, though the company's shutdown interrupted continued operational support before Echo's acquisition.
The company shut down in August 2026 after raising $51M, returning remaining cash to investors — a clear negative momentum signal, independently reported, despite the subsequent asset sale to Echo.
Building minimal, from-scratch container images to eliminate vulnerabilities at the source rather than scanning after the fact is a genuinely sound architectural approach within the secure-software-supply-chain category.
The company's own claim of eliminating 95%+ of vulnerabilities was never independently benchmarked, and the business ultimately could not sustain itself despite the technical approach and founder pedigree.
Software supply-chain and container vulnerability reduction remains a consistently important security priority, even as this particular vendor did not survive as an independent company.
Why CISOs Should Care
Championed eliminating container vulnerabilities at the build stage rather than scanning for them after the fact — a technically sound approach now continuing under Echo's ownership rather than as a standalone vendor.
What Makes It Different
Built by repeat, proven founders (the Twistlock team) with a from-scratch, upstream-source container-hardening approach, but ultimately could not sustain an independent business despite $51M raised and a strong technical thesis.
The Matrix Verdict
43/100 — EMERGING / UNRANKED
A cautionary but instructive case: a well-funded, credibly founded company with a sound technical approach that nonetheless could not survive independently in a consolidating market, with its assets salvaged by a competitor days after shutdown — evidence of real technology value but a failed standalone business.
Editorial Note: Claims vs. Verified Findings
The shutdown, asset acquisition by Echo, founder backgrounds, and funding history are independently reported (SiliconANGLE, GovInfoSecurity, Calcalist); Minimus's own efficacy claims (95%+ vulnerability elimination) are company-sourced and were never independently benchmarked before the company wound down.
Sources
Alternatives to Minimus
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…