All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Echo sells CVE-free container base images, OS packages, libraries, and Helm charts that teams adopt by changing one line in a Dockerfile, with critical fixes committed within seven days. Eilon Elhadad and Eylam Milner, who sold their previous supply-chain company Argon to Aqua Security, founded Echo in early 2025 and raised $50 million within ten months, and Varonis, EDB, and UiPath run its artifacts in production. A team of 35 maintains more than 600 images, the press reports, because AI agents research each new vulnerability, rebuild the affected artifacts, and test the fixes. Adoption is a one-line swap, and exit appears technically simple because artifacts are drop-in, though compliance evidence and renewed patch toil may create friction, and Chainguard sells into the same budget.
| Description | Supplies CVE-free container base images, OS packages, open-source libraries, and Helm charts, rebuilt from source and maintained by AI agents under a patch SLA as drop-in replacements for standard artifacts. | [f1] |
|---|---|---|
| Founded | 2025 | [f2] |
| HQ | New York and Tel Aviv | [f2] |
| Funding | $50M total | [f3] |
| Latest funding | Series A, $35M (December 2025) | [f4] |
| Product | What it does |
|---|---|
| Echo | Catalog of secure-by-design software artifacts spanning container images, OS packages, libraries, Helm charts, VMs, and serverless, with FIPS-validated and STIG-hardened variants. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Hardened, CVE-free base images, OS packages, and libraries replace vulnerable upstream components across container workloads and application dependencies. The company is mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The quantified pain (over 1,000 CVEs in base images and 120-day remediation) traces to Echo's own research and customer case studies, with press relaying that vendor framing rather than independently quantifying it, which the raised bar reads as a 3. [s17, s21, s22, s9] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Reviewed pages carry no docs portal or browsable catalog and the differentiating AI rebuild factory rests on press and founder interviews, so although FIPS 140-3 and the SLSA Level 3 pipeline add external signals, the core capability lacks inspectable documentation. [s4, s22, s19, s9] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Compliance demand is current and documented, with Varonis crediting Echo for met FedRAMP deadlines and dedicated FedRAMP and EU CRA use-case content, and Series A press reports enterprises moving production workloads onto Echo artifacts within the company's first year. The EU adopted the Cyber Resilience Act in October 2024 and its Article 14 reporting obligations apply from 11 September 2026. Buyers racing those deadlines are shopping now, and that urgency ends once the rules fully apply in December 2027. [s9, s12, s21, s23, s24] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Press verifies a prior exit in the same domain, with Argon sold to Aqua Security for a reported $100 million within a year of its founding, plus Unit 8200 and Ofek unit backgrounds for both founders. [s18, s21] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Varonis, EDB, and UiPath are press-named production customers, vendor case studies attach outcome figures, and EDB's CISO is quoted on per-release savings, which puts the traction evidence in multiple sources beyond the vendor's own pages. [s21, s19, s10, s9] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The 15 million seed and 35 million Series A within ten months funded a 600-image catalog with 35 people, visible shipping but with no disclosed revenue or margin, so output per dollar is unconfirmed for a company barely a year old rather than lean shipping at scale. [s19, s20, s16] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Buyers can place CVE-free base images in an existing vulnerability management budget, press consistently labels Echo a vulnerability-free image vendor, and Echo's own Chainguard comparison shows buyers already shop this category. The broader agentic-ready software framing is newer and less placeable. [s19, s14, s2] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Operating a from-source rebuild factory with FIPS validation and a patch SLA exceeds a quarterly feature release, but Docker publishes the images Echo replaces, Chainguard competes for the same compliance budget, and Echo's own one-line Dockerfile swap suggests switching back is similarly simple, so no structural moat against an equivalent competitor is visible in public evidence. [s17, s14, s4] |
Echo sells the removal of inherited vulnerabilities from the software supply chain rather than another tool for managing them. Nearly all cloud applications build on open-source container base images, and Echo's research, relayed in funding coverage, indicates that official Docker images often contain over 1,000 known vulnerabilities at download. The company argues that scan-and-patch workflows leave engineering teams remediating flaws in infrastructure they did not write.
Independent reporting corroborates the urgency. Coverage of both funding rounds describes base images as a major source of enterprise security debt and relays the company's claim that typical remediation takes up to 120 days against the 24 hours Echo commits to. VentureBeat adds that AI coding tools now generate a growing share of software and often select outdated or vulnerable libraries, which expands the same problem.
Named buyers describe the pain in their own words. Varonis reports FedRAMP deadlines met with every vulnerability remediated, EDB's CISO Dan Garcia is quoted saying Echo saves at least 235 developer hours per release, and Port's R&D director reports customer CVE requests dropping to nearly zero. Those statements come from security, engineering, and compliance owners, the buying group Echo addresses. [s17, s21, s22, s9, s10]
Echo ships families of prebuilt artifacts rather than a scanner or an agent. The catalog covers container base images, OS packages, open-source libraries, Helm charts, virtual machines, and serverless runtimes, and FIPS-validated, STIG-hardened variants serve FedRAMP-bound customers. Adoption is a one-line change, since a team points the FROM line of a Dockerfile at Echo's registry and keeps its existing workflow.
The build mechanic is reconstruction rather than patching. Press describes an AI-driven image factory that determines the essential components of an artifact and rebuilds it from scratch without unnecessary or vulnerable packages, and VentureBeat reports the pipeline builds to SLSA Level 3 with every artifact signed and tested. Echo states its images stay compatible as drop-in replacements because an internal lab tests them across environments.
Maintenance is where the AI claim concentrates. Press describes agents that monitor the thousands of new CVEs entering the National Vulnerability Database each month, search developer forums for unpublished patches, identify affected images in a pool of more than 600, apply fixes, run compatibility tests, and open pull requests for human review. The published service commitment triages critical and high CVEs within 24 hours and fixes them in up to seven days.
Public verifiability has limits. Reviewed pages include no public documentation portal or browsable image catalog, access appears gated behind the login and demo flow, and the capability claims appear on marketing pages, in founder interviews, and in customer case studies rather than in inspectable documentation. [s1, s4, s5, s6, s12, s17, s19, s20, s22]
Echo competes head-on with Chainguard in hardened minimal base images, and says so itself. The company published an April 2026 comparison post titled Echo vs. Chainguard and tags blog content for readers searching for Chainguard alternatives, so the rivalry is Echo's own framing rather than an analyst's. Against that rival Echo emphasizes automation economics, version stability without forced migrations, and its patch SLA.
The adjacency that matters most over time is Docker. Echo's artifacts replace the standard images Docker publishes, and the registries that mirror Echo's catalog are the same channels an incumbent could use to distribute hardened variants of its own. Echo's founders frame a larger ambition, telling VentureBeat that, just as Red Hat professionalized open-source Linux for the corporate world, Echo aims to be the enterprise AI native OS, a hardened, curated foundation for the AI era.
Scanners and cloud security platforms are positioned as complements rather than competition. Calcalist reports integrations with Wiz, Orca, Aqua, and Mend, and Echo's pitch is that its artifacts make those tools report zero findings, which keeps the scanner in place while removing its workload. [s14, s17, s22, s18, s7]
Echo runs a sales-assisted enterprise motion with founder-heavy selling and no self-service tier. Pricing requires a quote, a demo is the entry point, and the site offers a chat contact link with the team. The integrations page lists AWS and Azure Marketplace availability, each marked available for consumption, and the pricing FAQ says Echo supports the AWS, Azure, and GCP marketplaces, while the partner program is an early invitation to join what Echo calls the echosystem, so reseller and channel depth stay unclear from reviewed pages.
Named traction spans press and vendor case studies. Series A coverage reports production workloads at Varonis, EDB, and UiPath, the trust center lists Aqua Security, Varonis, UiPath, EDB, Vectra AI, and Webflow under reviewed and trusted by, and the case studies attach figures, with Port claiming $3.2M in annual savings across more than 100 integrations and Varonis crediting Echo for met FedRAMP deadlines. The customer set arrived within roughly a year of the company's founding.
Content is the visible demand engine. The founders appear as authors on some of the blog's vendor comparisons and vulnerability explainers, and funding coverage across at least five outlets in 2025 carried the category education. Revenue, pipeline, and retention figures remain undisclosed, so depth beyond the referenced accounts is not publicly verifiable. [s3, s7, s13, s21, s11, s10, s9, s14, s19]
Echo is the founders' second software supply-chain security company. Calcalist reports that Eilon Elhadad and Eylam Milner founded Echo in early 2025 after co-founding Argon in 2020 and selling it to Aqua Security for $100 million within a year, and that both are alumni of Israel's Unit 8200 and Ofek technology units.
The team is small by design. Calcalist counted 25 employees across Israel and New York at the seed announcement, SiliconANGLE reports 35 at the Series A, and Eilon argues the AI-agent pipeline does work that would otherwise require hundreds of security researchers. The headcount-to-catalog ratio is itself the company's favorite credibility exhibit.
Investor signals add execution validation. Notable Capital and Hyperwise Ventures led the seed with SVCI participating, N47 led the Series A with SentinelOne's S Ventures joining, and the strategic investor sells to the same enterprise security buyer Echo courts. [s18, s19, s16, s20]
Echo's trust posture leads with the certifications its compliance-driven buyers check first. The SafeBase-hosted trust center lists SOC 2 Type 2, ISO/IEC 27001:2022, and FIPS 140-3, the site carries an images SLA and a vulnerability disclosure page, and the FedRAMP materials advertise continuous-monitoring and POA&M readiness.
The product asks for unusual trust, because customers source their foundational software from Echo's build pipeline. A compromise of that pipeline would distribute malicious components to every consuming customer at once. The press-reported SLSA Level 3 pipeline with signed, verifiable artifacts is the public answer, and reviewed pages stop short of a published threat model or third-party audit of the pipeline itself.
Marketing accuracy shows one visible seam. The Port case study's headline and its body state different annual savings figures, and the body's $3.2M claim repeats on the customers page, a small inconsistency in a case study the company features prominently. [s11, s22, s10, s12, s4]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Chainguard | competes with | Hardened minimal-image vendor that Echo names directly in its own comparison content, competing for the same CVE-free base image purchase. | |
| Docker | adjacent | Publisher of the upstream images Echo replaces, with the registry distribution position to bundle hardened alternatives. | |
| Red Hat | adjacent | Enterprise packager of open-source software whose model Echo's founders cite as the precedent for a curated, secured software layer. |
Add analyzed competitors to compare them side by side with Echo.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
A customer can leave Echo the way it arrived, by pointing one Dockerfile line at another image. Customers who leave take back the work Echo absorbed: the compliance team re-creates the FIPS 140-3 evidence auditors expect, and developers resume the remediation cycles Port's case study describes across more than 100 integrations. That returned work is the main friction, modest rather than binding, because rivals such as Chainguard can meet the same compliance requirements and win customers with the same one-line change. Echo's firmer assets are its buyers, enterprises that buy through procurement reviews, and its place as the base of the customer's software rather than a tool watching from outside.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 2/3 | Customers buy artifacts plus an ongoing remediation commitment, with a published patch SLA and a legal images-SLA document, so the offer includes accountability for keeping the catalog clean rather than software alone. No judgment or managed-service layer goes further than that. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Leaving Echo is a one-line repoint by design, but compliance customers would re-establish FIPS evidence and audit trails and reabsorb patch toil across services, with Port's 100-plus integrations as the visible example. The friction is real and modest. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | FIPS 140-3 validation, STIG hardening, and FedRAMP evidence readiness are genuine procurement assets that took effort to build, but no regulation mandates Echo specifically and these are published standards a competitor could be certified against. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 2/3 | Rebuilding and continuously maintaining hundreds of artifact lineages from source with compatibility guarantees is hard operational engineering, but the hardened-image playbook is established and rival catalogs demonstrate it is replicable with capital and expertise. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Press-named customers are enterprises, with Varonis the documented compliance-bound example, remediating every in-scope container to meet federal requirements, and quote-gated pricing implies procurement-mediated deals, a buyer base that carries the gates slowing commodity substitution. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | Base images, OS packages, and libraries are the layer applications are built on, and Echo's artifacts become part of the customer's running software rather than a tool observing it from outside. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The maintained catalog, build pipelines, and agent-collected vulnerability intelligence are accumulated IP, but public materials claim no dataset a rival could not recreate and competing catalogs already exist, so it is replicable rather than a proprietary moat. |
Echo targets enterprises whose engineering organizations inherit vulnerability debt from open-source infrastructure, with compliance-bound software vendors as a visible beachhead segment. The named customers, Varonis, EDB, UiPath, Vectra AI, and Port, are software companies whose own customers scan what they ship, and the FedRAMP use case gives that group a deadline-driven reason to buy.
Two personas appear in the public record. Security leaders supply the quotes about risk and audit outcomes, with EDB's CISO and Varonis's Deputy CTO quoted by name, while engineering leaders such as Port's R&D director describe reclaimed developer time. Echo's messaging serves both, selling eliminated CVEs to security leaders and eliminated toil to engineering.
Geography and deal size stay implicit. The company employs people in Israel and New York, the press-named customers are technology firms, and quote-gated pricing implies mid-market and enterprise contracts rather than self-service. The newest public proof of demand is current, with Series A coverage from December 2025, case studies live on the site, and sustained recent blog activity.
Echo's product claim is subtraction, since artifacts arrive without the vulnerabilities other vendors help customers find. Product pages enumerate the families, container images, OS packages, libraries, Helm charts, VMs, and serverless runtimes, and the libraries page extends the claim past CVEs to malware sandboxing and maintainer-drift quarantine, which addresses supply-chain attacks rather than only stale packages.
The AI advantage is operating economics rather than a data moat. Press describes agents that research each new National Vulnerability Database entry, identify affected images among more than 600, build and test fixes, and open pull requests for human review, and Eilon says that pipeline lets 35 people do work that would otherwise need hundreds of researchers. That cost structure is the company's stated edge over rivals that staff comparable catalogs manually.
Durability of the advantage is the open question. The pipeline is process and tooling rather than proprietary data, public materials claim no compounding dataset, and a rival with comparable agent engineering could replicate the economics. Echo's positioning for AI consumers of software, agentic-ready artifacts on the about page and the enterprise AI native OS framing CEO Eilon Elhadad gives VentureBeat, sketches where the company wants its differentiation to move next.
Echo sells founder-forward into enterprises. The founders appear as authors on some of the blog's comparison and explainer posts, front the funding press, and give the technical interviews, a motion that fits a company in its first revenue years, and the visible commercial surface is a demo request and quote-based pricing. The integrations page lists AWS and Azure marketplace availability, each marked available for consumption, while the partners page is an early invitation to join the ecosystem, so reseller and channel depth stay unclear from the reviewed pages.
Distribution rides infrastructure customers already operate. Echo mirrors artifacts to the registries enterprises pull from, including Azure, Google, JFrog, Docker Hub, GitHub, Nexus, Harbor, and Red Hat Quay, and integrates with the scanners that would otherwise flag findings, with Calcalist naming Wiz, Orca, Aqua, and Mend. That placement removes adoption friction, though none of these channels would resist a well-funded rival, since registries mirror anyone's artifacts.
Traction evidence is strong for the company's age and thin on depth. Press names production customers and the case studies quantify outcomes, while revenue, pipeline, customer counts, and expansion rates remain undisclosed, so the repeatability of the motion beyond the referenced accounts is not publicly verifiable.
Echo publishes its packaging logic but not its prices. The pricing page offers a per-artifact model, quoted on the number consumed, or access to the full catalog priced by the size of the engineering organization, and a custom quote is the route to a number.
Both units track how the buyer measures the problem. Artifacts consumed equal the dependency surface being secured, and engineering-organization size scales with how much software the customer builds, so Echo charges by the units customers use to size their own exposure. VentureBeat relays the company's framing that consumption pricing scales with how customers actually build and ship software.
The premium question stays unanswered in public. Reviewed pages never position Echo's cost against Chainguard's or against the internal cost of a patching team beyond case-study savings claims, and the full-catalog option suggests Echo prefers platform-wide adoption over metered growth.
Delivery is registry-native and demands almost no deployment. Customers repoint a Dockerfile FROM line or a package source at Echo's mirrored artifacts in the registries they already use, keep their CI/CD unchanged, and let their existing scanners verify the result. Echo claims drop-in compatibility, tested by an internal lab across environments.
Operations carry the product's substance. Echo rebuilds images continuously as fixes land, commits to triage of critical and high CVEs within 24 hours and fixes within seven days, keeps workloads on the versions they need without forced migrations, and reports both fixed and unresolved vulnerabilities to customers.
The failure modes are asymmetric. An Echo outage leaves customers running but freezes their patch supply, while a compatibility regression in a rebuilt artifact would surface as a customer production incident, the scenario the compatibility-testing claims exist to prevent. The site publishes the images SLA as a legal document and the trust center names SLA documents, but public pages do not publish uptime or support-tier terms.
Echo's certifications match its buyers' strict procurement reviews. SOC 2 Type 2, ISO/IEC 27001:2022, and FIPS 140-3 appear in the SafeBase-hosted trust center, the site carries a vulnerability disclosure page, and the FedRAMP materials advertise continuous-monitoring and POA&M readiness, which makes the compliance evidence part of the product.
The deeper trust question is concentration. Echo asks customers to source their foundational software from one vendor's build pipeline, so a compromise at Echo would deliver malicious components downstream at scale. The public mitigation is the press-reported SLSA Level 3 pipeline with signed, verifiable artifacts, and reviewed pages stop short of a published threat model or a third-party audit of the pipeline itself.
Small accuracy seams matter for a company selling trust. The Port case study's headline and its body state different annual savings figures, with the body's $3.2M repeated on the customers page, and the about page's statistics counters render as zeros without JavaScript, details a skeptical security buyer notices.
Echo plugs into the container ecosystem on both sides rather than operating its own platform surface. Inbound, its artifacts are mirrored to the registries customers pull from, and outbound, integrations make scanners and cloud security platforms recognize Echo packages, with Calcalist naming Wiz, Orca, Aqua, and Mend.
The stated ambition is to become the layer others depend on. CEO Eilon Elhadad tells VentureBeat that Echo aims to be the enterprise AI native OS and the foundation of everything in the AI native era, and the about page frames a trusted source for agentic-ready software, which together sketch a move from artifact catalog to foundation layer. The reviewed pages identify integrations and partners but no third-party products built on Echo, and the partner program is an early invitation page.
Ecosystem dependencies cut both ways. Echo depends on the upstream open-source projects it repackages and on registry and scanner cooperation it does not control, and a registry owner such as Docker is simultaneously a distribution channel and a likely bundler of a competing hardened catalog.
The founding team has built this company shape before. Eilon Elhadad and Eylam Milner co-founded Argon in 2020, sold it to Aqua Security for a reported $100 million within a year, and started Echo in early 2025 with backgrounds in Unit 8200 and the Ofek technology unit. The repeat shows in pace, with $50 million raised within ten months of founding.
Execution capacity concentrates in automation by design. Headcount grew from 25 at the seed, when the company employed people in Israel and New York, to 35 at the Series A, the catalog passed 600 images in the same window, and Eilon presents that ratio as proof that agents replace researcher headcount.
The public roster beyond the founders is thin. Reviewed pages and press name no sales, marketing, or federal-compliance leadership, so the bench behind a fast-scaling enterprise and FedRAMP motion is not publicly visible, the main execution unknown.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Echo homepage | official | 2026-06-11 |
| f2 | Former Argon founders launch Echo with $15M to tackle open source risk | press | 2026-06-11 |
| f3 | Echo Raises $35 Million in Series A Funding | press | 2026-06-11 |
| f4 | Vulnerability-free container image startup Echo Software raises $35M | press | 2026-06-11 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Echo homepage “Eliminate both OS and language-level vulnerabilities without sacrificing functionality.” | official | 2026-06-18 |
| s2 | Echo about page “Rather than finding and fixing vulnerabilities in production, we eliminate them at the source – ensuring a software supply chain that's secure by default.” | official | 2026-06-12 |
| s3 | Echo pricing page “Which cloud marketplaces does Echo support? We support all of the popular marketplaces, including AWS, Azure, and GCP.” | official | 2026-06-18 |
| s4 | Echo container images product page “Critical and high CVEs are triaged within 24 hours and fixed in up to 7 days.” | official | 2026-06-12 |
| s5 | Echo libraries product page “By monitoring the health of the upstream project and maintainer, Echo detects and quarantines any drift in the author, behavior, and release cadence.” | official | 2026-06-12 |
| s6 | Echo OS packages product page | official | 2026-06-12 |
| s7 | Echo integrations page “aws Marketplace Available for consumption · Azure Marketplace Available for consumption” | official | 2026-06-18 |
| s8 | Echo customers page | official | 2026-06-12 |
| s9 | Varonis case study “We reached our FedRAMP deadlines with everything remediated.” | official | 2026-06-12 |
| s10 | Port case study “Without those mid-sprint interruptions and time-draining remediation cycles across 100+ integrations, Port has saved thousands of developer and security hours each year, translating into $3.2M saved annually.” | official | 2026-06-12 |
| s11 | Echo trust center “Compliance: SOC 2 Type 2 · ISO/IEC 27001:2022 · FIPS 140-3” | official | 2026-06-12 |
| s12 | Echo FedRAMP use case “FIPS 140-3 Validated” | official | 2026-06-12 |
| s13 | Echo partners page | official | 2026-06-12 |
| s14 | Echo blog index “Echo vs. Chainguard: Choosing the right vendor” | official | 2026-06-18 |
| s15 | Echo seed funding press release “NEW YORK, July 31, 2025 /PRNewswire/ -- Echo, an innovative startup building enterprise-grade software infrastructure, has raised $15 million in Seed funding.” | official | 2026-06-12 |
| s16 | SecurityWeek on the Echo seed round “The funding round was led by Notable Capital and Hyperwise Ventures, with participation from SVCI.” | press | 2026-06-12 |
| s17 | SiliconANGLE on the Echo seed round “Echo uses what it calls an AI-driven image factory, a feature that analyzes existing container images, determines the essential components and rebuilds them from scratch without unnecessary or vulnerable packages.” | press | 2026-06-12 |
| s18 | Calcalist on the Echo launch and seed round “The duo previously co-founded Argon in 2020, which was acquired within a year by Aqua Security for $100 million.” | press | 2026-06-12 |
| s19 | SiliconANGLE on the Echo Series A “Echo co-founder and Chief Executive Eilon Elhadad (left) said this AI-first approach enables the company to maintain a library of more than 600 secure container images, despite only having a team of 35.” | press | 2026-06-12 |
| s20 | SecurityWeek on the Echo Series A “Echo today announced raising $35 million in a Series A funding round that brings the total raised by the company to $50 million.” | press | 2026-06-12 |
| s21 | Ynetnews on the Echo Series A “Echo is already securing production workloads for enterprise customers, like Varonis, EDB, and UiPath, with its AI-powered approach to eliminating container vulnerabilities at the source.” | press | 2026-06-12 |
| s22 | VentureBeat on the Echo Series A “Crucially, the build pipeline adheres to SLSA Level 3 standards (Supply-chain Levels for Software Artifacts), ensuring that every artifact is signed, tested, and verifiable.” | press | 2026-07-01 |
| s23 | Echo EU CRA use case “CRA ready for September 11, 2026” | official | 2026-06-12 |
| s24 | Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act) on EUR-Lex “This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026” | regulatory | 2026-06-12 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Echo homepage “Eliminate both OS and language-level vulnerabilities without sacrificing functionality.” | official | 2026-06-11 |
| s2 | Echo about page “Rather than finding and fixing vulnerabilities in production, we eliminate them at the source – ensuring a software supply chain that's secure by default.” | official | 2026-06-18 |
| s3 | Echo pricing page “Get access to all of our secure artifacts, paying based on the size of your engineering organization.” | official | 2026-06-11 |
| s4 | Echo container images product page “Critical and high CVEs are triaged within 24 hours and fixed in up to 7 days.” | official | 2026-06-11 |
| s5 | Echo libraries product page “By monitoring the health of the upstream project and maintainer, Echo detects and quarantines any drift in the author, behavior, and release cadence.” | official | 2026-06-11 |
| s6 | Echo OS packages product page | official | 2026-06-11 |
| s7 | Echo integrations page “Marketplace aws Marketplace Available for consumption Marketplace Azure Marketplace Available for consumption” | official | 2026-06-15 |
| s8 | Echo customers page | official | 2026-06-11 |
| s9 | Varonis case study “We reached our FedRAMP deadlines with everything remediated.” | official | 2026-06-18 |
| s10 | Port case study “Without those mid-sprint interruptions and time-draining remediation cycles across 100+ integrations, Port has saved thousands of developer and security hours each year, translating into $3.2M saved annually.” | official | 2026-06-11 |
| s11 | Echo trust center “Compliance: SOC 2 Type 2 · ISO/IEC 27001:2022 · FIPS 140-3” | official | 2026-06-11 |
| s12 | Echo FedRAMP use case “FIPS 140-3 Validated” | official | 2026-06-11 |
| s13 | Echo partners page | official | 2026-06-11 |
| s14 | Echo blog index “Echo vs. Chainguard: Choosing the right vendor” | official | 2026-06-18 |
| s15 | Echo seed funding press release “NEW YORK, July 31, 2025 /PRNewswire/ -- Echo, an innovative startup building enterprise-grade software infrastructure, has raised $15 million in Seed funding.” | official | 2026-06-11 |
| s16 | SecurityWeek on the Echo seed round “The funding round was led by Notable Capital and Hyperwise Ventures, with participation from SVCI.” | press | 2026-06-11 |
| s17 | SiliconANGLE on the Echo seed round “Echo uses what it calls an AI-driven image factory, a feature that analyzes existing container images, determines the essential components and rebuilds them from scratch without unnecessary or vulnerable packages.” | press | 2026-06-11 |
| s18 | Calcalist on the Echo launch and seed round “Echo was founded in early 2025 by Eilon Elhadad (CEO) and Eylam Milner (CTO), both alumni of Unit 8200 and the Ofek unit, with over a decade of experience in cybersecurity. The duo previously co-founded Argon in 2020, which was acquired within a year by Aqua Security for $100 million.” | press | 2026-06-11 |
| s19 | SiliconANGLE on the Echo Series A “Echo co-founder and Chief Executive Eilon Elhadad (left) said this AI-first approach enables the company to maintain a library of more than 600 secure container images, despite only having a team of 35.” | press | 2026-06-11 |
| s20 | SecurityWeek on the Echo Series A “Echo today announced raising $35 million in a Series A funding round that brings the total raised by the company to $50 million.” | press | 2026-06-11 |
| s21 | Ynetnews on the Echo Series A “"Echo saves at least 235 developer hours per release and has helped cut critical vulnerabilities," said Dan Garcia, CISO of EDB.” | press | 2026-06-11 |
| s22 | VentureBeat on the Echo Series A “Crucially, the build pipeline adheres to SLSA Level 3 standards (Supply-chain Levels for Software Artifacts), ensuring that every artifact is signed, tested, and verifiable.” | press | 2026-07-01 |
| s23 | Ynetnews on the Echo customers naming UiPath in production “Echo is already securing production workloads for enterprise customers, like Varonis, EDB, and UiPath, with its AI-powered approach to eliminating container vulnerabilities at the source.” | press | 2026-06-11 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.