All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This analysis draws mostly on the vendor's own published materials, with limited outside corroboration.
This analysis is scoped to Minimus Hardened Images and Minimus Image Creator.
Minimus supplies hardened container images, minimal base images it rebuilds when updates occur to carry far fewer known vulnerabilities than public ones. Compliance-bound enterprises adopt them as the base layer of their software. Customer evidence as of July 2026 is homepage testimonials rather than named case studies. A $51 million seed co-led by YL Ventures and Mayfield funds the company. Founders Ben Bernstein, Dima Stopel, and John Morello built Twistlock, so the bet investors fund is the team's record. The homepage shows a free Community Edition and a quote from Camunda's security leader. Adoption is a one-line change to the image reference, so technical substitution is simple in both directions. That ease means the founders' record does not yet show as customer lock-in.
| Description | Builds hardened, minimal container images and virtual machines from upstream source, rebuilt continuously in a SLSA Level 3 pipeline, as drop-in replacements that strip out most known vulnerabilities and carry FIPS, STIG, and CIS hardening plus signed SBOMs. | [f1] |
|---|---|---|
| Founded | 2022 | [f2] |
| HQ | Baton Rouge, Louisiana (with offices in New York, Tel Aviv, and Portland) | [f3] |
| Funding | $51M total | [f4] |
| Latest funding | $51M seed, co-led by YL Ventures and Mayfield (2025) | [f4] |
| Product | What it does |
|---|---|
| Minimus Hardened Images | Distroless container images and virtual machines rebuilt continuously from source with over 97% fewer CVEs, FIPS 140-3, STIG, and CIS hardening, and signed SBOMs, deployed as drop-in replacements. |
| Minimus Image Creator | Lets customers build and manage their own hardened container images atop the Minimus platform, with integrated exploit intelligence, signed SBOMs, and continuous rebuilds from source. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Hardened, minimal container images and virtual machines replace vulnerable upstream open-source components across container workloads and application dependencies. The products protect conventional software infrastructure rather than AI assets, so the company is mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The over-97-percent-fewer-CVEs pain figure is vendor-supplied and matched by the rival's near-identical claim, and while federal patch directives ground the urgency, the buyer pain is not independently quantified across multiple non-vendor sources. [s1, s2, s5] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The product pages detail a SLSA Level 3 pipeline, FIPS and STIG hardening, signed SBOMs, and KEV and EPSS prioritization, and as of July 2026 the catalog is publicly browsable through the homepage gallery with named images such as nginx and postgres, but no third-party benchmark or OSS release corroborates the CVE-reduction claims, so the depth rests on vendor pages alone. [s2, s6, s1] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Buyer-side demand is active and dated, with FedRAMP and STIG content, CISA KEV patch directives named in public materials, and two rivals selling the same hardened-image answer, signals that buyers are searching now rather than the vendor arguing a future need. The enabler is the past three to four years of SLSA and Sigstore provenance standards plus federal supply-chain mandates that made prevention buyable. [s2, s5, s8] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 5/5 | The founders are the Twistlock team with a prior build in container security and author credit for NIST SP 800-190, a verifiable prior build and standards credit in the exact domain, reinforced by an angel roster of sitting security-company founders named on the about page. [s6, s3, s5] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Attributed homepage testimonials as of July 2026 include a named customer, Camunda, whose senior director of information security describes partnering with Minimus, which meets the named-customer level without independent corroboration of scale. Corrected from 2 after the testimonials appeared, since the prior no-named-customer basis no longer holds. No case studies, counts, or revenue are disclosed. [s1, s5, s3] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | A $51 million seed is outsized for the stage, the company discloses no revenue or adoption counts, and customer evidence is limited to homepage testimonials, so the raise materially outruns verifiable commercial results despite a shipped catalog, a free Community Edition, and a generally available Image Creator. [s5, s6, s1] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Hardened minimal images are now an established category buyers place without coaching, evidenced by Chainguard alternatives being a recognized comparison frame, and Minimus fits it cleanly as a fast-follower rather than coining new language. [s8, s2] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 | Adoption and reversal are both one-line configuration changes, the catalog is recreatable, the exploit feeds named in public materials are CISA KEV and EPSS, both public data, and registry owners such as Docker can bundle hardened images, so the position reads as a plausible platform feature rather than a friction-protected moat. [s2, s8] |
Minimus sells the removal of inherited vulnerabilities from the software supply chain rather than another tool for finding them. Nearly all cloud applications build on open-source container images, and Minimus advertises its images at over 97% fewer CVEs than public images, framing the pitch around the wasted hours engineering teams spend triaging and remediating flaws in infrastructure they did not write.
The threat backdrop is concrete and current. The company's public materials lean on CISA KEV prioritization and federal patch directives, the kind of mandate that puts supply-chain security on CISO agendas, and the company organizes its pitch by industry and by role so both the security owner and the engineering owner see their problem named.
Demand evidence is the segment's main gap. The compliance and FedRAMP framing signals a deadline-driven reason to buy, and as of July 2026 the homepage displays testimonials from security and platform leaders, including a quote crediting Minimus for a safer foundation for every customer running Camunda, but the company still publishes no named case studies, adoption counts, or revenue, so the size and velocity of the segment it is winning are not yet visible in public. [s1, s2, s5]
Minimus ships prebuilt hardened artifacts rather than a scanner. The catalog spans container images and virtual machines built from upstream source with only the software an application needs, advertised at over 97% fewer CVEs, with FIPS 140-3, STIG, NIST, and CIS-ready variants for sensitive and air-gapped workloads, deployed as drop-in replacements through a single configuration change.
The build mechanic is continuous reconstruction with verifiable provenance. Minimus monitors tens of thousands of open-source projects and rebuilds affected images in a SLSA Level 3 pipeline when upstream changes, ships signed SBOMs, and layers real-time exploit intelligence from CISA KEV and EPSS so teams can prioritize the residual CVEs the minimal images do not eliminate.
Minimus opened its catalog to public inspection during 2026. The homepage links a browsable image gallery with named images such as nginx, python, argo-cd, and postgres, free to pull without a login, so the catalog scale the company advertises is now inspectable, though no third-party benchmark corroborates the CVE-reduction figures. Image Creator, generally available since November 2025, lets customers build their own hardened images, a capability the launch release describes as powered and secured by Minimus's container-security and software supply-chain technology. [s2, s6, s1]
Minimus enters a category another vendor defined. Chainguard set the hardened-image template and reports the scale, and Minimus markets itself directly as a Chainguard alternative, so the category organizes around the incumbent rather than the newcomer, with Echo a third rival whose own site markets CVE-free base images and libraries.
The adjacency that matters most over time is Docker and the cloud registries. Minimus images replace the standard images those registries publish, and the registries that distribute hardened images are the same channels an incumbent could use to bundle its own hardened variants into subscriptions buyers already hold, the structural pressure on any standalone catalog.
Against direct rivals the contest is pedigree and breadth. Minimus counters Chainguard's scale and Echo's CVE-free pitch with the deepest founder authority in container security, but it trails both on disclosed traction, so its differentiation today rests on the team rather than on a proven catalog or named accounts. [s8, s2, s5, s10]
Minimus runs a founder-forward enterprise motion with a self-service front door added during 2026. The CEO fronts the funding press and writes the company's opinion posts on vulnerability-management policy, and as of July 2026 the visible commercial surface spans a free Community Edition, a publicly browsable image gallery, published Community and Enterprise pricing tiers, a demo request, and a partner-ecosystem invitation.
Distribution is designed to ride infrastructure customers already operate. Minimus images are drop-in replacements deployed with a single configuration change, integrate with development, chat, and ticketing tools, and connect to the rest of a customer's security stack, which removes adoption friction without resisting a well-funded rival.
Traction evidence is the weak point. The fifty-one-million-dollar seed, the angel roster of sitting security-company founders, and the founders' track record are strong indirect signals, and the homepage now displays testimonials under the heading Loved by security and platform teams, including a quote from Camunda's senior director of information security. Minimus still publishes no named case studies, revenue, or adoption counts, so the repeatability of the motion is not yet verifiable in public. [s5, s3, s1]
Minimus is led by the team that built the modern container-security category. Ben Bernstein, Dima Stopel, and John Morello are the team behind Twistlock and reunited to found Minimus in October 2022, the about page lists their backgrounds at Twistlock and Palo Alto Networks, and Minimus credits the team as author of NIST SP 800-190, the federal guidance on container security.
The bench is publicly named and domain-deep. The about page lists the three co-founders alongside a COO, CFO, CBO, VP of R&D, and general counsel with backgrounds at Twistlock, Palo Alto Networks, Orca Security, and Torq, and the board includes Mayfield's Navin Chaddha and YL Ventures' Yoav Leitersdorf.
The investor roster reinforces the pedigree more than the traction. The seed drew sitting security-company founders and CEOs as angels, including Assaf Rappaport, Udi Mokady, George Kurtz, and Mickey Boodaei named on the about page, unusual validation of the team, while the named case studies and revenue that would corroborate execution remain undisclosed and customer evidence is limited to homepage testimonials. [s6, s3, s5]
Minimus holds its own attestations, which match its buyers' strict procurement reviews. The trust center states the company is both SOC 2 and ISO 27001 certified with reports available by request, and the products ship FIPS 140-3 and STIG-ready images with SBOMs and native compliance dashboards, so the compliance evidence is built into both the company and the product.
The federal story is a feature rather than the company's own authorization. The FedRAMP and NIST SP 800-190 content frames Minimus images as making compliance easier to achieve and demonstrate, and Minimus credits the team as author of that NIST guidance, but reviewed pages show no FedRAMP authorization Minimus itself holds, so the federal positioning serves the buyer's mandate.
The deeper trust question is concentration. Customers would source foundational software from one vendor's build pipeline, so a pipeline compromise would distribute malicious components downstream at scale, and the public mitigation is the signed SBOM and SLSA Level 3 provenance chain rather than a published third-party audit of the pipeline itself. [s4, s2, s6]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Chainguard | competes with | The category-defining hardened-image vendor with disclosed revenue and named customers that Minimus markets itself directly against as a Chainguard alternative. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Echo | competes with | A rival whose own site markets CVE-free base images and libraries. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Docker | adjacent | A registry and image-distribution owner positioned to bundle a competing hardened catalog into the channel customers already use. |
Add analyzed competitors to compare them side by side with Minimus.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Minimus is durable where its buyers face audits and exposed where its product is convenient to drop in. Its images become the base layer of customer software, sold into compliance-bound enterprises, and the SOC 2 and ISO 27001 attestations plus the patch commitments matter in the audits those buyers must pass. The same design that wins adoption undoes lock-in, because a one-line swap reverses, rivals can clear the same FIPS and STIG bars, the catalog is recreatable, and the exploit feeds named in its public materials, KEV and EPSS, are public data. It is defensible mainly for compliance-bound buyers and weakest where a customer can swap its images back cheaply. Watch whether the founders turn their domain authority and angel backing into named case studies beyond the homepage testimonials.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 2/3 | Customers buy hardened artifacts plus an ongoing remediation commitment, and the vendor's pages state two patch clocks. The trust center commits to critical CVEs within 48 hours of upstream availability with high and medium within 14 days, while the homepage advertises a 24 hour SLA for critical and high CVEs on KEV and 48 hours for all other critical and high. Image Creator extends that maintenance to customer-built images, so the offer is software with accountability for keeping it clean rather than a judgment or managed-service layer. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Minimus images are drop-in replacements deployed with a single configuration change, so substituting back to another source is mechanically cheap, but a compliance customer would re-establish FIPS and STIG evidence, re-tune scanner integrations, and reabsorb patch toil across services, so the friction is real and modest rather than a hard lock. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Minimus holds its own SOC 2 and ISO 27001 certifications and ships FIPS 140-3 and STIG-ready images plus FedRAMP-readiness materials, but these are company-level commercial attestations and product features that help customers meet their own mandates, with no regulation mandating Minimus specifically and no Minimus-held federal authorization. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 2/3 | Rebuilding thousands of artifact lineages from source in a SLSA Level 3 pipeline with continuous updates while maintaining drop-in compatibility is hard operational engineering, but the hardened-image playbook is established and a rival catalog such as Chainguard's demonstrates it is replicable with capital and expertise. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Minimus targets compliance-bound enterprises in finance, technology, and healthcare with FedRAMP and STIG content and quote-gated enterprise procurement, a buyer identity that carries the gates slowing commodity substitution, though customer evidence as of July 2026 is homepage testimonials, including a quote from Camunda's senior director of information security, rather than named reference case studies. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | Base container images and virtual machines are the layer applications are built on, and Minimus artifacts become part of the customer's running software rather than a tool observing it from outside. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The maintained catalog, SLSA pipeline, and exploit-prioritization tooling are real engineering, but the exploit feeds named in public materials are CISA KEV and EPSS, both public data, those materials name no dataset a rival could not recreate, and competing catalogs already exist, so it is replicable rather than a proprietary moat. |
Minimus targets enterprises whose engineering organizations inherit vulnerability debt from open-source infrastructure, with compliance-bound buyers as the visible high-value segment. The site organizes its pitch by industry, naming finance, technology, healthcare, and retail, and by role, naming platform engineers, security engineers, developers, and CISOs, so the company addresses both the security buyer who owns risk and the engineering buyer who owns delivery.
Two personas drive the purchase. Security leaders are sold measurable risk reduction, framed as over 97% fewer CVEs and real-time prioritization of the remainder, while engineering leaders are sold reclaimed time, framed as eliminated triage and remediation work. CEO Ben Bernstein states the thesis directly, that application security should not be reactive and that developers waste countless hours on triage and remediation.
Demand evidence is the segment's main gap, though it is not empty: Minimus reports that Image Creator underwent private testing with select customers and that thousands of users had adopted its images since April 2025, both vendor-reported. The compliance and FedRAMP framing signals a deadline-driven reason to buy, and as of July 2026 the homepage displays testimonials from security and platform leaders, including a quote crediting Minimus for a safer foundation for every customer running Camunda, but the company still publishes no named case studies, no independently verified or precise adoption metrics, and no revenue, so the size and velocity of the segment it is winning are not yet visible in public.
Minimus sells subtraction, since its artifacts arrive without the vulnerabilities other vendors help customers find. The catalog spans container images and virtual machines built from upstream source with only the software an application needs, advertised at over 97% fewer CVEs than public images, with FIPS 140-3, STIG, NIST, and CIS-ready variants for sensitive and air-gapped workloads.
The build mechanic is continuous reconstruction with verifiable provenance. Minimus monitors tens of thousands of open-source projects and automatically rebuilds affected images in a SLSA Level 3 pipeline when upstream changes, ships SBOMs and signatures for every build, and layers real-time exploit intelligence from CISA KEV and EPSS so teams can prioritize the residual CVEs the minimal images do not eliminate. Image Creator, generally available since November 2025, lets customers build their own hardened images, a capability the launch release describes as powered and secured by Minimus's container-security and software supply-chain technology.
The advantage is operating maturity and pedigree rather than a proprietary dataset. The exploit feeds named in public materials, CISA KEV and EPSS, are data any vendor can use, and rival catalogs demonstrate the hardened-image recipe, so Minimus differentiates through the founders' depth in this exact problem and the quality of the catalog they run rather than through data a competitor could not assemble.
Minimus sells founder-forward into enterprises, with a self-service front door visible as of July 2026. The CEO fronts the funding press and writes the company's opinion posts on vulnerability-management policy, and as of July 2026 the visible commercial surface spans a free Community Edition, a publicly browsable image gallery, published Community and Enterprise pricing tiers, and a demo request. The site includes a partner-ecosystem invitation, and Minimus names Aqua Security, AWS, Google Cloud, Orca Security, Snyk, Upwind, and Wiz as supporting its images in relationships it calls partnerships serving joint customers. Those are vendor-reported, and the reviewed record carries no independently verified partner-driven revenue or deployments.
Distribution is designed to ride infrastructure customers already operate. Minimus images are drop-in replacements deployed with a single configuration change, integrate with development, chat, and ticketing tools, and connect to the rest of a customer's security stack, which removes adoption friction, though that same registry-native placement would not resist a well-funded rival.
Traction evidence is the weak point. The funding, the angel roster of named cyber-industry investors, and the founders' track record are strong indirect signals, and the homepage now displays testimonials under the heading Loved by security and platform teams, including a quote from Camunda's senior director of information security. Minimus still publishes no named case studies, no revenue, and no independently verified or precise adoption metrics, so the repeatability of the motion is not yet verifiable in public and the indirect signals carry the case.
As of July 2026 Minimus published pricing tiers, splitting a free Community tier from a custom-priced Enterprise tier. The pricing page invites buyers to start free and scale when ready, lists the Community tier at zero dollars for individuals exploring secure container images, and routes the Enterprise tier for teams shipping production at scale through a talk-to-us motion, so the enterprise buyer still reaches a number through sales while the community user pulls images without paying.
The packaging logic tracks how buyers measure the problem. The Community tier includes thousands of near-zero-CVE images built from source with FIPS, CIS, NIST, and STIG compliant variants, and the Enterprise tier adds contractually guaranteed CVE remediation, 24x7 support with guaranteed SLAs, Image Creator, tooling integrations, supply-chain protection, and enterprise SSO and RBAC, so the unit of paid value is the remediation guarantee and controls wrapped around the catalog rather than image access itself.
The premium question narrows to the enterprise tier. Minimus prices catalog access at zero and sells the SLAs, custom builds, and enterprise controls above it, and reviewed pages do not position that enterprise cost against rival hardened-image vendors or against the internal cost of a patching team beyond the CVE-reduction outcome claims, so how Minimus expects buyers to justify the spend is not stated in public.
Delivery is registry-native and demands almost no deployment. Minimus images are drop-in replacements for the software organizations already run, deployed with a single configuration-file change for nearly instant time to value, so customers point their builds at Minimus artifacts and let their existing tools verify the result, including air-gapped environments.
Operations carry the product's substance. Minimus rebuilds images continuously as upstream fixes land, ships SBOMs and signatures with each artifact, and runs round-the-clock support, and its pages state two different patch clocks. The trust center commits to patching critical CVEs within 48 hours of upstream availability, with high and medium within 14 days, while the homepage advertises a 24 hour SLA for critical and high CVEs on KEV and 48 hours for all other critical and high, and the pages do not say which clock governs.
The failure modes are asymmetric. A Minimus outage would leave customers running but freeze their patch supply, while a compatibility regression in a rebuilt artifact would surface as a customer production incident, which is why minimality and rebuild discipline are the operational core, and reviewed pages do not publish an uptime commitment beyond the patch and support SLAs.
Minimus holds its own compliance attestations, which match its buyers' strict procurement reviews. The trust center states the company is both SOC 2 and ISO 27001 certified with reports available by request, and the product line ships FIPS 140-3 and STIG-ready images with SBOMs and native compliance dashboards, so the compliance evidence is built into both the company and the product.
The federal story is a feature rather than the company's own authorization. The FedRAMP and NIST SP 800-190 content frames Minimus images as making compliance easier to achieve and demonstrate, and Minimus credits the team as author of that NIST guidance, but reviewed pages show no FedRAMP authorization that Minimus itself holds, so the federal positioning serves the buyer's mandate rather than functioning as the company's moat.
The deeper trust question is concentration. Customers would source foundational software from one vendor's build pipeline, so a pipeline compromise would distribute malicious components downstream at scale, and the public mitigation is the per-build SBOM, signature, and SLSA Level 3 provenance chain rather than a published third-party audit of the pipeline itself.
Minimus plugs into the container ecosystem rather than operating its own platform surface. Its images are pulled as drop-in replacements through the registries customers already use, and its integrations connect to development, chat, ticketing, and security-stack tools, so the company sits inside existing workflows rather than asking customers to adopt a new console.
The stated ambition reaches toward a broader trusted-software foundation. Image Creator extends the platform from a fixed catalog to customer-built hardened images, described in the launch release as powered and secured by Minimus's container-security and software supply-chain technology, which sketches a move from image catalog toward a platform other software depends on.
Ecosystem dependencies cut both ways. Minimus depends on the upstream open-source projects it repackages and on registry and scanner cooperation it does not control, and a registry owner is simultaneously a distribution channel and the most likely bundler of a competing hardened catalog.
Minimus is led by the team that built the modern container-security category. Ben Bernstein, Dima Stopel, and John Morello are the team behind Twistlock and reunited to found Minimus in October 2022, the about page lists their backgrounds at Twistlock and Palo Alto Networks, and Minimus credits the team as author of NIST SP 800-190, the federal guidance on container security, so the founders bring a recognized prior build and standards credit in the exact domain.
The bench is publicly named and domain-deep. The about page lists the three co-founders alongside a COO, CFO, CBO, VP of R&D, and general counsel with backgrounds at Twistlock, Palo Alto Networks, Orca Security, and Torq, and the board includes Mayfield's Navin Chaddha and YL Ventures' Yoav Leitersdorf, so the leadership behind an enterprise motion is visible.
The investor roster reinforces the pedigree more than the traction. YL Ventures and Mayfield funded the fifty-one-million-dollar seed, and Minimus separately lists Assaf Rappaport, Udi Mokady, George Kurtz, and Mickey Boodaei among its investors on the about page, which is unusual validation of the team, while the named case studies and revenue that would corroborate execution remain undisclosed and customer evidence is limited to homepage testimonials.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Minimus product page | official | 2026-06-21 |
| f2 | PR Newswire: Minimus Revolutionizes Container Security with Image Creator | press | 2026-06-21 |
| f3 | Minimus about page | official | 2026-06-21 |
| f4 | Ynetnews: Minimus raises $51 million to kill 95% of software vulnerabilities | press | 2026-06-21 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Minimus homepage “Community Edition Done Right ... Browse All Images ... Loved by security and platform teams ... Partnering with Minimus ... safer foundation for every customer running Camunda ... 24 hour SLA for critical and high CVEs on KEV; 48 hours for all other critical and high” | official | 2026-07-02 |
| s2 | Minimus product page “automatically rebuilds images in a SLSA Level 3 pipeline when updates occur ... over 97% fewer CVEs than public container images ... FIPS 140-3, STIG, NIST and CIS ready images for sensitive workloads” | official | 2026-06-21 |
| s3 | Minimus about page “Founded and led by the same team behind Twistlock ... Ben Bernstein CEO & Co-Founder ... John Morello CTO & Co-Founder ... Backed by Builders ... Assaf Rappaport Udi Mokadi George Kurtz Mickey Boodaei” | official | 2026-06-21 |
| s4 | Minimus Trust Center “Minimus is both SOC-2 and ISO 27001 certified. Reports are available by request ... We patch critical CVEs within 48 hours of upstream availability; high and medium within 14 days.” | official | 2026-06-21 |
| s5 | Ynetnews: Minimus raises $51 million to kill 95% of software vulnerabilities “raised $51 million in seed funding ... co-led by YL Ventures and Mayfield ... who founded the company in October 2022 ... Minimus has not disclosed customers or timelines for broader rollout ... CISA's Known Exploited Vulnerabilities (KEV) and Exploit Prediction Scoring System (EPSS) data” | press | 2026-06-21 |
| s6 | PR Newswire: Minimus Revolutionizes Container Security with Image Creator “general availability of Image Creator ... build their own hardened container images, fully powered and secured by Minimus' industry-leading container security software and software supply chain security technology ... Founded in October 2022 by Ben Bernstein, Dima Stopel, and John Morello” | press | 2026-06-21 |
| s7 | Chainguard Containers product page (category anchor) “~97.6% fewer vulnerabilities than typical alternatives” | official | 2026-06-20 |
| s8 | Minimus: Chainguard Alternatives, Best Hardened Image Providers 2026 “Chainguard alternatives for hardened container images: minimal bases, continuous rebuilds, SBOMs, CVE reduction, and compliance-ready” | press | 2026-06-21 |
| s10 | Echo homepage (competitor-controlled page): CVE-free Base Images and Libraries “Vulnerability-free containers and libraries built for supply chain security.” | official | 2026-07-02 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Minimus homepage “Community Edition Done Right ... Browse All Images ... Loved by security and platform teams ... Partnering with Minimus ... safer foundation for every customer running Camunda ... 24 hour SLA for critical and high CVEs on KEV; 48 hours for all other critical and high” | official | 2026-07-02 |
| s2 | Minimus product page “automatically rebuilds images in a SLSA Level 3 pipeline when updates occur ... over 97% fewer CVEs than public container images ... FIPS 140-3, STIG, NIST and CIS ready images for sensitive workloads” | official | 2026-06-21 |
| s3 | Minimus about page “Founded and led by the same team behind Twistlock ... Ben Bernstein CEO & Co-Founder ... John Morello CTO & Co-Founder ... Backed by Builders ... Assaf Rappaport Udi Mokadi George Kurtz Mickey Boodaei” | official | 2026-06-21 |
| s4 | Minimus Trust Center “Minimus is both SOC-2 and ISO 27001 certified. Reports are available by request ... We patch critical CVEs within 48 hours of upstream availability; high and medium within 14 days.” | official | 2026-06-21 |
| s5 | Ynetnews: Minimus raises $51 million to kill 95% of software vulnerabilities “raised $51 million in seed funding ... co-led by YL Ventures and Mayfield ... who founded the company in October 2022 ... Minimus has not disclosed customers or timelines for broader rollout ... CISA's Known Exploited Vulnerabilities (KEV) and Exploit Prediction Scoring System (EPSS) data” | press | 2026-06-21 |
| s6 | PR Newswire: Minimus Revolutionizes Container Security with Image Creator “general availability of Image Creator ... build their own hardened container images, fully powered and secured by Minimus' industry-leading container security software and software supply chain security technology ... Founded in October 2022 by Ben Bernstein, Dima Stopel, and John Morello” | official | 2026-06-21 |
| s7 | Chainguard Containers product page (category anchor) “Every Chainguard image ships with Sigstore signatures, a signed SBOM, and SLSA L2 provenance ... ~97.6% fewer vulnerabilities than typical alternatives” | official | 2026-06-20 |
| s8 | Minimus: Chainguard Alternatives, Best Hardened Image Providers 2026 “Chainguard alternatives for hardened container images: minimal bases, continuous rebuilds, SBOMs, CVE reduction, and compliance-ready” | official | 2026-06-21 |
| s9 | Minimus: Pricing Plans - Free & Enterprise “Start free. Scale when you're ready. Upgrade for private builds, SLA-backed support, and the controls enterprise teams need. Community For individuals exploring secure container images. $0 ... Enterprise For teams shipping production at scale. Custom Let's Talk” | official | 2026-07-02 |
| s10 | Minimus Opinions post: Three Days to Patch, by CEO Ben Bernstein “Three Days to Patch: Why CISA's New Directive Is a Wake-Up Call to Stop Playing Whack-a-Mole By Ben Bernstein June 12, 2026 ... Ben Bernstein CEO & Co-Founder” | official | 2026-08-01 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.