vectorfusionart - stock.adobe.co

Rival buyout aids customers after DevSecOps firm shutters

One DevSecOps company shut its doors. Just days later, the company was acquired, saving customers from a potentially difficult migration.

A DevSecOps company that garnered a historic seed round just three years ago shut its doors this week, leaving customers just 60 days to migrate. Days later, a competitor swooped in with an acquisition offer, giving customers a life raft.

The shuttered company, Minimus, originally named Gutsy, operated in the hardened container market. It didn't shut down due to lack of demand for such tools; a June 2026 IDC survey found that around a third of enterprises were using hardened images across most production application workloads. Almost 60% were either using or piloting them in select workloads and on a smaller scale.

"Growth in this category attracted suppliers faster than it created a dedicated budget for them," Katie Norton, IDC analyst, told TechTarget. "There are now at least 10 credible providers of hardened container images, most of which entered within the last two years." Some of those providers include Chainguard, Docker, RapidFort, RedHat and Wiz.

Also included in that list is the acquiring company, Echo.

"After we'd seen the Minimus announcement, immediately I picked up the phone, called Ben [Bernstein, co-founder and CEO of Minimus] and said 'Let's do it, we'll take it,'" Eilon Elhadad, co-founder and CEO of Echo, told TechTarget. "Now, [users] don't have 60 days. They have endless days. All of the customer base is moving to Echo, and we are maintaining the Minimus platform."  Elhadad also said he hopes many members of the Minimus team will join Echo. "Some will join us," said Elhadad.

Minimus customers dodge migration disruption  

Minimus's closure created an immediate transition problem for customers whose images are embedded in development and deployment pipelines. Both Chainguard and Docker offered migration assistance for Minimus customers in the day following Minimus's shutdown.

"The migration support from other providers reflects both the urgency for customers and the competitive opportunity to win organizations that already recognize the value of hardened images. It also underscores that buyers are depending not just on an image, but on a vendor to maintain that foundation continuously, making supplier stability and portability important evaluation criteria," Norton wrote. 

Buyers are depending not just on an image, but on a vendor to maintain that foundation continuously, making supplier stability and portability important evaluation criteria.
Katie NortonAnalyst, IDC

Echo will provide Minimus customers with continuity in their current architecture, which is especially pertinent for users with hardened containers compliant with Federal Information Processing Standards or Security Technical Implementation Guide guidelines. These users would have likely had a more challenging migration because of more stringent security requirements, said Chris Hughes, vice president of security strategy at agentic AI security platform provider Noma Security.

DevSecOps caveat emptor

The fact that hardened container images become foundational components of the software supply chain makes the maintenance commitment central to the value that these vendors offer. It can also make them more of a risk than scanning tools that sit outside DevSecOps pipelines if they disappear.

"When you lose a scanner vendor, you lose a dashboard," Hughes said. "When the image provider shuts down, it's a supply chain input that is impacting everything you ship and your underlying infrastructure." 

Buyers should consider this continuity risk carefully when choosing a vendor, Norton said.


"Long-term support commitment was already a stated selection criterion for about one in five organizations according to IDC's survey," she wrote. "It is now a demonstrated risk. Organizations standardizing on a single supplier should be asking about migration paths and image portability before they need them." 

Buyers should also consider whether their provider is a standalone hardened image supplier or if they provide hardened images as part of a larger group of products. Choosing a standalone supplier often requires evaluating deep technical details to differentiate it from competitors, Norton said.

 "What separates one from another ends up being very technical: how the build is constructed, how packages are composed and versioned, what the catalog covers and how customization is handled without losing support," she wrote.

Overstock in the hardened container market

Minimus was a standalone supplier and had a formidable predecessor, Norton said.

"Chainguard can certainly be credited with defining this category and had a pretty lengthy runway before seeing significant competition. Everyone entering after it faced a choice: Attach hardened images to a registry, distribution or security platform the buyer already pays for, or compete as a dedicated supplier against the company that set the terms of the market," Norton wrote. The market is bifurcating into platform-attached supply -- like RedHat, Docker, Broadcom and Wiz -- and a small number of scaled specialists, she said.

Over the last year, larger competitors began offering hardened images for free, further pressuring standalone suppliers such as Minimus.

"Everyone kind of raced to 'out-free' each other," Hughes said. Docker, for example, began offering thousands of images under the Apache 2 license in December 2025; Red Hat followed suit with Red Hat Hardened Images in May. In June, Minimus opened its catalog.

Chainguard also moved out of containers and expanded into libraries and GitHub Actions. Echo has four product lines besides hardened containers, including VMs and open source libraries.

Container environment

These market pressures emerged as organizations rushed to fortify software supply chains against AI tooling capable of uncovering vulnerabilities at machine speed. IT organizations have looked to these companies to provide updated, secure container images with few or no vulnerabilities on their behalf at a time when vulnerabilities can be found by attackers and exploited faster than organizations can patch them.

"Minimus shutting down says more about market structure than about the technology or the team. Demand for hardened images is not the question," Norton wrote. "The question is who captures that demand.”

Echo was founded in 2025 with a $15 million seed round and already has 100 customers in the first year of selling. It's the founders' second company in the cybersecurity space. The first, Argon security, was acquired by Aqua for $100 million.

"We've never seen demand like this in the market ever," Elhadad said. "I see companies that thought they [could] enter our market and they disappear very fast."

Minimus raised a $51 million seed round in 2023, among the largest seed funding rounds in Israeli history, according to Globes. The Minimus funding came toward the end of a post-pandemic spree in cybersecurity funding, peaking in 2021 at more than $20 billion, then $14.45 billion in 2022 and $8.7 billion in 2023, according to Pinpoint Search Group.

"Many companies will not make it despite the outsized funding rounds and a lot of the hype and excitement in the ecosystem," Hughes said. "If you look at the kind of AI hype and excitement that we're in with AI security -- tons and tons of huge, massive seed and Series A rounds -- I suspect in a few years we'll likely see similar stories like this among AI and agentic AI security [companies], or cybersecurity [companies] more broadly."

Ben Lutkevich is an award-winning writer and editor focusing on IT infrastructure.

Dig Deeper on Application Architecture