Echo
Echo is a software supply-chain security company that delivers vulnerability-free (CVE-free), secure-by-design base container images, language libraries, hardened virtual machines, serverless runtimes, and OS packages. Its artifacts are built as drop-in replacements so engineering teams eliminate known CVEs across their software supply chain without changing application code, cutting remediation toil and easing compliance with frameworks like FedRAMP, FIPS, PCI DSS, DORA, and the EU Cyber Resilience Act. Echo operates as a CVE Numbering Authority (CNA) and publishes a Trust Center with SOC 2 Type 2, ISO/IEC 27001:2022, and FIPS 140-3 assurance. The company is backed by GGV Capital.
Echo is profiled on the APIs.io network. Tagged areas include Company, Security, Supply Chain Security, Container Security, and Vulnerability Management.
Echo’s developer surface includes engineering blog, pricing, and 9 more developer resources.
Kin Score
Security Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Access & Security 5
Authentication, authorization, and security posture
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API