Echo website screenshot

Echo

Echo is a software supply-chain security company that delivers vulnerability-free (CVE-free), secure-by-design base container images, language libraries, hardened virtual machines, serverless runtimes, and OS packages. Its artifacts are built as drop-in replacements so engineering teams eliminate known CVEs across their software supply chain without changing application code, cutting remediation toil and easing compliance with frameworks like FedRAMP, FIPS, PCI DSS, DORA, and the EU Cyber Resilience Act. Echo operates as a CVE Numbering Authority (CNA) and publishes a Trust Center with SOC 2 Type 2, ISO/IEC 27001:2022, and FIPS 140-3 assurance. The company is backed by GGV Capital.

Echo is profiled on the APIs.io network. Tagged areas include Company, Security, Supply Chain Security, Container Security, and Vulnerability Management.

Echo’s developer surface includes engineering blog, pricing, and 9 more developer resources.

20.7/100 emerging ▬ flat Agent 0/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
CompanySecuritySupply Chain SecurityContainer SecurityVulnerability ManagementDevSecOpsComplianceOpen Source

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 20.7/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 0.4 / 20
Commercial Clarity 12.1 / 20
Operational Transparency 1.4 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 0/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/echo: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Echo Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Echo Vulnerability Disclosure

contact published

SECURITY

Echo Trust Center

SOC 2 Type 2, ISO/IEC 27001:2022, FIPS 140-3

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Access & Security 5

Authentication, authorization, and security posture

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: echo
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/echo.png
name: Echo
description: Echo is a software supply-chain security company that delivers vulnerability-free (CVE-free), secure-by-design
  base container images, language libraries, hardened virtual machines, serverless runtimes, and OS packages. Its artifacts
  are built as drop-in replacements so engineering teams eliminate known CVEs across their software supply chain without changing
  application code, cutting remediation toil and easing compliance with frameworks like FedRAMP, FIPS, PCI DSS, DORA, and
  the EU Cyber Resilience Act. Echo operates as a CVE Numbering Authority (CNA) and publishes a Trust Center with SOC 2 Type
  2, ISO/IEC 27001:2022, and FIPS 140-3 assurance. The company is backed by GGV Capital.
url: https://raw.githubusercontent.com/api-evangelist/echo/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- ggv-capital
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-19'
tags:
- Company
- Security
- Supply Chain Security
- Container Security
- Vulnerability Management
- DevSecOps
- Compliance
- Open Source
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: TrustCenter
  url: security/echo-trust-center.yml
- type: Compliance
  url: https://trust.echo.ai/
- type: VulnerabilityDisclosure
  url: security/echo-vulnerability-disclosure.yml
- type: Security
  url: https://www.echo.ai/vulnerability-disclosure
- type: DomainSecurity
  url: security/echo-domain-security.yml
- type: Blog
  url: https://www.echo.ai/blog
- type: Pricing
  url: https://www.echo.ai/pricing
- type: Login
  url: https://app.echohq.com/sign-in
- type: TermsOfService
  url: https://www.echo.ai/legal/terms-of-use
- type: PrivacyPolicy
  url: https://www.echo.ai/legal/privacy-policy
- type: Website
  url: https://www.echo.ai/
x-enrichment:
  date: '2026-07-19'
  status: backfilled
  pass: local-v1
  note: backfilled from .gitignore signal + verified work evidence