# Echo

**Canonical:** https://apis.io/providers/echo/  
**Website:** https://www.echo.ai/  
**APIs profiled:** 0

Echo is a software supply-chain security company that delivers vulnerability-free (CVE-free), secure-by-design base container images, language libraries, hardened virtual machines, serverless runtimes, and OS packages. Its artifacts are built as drop-in replacements so engineering teams eliminate known CVEs across their software supply chain without changing application code, cutting remediation toil and easing compliance with frameworks like FedRAMP, FIPS, PCI DSS, DORA, and the EU Cyber Resilience Act. Echo operates as a CVE Numbering Authority (CNA) and publishes a Trust Center with SOC 2 Type 2, ISO/IEC 27001:2022, and FIPS 140-3 assurance. The company is backed by GGV Capital.

## Kin Score — 17.6 / 100 (emerging)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 17.6).

| Facet | Score |
|---|---|
| Discoverability | 50.0 |
| Contract Quality | 0.0 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 10.5 |
| Developer Ergonomics | 2.4 |
| Commercial Clarity | 53.9 |
| Access Clarity | 53.9 |

## Agent readiness — 0.0 (human-only)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Unknown — onboarding: unknown, pricing: unknown, trial: no (confidence: low).

## Security (3)

- **Echo Domain Security** — TLSv1.3 · HSTS · DMARC
- **Echo Vulnerability Disclosure** — contact published
- **Echo Trust Center** — SOC 2 Type 2, ISO/IEC 27001:2022, FIPS 140-3

## Tags

Company, Security, Supply Chain Security, Container Security, Vulnerability Management, DevSecOps, Compliance, Open-Source

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/echo/). Scores are computed from the provider's own public artifacts under a published rubric.
