Minimus
Minimus provides free, hardened distroless container images built from source, eliminating ~95% of CVEs and supporting FedRAMP, NIST, FIPS, and SLSA compliance for security and platform engineering teams in regulated industries.
- Company typePrivate
- Founded2025
- HeadquartersNew York, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Minimus does
Minimus is a container security company headquartered in Baton Rouge, Louisiana, that builds hardened, distroless container images directly from source rather than repackaging standard Linux distributions. Its core technology strips shells, package managers, compilers, and unnecessary utilities, producing images that are 90-95% smaller than standard equivalents (e.g., Python 850MB to 48MB) with an average 97% reduction in CVEs. Images are rebuilt daily with a 24-hour SLA for KEV-listed critical/high vulnerabilities, and every build produces a cryptographically signed SBOM under an SLSA Level 3 compliant pipeline.
The platform centers on a free Community Edition of over 1,200 near-zero CVE images distributed via a self-serve image gallery with no login required, layered with an Enterprise Subscription that adds contractually guaranteed CVE remediation SLAs, Image Creator for custom private images, Actions (webhooks/Slack/GitHub/email), Threat Intelligence (CISA KEV + EPSS), Supply Chain Protection, Secure Helm Charts, Compliance Dashboards, Enterprise SSO/RBAC, and Registry Synchronization to private OCI registries including air-gapped environments. The product is sold via a hybrid GTM: product-led growth at the free tier plus an enterprise field sales motion targeting CISOs, Platform Engineers, and Security Engineers in regulated industries.
Minimus monetizes through annual enterprise subscriptions with custom quote-based pricing; the free tier drives developer adoption and top-of-funnel demand. Named customers span healthcare (Jimini Health, Hinge Health), defense/public safety (ZeroEyes), insurance (Verisk, Great American Insurance Group), financial services (RBS), cybersecurity (SentinelOne, Cycode, Oligo), and technology (Camunda, Highway 9 Networks, Knightscope). Strategic distribution partnerships include AWS, Google Cloud, and Wiz for cloud marketplace reach, and Knox Systems for FedRAMP-authorized delivery into U.S. Government customers.
Minimus firmographics
Firmographics- Name
- Minimus
- Legal name
- Minimus Inc.
- Website
- https://minimus.io
- Company type
- Private
- Founded year
- 2025
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Minimus provides free, hardened distroless container images built from source, eliminating ~95% of CVEs and supporting FedRAMP, NIST, FIPS, and SLSA compliance for security and platform engineering teams in regulated industries.
- Ownership category
- akta.pro rank
Minimus industry classification
Industry- Product category
- Container Security
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Container & Kubernetes Application Security (HDADACAE)
- akta.pro secondary industries
- DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI), Container Runtime & Image Infrastructure (HDABADAG)
Keywords
Where Minimus is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Minimus business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Community Edition: Free tier providing access to thousands of near 0 CVE images built from source, FIPS/CIS/NIST/STIG compliant images, agent optimization, and all major/minor versions. Generates community adoption and brand awareness.
- Enterprise Subscription: Custom pricing for production teams requiring contractually guaranteed CVE remediation, 24x7 enterprise support with SLAs, Image Creator for custom images, GitHub/Slack/webhook integrations, supply chain protection, Enterprise SSO/RBAC, registry sync including air-gapped, and AI-ready features.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Community Edition - Free tier for individuals exploring secure container images |
| Subscription | Annual | Enterprise - For teams shipping production at scale with SLA-backed support |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
Minimus product offering
Product offeringCore offering
Minimus builds and distributes minimal, hardened, distroless container images directly from source, replacing bloated upstream base images used in CI/CD pipelines. The core offering is a library of over 1,200 signed container images (nginx, python, postgres, node, etc.) that ship with near-zero CVEs, are 90-95% smaller than standard images, and are rebuilt daily with the latest security patches. Enterprise customers pay for SLA-backed remediation, Image Creator, air-gapped registry sync, SBOM/provenance, and FedRAMP/FIPS/STIG compliance.
Product overview
Minimus is a container security company offering a unified platform centered on free, hardened, minimal container images that are rebuilt daily. The core product is the Hardened Container Images library providing over 1,200 near-zero CVE images (nginx, python, postgres, node, etc.) that are 90-95% smaller than standard images. Enterprise add-ons include Image Creator for custom private images, Actions for automated notifications (Slack, GitHub, webhooks, email), Secure Helm Charts for Kubernetes deployment, Threat Intelligence for CVE prioritization using CISA KEV and EPSS, Supply Chain Protection for package integrity, and Image Compliance Reports (CIS, NIST-800-190, FIPS, STIG). Additional offerings include Software Bill of Materials (SBOM) generation with cryptographic signing, Registry Synchronization for air-gapped environments, and an Open Source Program providing free access to eligible projects. Images are offered in variants: Standard, FIPS (FedRAMP-compliant cryptography), Hardened (CIS benchmark compliance), Advanced (Kubernetes-optimized with Helm support), and Dev (with shells for development).
Differentiator
Problem solved
Functional benefit
Products and services
- Hardened Container Images Distroless, signed container images built from source for nginx, python, postgres, node, and 1,200+ other applications. Sold free via Community Edition and as the foundation of the Enterprise subscription. Targets platform engineers, security engineers, and developers needing to reduce CVE surface and image bloat in CI/CD and Kubernetes.
- Image Creator Enterprise module that lets customers author and maintain private, customized hardened container images (added packages, env vars, config files) with continuous vulnerability scanning, SBOMs, signatures, and daily updates. Sold to enterprise platform and security teams with custom build requirements.
- Actions (Automated Notifications & Workflows) Automated notification and workflow product that triggers Slack alerts, GitHub Actions, webhooks, or emails when vulnerabilities are fixed, new image versions release, or EOL dates approach. Filterable by image, severity, and exploitability. Sold to enterprise DevOps and security teams.
- Secure Helm Charts Pre-configured, continuously maintained Helm charts for deploying Minimus images in Kubernetes with health probes, least-privilege defaults, and CIS Kubernetes Benchmark alignment. Sold to platform engineering teams deploying complex multi-image applications on Kubernetes.
- Registry Synchronization Synchronization product that mirrors the hardened image library into private OCI-compliant registries (AWS ECR, Azure ACR, Google Artifact Registry, JFrog Artifactory, Sonatype Nexus), with native air-gapped support. Sold to enterprise and government customers needing on-premises or disconnected deployments.
Quantifiable outcome
- 95%+ CVE elimination from software supply chains
- +4 more outcomes
Companies that use Minimus
Customer profileNamed customers14 records
Segments7 records
Ideal customer profiles4 records
Minimus technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
AI capability2 records
Feature6 records
Minimus partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core.
- Knox SystemscoreKnox and Minimus partnered to streamline secure software delivery for the U.S. Government by combining Knox's FedRAMP-ready cloud platform with Minimus's high-performance microservices infrastructure, enabling faster deployment of compliant applications for government customers.
- AWScoreAWS integration allows Minimus hardened images to be synced and deployed within AWS environments, with native compatibility for AWS security services.
- Google CloudcoreGoogle Cloud integration enables Minimus image deployment across Google Cloud Platform with native artifact registry support.
- WizcoreWiz integration provides security scanning and monitoring capabilities for Minimus container images within the Wiz cloud security platform.
Scale indicators6 records
Recent moves6 records
Expansion highlights5 records
Minimus competitors and assessment
Company assessmentEmerging players
- JFrog (JFrog Xray / Curation): Artifact management platform with Curation and Xray providing trusted container image distribution and security scanning. Overlaps with Minimus in registry sync, vulnerability detection, and DevSecOps workflows.
- Wiz: Cloud security platform with a partnership (and partial overlap) with Minimus. Wiz scans and monitors Minimus images within its CNAPP; broader overlap exists in cloud workload protection and image vulnerability context.
Direct peers
- Chainguard: Direct competitor offering minimal, hardened container images built from source with near-zero CVEs and Wolfi-based distroless base images. Closest comparable to Minimus in product, positioning, and enterprise compliance focus (FedRAMP, FIPS, STIG).
- Aqua Security: Established container security platform offering image scanning, runtime protection, and CI/CD security. Provides hardened base images as part of its broader platform, overlapping with Minimus's image-centric approach.
- Anchore: Container security and compliance platform providing image scanning, SBOM generation, and policy enforcement for enterprises, particularly in federal/regulated markets. Directly comparable to Minimus's compliance-driven positioning.
Broad incumbents
- Palo Alto Networks (Prisma Cloud / TwistLock): Owner of TwistLock (founded by Minimus's CEO Ben Bernstein). Offers Prisma Cloud for container and cloud-native security. Competes with Minimus through a broader CNAPP platform that includes image scanning, runtime defense, and CSPM.
- Snyk: Developer security platform with container and IaC scanning capabilities (Snyk Container). Competes with Minimus at the developer/CI layer for image vulnerability detection, though without a focused distroless image product.
- Docker (Docker Scout): Upstream provider of standard base images and Docker Scout vulnerability analysis. Competes indirectly through the ubiquity of Docker Official Images and built-in scanning, though without the distroless/zero-CVE posture.
- Red Hat (Red Hat Trusted Software Supply Chain): Provides trusted container images and supply chain security tooling (Sigstore, Red Hat Trusted Profile Analyzer) through the OpenShift and RHEL ecosystems. Competes in regulated/enterprise markets where Red Hat is already a standard.
Others
- Knox Systems: FedRAMP-ready cloud platform partnered with Minimus to streamline secure software delivery to U.S. Government. Comparable as a complementary go-to-market partner rather than a direct competitor.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Minimus social profiles
Digital presenceMinimus compliance and trust
Trust signalCompliance18 records
Minimus financial estimates
Financial estimateRevenue estimate
Valuation estimate
Minimus leadership team
Management profileNumber of profiles
Profiles4 records
Minimus funding detail
Funding detailFunding overview
Funding rounds1 record
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Minimus M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Minimus
What does Minimus do?
Minimus builds and distributes minimal, hardened, distroless container images directly from source, replacing bloated upstream base images used in CI/CD pipelines. The core offering is a library of over 1,200 signed container images (nginx, python, postgres, node, etc.) that ship with near-zero CVEs, are 90-95% smaller than standard images, and are rebuilt daily with the latest security patches. Enterprise customers pay for SLA-backed remediation, Image Creator, air-gapped registry sync, SBOM/provenance, and FedRAMP/FIPS/STIG compliance.
Is Minimus a public or private company?
Minimus is a private company. It is classified as venture growth investor backed and is currently operating.
When was Minimus founded?
Minimus was founded in 2025. It employs 51 to 100 people.
Where is Minimus based?
Minimus is headquartered in New York, United States, in the North America region.
How does Minimus make money?
Two revenue lines are on record. Community Edition is the primary driver. The others are enterprise Subscription.
Who are Minimus's main competitors?
Emerging players on record are JFrog (JFrog Xray / Curation) and Wiz. Direct peers are Chainguard, Aqua Security and Anchore. Broad incumbents are Palo Alto Networks (Prisma Cloud / TwistLock), Snyk, Docker (Docker Scout) and Red Hat (Red Hat Trusted Software Supply Chain). Knox Systems is listed as an others.
Does Minimus have an API?
No public API is recorded for Minimus.
What industry is Minimus in?
Minimus's product category is Container Security. Its primary akta.pro industry code is HDADACAE, Container & Kubernetes Application Security, with a secondary code of BPAEAKAI, DevSecOps & Supply Chain Security (DevOps toolchain security). Its NAICS code is 5132 and its SIC code is 7372.