Listen to this Post

In an industry overwhelmed by reactive tools and vulnerability scanners, a new startup is turning heads by proposing a radical change in how we approach software security. Minimus—formerly known as Gutsy—has officially emerged from stealth, introducing a bold preventive approach to software vulnerability management. Created by the original minds behind Twistlock, this venture doesn’t just patch flaws; it aims to eliminate them altogether.
The founders of Twistlock are back—this time under a new banner and a refined vision. Minimus, the newly rebranded version of Gutsy, has launched with the ambitious goal of wiping out 95% of software vulnerabilities before they even reach production environments.
Ben Bernstein, Dima Stopel, and John Morello, the trio behind the container security powerhouse Twistlock, have returned to the cybersecurity arena with a strong pedigree. Their previous company was acquired by Palo Alto Networks for $410 million, and with Minimus, they are aiming to upend traditional approaches to software risk management.
Since its quiet founding in late 2022, Minimus has already drawn significant attention, securing $51 million in a seed round from YL Ventures and Mayfield—an unusually high amount for a seed-stage startup. Their early success suggests growing investor confidence in the emerging concept of “preventive cybersecurity.”
Rather than relying on reactive scanning tools to catch vulnerabilities post-deployment, Minimus is betting on a preventive model. Its solution involves providing minimal, tightly controlled container images and virtual machines that are designed from the ground up to exclude most known vulnerabilities. According to the startup, this architectural shift can eliminate more than 95% of the Common Vulnerabilities and Exposures (CVEs) found in traditional setups.
This debut couldn’t be more timely. Software supply chain attacks—from the infamous SolarWinds hack to the widespread Log4j vulnerability—have revealed how fragile and insecure the foundational layers of modern IT infrastructure can be. In the face of growing threats and complex cloud-native environments, security leaders are actively searching for proactive solutions.
Minimus differentiates itself by addressing the software foundation, where many issues begin. Instead of layering more detection tools on top of vulnerable codebases, it rebuilds the environment to be secure by design. This minimalist approach to containers and virtual machines significantly reduces the attack surface.
The idea of “security from the start” isn’t new—but its implementation at scale has remained elusive. Minimus is gambling that its technology can finally deliver on that promise, offering organizations a way to adopt secure infrastructure without overhauling their existing workflows.
The company’s vision represents a pivot from detection to prevention, one that could redefine cybersecurity practices in DevOps and cloud-native development. While adoption remains to be seen, the startup’s early momentum, experienced team, and sizable funding round suggest that the industry is paying close attention.
What Undercode Say:
Minimus is not just another cybersecurity
Here’s a detailed breakdown of what makes Minimus noteworthy and how it aligns with broader trends:
- Founders with Proven Credentials: The same team that led Twistlock—once the benchmark in container security—is behind this new venture. Their success story and exit to Palo Alto Networks give Minimus instant credibility in the cybersecurity ecosystem.
-
High-Confidence Seed Round: A $51 million seed investment is nearly unprecedented. It reflects investor confidence not just in the team, but in the shift toward prevention-based security. YL Ventures and Mayfield are both highly specialized in cybersecurity, signaling strategic backing.
-
Minimal Images = Minimal Risk: By delivering ultra-slim containers and VMs stripped of unnecessary libraries and components, Minimus reduces the surface area for attacks. Fewer dependencies mean fewer entry points for adversaries.
-
Aligns with SBOM Trends: As Software Bill of Materials (SBOM) mandates grow, organizations are being forced to track every component in their systems. Minimus simplifies this burden by shrinking what needs to be tracked in the first place.
-
Supply Chain Security in the Spotlight: Post-SolarWinds and Log4j, enterprises are no longer just looking at their code—they’re scrutinizing the entire supply chain. Minimus positions itself as a front-line defense by securing the base layers of software environments.
-
Reduced Operational Overhead: Most security platforms require continuous patching and monitoring. Minimus cuts down that effort by making systems secure by design, not by continuous intervention.
-
Scalability with DevOps Practices: Their approach integrates well with cloud-native and containerized pipelines. It allows DevOps teams to maintain velocity while reducing risk—an appealing balance for fast-moving tech companies.
-
Build Once, Secure Forever: Unlike tools that rely on scanning and fixing, Minimus promotes a “build secure” philosophy. This long-term thinking could save organizations millions in patching and breach remediation.
-
Risk Transfer vs. Risk Elimination: Traditional tools transfer or mitigate risk (e.g., through detection, alerts, and patches). Minimus attempts to eliminate it at the root, offering a potentially revolutionary value proposition.
-
Potential Compliance Impact: In highly regulated industries, having a reduced CVE footprint could simplify audits and compliance processes—especially with emerging regulations around secure software development.
In sum, Minimus represents a promising leap forward for companies tired of playing defense in an endless cat-and-mouse game with attackers. Its approach, while not entirely new in concept, could be transformative in execution—particularly if widely adopted across cloud infrastructure and development pipelines.
Fact Checker Results:
- The $51 million seed round was verified through public announcements from YL Ventures and Mayfield.
- The founding team’s connection to Twistlock and its acquisition by Palo Alto Networks is well-documented.
- Claims of reducing 95% of CVEs align with Minimus’ own marketing materials, but lack independent third-party verification as of now.
Would you like a visual breakdown or diagram of Minimus’ architecture to include in your post?
References:
Reported By: calcalistechcom_dafdc21ee476190a8196cfe7
Extra Source Hub:
https://www.medium.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




