Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AIData Security

NanoClaw and Echo Launch Hardened AI Agent Runtime


NanoClaw and Echo Launch Hardened AI Agent Runtime
  • by: PR Newswire
  • |
  • July 31, 2026

NanoClaw and Echo have partnered to introduce a hardened runtime for AI agents, aiming to improve software security for open source AI agent deployments. The collaboration combines NanoClaw's secure AI agent framework with Echo's vulnerability-free application infrastructure to create a runtime environment that minimizes software vulnerabilities while supporting enterprise AI adoption.

Quick Intel

  • NanoClaw and Echo launch a hardened runtime for AI agents.
  • Partnership introduces the first hardened environment for an open source AI agent framework.
  • Echo rebuilds the agent runtime to reduce known software vulnerabilities to near zero.
  • Hardened runtime includes Chromium, Node, Bun, pnpm, Git, Curl, and other essential components.
  • NanoClaw users can opt into the secure runtime at no additional cost with authentication.
  • Collaboration strengthens AI agent security, software supply chain protection, and enterprise AI deployments.

NanoClaw and Echo Partner to Strengthen AI Agent Security

NanoClaw and Echo have announced a strategic partnership focused on improving the security of AI agent environments. By integrating Echo's hardened application infrastructure into NanoClaw's open source AI agent framework, the companies aim to provide developers with a more secure foundation for deploying AI agents in enterprise environments.

The announcement marks the first time an open source AI agent framework has offered a hardened runtime designed to secure not only AI agent behavior but also the underlying software environment where agents execute tasks. NanoClaw has gained significant adoption since its open source release, surpassing 30,000 GitHub stars and 250,000 downloads while being used by organizations including Amazon, Gap, Google, Meta, SentinelOne, and Accenture.

Addressing Software Vulnerabilities in AI Agent Environments

AI agents routinely perform tasks such as browsing websites, accessing files, executing code, and interacting with enterprise applications. While isolation techniques help restrict agent access, they do not eliminate vulnerabilities within browsers, system libraries, language runtimes, or software dependencies that agents rely on.

According to the companies, these software components often contain thousands of known vulnerabilities that can expose sensitive data or compromise AI agents through techniques such as prompt injection or malicious file execution.

Gavriel Cohen, co-founder and CEO of NanoCo, said, "For years the industry has tolerated known vulnerabilities sitting unpatched, because exploiting them took a serious attacker and most systems were never worth the effort. A modern prompt injection is like a social engineering attack: it lures the agent to an innocent-looking page, and a known hole in the browser turns that visit into a compromise. Or it hands the agent a file, and a vulnerable parser turns opening it into code execution. NanoClaw tackled agent isolation, access control, and human approval on sensitive actions, allowing hundreds of thousands of people to use agents for real work. We're now making sure the software the agents use carries no known holes, the same way you keep an employee's laptop and browser patched."

Hardened Runtime Reduces Software Supply Chain Risk

The jointly developed runtime combines NanoClaw's policy enforcement, agent isolation, and access controls with Echo's approach to rebuilding software components from scratch using only essential packages. This process reduces the number of known vulnerabilities from thousands to near zero while preserving compatibility for developers.

The hardened runtime includes core technologies commonly used by AI agents, including Chromium, Node, Bun, pnpm, Corepack, Git, Curl, and Unzip. Echo will host and continuously maintain the runtime, while NanoClaw users can enable it during setup with a simple authenticated login. Developers who prefer local builds can continue using the existing self-managed runtime.

Eylam Milner, co-founder and CTO of Echo, said, "An agent reaches the world through a browser, a set of parsers, and dozens of libraries, which can all carry known vulnerabilities. The standard software agents are built on carries thousands, and most come from the underlying layers, not the application code. We rebuild that whole environment as a drop-in replacement so it starts secure, and our agents keep it that way as new vulnerabilities appear."

AI-Powered Maintenance for Secure Software

Echo's platform uses AI agents to continuously monitor newly disclosed software vulnerabilities, identify affected components, develop or locate fixes, perform compatibility testing, and generate pull requests for human review. This automated process enables the company to maintain secure containers, operating system packages, software libraries, and application dependencies at scale.

The hardened NanoClaw runtime is now available to the open source community, providing developers with a more secure environment for deploying AI agents while helping organizations reduce software supply chain risks and strengthen enterprise AI security.

About NanoClaw

NanoClaw is the secure open source AI agent framework created by NanoCo, with more than 250,000 downloads and 30,000 GitHub stars. NanoCo delivers a professional assistant to every employee inside the tools they already use, with each agent running in its own sandbox, credentials injected at runtime through a policy-enforcing gateway, human approval on sensitive actions, and full auditability. Based in Tel Aviv, NanoCo was founded in 2026 and is backed by Valley Capital Partners, Docker, Vercel, Monday.com, Slow Ventures and others.

About Echo

Echo is building the trusted source for secure software. Its AI-powered platform continuously rebuilds and maintains secure artifacts, eliminating known vulnerabilities before they reach production. By providing organizations with a trusted source for the software they already depend on, Echo helps customers including Varonis, EDB, Webflow, and UiPath reduce software supply chain risk without slowing development. Founded by Eilon Elhadad and Eylam Milner, veterans of Israel's Unit 8200 and the IAF's Ofek unit, who previously sold their software supply chain security company Argon to Aqua Security, Echo raised $50 million within 10 months of founding.

  • Agentic AIOpen Source AICyber SecuritySoftware Supply ChainAI Security
News Disclaimer
  • Share