Features
Most tools check your package against the regulation. We check it against how the regulation is enforced.
The actual gap, against the actual rule
Findings are phrased the way a reviewer phrases them, and each one cites the requirement it maps to and the evidence behind it. No vague “improve your documentation”, and where the support for a finding is not there, the report says so.
Graded against how the rule is enforced
The checks reflect what FDA is actually catching, rejecting, and requiring, not just what the written guidance says. That is the difference between checking your package against the regulation and checking it against the way the regulation is applied.
One connected package
The scan reads your threat model, risk assessment, and SBOM as one body of evidence, the same way a reviewer does. Gaps between documents surface, not just gaps within them.
How we work with your team
Three steps, and the last one is a conversation.
The scan does the comparing. What makes a findings report useful is the part after it, when someone who has run these reviews tells you which findings would actually have held your submission.
Bring the package you already have.
Upload your submission documents or pull them from the collections you already keep. There is no reformatting to do first and no new template to author. Your threat model, risk assessment, and SBOM go in as they are.
Documents
Source documentStatusArchitectureParsedInterfacesParsedData flowsReadingExtracting assets and data-flow diagramEvery gap, filed where a reviewer would look for it.
Your design and documentation are compared against the requirements a reviewer actually applies, and each gap is filed into the eSTAR section your submission will move through. Findings come back ranked by severity, so the ones that could genuinely hold your submission surface first instead of sitting in a queue beside the wording fixes.
Findings
FindingeSTAR sectionCitesSeverityCybersecurity3CriticalRisk analysis5MajorSBOM7MajorLabeling9MinorChecking against FDA premarket requirementsA person decides what is worth your time.
Former FDA reviewers work through the findings with you. They separate the real risks from the noise, so a long report becomes a short list, and they help you shape the response you will actually file.
Findings review
CriticalRemediationMajorRemediationMajorIn reviewMinorNot a gapTriaged with former FDA reviewers
What you get
What lands in your hands.
A reviewer-style findings report
- The gaps a reviewer would raise, each ranked Critical, Major, or Minor and written the way a deficiency is written, with the requirement it cites attached.
Readiness by eSTAR section
- Where each part of your submission stands against the structure it will be reviewed in, so you can see which sections are ready to file and which still owe evidence.
Gap tracking and remediation
- Each finding stays open until it is closed or dismissed with a reason, so a package that has been worked through can be told apart from one that has only been scanned.
Traceable evidence, end to end
- Every finding shows the evidence behind it, verified against your documents or flagged plainly when the support is missing, so you and your regulators can audit why the platform said what it said. Run the same scan on every device, not just the one with a deadline.