Features
Teams don't do this for the regulator.
The act of doing it is the win
Working through your architecture surfaces design weaknesses before a pen test or a field deployment finds them for you. Teams come out of the exercise with a better device, not just a better document.
Efficiency is how it scales
Scenarios and attack trees arrive drafted from your architecture instead of starting from a blank page, so one team can cover a whole portfolio without adding headcount to do it.
Compliance is the icing
Because the work is built to recognized methodologies and checked by former FDA reviewers, the submission artifact falls out of it. You do the engineering; the evidence is a by-product.
How we work with your team
Three steps, and your team keeps the last word.
You are not handing the work over. The platform does the drafting and the consistency checking; every judgment call stays with the people who know the device.
Bring the documents you already have.
You bring the architecture documents and system descriptions you already maintain. There is no new format to author first and no modelling tool to learn. Because the model is built from how the device is designed rather than from its source, it surfaces architectural weaknesses a code scan structurally cannot see.
Documents
Source documentStatusArchitectureParsedInterfacesParsedData flowsReadingExtracting assets and data-flow diagramDrafted from your architecture, then checked against itself.
Medcrypt drafts the scenarios and attack trees from that architecture, in the methodology your team already works in. Then it checks its own output: inconsistent scoring, structural gaps, and the mismatches an FDA reviewer tends to flag.
Threat register
IDThreatCheckT-001SClearT-002TScoreT-003IClearT-004EGapNothing lands until your team accepts it.
The run stops for review at every stage, so nothing enters the model until your team approves it. Once you have approved a stage your judgment stands: a later run proposes changes rather than overwriting what you decided. Our former FDA reviewers check the finished model for submission-readiness.
Threat model run
Assets extractedThreats identifiedRisks scoredControls mappedAwaiting reviewTraceability reportRequest changesApprove stage
What you get
What lands in your hands.
Accelerated drafting
- Scenarios and attack trees drafted from your architecture, in the methodology your team already works in.Explore automated threat model generation
Accuracy and consistency checks
- Flags inconsistent CVSS scoring, structural gaps, and mismatches with what reviewers expect to see.
Answers in plain language
- Ask questions of FDA cybersecurity guidance, vulnerability data, and threat intelligence without leaving the model.
Submission-ready export
- Structured output that drops into your ISO 14971 and AAMI SW96 templates, so the threat model feeds your security risk assessment rather than sitting beside it.