Know which vulnerabilities actually matter to your device.

Ingest SBOMs from your build pipeline, match every component against known software in the NVD, and see each advisory ranked by whether it is genuinely being exploited. Then export the FDA-ready evidence in a click.

Features

Most SBOM tools give you volume. You need the short list.

The alert count is not the problem. The wrong alerts are.

Most tools match components loosely, and one bad match cascades. In independent testing a competitor mapped a single npm package to unrelated Adobe software and produced 31 irrelevant alerts from that one error. Matching every component against known software in the NVD, with alias rules for the ambiguous ones, is what keeps the queue worth reading.

An SBOM is never reviewed once

New advisories land against the SBOM you already have, and the dispositions you set import forward into the next version rather than being retyped. Alias and lifecycle rules apply themselves to every SBOM you have already uploaded and every one you upload later, so a new release means reviewing a short diff rather than the whole bill of materials.

Measured against the tools you would otherwise buy

In three head-to-head tests against Grype, Dependency Track and Blackduck, Medcrypt averaged 96% accuracy where those tools ranged from 63% to 92%, and matched all 117 components in the test SBOM. The platform is tuned by former FDA reviewers, so what it reports is what a reviewer expects to see.

How it runs

From build output to submission evidence.

Three stages, and the middle one is the product. Getting an SBOM in and getting a report out are table stakes; deciding which of two hundred advisories deserve your engineers' week is the work.

  1. However your SBOM is produced, it lands here.

    Push CycloneDX or SPDX from your build pipeline through the Helm API, a GitHub action, or the Azure DevOps extension, or upload one by hand. Every component is then matched against known software in the NVD, and alias rules resolve the ambiguous ones automatically across existing and future SBOMs. That matching step is where accuracy is won or lost: one component mapped to the wrong package is what turns into dozens of irrelevant alerts downstream.

    Components

    ComponentMatch status
    opensslMatched to NVD
    busyboxMatched to alias
    zlibMatched to CPE
    libwebpSelect match
    CycloneDX 1.3–1.5 and SPDX 2.2–2.3
  2. Exploitability evidence first, then your call.

    Every advisory arrives scored against EPSS, the CISA KEV list, the Exploit Database, Metasploit and the CWE Top 25, so you can see what is genuinely being exploited rather than sorting by CVSS alone. Impacted tech stacks narrow it further. Your team then sets the disposition, and marking something not affected asks for the justification that makes it defensible later.

    Vulnerabilities

    Vuln IDCVSSStatus
    CVE-2022-3602openssl7.5Exploitable
    CVE-2023-4863libwebp8.8Not affected
    CVE-2023-38545curl7.5In triage
    CVE-2023-44487nghttp27.5Not affected
    CVE-2024-2961glibc5.9Resolved
    214 advisories matched12 need action
  3. The submission artifact is a byproduct, not a project.

    Export the FDA-ready SBOM alongside VEX and VDR reports, for one product version or several at once. Each report is a snapshot in time kept in your report history, so an auditor asking what you knew last March gets an answer rather than a reconstruction. And as exploit maturity and fix availability change upstream, findings rescore themselves so the next report reflects it.

    Reports

    FDA-ready SBOM
    CycloneDX SBOM
    SPDX SBOM
    CycloneDX VEXExploitability statements
    CycloneDX VDRVulnerability disclosure report
    Report history
    Generate reports

What you get

What lands in your hands.

A component inventory that stays current

Every component across every product version, with license data, corrected CPEs and PURLs, and end-of-support metadata applied by rule rather than by hand.

A queue ranked by real risk

Advisories filtered by EPSS score, KEV listing and known exploit code, each carrying suggested short-term mitigations and specific upgrade recommendations, so triage starts with what is being exploited instead of with row one.

A hook into the build you already run

The Helm API, a GitHub action, and a Microsoft Azure DevOps extension, so a new build produces a new SBOM analysis without anyone remembering to start one.

Submission-ready reports on demand

The FDA-ready SBOM, CycloneDX and SPDX exports, VEX and VDR reports, for a single product or a whole portfolio, with a retained history for audits.

Know where you are in 1 hour.

Run the free check or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness