Security Stack Logo
Threat Detective logo

Supply Chain SecurityCyber-Physical Systems (CPS) Security

Threat Detective

Validates medical device SBOMs, triages component CVEs, and produces FDA eSTAR submission evidence.

Threat Detective Overview

What it does

Threat Detective is a Software Bill of Materials (SBOM) management and vulnerability documentation platform built for medical device manufacturers rather than software development teams. It takes the CycloneDX or SPDX SBOM a device team already produces, validates it against the NTIA minimum elements, matches every component to known vulnerabilities, and turns the resulting exploitability decisions into the cybersecurity evidence that FDA premarket reviewers and EU Notified Bodies expect, then keeps that evidence current through post-market surveillance of every fielded software version.

How it works

The platform ingests the Software Bill of Materials (SBOM) a team already produces, validates supplier, version, identifier, and dependency fields, and pulls component end-of-life dates from endoflife.date. Components are matched daily against the National Vulnerability Database, GitHub Security Advisories, and OSV, merging duplicates into one triage queue. Analysts prioritise with CVSS, EPSS, and CISA Known Exploited Vulnerabilities (KEV) data, record exploitability and compensating controls once across all affected versions, and a later KEV listing reopens a closed decision. Outputs include FDA eSTAR cybersecurity sections, EU Notified Body summaries, enriched SBOMs, and Vulnerability Exploitability eXchange (VEX) statements on a hosted portal.

Credentials and traction

Threat Detective publishes a vulnerability disclosure policy aligned with the NCSC toolkit and ISO/IEC 29147 and its own Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) statements through the same hosted transparency portal customers receive. It is UK GDPR and EU GDPR compliant with a Data Processing Addendum, hosts standard-plan customer data in Germany, and processes no protected health information. The product targets medical device manufacturers preparing 510(k), De Novo, PMA, and EU MDR or IVDR submissions.

Key Capabilities

mapped to solution categories
Medical Device Security

Generates or ingests machine-readable SBOMs for medical devices (CycloneDX, SPDX) covering commercial, open-source and off-the-shelf components, and keeps them current per device model and software version. Serves a manufacturer documenting its own device portfolio for premarket submissions and postmarket management, and a healthcare provider tracking component vulnerabilities across the devices it operates. Required of cyber devices by FD&C Act section 524B and expected under EU MDR.

Assembles the cybersecurity documentation a premarket submission needs (security risk management report, threat model, security architecture views, SBOM, a cybersecurity management plan with vulnerability monitoring sources and patch release timelines, and labeling) in the structure the FDA premarket cybersecurity guidance and FD&C Act section 524B expect, and maps the same evidence to EU MDR cybersecurity requirements for devices sold in Europe.

Records the support level and end-of-support date of every software component in a device SBOM (actively maintained, no longer maintained, abandoned) and checks them against the years the device is expected to stay on the market, so a manufacturer can supply the per-component support information a premarket submission needs and plan replacements before a component loses support during the device lifetime.

Continuously rechecks the components in a manufacturer's device SBOMs against vulnerability and exploit intelligence (the NVD, EPSS, the CISA Known Exploited Vulnerabilities catalog and exploit databases), records an exploitability decision for each finding in the context of the device, and produces VEX and vulnerability disclosure report (VDR) documents that evidence the postmarket vulnerability monitoring plan FD&C Act section 524B requires of cyber devices and that EU MDR post-market surveillance expects.

SBOM Management

Creates, imports, and manages Vulnerability Exploitability eXchange statements asserting the exploitability status of CVEs for specific product versions, reducing false positive noise for downstream consumers.

Normalizes ingested SBOMs to the CISA minimum elements by resolving missing or inaccurate component identifiers such as PURL and CPE and dependency relationships, and enriches components with license, supplier and support metadata, so SBOMs from any generator can be analyzed for third-party risk consistently.

Generates formatted evidence packages for SBOM-related regulatory requirements: FDA pre-market cybersecurity guidance, Executive Order 14028 SBOM requirements, EU Cyber Resilience Act Article 13.

Validates imported SBOMs against minimum-element requirements (NTIA baseline and successor CISA guidance), flagging missing supplier names, versions, unique identifiers, and dependency relationships before the SBOM is exchanged or submitted as regulatory evidence. Checks declared data-field completeness rather than verifying declarations against compiled binaries.

Tracks the support level and end-of-support date of each SBOM component, flagging components that will lose security maintenance while the product is still on the market. Covers the two per-component elements FDA premarket cybersecurity guidance requires beyond the NTIA baseline.

Manages the SBOM life cycle including discovery, access and secure exchange between software suppliers and consumers.

Monitors SBOMs against live vulnerability feeds, alerts when new CVEs affect components in managed SBOMs. Latency to alert after new CVE publication varies.

Imports and exports SBOMs in CycloneDX, SPDX, and SWID formats, enabling interoperability with scan tools, procurement workflows, and regulatory evidence systems.

Compliance

certifications
GDPR

Integrations

compatible tools
CISA KEVendoflife.dateEPSSGitHub Security AdvisoriesGoogle WorkspaceMicrosoft Entra IDNVDOktaOSV

Implementation & support

Deployment model
Private CloudSaaS
Support channels
Customer Success Manager (CSM)Email SupportKnowledge Base

Info last updated on September 8, 2026

Buyers

See how Threat Detective fits your stack

Add Threat Detective to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.