
Supply Chain SecurityCyber-Physical Systems (CPS) Security
Threat Detective
Validates medical device SBOMs, triages component CVEs, and produces FDA eSTAR submission evidence.
Threat Detective Overview
What it does
Threat Detective is a Software Bill of Materials (SBOM) management and vulnerability documentation platform built for medical device manufacturers rather than software development teams. It takes the CycloneDX or SPDX SBOM a device team already produces, validates it against the NTIA minimum elements, matches every component to known vulnerabilities, and turns the resulting exploitability decisions into the cybersecurity evidence that FDA premarket reviewers and EU Notified Bodies expect, then keeps that evidence current through post-market surveillance of every fielded software version.
How it works
The platform ingests the Software Bill of Materials (SBOM) a team already produces, validates supplier, version, identifier, and dependency fields, and pulls component end-of-life dates from endoflife.date. Components are matched daily against the National Vulnerability Database, GitHub Security Advisories, and OSV, merging duplicates into one triage queue. Analysts prioritise with CVSS, EPSS, and CISA Known Exploited Vulnerabilities (KEV) data, record exploitability and compensating controls once across all affected versions, and a later KEV listing reopens a closed decision. Outputs include FDA eSTAR cybersecurity sections, EU Notified Body summaries, enriched SBOMs, and Vulnerability Exploitability eXchange (VEX) statements on a hosted portal.
Credentials and traction
Threat Detective publishes a vulnerability disclosure policy aligned with the NCSC toolkit and ISO/IEC 29147 and its own Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) statements through the same hosted transparency portal customers receive. It is UK GDPR and EU GDPR compliant with a Data Processing Addendum, hosts standard-plan customer data in Germany, and processes no protected health information. The product targets medical device manufacturers preparing 510(k), De Novo, PMA, and EU MDR or IVDR submissions.
Key Capabilities
mapped to solution categoriesGenerates or ingests machine-readable SBOMs for medical devices (CycloneDX, SPDX) covering commercial, open-source and off-the-shelf components, and keeps them current per device model and software version. Serves a manufacturer documenting its own device portfolio for premarket submissions and postmarket management, and a healthcare provider tracking component vulnerabilities across the devices it operates. Required of cyber devices by FD&C Act section 524B and expected under EU MDR.
Assembles the cybersecurity documentation a premarket submission needs (security risk management report, threat model, security architecture views, SBOM, a cybersecurity management plan with vulnerability monitoring sources and patch release timelines, and labeling) in the structure the FDA premarket cybersecurity guidance and FD&C Act section 524B expect, and maps the same evidence to EU MDR cybersecurity requirements for devices sold in Europe.
Records the support level and end-of-support date of every software component in a device SBOM (actively maintained, no longer maintained, abandoned) and checks them against the years the device is expected to stay on the market, so a manufacturer can supply the per-component support information a premarket submission needs and plan replacements before a component loses support during the device lifetime.
Continuously rechecks the components in a manufacturer's device SBOMs against vulnerability and exploit intelligence (the NVD, EPSS, the CISA Known Exploited Vulnerabilities catalog and exploit databases), records an exploitability decision for each finding in the context of the device, and produces VEX and vulnerability disclosure report (VDR) documents that evidence the postmarket vulnerability monitoring plan FD&C Act section 524B requires of cyber devices and that EU MDR post-market surveillance expects.
Creates, imports, and manages Vulnerability Exploitability eXchange statements asserting the exploitability status of CVEs for specific product versions, reducing false positive noise for downstream consumers.
Normalizes ingested SBOMs to the CISA minimum elements by resolving missing or inaccurate component identifiers such as PURL and CPE and dependency relationships, and enriches components with license, supplier and support metadata, so SBOMs from any generator can be analyzed for third-party risk consistently.
Generates formatted evidence packages for SBOM-related regulatory requirements: FDA pre-market cybersecurity guidance, Executive Order 14028 SBOM requirements, EU Cyber Resilience Act Article 13.
Validates imported SBOMs against minimum-element requirements (NTIA baseline and successor CISA guidance), flagging missing supplier names, versions, unique identifiers, and dependency relationships before the SBOM is exchanged or submitted as regulatory evidence. Checks declared data-field completeness rather than verifying declarations against compiled binaries.
Tracks the support level and end-of-support date of each SBOM component, flagging components that will lose security maintenance while the product is still on the market. Covers the two per-component elements FDA premarket cybersecurity guidance requires beyond the NTIA baseline.
Manages the SBOM life cycle including discovery, access and secure exchange between software suppliers and consumers.
Monitors SBOMs against live vulnerability feeds, alerts when new CVEs affect components in managed SBOMs. Latency to alert after new CVE publication varies.
Imports and exports SBOMs in CycloneDX, SPDX, and SWID formats, enabling interoperability with scan tools, procurement workflows, and regulatory evidence systems.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 8, 2026
Buyers
See how Threat Detective fits your stack
Add Threat Detective to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.