Know the moment it matters.
GrapeBeaver reads FDA, CISA, IMDRF, EU MDR and manufacturer advisories every day and tells you which kinds of regulatory and security pressure land on the products you actually ship — and which of them moved this week.
$5 a month. 14-day trial, no card required.
Every item, scored, sourced — and answered once
One row per advisory, with the products it reached, why it reached them, and where your team got to. Severity is the only thing on the page allowed to be loud — so when something is red, it means something.
The UK MHRA has issued a Device Safety Information notice covering multiple cobalt-chrome (Co-Cr) dual taper modular neck hip stem systems, following an earlier investigation into the Profemur …
Aligned Medical Solutions (manufactured by Windstone Medical Packaging) recalled 17 surgical convenience kits — including ENT, rhinoplasty, spine, septoplasty, laryngoscopy, and sinus packs — because they contain Medicom …
FDA has published a Paperwork Reduction Act notice seeking public comment on its proposed extension of a generic information collection covering focus groups and interviews used across all …
BIS issued a Proposed Charging Letter against Container Manufacturing Ltd., an Ohio-based supplier of can-end shell system equipment and spare parts, alleging ten violations of the Export Administration …
A match is not a claim that your product is affected. When an advisory names something you ship — by component, package, or vendor and product — the feed says so. When it does not, and we have matched on the kind of device or the kind of exposure, it says that instead: worth checking, not something you are affected by. Most advisories are about somebody else's device, and saying so plainly is the point.
One page: what is open, what to do, what is coming
A briefing written once a day, the work still open against your products, and the dated obligations landing in the next fortnight. Not a dashboard of counters — counters are how you check a feeling you already have.
Two advisories reached InfusionSuite Gateway; the FDA's updated premarket expectations name support-level information in the SBOM, which is the part your current submission pack does not carry.
Illustrative. The exposure board is derived from the products you register — no similarity score, nothing you cannot check and disagree with.
Your SBOM says what is inside. It does not say what is still supported.
A component does not have to be vulnerable to be a problem. It just has to stop being maintained — no CVE, no advisory, no notification. Regulators increasingly expect a manufacturer to know the support status of what they ship and to have a plan for when it ends, and that is not something a scanner tells you.
- Every component in every SBOM you upload is resolved against published end-of-life dates, release history and repository activity.
- A publisher's stated end of life outranks three years of silence — it is better evidence, and the action is the same.
- Labels say what was measured. "No release in 3 years", never "Abandoned" — log4j-core's newest release is recent and it is not abandoned.
Gathered, assessed, reviewed, sent
Every source, one feed
Regulators, standards bodies, sector coordinating councils and manufacturer PSIRTs — the FDA, CISA, the UK MHRA, EU MDR/IVDR, Health Canada and IMDRF among them, alongside the industry and trade publishers that carry what the regulators have not said yet. Anything that publishes into this space can be added as a source, so the list grows rather than being the five names on a slide. Everything is normalised and deduplicated as it arrives, so a cross-posted advisory reaches you once. Vulnerability feeds (NVD, CISA KEV) are read as evidence for what is in your SBOM, not forwarded to you one CVE at a time; your scanner already does that better.
A score you can argue with
Each item gets one summary and a 0–100 impact score weighing exploitability against clinical consequence — with the reasoning shown, so you can disagree on the evidence rather than take it on trust.
A person signs off
Nothing reaches your inbox until someone has read the assessment against the source and approved it. That gate is not optional, and it is why a summary here means something.
Digests that respect your inbox
Daily or weekly, at a time you choose. It leads with a one-line count, groups by severity with the most serious first, and links each item back to the full assessment.
- Nothing new means nothing sent — an empty digest is just noise.
- Set a severity floor and never see below it.
- Every digest is archived and searchable, so "that thing from three weeks ago" is findable without digging through mail.
- No hero images. A compliance inbox is not the place for one.
Two plans. No seat minimum.
Start on your own for $5 a month with three registered products. Move up when you need your SBOM read, your documents assessed, and your team on it — from a single seat.
For a practitioner, consultant or engineer who needs to know what actually affects the devices they work with.
- Every source — regulators, standards bodies and manufacturer PSIRTs, from the FDA and CISA to EU MDR/IVDR, the MHRA and IMDRF
- Human-reviewed summary and severity score on every item
- Up to 3 registered products, and what you are exposed to because of them
- Up to 7 tracked device categories
- Daily or weekly digest, and the obligations calendar
For a manufacturer or health delivery organization that needs advisories matched against the devices it actually ships or runs.
- Everything in Individual, for three of the team — and $7 a month for anyone after that
- Unlimited products, matched by CPE, purl, vendor and category
- SBOM upload (CycloneDX, SPDX or CSV) with component-level matching and end-of-life tracking
- An assessment written against your devices, not the general advisory
- Your policies and SOPs assessed for impact, with the section to review
- Priority alerts outside the digest when something critical matches
New accounts are closed while this deployment is being tested. If you were invited, use the link you were sent.
Running a fleet across multiple sites, or need API access, SSO and your own risk framework? Get in touch.
Assessments are AI-assisted and human-reviewed
Every summary and severity score is produced by an analysis agent and then read, corrected where needed, and approved by a person before it is published. GrapeBeaver surfaces intelligence for you to act on — it does not replace your own regulatory judgment, and it makes no compliance guarantee.