Know the moment it matters.
The FDA, CISA, IMDRF and EU MDR are where we start. GrapeBeaver reads them alongside dozens of other regulators, standards bodies, notified bodies and manufacturer advisories every day, and tells you what impacts your organization, your products, and the policies, standards and operating guidance you have already written — alongside the events shaping the industry you work in.
Accounts are by invitation while we are in testing — your code starts the trial, no card required.
Every item, scored, sourced — and answered once
One row per advisory, with everything it impacts and why: the products you ship, the obligations it changes for your organization, the policies, standards and operating guidance it bears on, and the industry events it belongs to. Answered once, by your team, in one place. Severity is the only thing on the page allowed to be loud — so when something is red, it means something.
Dentsply Sirona (manufactured by SDI Limited) issued an urgent recall for its Capsule Mixer, Model No. 5546068, due to a potential for electrical discharge from the unit when …
MHRA issued a Class 4 Medicines Defect Notification (EL(26)A/38) for Martindale Pharmaceuticals' Clobazam Martindale Pharma 5 mg/5 mL and 10 mg/5 mL Oral Suspension 150ml, covering batches 0162858, …
FDA published a final order denying a petition that had requested a partial exemption from premarket notification (510(k)) requirements for several generic device types: radiological computer-assisted diagnostic software …
FDA has announced a public meeting of the Microbiology Devices Panel of the Medical Devices Advisory Committee to discuss pathogen-agnostic sequencing for emergency preparedness and outbreak response, covering …
A match is not a claim that your product is affected. When an advisory names something you ship — by component, package, or vendor and product — the feed says so. When it does not, and we have matched on the kind of device or the kind of exposure, it says that instead: worth checking, not something you are affected by. Most advisories are about somebody else's device, and saying so plainly is the point.
One page: what is open, what to do, what is coming
Written once a day and read by your whole team: what may bear on your organization, what reached your products and your policies, standards and operating guidance and is still open, the dated obligations arriving in the next fortnight, and the events shaping the industry around them. Not a dashboard of counters — counters are how you check a feeling you already have.
Two advisories reached InfusionSuite Gateway; the FDA's updated premarket expectations name support-level information in the SBOM, which is the part your current submission pack does not carry.
Illustrative. The exposure board is derived from the products you register — no similarity score, nothing you cannot check and disagree with.
Your SBOM says what is inside. It does not say what is still supported.
A component does not have to be vulnerable to be a problem. It just has to stop being maintained — no CVE, no advisory, no notification. Regulators increasingly expect a manufacturer to know the support status of what they ship and to have a plan for when it ends, and that is not something a scanner tells you.
- Every component in every SBOM you upload is resolved against published end-of-life dates, release history and repository activity.
- A support status for every component, with the date behind it: still supported, end of life stated for a date, out of support, or no release in three years. The answer a reviewer, an auditor and a 524B submission all ask for.
- Sourced and dated, so it goes straight into your documentation. Each status names where it came from — the publisher's own end-of-life notice, the release history, the repository — and when it was checked.
- This is the number teams currently chase by hand across a dozen vendor pages, and the one regulators increasingly expect you to have an answer for.
Gathered, assessed, reviewed, sent
Every source, one feed
Regulators, standards bodies, sector coordinating councils and manufacturer PSIRTs — the FDA, CISA, the UK MHRA, EU MDR/IVDR, Health Canada and IMDRF among them, alongside the industry and trade publishers that carry what the regulators have not said yet. Finding the rest is a standing job rather than a finished list: we keep hunting for publishers worth watching, check each one before it goes in, and add it for everybody. Everything is normalised and deduplicated as it arrives, so a cross-posted advisory reaches you once. Vulnerability feeds (NVD, CISA KEV) are read as evidence for what is in your SBOM, not forwarded to you one CVE at a time; your scanner already does that better.
Scored on what it means for patients
Every item is summarised once and scored 0–100 on how exploitable it is against what happens clinically if it is — because a flaw in a firewall appliance and the same flaw in an infusion pump are not the same finding. The reasoning is on the page with the score, so you can check it against the source and disagree where you should.
A person signs off
Nothing reaches your inbox until someone has read the assessment against the source and approved it. That gate is not optional, and it is why a summary here means something. GrapeBeaver is built and run by product security professionals for product security professionals — the reviewer knows what a 524B submission needs, and reads it that way.
Digests that respect your inbox
Daily or weekly, at a time you choose. It leads with a one-line count, groups by severity with the most serious first, and links each item back to the full assessment.
- It arrives on your cadence even on a quiet week — carrying what is still open and what is coming, so silence never has to mean "nothing happened" or "something broke".
- Set a severity floor and never see below it.
- Every digest is archived and searchable, so "that thing from three weeks ago" is findable without digging through mail.
- No hero images. A compliance inbox is not the place for one.
One plan. Free to try.
Start with a free 14-day trial — no card required, every feature included. After that it is $29 a month for one person, with your SBOM read, your documents assessed and every product matched, and a few dollars for each colleague. No seat minimum.
For a manufacturer, health delivery organization or consultant that needs to know what bears on the products it actually ships or runs.
- Dozens of sources read every day — the FDA, CISA, EU MDR/IVDR, the MHRA and IMDRF among them, plus standards bodies, notified bodies, sector councils and manufacturer PSIRTs, deduplicated into one feed
- Human-reviewed summary and severity score on every item
- Unlimited products, matched by CPE, purl, vendor and category
- SBOM upload (CycloneDX, SPDX, SWID or CSV) with component-level matching and end-of-life tracking
- An assessment written against your products, not the general advisory
- Your policies, standards and operating guidance assessed for impact, with the section to review
- A daily briefing, digests, the obligations calendar and priority alerts
New accounts are by invitation while this deployment is being tested. If you were sent a code or an invitation link, use it here. An invitation code starts a trial of whatever length it was issued for, with no card.
GrapeBeaver Intelligence is operated by Matt Hillyer LLC, a Wisconsin limited liability company.
Have an invitation code?
Accounts are by invitation while we are in testing. Your code starts a free trial, no card required.
Redeem an invitation codeAssessments are AI-assisted and human-reviewed
Every summary and severity score is produced by an analysis agent and then read, corrected where needed, and approved by a person before it is published. GrapeBeaver surfaces intelligence for you to act on — it does not replace your own regulatory judgment, and it makes no compliance guarantee.