$5 a month
One plan with everything in it. No feature held back for a higher tier, because there isn't one.
For a practitioner, consultant or engineer who needs to know what actually affects the devices they work with.
- Dozens of sources read every day — the FDA, CISA, EU MDR/IVDR, the MHRA and IMDRF among them, plus standards bodies, notified bodies, sector councils and manufacturer PSIRTs, deduplicated into one feed and growing
- Human-reviewed summary and severity score on every item
- Up to 3 registered products, and what you are exposed to because of them
- Up to 7 tracked device categories
- Daily or weekly digest, and the obligations calendar
For a manufacturer or health delivery organization that needs advisories matched against the devices it actually ships or runs.
- Everything in Individual, for three of the team — and $7 a month for anyone after that
- Unlimited products, matched by CPE, purl, vendor and category
- SBOM upload (CycloneDX, SPDX, SWID or CSV) with component-level matching and end-of-life tracking
- An assessment written against your devices, not the general advisory
- Your policies, standards and operating guidance assessed for impact, with the section to review
- Priority alerts outside the digest when something critical matches
New accounts are closed while this deployment is being tested. If you were invited, use the link you were sent.
What you're paying for
Sources watched continuously. Regulators, standards bodies, sector coordinating councils and manufacturer PSIRTs — the FDA, CISA, the UK MHRA, EU MDR/IVDR, Health Canada and IMDRF among them, and the industry publishers that carry the rest. Each is polled on its own schedule and deduplicated, so an advisory cross-posted between three of them reaches you once, and a source can be added without waiting for a release.
A severity score with its reasoning shown. Each item is scored 0–100 on exploitability against clinical and operational consequence. The rationale is on the page, so you can disagree with it on the evidence rather than take it on faith.
A person between the agent and your inbox. Nothing is published until a reviewer has read the assessment against the source and approved it. That is the whole reason a summary here is worth reading.
A history you can search. Every digest is archived exactly as it was sent — not regenerated against today's data — so what you were told in March still reads the way it did in March.
The honest limits
Assessments are AI-assisted and human-reviewed. They support your regulatory judgment; they do not replace it, and nothing here is a compliance determination.
Individual accounts are scoped by device category, not by a registered portfolio. You will see what is relevant to the kinds of device you track, not a per-component match against your own bill of materials.