Regulatory intelligence for medical device & software security

Know the moment it matters.

GrapeBeaver watches FDA, CISA, NVD, IMDRF, and manufacturer advisories continuously, and tells you exactly what's relevant to the devices you actually ship.

$20 a month. 14-day trial, no card required.

FDA · CLASS II RECALL  ·  CISA · ICS-CERT ADVISORY  ·  NVD · CVE-2026-41287  ·  IMDRF · GUIDANCE UPDATE

Every item, scored and sourced

Reverse-chronological, filtered to the device categories you track. Severity is the only thing on the page allowed to be loud — so when something is red, it means something.

grapebeaver.io/app/feed
Critical · 92 CISA — ICS medical advisories · 12 Aug 2026 ICSMA-26-198-01
Hardcoded credentials in radiotherapy treatment planning system

Successful exploitation could allow an attacker with network access to read or alter treatment plan data. The vendor has released a version removing the credentials and recommends network segmentation where updating is not immediate.

RadiotherapyNetwork-connected device infrastructure
Medium · 55 FDA — device recalls · 11 Aug 2026 Z-1842-2026
Class II recall: patient monitor alarm may not sound at configured threshold

Under a specific combination of alarm profile settings, the audible alarm may not sound when a physiological parameter crosses its threshold. A corrective software update is being issued.

Patient monitoring
6
Sources watched continuously
41
Device categories in the taxonomy
100%
Items read by a person before you see them

Gathered, assessed, reviewed, sent

01 · GATHER

Every source, one feed

FDA recalls and MAUDE reports, CISA ICS-CERT, NVD/CVE, IMDRF, EU MDR/IVDR, and manufacturer PSIRT bulletins — normalized and deduplicated as they publish, so a cross-posted advisory reaches you once.

02 · ASSESS

A score you can argue with

Each item gets one summary and a 0–100 impact score weighing exploitability against clinical consequence — with the reasoning shown, so you can disagree on the evidence rather than take it on trust.

03 · REVIEW

A person signs off

Nothing reaches your inbox until someone has read the assessment against the source and approved it. That gate is not optional, and it is why a summary here means something.

Digests that respect your inbox

Daily or weekly, at a time you choose. It leads with a one-line count, groups by severity with the most serious first, and links each item back to the full assessment.

  • Nothing new means nothing sent — an empty digest is just noise.
  • Set a severity floor and never see below it.
  • Every digest is archived and searchable, so "that thing from three weeks ago" is findable without digging through mail.
  • No hero images. A compliance inbox is not the place for one.
See a full sample
GRAPEBEAVER DAILY DIGEST
3 new items, 1 at high or critical severity.
Critical
Hardcoded credentials in radiotherapy planning system
CISA · 12 Aug
Medium
Class II recall: patient monitor alarm threshold
FDA · 11 Aug
Low
MDCG guidance on cybersecurity under MDR Annex I
EU MDR · 10 Aug

One plan. No tiers to decode.

Individual

For a practitioner, consultant or engineer who needs to know what actually affects the devices they work with.

  • Every source — FDA recalls and MAUDE, CISA ICS-CERT, NVD/CVE, IMDRF, EU MDR/IVDR, manufacturer PSIRT
  • Human-reviewed summary and severity score on every item
  • Up to 7 tracked device categories
  • Daily or weekly digest, your choice of time
  • Searchable history of everything you were sent

New accounts are closed while this deployment is being tested. If you were invited, use the link you were sent.

Running a fleet across multiple sites, or need API access, SSO and your own risk framework? Talk to us about Enterprise.

Assessments are AI-assisted and human-reviewed

Every summary and severity score is produced by an analysis agent and then read, corrected where needed, and approved by a person before it is published. GrapeBeaver surfaces intelligence for you to act on — it does not replace your own regulatory judgment, and it makes no compliance guarantee.