$20 a month

One plan with everything in it. No feature held back for a higher tier, because there isn't one.

Individual

For a practitioner, consultant or engineer who needs to know what actually affects the devices they work with.

  • Every source — FDA recalls and MAUDE, CISA ICS-CERT, NVD/CVE, IMDRF, EU MDR/IVDR, manufacturer PSIRT
  • Human-reviewed summary and severity score on every item
  • Up to 7 tracked device categories
  • Daily or weekly digest, your choice of time
  • Searchable history of everything you were sent

New accounts are closed while this deployment is being tested. If you were invited, use the link you were sent.

Running a fleet across multiple sites, or need API access, SSO and your own risk framework? Talk to us about Enterprise.

What you're paying for

Sources watched continuously. FDA recalls and MAUDE, CISA ICS-CERT, NVD/CVE, IMDRF, EU MDR/IVDR and manufacturer PSIRT bulletins — polled on their own schedules and deduplicated, so an advisory cross-posted between three of them reaches you once.

A severity score with its reasoning shown. Each item is scored 0–100 on exploitability against clinical and operational consequence. The rationale is on the page, so you can disagree with it on the evidence rather than take it on faith.

A person between the agent and your inbox. Nothing is published until a reviewer has read the assessment against the source and approved it. That is the whole reason a summary here is worth reading.

A history you can search. Every digest is archived exactly as it was sent — not regenerated against today's data — so what you were told in March still reads the way it did in March.

Bigger than one person?

Teams tracking a real device or SBOM portfolio need advisories matched against their actual components rather than category interests, plus seats, priority alerts and API access. That is set up per organization rather than sold from a page — tell us what you're tracking.

The honest limits

Assessments are AI-assisted and human-reviewed. They support your regulatory judgment; they do not replace it, and nothing here is a compliance determination.

Individual accounts are scoped by device category, not by a registered portfolio. You will see what is relevant to the kinds of device you track, not a per-component match against your own bill of materials.