Regulatory intelligence for medical device & software security

Know the moment it matters.

GrapeBeaver reads FDA, CISA, IMDRF, EU MDR and manufacturer advisories every day and tells you which kinds of regulatory and security pressure land on the products you actually ship — and which of them moved this week.

$5 a month. 14-day trial, no card required.

Every item, scored, sourced — and answered once

One row per advisory, with the products it reached, why it reached them, and where your team got to. Severity is the only thing on the page allowed to be loud — so when something is red, it means something.

grapebeaver.io/app/impact · News feed
Medium · 55 UK MHRA — Medical Device Alerts · 26 Aug 2026
Cobalt-chrome modular neck hip replacements: risk of metal-wear effects and revision surgery (D…

The UK MHRA has issued a Device Safety Information notice covering multiple cobalt-chrome (Co-Cr) dual taper modular neck hip stem systems, following an earlier investigation into the Profemur …

Privacy and data protectionRegulatory guidanceImaging systems
Medium · 40 FDA — device recalls · 8 Jun 2026 99323
FDA recall: AMS ALIGNED MEDICAL SOLUTIONS medical convenience kits labeled as: 1) ENT Pack, Par…

Aligned Medical Solutions (manufactured by Windstone Medical Packaging) recalled 17 surgical convenience kits — including ENT, rhinoplasty, spine, septoplasty, laryngoscopy, and sinus packs — because they contain Medicom …

Imaging systems
Low · 2 Federal Register — FDA medical devices · 28 Aug 2026 2026-17598
Agency Information Collection Activities; Proposed Collection; Comment Request; Focus Groups an…

FDA has published a Paperwork Reduction Act notice seeking public comment on its proposed extension of a generic information collection covering focus groups and interviews used across all …

Laboratory automation and LIS
Low BIS — Entity List Updates · 28 Aug 2026 watch-8b41bf97a6862c6e
Department of Commerce Homepage Email notifications Regulations Licensing Learn & Support News …

BIS issued a Proposed Charging Letter against Container Manufacturing Ltd., an Ohio-based supplier of can-end shell system equipment and spare parts, alleging ten violations of the Export Administration …

Laboratory automation and LIS

A match is not a claim that your product is affected. When an advisory names something you ship — by component, package, or vendor and product — the feed says so. When it does not, and we have matched on the kind of device or the kind of exposure, it says that instead: worth checking, not something you are affected by. Most advisories are about somebody else's device, and saying so plainly is the point.

71
Sources watched continuously
41
Device categories in the taxonomy
100%
Items read by a person before you see them

One page: what is open, what to do, what is coming

A briefing written once a day, the work still open against your products, and the dated obligations landing in the next fortnight. Not a dashboard of counters — counters are how you check a feeling you already have.

grapebeaver.io/app · example
RIGHT NOW · FOR NORTHLAKE MEDICAL
Third-party component provenance is where the pressure is this week, and three of your four products ship components you do not maintain.

Two advisories reached InfusionSuite Gateway; the FDA's updated premarket expectations name support-level information in the SBOM, which is the part your current submission pack does not carry.

WHAT YOU ARE EXPOSED TO
Third-party component provenance 2 new · 4 open
because InfusionSuite Gateway and VitalView M400 — contains open-source components
Exposure on the clinical network 1 new · due 14 Sep
because InfusionSuite Gateway — connected to the clinical network
Premarket cybersecurity evidence nothing moved
watched, and worth saying it was quiet
COMING UP · NEXT 14 DAYS
14 Sep — comment period closes on the draft premarket guidance
11 Dec 2027 — Cyber Resilience Act applies, and it applies to you

Illustrative. The exposure board is derived from the products you register — no similarity score, nothing you cannot check and disagree with.

Your SBOM says what is inside. It does not say what is still supported.

A component does not have to be vulnerable to be a problem. It just has to stop being maintained — no CVE, no advisory, no notification. Regulators increasingly expect a manufacturer to know the support status of what they ship and to have a plan for when it ends, and that is not something a scanner tells you.

  • Every component in every SBOM you upload is resolved against published end-of-life dates, release history and repository activity.
  • A publisher's stated end of life outranks three years of silence — it is better evidence, and the action is the same.
  • Labels say what was measured. "No release in 3 years", never "Abandoned" — log4j-core's newest release is recent and it is not abandoned.
grapebeaver.io/app/portfolio/lifecycle · example
openssl 3.0.8
InfusionSuite Gateway · End of life stated by the publisher, 7 Sep 2026
linux-kernel 5.10.180
VitalView M400 · Version series out of support
dcmparse 3.9.1
VitalView M400 · No release in 3 years
mosquitto 2.0.15
InfusionSuite Gateway · Supported
4 of 61 components need a look · 12 not identifiable upstream

Gathered, assessed, reviewed, sent

01 · GATHER

Every source, one feed

Regulators, standards bodies, sector coordinating councils and manufacturer PSIRTs — the FDA, CISA, the UK MHRA, EU MDR/IVDR, Health Canada and IMDRF among them, alongside the industry and trade publishers that carry what the regulators have not said yet. Anything that publishes into this space can be added as a source, so the list grows rather than being the five names on a slide. Everything is normalised and deduplicated as it arrives, so a cross-posted advisory reaches you once. Vulnerability feeds (NVD, CISA KEV) are read as evidence for what is in your SBOM, not forwarded to you one CVE at a time; your scanner already does that better.

02 · ASSESS

A score you can argue with

Each item gets one summary and a 0–100 impact score weighing exploitability against clinical consequence — with the reasoning shown, so you can disagree on the evidence rather than take it on trust.

03 · REVIEW

A person signs off

Nothing reaches your inbox until someone has read the assessment against the source and approved it. That gate is not optional, and it is why a summary here means something.

Digests that respect your inbox

Daily or weekly, at a time you choose. It leads with a one-line count, groups by severity with the most serious first, and links each item back to the full assessment.

  • Nothing new means nothing sent — an empty digest is just noise.
  • Set a severity floor and never see below it.
  • Every digest is archived and searchable, so "that thing from three weeks ago" is findable without digging through mail.
  • No hero images. A compliance inbox is not the place for one.
See a full sample
GRAPEBEAVER DAILY DIGEST
3 new items, 1 at high or critical severity.
Medium
Cobalt-chrome modular neck hip replacements: risk of metal-wear…
UK MHRA — Medical Device Alerts · 26 Aug
Medium
FDA recall: AMS ALIGNED MEDICAL SOLUTIONS medical convenience k…
FDA — device recalls · 8 Jun
Low
Agency Information Collection Activities; Proposed Collection; …
Federal Register — FDA medical devices · 28 Aug

Two plans. No seat minimum.

Start on your own for $5 a month with three registered products. Move up when you need your SBOM read, your documents assessed, and your team on it — from a single seat.

Individual

For a practitioner, consultant or engineer who needs to know what actually affects the devices they work with.

  • Every source — regulators, standards bodies and manufacturer PSIRTs, from the FDA and CISA to EU MDR/IVDR, the MHRA and IMDRF
  • Human-reviewed summary and severity score on every item
  • Up to 3 registered products, and what you are exposed to because of them
  • Up to 7 tracked device categories
  • Daily or weekly digest, and the obligations calendar

New accounts are closed while this deployment is being tested. If you were invited, use the link you were sent.

Running a fleet across multiple sites, or need API access, SSO and your own risk framework? Get in touch.

Assessments are AI-assisted and human-reviewed

Every summary and severity score is produced by an analysis agent and then read, corrected where needed, and approved by a person before it is published. GrapeBeaver surfaces intelligence for you to act on — it does not replace your own regulatory judgment, and it makes no compliance guarantee.