Comparison

Threat Detective vs Ketryx.

Ketryx is an application lifecycle management platform that includes cybersecurity. Threat Detective does the cybersecurity part, and nothing else.

A platform to adopt, or a tool to add

Ketryx and Threat Detective overlap on SBOMs, vulnerabilities, and FDA cybersecurity expectations. Where they differ is what adopting each one costs you. Ketryx is a platform your development process moves onto, which is usually a decision for the start of a project. Threat Detective sits alongside the tools you already have.

Ketryx

Connected regulated lifecycle platform

Ketryx brings engineering and regulatory work together in one platform. Its scope reaches well past cybersecurity, into requirements, risk management, testing, and release documentation.

  • Requirements, risks, and tests connected in one system
  • Cybersecurity risk integrated with ISO 14971 risk management
  • STRIDE threat modelling traced to design controls
  • Part 11 electronic signatures and audit trails
  • Free plan for pre-market companies that have raised under $2 million

Threat Detective

Medical device cybersecurity evidence

Threat Detective starts with the SBOM you already produce. It validates that SBOM, finds the known vulnerabilities, guides a device-specific assessment, and keeps watching every released version.

  • SBOM validation against NTIA minimum elements
  • Vulnerability scanning across NVD, GitHub Advisories, and OSV
  • CVSS, EPSS, and CISA KEV in one prioritisation view
  • Submission-ready documentation in FDA eSTAR format
  • Per-device pricing at $189/month with unlimited team members

An ALM decision, or a cybersecurity one?

On SBOM and vulnerability management the two overlap considerably. The real difference is what surrounds that workflow, and it is not a feature question.

Ketryx is an application lifecycle management platform. It connects the tools your developers work in to the regulatory record, so a component and its vulnerabilities can be traced through to ISO 14971 risks, requirements, and releases. That breadth is its strength, and nothing here is an argument against it.

It is also a decision about your whole development process rather than your cybersecurity evidence. Ketryx connects the tools you have rather than replacing them, but the regulated record then runs through it, and keeping that record complete is the commitment. Most teams take that on at the start of a project. Part way through a submission it is rarely practical, and for a team that needs cybersecurity evidence and nothing else, it is more platform than the problem calls for.

Threat Detective is built for the other case. It takes the SBOM your build already produces and stops there: validation, vulnerability identification, assessment, evidence, and monitoring. Your QMS, issue tracker, and risk process stay exactly where they are, because changing them is not the price of solving this.

Medical device SBOM tools: feature-by-feature comparison

Ketryx capabilities below are taken from its public pages. Its product documentation sits behind a login, so anything described only there is marked “not documented”. That records what we could verify from outside rather than asserting a gap.

Ketryx capabilities verified 20 August 2026 against ketryx.com/pricing and the Ketryx SBOM capability page. Threat Detective capabilities are documented on our features page, and our hosting, data handling, and security posture on trust.

SBOM

CycloneDX and SPDX import

Threat Detective

Yes

Ketryx

Yes

Validate SBOM completeness for submission

Threat Detective

Yes

Ketryx

Yes

Component support status and end-of-life dates

Threat Detective

Yes

Ketryx

Yes

Vulnerability intelligence

Continuous vulnerability monitoring

Threat Detective

Yes

Ketryx

Yes

Named vulnerability data sources

Ketryx names continuous GHSA and NVD monitoring on its public pages. OSV, CISA KEV and EPSS are not named there, and its product documentation sits behind a login.

Threat Detective

NVD, GHSA, OSV, KEV, EPSS

Ketryx

GHSA and NVD

Assessment

CVSS 3.1 and 4.0

Threat Detective

Yes

Ketryx

Yes

MITRE rubric for applying CVSS to medical devices

Threat Detective

Yes

Ketryx

Not documented

Cybersecurity risk linked to safety risk

Threat Detective records the cybersecurity assessment and leaves ISO 14971 risk management where it already lives. Ketryx connects the two inside one platform.

Threat Detective

Your existing process

Ketryx

ISO 14971 integration

Threat modelling

Ketryx classifies findings with STRIDE and traces them to design controls.

Threat Detective

No

Ketryx

Yes

Requirements and test traceability

Threat Detective

No

Ketryx

Yes

Regulatory evidence

FDA and EU cybersecurity documentation

Threat Detective

Yes

Ketryx

Yes

FDA eSTAR-format cybersecurity evidence

Ketryx states support for FDA cybersecurity guidance without naming the eSTAR format.

Threat Detective

Yes

Ketryx

Not documented

Design-control documentation beyond cybersecurity

Threat Detective

No

Ketryx

Yes

Part 11 electronic signatures

Ketryx states Part 11-compliant electronic signatures, approved with multi-factor or biometric authentication, alongside Part 11 audit trails. Threat Detective records a full audit trail of who decided what and when, which is the evidence a reviewer asks for, but it does not offer electronic signatures.

Threat Detective

No

Ketryx

Yes

Post-market

Surveillance of every deployed software version

Threat Detective

Yes

Ketryx

Not documented

Reassessment when a vulnerability enters CISA KEV

Threat Detective

Yes

Ketryx

Not documented

Adoption

Works alongside your existing lifecycle tools

Breadth is the point of Ketryx. It is also what you take on when your requirements, risk, and test tools are already settled.

Threat Detective

Yes

Ketryx

Platform adoption

Requirements, risk, and test management

Threat Detective

No

Ketryx

Yes

Published paid pricing

Ketryx publishes a free plan at $0/year for pre-market companies that have raised under $2 million. Startup, Business, and Enterprise pricing is sales-led.

Threat Detective

Yes

Ketryx

No

Unlimited team members

Threat Detective

Yes

Ketryx

Not documented

Pricing model comparison

Ketryx publishes a free plan and prices its paid tiers through sales. Threat Detective publishes its prices and charges per medical device project.

Ketryx pricing

Sales-led above the free plan

Free
$0/year
under $2m raised, pre-market
Startup
Contact sales
Business
Contact sales
Enterprise
Contact sales

An early-stage manufacturer that qualifies can adopt a broad regulated-development platform at no cost, which is a strong offer if that breadth is what you need from the start.

Threat Detective pricing

Per medical device project

Pre-Market
$189/month
Post-Market
$249/month
Private Cloud
$1,495/month
12-month contract, 5 devices

All plans include SBOM management, vulnerability scanning, regulatory documentation, and unlimited team members. See full pricing details.

Why teams look for a Ketryx alternative

Teams reach this comparison for a few recognisable reasons, and none of them is that Ketryx is a weak product.

The free plan has a ceiling. It is for pre-market companies that have raised under $2 million. Raise more, or put a product on the market, and you move to a quoted tier. Teams that adopted Ketryx early sometimes reach that point at the same moment their first submission is due.

Paid pricing is sales-led. Startup, Business, and Enterprise tiers are quoted rather than published, so budgeting means a conversation before you know the number.

The platform is the commitment. Ketryx earns its value by holding your requirements, risks, and tests. If those already live somewhere that works, you are paying for breadth you will not use, and the migration is the larger part of the cost.

If the gap you actually have is cybersecurity evidence, a narrower tool closes it without touching anything else. That is the case this page is making.

Which one fits your situation

Choose Ketryx if you want one platform connecting much of your regulated software development: requirements, risks, and tests held together, cybersecurity risk integrated with ISO 14971, and design-control traceability with the Part 11 electronic signatures Ketryx describes. Those capabilities sit deliberately outside Threat Detective’s scope. If you need them, Threat Detective will not cover the gap, and we would rather say so here than after you have bought it.

Choose Threat Detective if you have a submission date and the cybersecurity documentation is the part still outstanding. That work has a deadline on it. The SBOM has to hold up, every known vulnerability needs an assessment a reviewer will accept, and it has to arrive in the shape the submission expects. Moving your requirements and tests onto a new platform does not get you closer to that date. What you need answered is narrower. Is the SBOM complete enough to submit? Which vulnerabilities actually affect this device, and is anything listed in CISA KEV? Can the ones you accept be justified in writing?

Then there is the part that outlasts the submission. Version 4.0 may be current while 3.8, 3.2 and 2.9 are still in clinics, and a vulnerability disclosed tomorrow may affect some and not others. Threat Detective monitors each deployed version against its own SBOM, so a new finding shows which versions are affected and whether the decision you already recorded still holds.

Running both makes less sense here than it does alongside a developer security tool, because the SBOM and vulnerability workflows genuinely overlap. If Ketryx already holds your requirements, risks and tests, the question is whether its cybersecurity evidence covers what your submission needs. If it does, you do not need us.

This is a question of scope, not quality. Ketryx asks you to bring more of your process onto one platform, and connects it once you do. Threat Detective asks for the SBOM and leaves everything else alone.

Still weighing it up? The features page covers what Threat Detective does in detail, and you can see how it differs from Snyk and Dependabot. Our consulting service will talk it through if you would rather not decide from a table.

Keep the tools you have.

Upload the SBOM you already have and see what still needs resolving before submission. No lifecycle migration, and nothing to move off the tools you already run.

Not sure where you stand? Find your SBOM gaps with the free scorecard