See what Threat Detective finds in your SBOM.
Upload the CycloneDX or SPDX SBOM you already have. Threat Detective checks it against the NTIA minimum elements, matches every component against three vulnerability databases, and shows you what needs a documented decision before you submit.
Use your existing SBOM. No software to install. Built for medical devices. No credit card required.

From upload to evidence in four steps.
01
Upload your SBOM
Import the CycloneDX or SPDX SBOM your development process already produces. Nothing to install, and no change to how your team builds software.
02
Find the gaps and the known vulnerabilities
Threat Detective validates the SBOM against NTIA minimum element expectations and flags what is missing, including supplier names, component versions, PURLs, CPEs and dependency relationships. It then matches your components against three vulnerability databases: NVD, GitHub Advisories and OSV.
03
Investigate what matters
Prioritise findings using CVSS severity, EPSS exploitation probability and CISA KEV, which flags vulnerabilities already known to be exploited in the wild. A high-severity finding that nothing is exploiting does not crowd out the one under active attack. Record the assessment status, security impact, analysis rationale and clinical impact for each finding you investigate.
04
Build your evidence
Turn the decisions you recorded into eSTAR-formatted cybersecurity documentation ready to include in your 510(k), De Novo or PMA application, plus Notified Body summary reports and QMS-ready reports. During the trial these carry a watermark, and the enriched CycloneDX or SPDX export is available on paid plans.

What can you do in your first session?
Enough to judge whether Threat Detective fits how your team works. You are not setting up a platform. You are running your own SBOM through it and looking at the result: about 20 minutes after uploading your SBOM you can have your first report.
- Create the project for the device you are working on
- Upload an SBOM you already have
- See the known vulnerabilities affecting its components
- Identify which findings need investigation and which do not
- Record your first vulnerability decisions with the rationale behind them
- See how that work becomes structured regulatory evidence
Already using Snyk, GitHub, Trivy or another security tool?
Keep the tools that work for your development team. Those tools live in the development and build process, finding issues in code, dependencies and images so your engineers can fix them. Threat Detective takes the SBOM they produce and adds the medical-device workflow that comes after it: vulnerability investigation, documented decisions, regulatory evidence and ongoing surveillance.
Nothing has to be switched off to run the trial, and your build pipeline does not need to change. If you can export an SBOM, you can evaluate Threat Detective.
- Development tools
- Generate SBOM
- Threat Detective
- Investigate and document
- Regulatory evidence
Designed around the medical-device cybersecurity workflow.
- Built around the regulatory workflow
- The vocabulary is the one your submission uses. Findings carry a security impact, an analysis rationale and a clinical impact, because a reviewer assessing an accepted vulnerability needs the security rationale and the clinical consequence, not just a severity score.
- Scoring against the published rubric
- Threat Detective applies MITRE’s Rubric for Applying CVSS to Medical Devices, developed for FDA and referenced in its premarket cybersecurity guidance, and documents the scoring process itself as part of the evidence.
- One decision, every affected version
- Apply the same rationale across multiple software versions rather than repeating it, with a full audit trail of who decided what and when.
- Evidence as an output, not a copy-paste job
- eSTAR-formatted documentation, Notified Body summary reports and enriched CycloneDX or SPDX exports come out of the work you already did, instead of being assembled by hand at the end.
- Monitoring continues after clearance
- New vulnerabilities are disclosed against your components every week. On the Post-Market plan, Threat Detective monitors them continuously, generates VEX documents and produces post-market cybersecurity surveillance reports that feed your PMS file.
- See it against your current tool
- vs Snykvs Dependabotvs Ketryx

“I was tired of stitching reports together from pricey SBOM tool exports and spreadsheets. They weren’t built for medical devices. So I built Threat Detective to give us regulator-ready outputs in minutes, not days.”
Can you safely upload a real SBOM?
An SBOM describes the software inside your device, so it is fair to ask before uploading anything.
- Hosted in the EU
- Customer data on the standard plans is held on dedicated servers at Hetzner in Falkenstein, Germany, and is stored and processed within the European Union. Private Cloud customers can choose the EU, UK or US.
- Encrypted in transit and at rest
- TLS 1.3 and 1.2 with modern ciphers only in transit, AES-256 at rest. Cloudflare terminates TLS at the edge and re-encrypts to our origin.
- Your organisation is isolated
- Customer data is logically isolated at the database and application layer, and every query is scoped to the authenticated customer. We do not commingle data between customers. Private Cloud is a physically isolated single-customer deployment.
- Your SBOM is not training data
- We do not use customer data to train AI or machine-learning models. Your SBOM, your vulnerability decisions and your documentation are used to run the service for you, and for nothing else.
- Access you control
- Sign in with a password, or with Google or GitHub. Passkeys are encouraged for multi-factor authentication. SAML and OIDC single sign-on are available on Private Cloud.
- Backed up, and deletable
- Automated daily backups, encrypted at rest and stored in a separate failure domain, with restore procedures tested regularly. You can request export or deletion of your data at any time, and on termination data stays available for export for 30 days, then it is deleted, and purged from backups within 90 days.
The full detail, including our subprocessors and vulnerability disclosure policy, is on the trust and security page. If you need something it does not cover, email security@threatdetectivehq.com.
Start with your own device.
Use the 14-day trial on the device you are actually working on, then choose the plan that matches where that device is in its lifecycle.
When the trial expires your data becomes read-only for 30 days and is then deleted, so the project and the decisions you recorded are still there if you subscribe within the month.
Before you upload.
Do I need an SBOM already, or will Threat Detective make one?
You need one. The product starts where your build process ends: it validates the SBOM your development tooling produces against NTIA minimum element expectations, enriches it with vulnerability and decision data, and exports it again in CycloneDX or SPDX. Generating the SBOM in the first place is the job of your build tooling. If you do not have an SBOM yet, start with the medical device SBOM guide.
Which SBOM formats are supported?
CycloneDX and SPDX, both for import and for export. Exports carry the vulnerability data, assessment status and decision records alongside the component list. During the trial, import and on-screen analysis work in full; machine-readable exports are available on paid plans.
Do I need to install any software?
No. Threat Detective is a web application. You upload an SBOM your existing tooling produced, so nothing needs to be installed and your build pipeline does not have to change.
How long does it take to see results?
About 20 minutes after uploading your SBOM you can have your first report. Creating the account and the project takes a few minutes more, so a single sitting is enough to see what Threat Detective finds in a real device.
Can I use a real device and a real SBOM during the trial?
Yes, and it is the point of the trial. Create the project for the device you are actually working on and upload its real SBOM. Two limits apply during the trial: exported reports carry a trial watermark, and machine-readable exports are unavailable.
Do I need a credit card?
No. Signing up takes a name, email address and password, nothing more. Because no card is taken, nothing can be charged when the trial ends: your data becomes read-only for 30 days while you decide.
What happens when the trial ends?
Your data becomes read-only when the trial expires and is kept for 30 days, then deleted. Subscribe within that window and full access is restored, with the project, the findings and the decisions exactly as you left them. You can make a data export or deletion request at any point by emailing privacy@threatdetectivehq.com.
Does Threat Detective replace Snyk, Dependabot or the tools my developers use?
Usually not. That is not what they are built for. Those tools find and fix issues as code is written. Threat Detective picks up from the SBOM they produce and handles the medical-device work that follows. Most teams keep both.
Where is my SBOM data hosted?
On the Pre-Market and Post-Market plans, at Hetzner in Falkenstein, Germany, with data stored and processed inside the European Union. Private Cloud customers choose between the European Union, the United Kingdom and the United States. Full detail is on our trust and security page.
Does using Threat Detective guarantee FDA acceptance?
No, and be wary of any tool that says otherwise. Threat Detective helps you identify gaps, investigate vulnerabilities and assemble structured cybersecurity evidence to support your submission. The regulatory judgement about your device, and the submission itself, remain yours. No tool can commit a reviewer to an outcome.
Run your own device through it before you commit.
14 days with your real SBOM. No credit card required.
Not ready to upload an SBOM? Book a 30-minute demo