If a tool produces evidence that goes into an FDA submission, that tool lives inside your quality system. Which means the FDA can ask whether it was validated for its intended use, the same way any other software tool in an ISO 13485 QMS has to be.
This is easy to overlook with security tooling, because scanners and pentest scripts feel like utilities rather than quality-system software. But the output of those tools is now regulatory evidence. An unvalidated tool producing your vulnerability ratings is a gap an auditor can pull on.
The moment a tool's output is defensible evidence, the tool itself becomes something you have to defend.
This is one reason we built ELTON to be pre-validated for use inside an ISO 13485 QMS, and backed the rating methodology with an FDA-recognized MDDT. It moves the validation burden off the manufacturer's plate for the part that matters most, the ratings that regulators will scrutinize.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.