Credentials

The most trusted name in medical device testing.

Since 2013 we have tested the devices other firms will not touch. Tested, cleared, and validated to the same standards our customers ship under.

1,000+
Devices tested & cleared
Across every major modality
2013
Supporting FDA submissions since
Over a decade of premarket work
100,000s
Vulnerabilities managed
Discovered, rated, dispositioned
6 of 10
Top device manufacturers
Trust ELTON to test
Trusted with the highest stakes

We tested a proton therapy machine.

A proton therapy system is among the most dangerous devices in medicine. A multi-ton synchrotron accelerates protons to two-thirds the speed of light and steers the beam into a patient with millimeter precision. Software decides where that beam stops.

When the manufacturer needed the beam-delivery and safety-interlock stack tested, they called ELTON. We modeled the control chain, drove the real interfaces, and proved which findings could reach the beam and which could not. That is the bar we test to.

Beam-delivery controlSafety interlocksMotion & dosimetry
A proton therapy treatment room: the gantry and beam nozzle surround the patient couch under purple light

FDA-Qualified MDDT

A rating the FDA already recognizes.

ELTON vulnerability ratings are qualified as an FDA non-clinical assessment tool. Deterministic, architecture-justified CVSS 4.0 ratings for cyber devices under FD&C Act § 524B(c), aligned to your device documentation.

CVSS 4.0

Deterministic vector + score

Per vulnerability and per initial-access path, justified to the architecture.

100%

Reproducibility

Bit-for-bit identical output on identical graphs. No rater drift.

6-stage

Property-graph pipeline

Ingest, transform, target, subgraph, score, explain. Every step traced.

§ 524B(c)

Cyber device coverage

Premarket submissions in the design evaluation phase.

More accurate than experts

Retrospective blinded comparison against the NVD baseline and independent third-party CVSS 4.0 raters, per vulnerability.

100% identical vectors

Repeated executions across version-controlled device documentation produced identical CVSS 4.0 vectors and scores.

Time reduction at scale

A large drop in the time to evaluate hundreds of findings across SAST, DAST, SBOM, and penetration testing.

Software Validation

Validated to the standards you ship under.

ELTON performs complex attack-surface analysis and defensibly rates vulnerabilities, often reducing a HIGH to a rating that fits the product. It is a validated solution, held to the same lifecycle rigor as a medical device.

460 / 460
Test cases passed
0 failures, 0 deviations, 0 nonconformances
182
Requirements traced
Full bidirectional SRS to SVP to SVR
23 / 23
Hazards mitigated
Per ISO 14971, residual risk acceptable
100%
Verification coverage
Every requirement to test case to evidence

Validation package

SRS Software Requirements Specificationv2.2
SDS Software Design Specification (Core API)v1.0
SVP Design Verification Test Protocolv1.1
SVR Software Verification Reportv1.0
RTM Requirements Traceability Matrixv1.0
RMF Software Risk Management Filev1.0

Standards alignment

  • IEC 62304 software lifecycle
  • ISO 14971 risk management
  • ISO 13485 design controls
  • IEC 81001-5-1 health software
  • 21 CFR Part 11 / Part 820
In their words

The teams shipping under FDA scrutiny.

“The vulnerabilities reported to us today by third parties are AI slop. ELTON helps us automate why they don't matter, it's the only method that has held up to FDA audit.”

Senior Product Security Engineer
Imaging Manufacturer

“We have done many FDA submissions with ELTON's data and had not a single deficiency, we test early and often with AI.”

VP Product Security
Top 10 Global Manufacturer

“We use ELTON's subscription testing services and it has changed how our organization views cybersecurity testing, it's flexible, fast, and better.”

Product Security Director
Top 5 Robotics Manufacturer
Put us to the test

See what a decade of device testing looks like.

The credentials are the floor, not the pitch. Bring us your hardest device and we will show you the evidence.

Questions

Common questions about ELTON credentials.

How many medical devices has ELTON tested?

More than 1,000 devices tested and cleared, across every major modality, with hundreds of thousands of vulnerabilities discovered, rated and dispositioned. ELTON has supported FDA submissions since 2013, and six of the top ten device manufacturers use it for testing.

Is ELTON's vulnerability rating recognized by the FDA?

ELTON vulnerability ratings are qualified as an FDA non-clinical assessment tool. The output is a deterministic, architecture-justified CVSS 4.0 rating, produced per vulnerability and per initial access path, for cyber devices under FD&C Act Section 524B(c) and aligned to your own device documentation.

Is the ELTON platform validated as software?

Yes, to the same lifecycle rigor as a medical device. Validation recorded 460 of 460 test cases passed with zero failures, deviations or nonconformances, 182 requirements traced bidirectionally, and 23 of 23 hazards mitigated under ISO 14971 with residual risk acceptable. The package aligns to IEC 62304, ISO 13485, IEC 81001-5-1 and 21 CFR Part 11 and Part 820.

How reproducible are ELTON's CVSS scores?

Bit-for-bit identical on identical graphs. Repeated executions across version-controlled device documentation produced the same CVSS 4.0 vectors and scores, so there is no rater drift. Each rating runs through a six stage property graph pipeline: ingest, transform, target, subgraph, score and explain, with every step traced.

What is the most dangerous device ELTON has tested?

A proton therapy system, among the most dangerous devices in medicine. A multi-ton synchrotron accelerates protons to two-thirds the speed of light and software decides where the beam stops. ELTON modeled the beam-delivery and safety-interlock control chain, drove the real interfaces, and proved which findings could reach the beam.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON