Health-ISAC member program

Are you Mythos-Secure?

What vulnerabilities can AI find in your medical device? Find out free, with a report you can submit to the FDA for a 510(k) or PMA and 30 days in the ELTON exploitability management platform.

Health-ISAC
Exclusive to Health-ISAC membersOne product per member organization. No cap on how many members take it up.
No cost45 days end to endRedeem by December 31, 2026
Request your evaluation
The partnership

Health-ISAC members get
what ELTON never gives away.

Health-ISAC is the non-profit information sharing community for the global health sector, and it connects thousands of security professionals across the Americas, Europe and Asia Pacific.

Who Health-ISAC is

A trusted community, not a vendor list

Health-ISAC (Health Information Sharing and Analysis Center) exists to help the health sector prevent, detect and respond to cyber and physical security events. Its membership spans providers, payers and the manufacturers who build the devices sitting on hospital networks. Medical device security is one of the areas it organizes around, because a device vulnerability lands on the manufacturer and the hospital at the same time.

What ELTON is offering

One product, tested end to end, at no cost

ELTON is opening its pipeline to Health-ISAC member organizations. One product per member gets the full test, a report written for a 510(k) or PMA submission, and 30 days inside the exploitability management platform to work the results. ELTON has not given away testing or platform access before this program, and it is not being offered anywhere else.

A comparable one off consulting penetration test runs about four weeks and roughly $100,000, with platform access quoted separately. That figure is a market equivalent, not an ELTON list price. This program is free, with no purchase obligation and nothing that auto renews.
Why both halves matter

Finding the bugs turned out to be
the easy part.

Frontier models now find bugs that survived decades of human review, which means the bottleneck moved from discovery to knowing which findings an attacker can actually reach.

Exploitability verification · the output you actually act on
1% needs fixing
99% proven and dismissed
EVERY FINDING LANDS IN ONE OF FOUR STATESDirectly exploitableReachable on its own from the attack surface, with a working test case behind itFIX THISConditionally exploitableReachable only if something else breaks first, with the chain and preconditions shownFIX THE ROOTUnexploitable weaknessIn scope, no exploit path on this product, dismissed with the reasoning attachedDISMISSED WITH EVIDENCEMitigated weaknessA control already on the product blocks it, and the control is namedTHE CONTROL IS NAMEDMost products do not have a thousand problems. They have four or five, plus a long list of things that look like problems.
act on itfix the root causedismissed with reasoningalready mitigated
A scanner gives you a list. Verification gives you a disposition you can put in a submission.
ELTON is Mythos-grade AI penetration testing for medical devices, paired with the exploitability management that makes the results usable. Without exploitability management you cannot tell which findings an attacker can reach on your product, which means you cannot act on any of them. ELTON does both halves. Not a scanner report. Not a consulting engagement.
What you get

Two phases. One product.
45 days end to end.

Phase one is the test and the report. Phase two starts the day the report lands and gives your teams 30 days inside the platform to work what it found.

The program · two phases, 45 days
15 days of testing
30 days in the platform
PHASE ONE. THE TESTPHASE TWO. 30 DAYS IN THE PLATFORMWHAT ELTON RUNSDAY 0 TO 15Digital twin of your productBuilt from documentation you already holdSBOM, generated or validatedComponents and CVEs mapped to the buildSAST and SCAOn any source code you provideDAST and interface fuzzingAgainst the running product and its exposed protocolsExploitability verificationEvery finding lands in one of four statesReport and live readoutSubmission ready for a 510(k) or PMAWHAT YOU WORKDAY 15 TO 45Your twin and its graph, liveFix a root cause and watch the chain collapseNew CVEs triaged as they publishMapped to your SBOM, checked against your twinRe-verificationShip a fix and the pipeline retests itEvidence generated as you goVEX, MDDT CVSS scoring, written rationaleSeats for your teamsEngineering, product security and regulatoryNo credit card, no auto renewalNothing to uninstall when the 30 days end45 days end to end. One product, one configuration, no cost.REDEEM BY DECEMBER 31, 2026
ELTON runs ityou work itno cost either way
The test tells you which findings are real. The 30 days tell you whether the fix held.
Phase one. The test

Days 0 to 15

  • A digital twin of your product, built from documentation you already hold. Interfaces, components, trust boundaries, and the attack surface an adversary can actually reach.
  • SBOM generation, or validation of the SBOM you have, with component and CVE mapping.
  • SAST and SCA on any source code provided.
  • DAST against the product's running interfaces.
  • Protocol and interface fuzzing across the exposed attack surface.
  • Exploitability verification on every finding, landing each one in one of the four states above.
  • Root cause collapse. Thousands of findings reduced to the handful of root causes that produce them.
  • A prioritized remediation plan, ordered so the fixes that close the most exploit paths come first.
  • A penetration test report ready for internal use or for a 510(k) or PMA submission. Scope, methods, coverage, findings, exploitability evidence, and the reasoning behind every dismissal, in the report format this team has used across more than 1,000 FDA submissions since 2013.
  • A live readout with the ELTON team.
Phase two. The platform

Days 15 to 45

  • Your digital twin and its dependency graph, live. Every finding in its state, with the conditions that make it reachable. Fix a root cause and watch the chain collapse.
  • New CVEs published during the window are mapped to your SBOM and triaged against your twin, so you see which ones reach your product and which ones cannot.
  • Re-verification. Ship a fix during the window and the pipeline retests it and updates the graph.
  • Evidence generated as you go. VEX output, CVSS scoring using the MITRE rubric qualified under FDA's MDDT program (Q171974), and the written rationale behind every dismissal.
  • Seats for your engineering, product security and regulatory teams.
  • No credit card, no auto renewal, and nothing to uninstall when the 30 days end.
Timeline

Two calls from you.
Findings by day two.

Kickoff and readout are the only two meetings the program asks for, and everything between them runs without your team in the room.

Day 0
Kickoff call. Scope confirmed, assets transferred.
Day 2
First findings start. The pipeline is already returning results.
Days 3 to 14
Discovery and exploitability verification run continuously.
Day 15
Readout. Penetration test report, prioritized remediation plan, evidence package.
Days 15 to 45
Your 30 days of platform access. 45 days end to end.
Eligibility

Who can take this up,
and what it takes to start.

Health-ISAC member organizations, one product each, tested against a lab or bench unit rather than anything in clinical use.

Who is eligible

Health-ISAC member organizations

  • One product per member organization.
  • You either manufacture the product, or you own it and hold written authorization from the manufacturer to test it.
  • Testing runs against a lab or bench unit, never a production or clinical environment.
  • No cap on the number of members who can take this up.
  • The offer closes December 31, 2026.
What ELTON needs from you

Paperwork, documents, and a build

  • A mutual NDA or MSA, your preference, and a signed zero dollar SOW for the product.
  • Product documentation. Architecture, interfaces, and a threat model if one exists.
  • One of: a firmware image, source code, or a deployable software build.
  • Physical device testing through ELTON TestLink, which runs out of band over 5G and never touches your enterprise network, may be available depending on the product and current lab capacity. It is not guaranteed and is confirmed case by case at kickoff.
  • A named engineering contact for two calls, kickoff and readout.

ELTON works with 6 of the top 10 medical device manufacturers and hundreds of smaller ones. Your source code, firmware, documents and findings stay inside the pipeline. AI builds the testing tools and decides which ones to run. Your data does not go into a public model.

The fine print, up front

What this covers,
and what it does not.

Everything below is stated before you sign rather than discovered at kickoff, because a free program with surprises in it is not free.

Limits

Scope of the program

  • One product, one configuration or firmware version, per member organization.
  • Remote delivery. No onsite work or travel included, unless travel is separately reimbursed.
  • Physical device testing through TestLink is case by case, not guaranteed, and confirmed at kickoff.
  • No testing against production or clinical environments. Lab or bench units only.
  • The report covers the cybersecurity testing and vulnerability management portion of a 510(k) or PMA submission. Labeling, architecture views and the rest of the SPDF stay with the manufacturer.
  • The program runs 45 days end to end. Redeem by December 31, 2026.
Terms

What you keep

  • No cost and no purchase obligation. Nothing auto renews. Continued platform access past day 45 is available for a fee. If you pass, the report is still yours and it is still submission ready.
  • ELTON has not offered free testing or free platform access before this program, and it is open only to Health-ISAC members.
  • All findings, reports and evidence belong to you. ELTON does not publish or share your results, and any use of anonymized aggregate statistics requires your written opt in.
  • Your source code, firmware, documents and findings stay inside the pipeline and do not go into a public model.
How to redeem

Two weeks to know what is real.
Thirty more to prove the fix.

Submit the form with your Health-ISAC member organization name and ELTON replies within one business day to schedule kickoff.

Most products do not have a thousand problems. They have four or five, plus a very long list of things that look like problems. The point of this program is to hand you the difference in writing, in a format the FDA already recognizes, and then give you a month to prove the fixes worked.

Questions go to jsinchak@eltoncyber.com. Health-ISAC and H-ISAC are registered trademarks of Health-ISAC, Inc. This program is an offer made available to Health-ISAC members by ELTON Cyber and does not constitute an endorsement of ELTON by Health-ISAC, Inc.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 MigrationProduct Tour
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Meet ELTON
See the graph decide, live >