Platform overview

All Testing.
All Management.
One Service.

ELTON AI for digital twinning and vulnerability testing. TestLink™ for the physical device. AI for chaining and lifecycle management. Each turn of the loop enriches history and traceability.

Directly exploitable
Web UI → runtime access
CVE-2024-8811 · proven on-device
Findings, this release
6
Direct
19
Conditional
4,187
Weakness
Chain proven
USB → RJ45 → Web UI → App
Reaches Patient PII · 4 hops
Directly exploitableConditionalExploit chain
How ELTON AI works

Total FDA Compliance.

Every release makes a turn, and every turn enriches the history. Below, the loop unpacked stage by stage: digital twin, identify, contextualize, monitor and track, respond.

ELTON AI 1 DIGITAL TWIN architecture · security design · threat model 2 IDENTIFY VULNERABILITIES findings · testing 3 CONTEXTUALIZE product-adjusted ratings · vulnerability chains 4 MONITOR & TRACK New CVEs · Vulnerability Lifecycle 5 RESPOND smart fix · what-if
Stage 01
Digital Twin
The model of your device that every stage reads from and writes back to.
Built from your QMS

The security model of your product.

No questionnaire. The twin is built from artifacts your quality system has produced, reviewed, and submitted. Most of the model already sits in your files.

Architecture and data flows

System diagrams, data flow maps, and deployment context define what the device is, what talks to it, and where it sits on a hospital network.

SBOM and components

The software bill of materials binds every component and version into the model, so a new CVE resolves to a real location instead of a keyword match.

Interfaces and countermeasures

DICOM, HL7, and MQTT listeners, trust boundaries, and documented countermeasures become claims the platform can test, not lines in a PDF.

Stage 02
Identify Vulnerabilities
Agentic testing on the real device. Every lane in, one verified stream out.
ELTON TestLink™

AI, meet the physical device.

Exploitability is only answered at runtime, on the real product. ELTON drives a purpose-built AI harness, decades of hands-on device security work encoded, against live device interfaces.

Out-of-band 5G No enterprise network Same AI harness, every path
ELTON TestLink™ appliance: a ruggedized case with 5G antennas, cooling, and a physical port panel for cabling to the device under test

Three ways in: ship the device to our lab, have us target the one in yours remotely, or run TestLink™, a pentester in a box on your bench.

ELTON PLATFORM AI Testing Harness Decades of device security expertise, encoded agents · fuzzers · exploits Digital Twin Per release: architecture, interfaces, trust boundaries DIRECT CONNECT REMOTE SESSION OUT-OF-BAND 5G ELTON LAB YOU SHIP IT Product shipped to ELTON. We connect the harness and run it for you, continuously. YOUR LAB ELTON MANAGED The critical device never leaves your building. ELTON targets it remotely for you. YOUR BENCH TESTLINK · SELF-SERVICE TESTLINK DEVICE UNDER TEST Any device on your premise. Plug in, pair, run. Test cases out Results + vulnerabilities back No LAN, no VPN, no agents
One AI harness behind every engagement. Only the connection to the device changes.
One stream

All vulnerability testing.

Raw tool output is where triage drowns. Here, every lane feeds exploitability verification before a human ever sees it, so what reaches your team is deduplicated, verified, and evidenced.

FOUR LANES IN. ONE VERIFIED STREAM OUT. SASTsource and binaries DASTrunning services FuzzingDICOM · HL7 · MQTT · proprietary Pentest-class test caseshuman techniques, encoded Exploitability verification twin · code · real hardware Verified findings deduplicated · evidenced
Every lane ends in the same place: verification against the twin, the code, and the real device.

Deduplicated first

Four lanes rediscover the same weakness four different ways. The platform collapses them into one finding before anyone spends a minute on triage.

Verified before assignment

Findings pass through L1, L2, and L3 verification, so developers only ever see work that survived a real exploitation attempt.

Weakness or vulnerability

Every verified finding leaves the stream tagged as one or the other. Stage 03 is where that line gets drawn, with the dependency graph holding the pen.

Verification, traced to the twin

FDA test case traceability.

A finding is not closed by opinion. Test cases generate from the threat model, execute at the deepest tier you open, and land as evidence. CVE to determination, unbroken.

FULL REGULATORY TRACEABILITY · EVERY RESULT TRACES BACK TO THE TWINDigital TwinComponents, interfaces,data flows, assetsTest CaseEMB3D PID + LLM logic,tailored to this deviceExecuteAt the deepestavailable tierResultPASSFAIL+ evidence and narrativeFindingAffected / Not AffectedVEX OUTDEEPER ACCESS, HIGHER CONFIDENCE, MORE FINDINGS CLEAREDLEVEL 1Digital Twin MetadataArchitecture, SBOM, reachability andsecurity-profile overlay. Reason aboutexploitability from composition.CLOSED AS NOT AFFECTED30-40%Baseline confidenceLEVEL 2Code & FirmwareCustom harnesses from real code. Staticanalysis and emulation confirm which paths areactually reachable.CLOSED AS NOT AFFECTED50-65%Strong confidenceLEVEL 3Real Hardware RuntimeLive exploit attempts on the actual device.What truly works, and what does not, on realsilicon.CLOSED AS NOT AFFECTED70-85%Highest confidence
Stage 03
Contextualize
Product-adjusted ratings, and the graph that decides what is actually exploitable.
At scale, in context

Product-Adjusted Ratings.

Applying a rubric to one CVE is easy. Every finding, every release, reasoning written down, is where humans run out of hours. ELTON runs the full backlog, rationale attached.

One CVE through the qualified rubric NVD generic score 9.8 MDDT RUBRIC · Q171974 Is the vulnerable service reachable?No Attack vector in deployment?Adjacent Privileges and interaction required?High / Yes Clinical impact if compromised?Limited each answer sourced from the digital twin, each answer recorded Device-contextual score 5.9 rationale trail attached defensible in review: questions, answers, evidence for every single rating
The score that leaves is not the score that entered, and the difference is documented.

Context moves the number. A generic 9.8 assumes network reachability and no controls. When the digital twin shows the path is blocked, the score drops, rationale on the record.

CVSSv4 changes the math and the vocabulary. We are building that path now: see CVSSv4 migration and Proof Over Probability.

Dependency graph & conditional exploit chaining

Vulnerability vs. Weakness.

ELTON rates each vulnerability in isolation, then lets the dependency graph decide what is actually exploitable. Entry vectors produce conditions. Findings require them.

TODAY · NO BREAKOUT EXISTSKiosk UILocked task, no shell, no filesystemKIOSK CONTAINMENT HOLDSCONDITION · RUNTIME OS ACCESS · UNMETCVE-2024-8811CVSS 9.8CVE-2023-4102CVSS 8.1CVE-2025-0233CVSS 7.8WEAKNESSES · NO PATH · RATING ALONE CHANGES NOTHINGThe OS behind the kiosk carries the CVEs. Nothing reaches them.The device is not exploitable here. It is fragile. THE DAY A KIOSK BREAKOUT SHIPSKiosk UIBreakout CVE · direct · rootCONDITION · RUNTIME OS ACCESS · METCVE-2024-8811CVSS 9.8CVE-2023-4102CVSS 8.1CVE-2025-0233CVSS 7.8SAME FINDINGS · NOW EXPLOITABLE · FIX THE ROOTSame defects, same CVSS. The condition is met, so the graphreclassifies them the moment the breakout lands.ELTON CALLS THIS FRAGILITYWeaknesses are not forgotten. The graph recomputes as new vulnerabilities surface,promoting weaknesses to vulnerabilities and back, on the fly, with the evidence attached.
Stage 04
Monitor & Track
Per-view clocks, and a lifecycle that writes the report as it moves.
The metrics

Three clocks, always view-relative.

MTTT, MTTV, and MTTM run per view. The same CVE yields different, independently correct numbers in v1.1, v1.2, and v1.3. Each version has its own exposure window.

Three clocks, always view-relativeMTTT to triage, MTTV to verify, MTTM to mitigate, walked across the clone chain.CLOCK BEHAVIOREnter Needs TriageMTTTstartLeave Needs TriageMTTVstartBecomes AffectedMTTMstartFixed / downstream closeMTTMstopCVE-2025-1234 · SAME FINDING, THREE VIEWSv1.1 ReleaseMTTT 4mMTTM 271dv1.2 DraftMTTT 6mMTTM unresolvedv1.3 DraftMTTT 5mNot Affected
MTTM in a Draft view is same-view. In a Release view it walks the clone chain until a downstream clone reaches Fixed or Not Affected.

MTTT

Time to triage. Starts when a finding enters Needs Triage, stops when it leaves. Once started it never resets on re-assessment.

MTTV

Time to verify. Starts at triage exit, stops when verification flips to Verified without the status changing. We verify a status, not a finding.

MTTM

Time to mitigate. Starts at Affected, stops at Fixed in the same Draft view, or when a downstream clone reaches Fixed or Not Affected.

The payoff

The lifecycle is the report.

Every status, rating, verification, mitigation, VEX reason, and clock is captured as the finding moves. The report is not assembled at the end. It is the lifecycle, read out.

The lifecycle is the reportStatus, rating, verification, mitigation, VEX reason, and clocks, captured as it moves.TriageAffectedVerifiedFixedONE RECORD, WRITTEN AS IT MOVESCycloneDX VEXall three dimensionsDashboard metrics% Affected and Fixed VerifiedeSTAR and HDO evidence
One record. Engineers, regulators, and HDOs all work from the same source, not from three reconstructions of it.

Percent Affected Verified

Of everything open in a view, how much rests on test evidence rather than analysis alone. ELTON reports it per view and pushes it up.

Percent Fixed Verified

Of everything closed as Fixed, how many closures have a PASS test proving the fix works. This is the number that survives an audit.

Stage 05
Respond
The minimal fix plan that collapses exploitable severity.
Remediation planning

The shortest path to zero exploitable severity.

Ranked by attack-path classification first, active CVSS second. The graph knows which chains share a root, so the plan is minimal: fix two findings, eliminate the exploitable severity.

EXPLOITABLE SEVERITY103.9● 1 High  ● 16 Medium  ● 2 LowUNEXPLOITABLE SEVERITY0.0nothing reachable left unratedINITIAL ACCESS SCOPEADMINCLINICIANUNAUTHENTICATEDWHAT TO FIX FIRSTranked by attack-path classification, then active CVSS1Transient Execution Side Channels PresentEL-jfc9v · Not verifiedDIRECT● High (7.4)2Command Injection Condition Present · FirmwareEL-BRjSm · Not verifiedDIRECT● Medium (6.2)3Debug Functionality Enabled in ProductionEL-uD77F · Not verifiedDIRECT● Medium (6.2)4Default Configuration Allows Excessive AccessEL-4flx4 · Not verifiedDIRECT● Medium (6.2)REMEDIATION PLANFix 2 findings to eliminate 100%of exploitable severity (3.6 total).1. Unnecessary Services Enabled · Bluetooth-1.82. Unnecessary Services · WPA Supplicant-1.8Not the twenty findings a scanner ranks by CVSS.The two the graph says collapse every open chain.Apply plan to what-if
Remediation planning in ELTON: the graph computes the minimal fix set, scoped to the initial access vectors you toggle.
See it run

Watch the full pipeline run on your device.

Start with one device. We build the twin from documents you already have, run AI discovery remotely, and show you the graph: the handful to fix, evidence for the rest.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo