Japan did not write its own rulebook. It adopted JIS T 2304 (IEC 62304) and JIS T 81001-5-1 (IEC 81001-5-1). One disciplines the software lifecycle, the other embeds cybersecurity inside it. Neither is satisfied by an annual assessment and a folder of PDFs. ELTON produces the living record both demand.
Read together, JIS T 2304 and JIS T 81001-5-1 close the loop most programs leave open. One makes maintenance a formal lifecycle phase with the same weight as development. The other makes security a property of every phase.
Defined development processes, structured software maintenance across the whole operational life, and risk management that traces software decisions back to patient safety.
Security requirements identified in design, continuous risk analysis of vulnerabilities and threats, secure implementation and verification, and postmarket monitoring.
The standard does not just want fixes. It wants a record showing why you fixed what you fixed and why you accepted what you accepted. That is the evidence most programs never produce.
Compliance at release is a moment. These standards describe a practice, and both keep asking what changed since the last time. ELTON is built as that continuous practice, not a point-in-time snapshot.
An assessment and a folder of PDFs answers the question once. Both JIS standards ask it again at every change, which a yearly engagement structurally cannot keep up with.
Every release is discovered and verified, every decision carries its reasoning, and the evidence updates as vulnerabilities surface. The record is defensible on the day a reviewer asks, not reconstructed for them.
Start with one device. We build the twin, run discovery across every release, and keep the defensible record JIS T 81001-5-1 expects, current and ready.