Solutions · Postmarket Surveillance

Continuous, not point-in-time.

Your last test report described the device that existed on the day of the test. New CVEs have published against your components since. The obligation to monitor never pauses, so the evidence cannot either. ELTON watches the feed against a living model of every release you support. ELTON is an exploitability management platform, delivered as a managed program. Our team runs discovery and verification against your device continuously, release after release.

The twin never stops watching

Each release is modeled as a digital twin built from documentation your QMS already holds. New CVEs are checked against it when they publish, not at the next annual engagement. The file updates itself while your team sleeps.

The problem

Point-in-time testing cannot carry a continuous obligation.

Section 524B and EU postmarket rules assume monitoring for the life of the device. An annual report is a snapshot standing in for a process. Regulators have noticed the difference.

Reports with expiration dates

A penetration test starts going stale on delivery day. Every disclosure after it lands in a gap where nobody is looking at your device.

The feed is accelerating

CVE publication volume is roughly tripling from 2024 to 2028. A manual process that barely kept up last year fails quietly next year, and nobody files a deviation for it.

Hospitals ask per product, per CVE

Every headline vulnerability triggers customer questionnaires. Answering from spreadsheets, one device at a time, stops scaling at the very first advisory.

What ELTON runs

A surveillance loop that closes itself.

Ingestion, triage, verification, and reporting run as one automated cycle against every supported release, with a person in the loop only where judgment is needed.

Continuous CVE ingestion

New disclosures are mapped against the digital twin of each supported release. Relevance is decided by your actual build, not a keyword match on a vendor name.

Auto-triage with verification

Candidates that could apply are verified for exploitability. Only proven true positives reach an engineer, with fix guidance attached. The rest are dismissed with evidence, automatically.

Per-release tracking

A fleet is not one device. ELTON knows which releases carry which components, so each disposition lands on every affected version and none of the others.

VEX your customers can ingest

Machine readable VEX in CycloneDX answers affected or not affected per product, so HDOs get their answer before the questionnaire goes out. Publish once, answer everyone.

Proof it works

Measured from the day the CVE publishes.

Surveillance you cannot measure is surveillance you cannot defend. ELTON reports mean time to triage and mean time to remediate per product, clocked from publication to evidenced disposition.

Between tests, the feed keeps publishing POINT-IN-TIME Test Test CVEs land unseen between engagements ELTON CONTINUOUS always on each CVE checked against the twin on publication, disposition evidenced the same day
Same feed, two postures. The difference is what exists in the file when someone asks.
MTTT

Mean time to triage

From CVE publication to an evidenced disposition on every affected release. ELTON drives it down by deciding relevance against the twin instead of a human queue.

MTTR

Mean time to remediate

From verified exploitable to re-verified fixed. Prescriptive guidance shortens the fix. Re-verification closes it with proof, and the metric goes straight to your quality review.

Get started

Keep the file current between releases.

ELTON monitors every supported release continuously and evidences each disposition as it happens. Postmarket becomes a record, not a scramble.

Questions

Common questions about postmarket surveillance.

Why can point-in-time testing not carry a postmarket obligation?

Section 524B and EU postmarket rules assume monitoring for the life of the device, so an annual report is a snapshot standing in for a process. A test report describes the device that existed on the day of the test, and every disclosure after it lands in a gap where nobody is looking.

How do you keep up with the volume of new CVEs?

CVE publication volume is roughly tripling from 2024 to 2028, so a manual process that barely kept up last year fails quietly next year. ELTON maps each new disclosure against the digital twin of every supported release when it publishes, and relevance is decided by your actual build rather than a keyword match on a vendor name.

How do you answer hospital questionnaires about a new vulnerability?

Publish machine readable VEX in CycloneDX. It states affected or not affected per product, so hospitals get their answer before the questionnaire goes out. Publish once, answer everyone. Answering from spreadsheets, one device at a time, stops scaling at the very first advisory.

How do you track one vulnerability across multiple product releases?

A fleet is not one device. Each supported release is modeled as its own digital twin, built from documentation your quality system already holds, so ELTON knows which releases carry which components. Every disposition lands on every affected version and none of the others.

How do you measure postmarket surveillance performance?

With mean time to triage and mean time to remediate, reported per product and clocked from the day the CVE publishes. Mean time to triage runs from publication to an evidenced disposition on every affected release. Mean time to remediate runs from verified exploitable to re-verified fixed, and both feed your quality review.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON