The pipeline

Threat-Led
AI Pentesting.

ELTON builds a digital twin of your device, threat models it with MITRE EMB3D, generates a test case for every threat, and runs a proprietary toolchain against the real product. AI builds the tools. The pipeline does the testing. Your data never becomes the prompt.

Read the whitepaperHow the ELTON AI pipeline tests a medical device · PDF
The shape of the problem

A device is not a URL.

Autonomous pentesting is real and it is narrow. It is strong on a reachable web surface and blind to the firmware, hardware, and protocols where a medical device actually lives.

Two architectures · the surface decides the design
web outside-in
device inside-out
OUTSIDE-IN · WEB-APP AGENTStart at a URLno prior context, recon firstReach what is exposedHTTP surface, forms, APIsExploit or notbinary verdictReport, then stopscope was whatever it reachedINSIDE-OUT · ELTON PIPELINEStart from the twinarchitecture pre-loaded, zero reconReach the whole devicefirmware, code, hardware, protocolFour states, evidencedexploitable to mitigatedLiving recordVEX and traceability that compound
reaches what is exposedreaches the whole device
A web-app agent tests what it can reach. On a device, what it can reach from outside is the small part.
Point a web-app agent at a device and it maps the small part it can see from the outside, then declares the rest out of scope. The scope was decided by what the agent could reach, which is exactly the failure mode a regulator now asks about. ELTON runs the other direction: it starts from a model of the whole device and tests inward.
How it works

Twin, threat, test case,
evidence.

The pipeline runs in one direction and the trace never breaks. Each link carries an identifier, so coverage is a list you can read before the first packet is sent.

The traceable chain · twin to disposition
1 chain
2 directions
ONE CHAIN, WALKED IN EITHER DIRECTIONDIGITAL TWINComponents, SBOM,interfaces, controlsPROPERTY (PID)What the device is:bootloader, update pathTHREAT (TID)What can go wrong,pinned to a componentTEST CASEScope, pass and fail,executed on the targetRESULTExploitable, or NotAffected, with evidenceEvery link carries an identifier. A reviewer starts from a component or from a finding and the trace holds.
AI infers property and threatdeterministic execution decides the result
AI does two jobs: infer which threats apply, and write the tools that test them. Execution decides what is real.
1

The digital twin

Ground truth first. A model of the device's security architecture, built from the documentation your quality system already produces: components and SBOM, interfaces, trust boundaries, and documented countermeasures. It is Level 1 of verification and clears 30 to 40 percent of findings as Not Affected before anyone touches hardware.

2

Threat analysis with MITRE EMB3D

The twin becomes threats. Component types map to device properties, properties map to the threats EMB3D says apply, and ELTON extends both where the catalog stops. Every threat is pinned to a specific component, so nothing about the next step requires guessing where to look.

3

AI test-case generation, per threat

A procedure, not a prompt. For each pinned threat the pipeline generates a test case with a scope, a pass criterion, a fail criterion, and an execution tier. Because it descends from a threat that descends from the twin, coverage is auditable in both directions, which is the artifact FDA reviewers ask for.

4

The proprietary pipeline

AI writes the tools, the pipeline runs them. An orchestrator dispatches deterministic tools and specialized agents across network, firmware, code, and clinical workflow, carried onto the real device by TestLink™. More than five agentic loops write new tools around the clock. No finding reaches you before a qualified tester reviews it.

5

Verification and disposition

Proof, not a rating. Every test runs at the deepest tier you open. Each finding lands as directly exploitable, conditionally exploitable, an unexploitable weakness, or already mitigated, with an executed test case behind it and a rating on the FDA-qualified MDDT rubric.

Where your data goes

The boundary is structural,
not a policy promise.

Your source code, firmware, documents and findings stay inside the pipeline. What a model sees is ELTON's own engineering work: what a tool needs to do, and how a documented protocol behaves.

A prompt

Your product becomes the input

Pointing a general model at a device has no device context, verifies nothing, and returns something different every time. The output is a wall of maybe-issues with no evidence a reviewer can follow, and getting there meant handing over your source code.

The pipeline

The tools are the product

Tools are deterministic. They run the same way twice, against the real device, and produce evidence. The data path and the development path never meet, so the model improves on ELTON's engineering, never on your data.

When a vendor says they use AI on your product, the question that matters is where your data goes. If the answer is a general chat client, it left their control the moment they pressed send.
Verification

Deeper access dismisses more,
with stronger evidence.

The tiers run in your favor. More access does not surface more alarms, it retires more findings with evidence a regulator will accept.

Three-tier verification · graduated confidence, not a guess
L1 twin
L2 code
L3 hardware
DEEPER ACCESS DISMISSES MORE, WITH STRONGER EVIDENCEL1 · DIGITAL TWINReachability and control analysis on the model30-40% Not AffectedL2 · CODE & FIRMWAREStatic and dynamic analysis of the real implementation50-65% Not AffectedL3 · REAL HARDWAREOn-device exploitation through TestLink, pass or fail70-85% Not Affected
reachabilityimplementationon the real device
The Not Affected rate climbs with access, because the deeper the test, the more theory it kills.
The difference

Confirm the positives.
Evidence the negatives.

A web-app validator re-exploits a finding to prove it is real. ELTON also manufactures the negatives: the executed test that lets you defensibly dismiss the 99 percent that are not exploitable on your device.

Autonomous web-app pentesters point a model at a target and prove what they can reach. ELTON builds the device first, threat models it, tests every threat with tools the AI writes and a human reviews, and proves both what is exploitable and what is not, in evidence a reviewer will accept.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Meet ELTON
See the graph decide, live >