About
Threat Detective is SBOM and vulnerability management software for medical device teams. It imports and validates CycloneDX and SPDX SBOMs, identifies vulnerabilities using NVD, GitHub Security Advisories, and OSV, prioritises findings using CVSS, EPSS, and CISA KEV, and records exploitability, remediation, and mitigation decisions with an auditable history. It turns that vulnerability analysis into submission-ready cybersecurity evidence for medical device regulatory workflows, including FDA premarket submissions, and supports VEX generation. Continuous monitoring then tracks active device and software versions for newly disclosed vulnerabilities throughout post-market surveillance.
Related Vendors

Eracent provides automated SAM and ITAM solutions and a focused SBOM capability. The record describes a "CSMS SBOM Manager™" and "Comprehensive SBOM Management and Analysis" that support software supply chain security, list components in a Software Bill of Materials, and enable quick matching of vulnerabilities (CVEs) to affected software products. Eracent also references foundational data, asset and license management, cybersecurity & risk management, and coordination to support deployment of a NIST CSF 2.0 process. The content frames the offering as tools for application risk, security, obsolescence and licensing risk associated with open source software, and for enabling data sharing with complementary systems.

Finite State positions itself as a product cybersecurity platform for connected devices and embedded systems. The platform uncovers vulnerabilities in source code, binaries, and third-party components and consolidates risks into a unified view across a product portfolio. Finite State says it can dissect source code or binaries with precision to reduce false positives and help teams prioritize and fix issues, and it offers CI/CD integrations and automatic PRs for remediation workflows. The company highlights compliance-readiness, the ability to generate reports to meet regulatory compliance requirements, and notes it is SOC 2 Type 2 certified. The site also references recorded demos and access to expertise from former U.S. government officials.

Cloudsmith is a fully-managed, enterprise-scale solution for controlling, securing, and distributing software packages and containers. It provides supply chain security software with observability and governance, helping organizations protect their end users by mitigating compliance issues before they reach production systems. With a single, observable home for every package and container, Cloudsmith boosts productivity with global artifact distribution and powerful analytics. Streamline operations and drive innovation with integrated analytics, logging, and audit trail tools, making it the ideal platform for enterprises looking to enhance their software supply chain security.
