MedCrypt
MedCrypt provides a software-plus-services cybersecurity compliance platform (Helm, Guardian, MSI) that helps medical device manufacturers achieve FDA premarket approval and post-market cybersecurity management, serving 140+ MDMs including 13 of the Top 50 global device makers.
- Company typePrivate
- Founded2019
- HeadquartersSolana Beach, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What MedCrypt does
MedCrypt is a Solana Beach, California-based medical device cybersecurity company that helps medical device manufacturers (MDMs) achieve and maintain FDA cybersecurity compliance across the device lifecycle. The company sells a software-plus-services portfolio to device OEMs ranging from early-stage startups to 13 of the Top 50 global MDMs, anchored by three core products: Helm (SBOM and vulnerability management with AI-driven CVE screening), Guardian (cryptographic provisioning, certificate management, and secure OTA updates for connected devices), and MSI (MedCrypt Security Intelligence, an end-to-end compliance roadmap platform with financial risk quantification). Its expert services layer is staffed by former FDA reviewers and policy architects, and bundles pre-market offerings (FDA readiness assessments, threat modeling, PKI analysis) with post-market services (incident response, vulnerability management, regulatory change tracking).
The company monetizes through annual software subscriptions priced from $32,000/year in tiered bundles (Accelerator, Standard, Premium), a standalone Helm SKU starting at $299/month, and enterprise licensing for Guardian, supplemented by professional services engagements. Go-to-market blends product-led growth (a free 5-minute readiness check tool and a 6-week Helm trial) with enterprise field sales targeting Product Security Officers, Regulatory Affairs Leads, and C-suite executives; a separate self-serve path handles startups. Distribution channels include direct enterprise sales, inside sales, self-serve trials, and professional services, supported by content marketing, webinars featuring former FDA personnel, industry events, and threat-modeling training courses.
The company reports 140+ medical device manufacturer customers, 200+ projects delivered, and a 100% FDA approval rate for customers following its guidance since 2023, with cumulative disclosed funding of approximately $44.7M including a $25M Series B (Nov 2022) led by Intuitive Ventures and Johnson & Johnson, a Dexcom Ventures extension (Jan 2023), and an approximately $8.3M round in February 2025. It competes in a healthcare cybersecurity market projected to grow from $7.29B in 2025 to $22.69B by 2034, and has expanded its addressable scope from premarket filings into EU MDR, Health Canada, QMSR, and post-market vulnerabilities driven by EU CRA 2026 mandates.
MedCrypt firmographics
Firmographics- Name
- MedCrypt
- Legal name
- MedCrypt
- Website
- https://medcrypt.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- MedCrypt provides a software-plus-services cybersecurity compliance platform (Helm, Guardian, MSI) that helps medical device manufacturers achieve FDA premarket approval and post-market cybersecurity management, serving 140+ MDMs including 13 of the Top 50 global device makers.
- Ownership category
- akta.pro rank
MedCrypt industry classification
Industry- Product category
- Medical Device Cybersecurity Software
- NAICS
- Software Publishers (5132), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Health Services (8000)
- akta.pro primary industry
- Medical Device & IoT Security (Connected Devices/RPM/OT) (HLACAJAI)
- akta.pro secondary industries
- Vulnerability Management, Pen Testing & Attack Surface Management (ASM) (HLACAJAN), Governance, Risk & Compliance (GRC) + HIPAA/HITRUST/ISO Readiness (HLACAJAJ), Data Loss Prevention (DLP) & Sensitive Data Discovery (PHI/PII) (HLACAJAC)
Keywords
Where MedCrypt is headquartered
LocationHeadquarters
- HQ city
- Solana Beach
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
MedCrypt business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Subscriptions (Helm): SaaS subscription for SBOM and vulnerability management software. Standalone licensing available at $299/month, with bundle pricing from $32,000/year. Tiers include Accelerator (1 product, 1 user), Standard (10 products, 2 users), and Premium (unlimited products, 5 users). All bundles include Helm 6-week trial, regulatory templates, expert advisory, and drafting services.
- Professional Services: Cybersecurity consulting services including FDA cybersecurity readiness, threat modeling, PKI analysis, maturity assessments, SDLC integration, incident response, and regulatory compliance support. Provided by former FDA reviewers.
- Guardian Platform Licensing: Cloud-based certificate management and device security platform for cryptographic provisioning, device authentication, and secure communication. Sold as part of bundle packages or standalone enterprise agreements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Accelerator - Essential security for startups or budget-conscious MDMs |
| Subscription | Annual | Standard - Enhanced support for MDMs encountering growth obstacles and regulatory challenges |
| Subscription | Annual | Premium - Premium support for MDMs prioritizing innovation and regulatory excellence |
| Subscription | Monthly | Helm Standalone - Individual SBOM vulnerability management software |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels6 records
MedCrypt product offering
Product offeringCore offering
MedCrypt sells a medical device cybersecurity compliance platform comprising Helm (SBOM and vulnerability management), Guardian (cloud-based certificate/PKI management for device authentication), and MSI (regulatory readiness scoring and risk quantification), bundled with expert services from former FDA reviewers. Offerings target medical device manufacturers needing FDA, EU MDR, and Health Canada cybersecurity approvals for connected and software-enabled devices.
Product overview
MedCrypt offers a platform-plus-services cybersecurity portfolio for medical device manufacturers. The core product suite includes Helm (SBOM and vulnerability management), Guardian (cryptographic key and certificate management), and MSI (cybersecurity roadmap and compliance platform). These integrate with MedCrypt's expert consulting services spanning pre-market (FDA readiness, threat modeling, PKI analysis) and post-market (incident response, vulnerability management, regulatory compliance) support. The company leverages AI-driven automation within Helm for vulnerability screening and prioritization, and provides an API SDK for programmatic access.
Differentiator
Problem solved
Functional benefit
Brands
- Helm: SBOM and vulnerability management software platform for medical device manufacturers
- Guardian
- MSI (Medcrypt Security Intelligence)
Products and services
- Helm Helm is a SBOM and vulnerability management platform for medical device manufacturers that integrates and analyzes software supply chains to identify and mitigate vulnerabilities, featuring AI-driven automation with expert manual review for accurate CVE screening, bulk rescoring, continuous monitoring, and automated workflows. It reduces SBOM review time by 90% and is sold standalone from $299/month or bundled with services.
- Guardian Guardian is a cloud-based data security and privacy platform for medical device manufacturers providing cryptographic key provisioning, certificate lifecycle management, secure device authentication, Root of Trust establishment, encrypted communication, and secure over-the-air updates for connected and disconnected environments, without requiring source code modifications.
- MSI (Medical Device Product Security Intelligence Platform) MSI is an end-to-end cybersecurity roadmap and compliance platform for medical device manufacturers that benchmarks product security posture, quantifies financial risk exposure from unresolved vulnerabilities, and prioritizes mitigation with clear budget insights to accelerate FDA approvals and post-market compliance.
- Pre-market Services Pre-market Services is a consulting engagement from MedCrypt that prepares medical device manufacturers for FDA cybersecurity readiness across 510(k) and PMA submissions, covering threat modeling, PKI analysis, maturity assessments, SDLC integration, and regulatory strategy, led by former FDA policy reviewers and analysts.
- Post-market Services Post-market Services is an ongoing cybersecurity management offering from MedCrypt for medical device manufacturers covering incident response, vulnerability management, SBOM validation, risk management, and regulatory change management across the device lifecycle, delivered by former FDA reviewers.
- FDA Cybersecurity Filing Readiness FDA Cybersecurity Filing Readiness is a MedCrypt assessment and remediation service that gauges medical device manufacturers' submission readiness against FDA cybersecurity guidance, identifies documentation gaps, and creates prioritized remediation plans to support FDA 510(k) and PMA clearance.
- Threat Modeling Training Threat Modeling Training is a MedCrypt training course that teaches medical device teams how to create, maintain, and update threat models using MedCrypt's proprietary methodology, with hands-on application and alignment to FDA submission requirements.
Companies that use MedCrypt
Customer profileNamed customers6 records
Segments4 records
Ideal customer profiles3 records
MedCrypt technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability6 records
Feature4 records
MedCrypt partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Thirdwayv Inc.corePartnership announced at Diabetes Technology Society Conference 2025 to develop cybersecurity and interoperability standards for connected medical devices. Collaboration aims to address regulatory and operational demands by providing integrated solutions for secure device development, compliance, and secure over-the-air updates. Combines Thirdwayv's expertise in device security with MedCrypt's vulnerability management capabilities.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
MedCrypt competitors and assessment
Company assessmentDirect peers
- Cynerio: Healthcare-focused cybersecurity vendor specializing in medical and IoT device visibility, risk management, and clinical network protection. Direct competitor to MedCrypt in medical-device cybersecurity RFPs, particularly for hospital systems and connected device fleets.
- Claroty: Cybersecurity company focused on cyber-physical systems across OT, IoT, and connected medical devices in healthcare. Comparable to MedCrypt in device discovery, vulnerability management, and FDA cybersecurity compliance workflows for medical device manufacturers.
- Asimily: Medical device cybersecurity and risk management platform for healthcare providers, focused on inventory, vulnerability prioritization, and remediation. Direct competitor to MedCrypt in the medical device cybersecurity market, particularly for connected device fleets.
- MedSec: Cybersecurity services firm dedicated to medical devices and the healthcare ecosystem, offering pre- and post-market security services. Closely comparable to MedCrypt's pre-market FDA readiness and threat-modeling service layer.
Emerging players
- Ordr: Connected device security platform with strong healthcare exposure, focusing on medical device discovery, risk assessment, and segmentation. Comparable to MedCrypt's Guardian-style device identity and risk quantification capabilities.
- Armis: Asset intelligence and cybersecurity platform for connected devices across IT, OT, IoT, and medical devices. Adjacent competitor offering device-level visibility and vulnerability management that overlaps with MedCrypt's Helm/MSTM capabilities.
- Sternum IoT: Embedded runtime security and visibility platform for medical and industrial IoT devices, focused on device-side integrity. Comparable to MedCrypt's Guardian-side runtime/identity controls for connected medical devices.
Broad incumbents
- Palo Alto Networks: Global cybersecurity incumbent with an expanding healthcare and medical-device practice (Unit 42, IoT security portfolio). Represents the dominant broad incumbent that MedCrypt competes against for medical-device cybersecurity spend at large MDMs.
- Forescout: Network security vendor specializing in connected device visibility and OT/IoT security, with active healthcare / medical-device exposure (acquired CyberMDX). Comparable on medical device discovery and vulnerability workflows.
- CrowdStrike: Endpoint and cloud security leader expanding into IoT/OT and healthcare verticals. Broad incumbent whose Falcon platform competes against MedCrypt on enterprise-wide device cybersecurity programs at large MDMs.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
MedCrypt social profiles
Digital presenceMedCrypt financial estimates
Financial estimateRevenue estimate
Valuation estimate
MedCrypt leadership team
Management profileNumber of profiles
Profiles12 records
MedCrypt funding detail
Funding detailFunding overview
Funding rounds7 records
Investors18 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
MedCrypt M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about MedCrypt
What does MedCrypt do?
MedCrypt sells a medical device cybersecurity compliance platform comprising Helm (SBOM and vulnerability management), Guardian (cloud-based certificate/PKI management for device authentication), and MSI (regulatory readiness scoring and risk quantification), bundled with expert services from former FDA reviewers. Offerings target medical device manufacturers needing FDA, EU MDR, and Health Canada cybersecurity approvals for connected and software-enabled devices.
Is MedCrypt a public or private company?
MedCrypt is a private company. It is classified as venture growth investor backed and is currently operating.
When was MedCrypt founded?
MedCrypt was founded in 2019. It employs 11 to 50 people.
Where is MedCrypt based?
MedCrypt is headquartered in Solana Beach, United States, in the North America region.
How does MedCrypt make money?
Three revenue lines are on record. Software Subscriptions (Helm) is the primary driver. The others are professional Services and guardian Platform Licensing.
Who are MedCrypt's main competitors?
Direct peers on record are Cynerio, Claroty, Asimily and MedSec. Emerging players are Ordr, Armis and Sternum IoT. Broad incumbents are Palo Alto Networks, Forescout and CrowdStrike.
Does MedCrypt have an API?
Yes. Helm API SDK enables programmatic SBOM and vulnerability management, including uploading SBOMs, getting unmatched components, retrieving vulnerabilities, managing CISA KEV vulnerabilities, generating FDA SBOM and VEX reports, and user/product administration. Guardian provides API for device provisioning operations supporting connected, disconnected, and proxy provisioning methods. Developer documentation is at helm.docs.medcrypt.com/automate-and-integrate/api-sdk-documentation.
What industry is MedCrypt in?
MedCrypt's product category is Medical Device Cybersecurity Software. Its primary akta.pro industry code is HLACAJAI, Medical Device & IoT Security (Connected Devices/RPM/OT), with a secondary code of HLACAJAN, Vulnerability Management, Pen Testing & Attack Surface Management (ASM). Its NAICS code is 5132 and its SIC code is 8000.