Bulla · Regulatory Infrastructure

Premarket. Postmarket. Cybersecurity, sealed.

Bulla seals the cybersecurity evidence loop for FDA-regulated and EU-bound medical device manufacturers — SBOMs, threat models, postmarket surveillance, and 510(k) Section IX, generated on the right cadence and routed to the right regulator.

Sealed artifacts
SBOM · §IX · MDR · EU AIA
Review lifecycle
Diffed vs. last filed
Source of truth
Your QMS + vuln tools
Filed
Cycle 24.Q3

Evidence pack

510(k) §IX · EU MDR · EU AIA

  • SBOM1,247 packages
  • Threats mapped38
  • CVEs tracked12 open
  • Last diff3 hrs ago

In the loop today

FDA 510(k)Section IX cybersecurity
EU MDRAnnex I §17.2 + Annex III
EU AI ActRisk + post-market monitoring
ISO 81001-5-1Healthcare cybersecurity governance

01 · The loop

The same source feeds every regulated artifact.

Bulla ingests the engineering, QMS, vulnerability-management, and AI-governance data you already produce, then continuously generates the regulator-facing artifacts those streams imply. Pick a stream to see what we read and what you file.

We ingest

  • Code commits
  • SBOM feed
  • CI/CD security tests
  • Design docs

You file

  • SBOM (CycloneDX + SPDX)
  • Threat model diff
  • Security test reports

02 · Artifact register

What we seal, who owns it, where it goes.

Every artifact in the regulated pack — version-controlled, signed, and diffed against your last filed snapshot.

01
Software Bill of Materials
Eng / AppSec
on every build
510(k) §IX · EU MDR Annex I §17.2
02
Threat model + design controls
Security architect
on design change
510(k) §IX · ISO 27001 A.8
03
Security test report
QA / Pentest
release + quarterly
510(k) §IX · EU MDR §10.4
04
Vulnerability management record
PSIRT
CVE-driven
Postmarket §522 · MDR Annex III
05
Postmarket surveillance entry
QMS lead
monthly
21 CFR 822 · EU MDR §84
06
510(k) Section IX statement
Regulatory affairs
on submission
FDA
07
EU AI Act conformity annex
AI governance
quarterly
EU AIA Annex IV
08
Traceability matrix
Compliance analyst
on change
FDA · Notified Body

All entries diff against the last filed snapshot; reviewers sign before anything is routed.

03 · Cadence

The analyst’s quarter, before and after.

What changes when the loop runs continuously instead of by hand.

Today
Bulla
Compliance analyst republishes the SBOM and threat model every quarter by hand.
Bulla
The same artifacts rebuild from the same source on every push.
A CVE lands; the response ticket meets the Section 522 window only if someone notices.
Bulla
A CVE lands; the postmarket record and Section IX draft update the same hour.
510(k) §IX paragraphs traced back to Jira tickets via tribal memory.
Bulla
Every §IX sentence traces back to a live source — diff, comment, sign.
EU AI Act post-market monitoring sits in a separate binder no one updates.
Bulla
EU AI Act monitoring reads from the same bug + bias data as FDA postmarket.
Pricing scales with seats of a tool the buyer’s team doesn’t really use.
Bulla
Pricing scales with devices under management and the cost of getting it wrong.

04 · Built on a vertical playbook

Two decades of FDA + EU cyber, in one loop.

Bulla is built by a 20-year medical device IT executive who led cybersecurity, cyber-risk, and IT compliance architecture for a Stryker-scale device manufacturer and now runs IT as VP at Argon Medical Devices.

The accumulated playbook — proprietary evidence templates, mapped regulatory narrative, and workflow lock-in at the QMS / vulnerability-management boundary — is the moat a generic AI wrapper cannot copy.

Evidence templates

Proprietary, regulator-shaped.

Reg narrative

Mapped to §IX, MDR, EU AIA.

QMS lock-in

Writes back to your QMS.

05 · FAQ

What buyers ask before signing.

Five questions we hear from VP Quality, Regulatory Affairs, and CISOs in medical-device programs.

06 · Seal the loop

Get in touch.

We reply from a real inbox, to a real engineer or regulatory lead. No SDR funnel, no scheduling link — a 30-minute note on whether Bulla maps to your program.

Talk to us
Built byArgon Medical IT · Vertical team
PrivacyNo tracking before sign-in