Class II / III SaMD development
IEC 62304-aligned SDLC from project start. Design History File (DHF) produced inline, not patched at submission.
Service · SaMD & medical device software
IEC 62304-aligned development, ISO 13485 quality system, FDA submission documentation, firmware-to-cloud pipelines, and the companion mobile apps that ship alongside your device — all under one team, one contract.
FDA submission · SaMD & medical device
0%What we build
IEC 62304-aligned SDLC from project start. Design History File (DHF) produced inline, not patched at submission.
Software documentation per FDA premarket guidance. Validation protocols, hazard analysis, cybersecurity SBOM, predicate analysis.
OTA firmware updates, telemetry, fleet management, edge inference. AWS IoT, Azure IoT Hub, GCP IoT.
iOS and Android apps designed to clear App Store / Play Store medical-device review. Apple HealthKit + CareKit, Android Health Connect.
Aligned QMS for engagements that need it. Document control, change control, design controls, CAPA workflows.
SBOM, threat model, vulnerability response plan, secure update mechanism documentation. Per FDA 2023 final guidance.
Who it's for
Tech we work with
Compliance scope
Our process
We review your code, infrastructure, and compliance posture. You get a written report, architecture diagram, gap analysis, and a fixed-price roadmap.
Weekly demo. Live dashboard with sprint velocity, open issues, and burndown. Read access to our repo from day one.
Automated and manual testing, security review, HIPAA-readiness check, optional third-party penetration test.
Production launch with monitoring, on-call rotation if you want it, continuing development at a steady cadence.
FAQ
Yes. Our SDLC is 62304-aligned by default for SaMD engagements. We bring the templates, traceability matrix, and document control. Your QMS lead sees the artifacts produced alongside the code.
Yes, with partner regulatory consultants for the parts that require submission-specialist depth. We've supported Class III SaMD as the software engineering partner.
Per the 2023 FDA final guidance, you need: SBOM (we generate from CI), threat model (we author with your team), vulnerability response plan (we draft, you adopt), and secure-update mechanism documentation. All produced as part of the engagement.
Insights · Read more

62304 doesn't tell you to write tests. It tells you to write tests that trace to requirements that trace to user needs. Here's what that looks like in a real codebase.

Serhii Kholin · 14 min

The new guidance pushed cybersecurity from optional to mandatory in the submission package. Here's what your DHF needs to include now.

Serhii Kholin · 10 min

Most teams build to a checklist and hope. We've sat across from the auditor — here's what they actually ask, and what surprises engineering teams.

Denis Sheremetov · 8 min
Start with the audit
Tell us what you're building or what's not working. We'll come back with a written audit and a fixed-price plan.