Skip to main content

Trust & Security

Last updated: June 2026

DeviceWatch helps medical device teams monitor FDA post-market safety signals. We treat the security of your account and your monitoring configuration with the same seriousness the work itself demands.

What data we handle

DeviceWatch monitors publicly available FDA adverse event data (AEMS, formerly MAUDE, via openFDA). We do not collect, store, or process protected health information (PHI), and we do not hold your proprietary clinical or quality records.

The data associated with your account is limited to:

  • Account & organization data — names, email addresses, roles, team membership
  • Monitoring configuration — the product codes and competitors you choose to track
  • Generated content — AI summaries derived from public FDA narratives, reports, and digests

Billing is handled entirely by Stripe; we never store payment card data.

How we protect it

  • Encryption everywhere — all data is encrypted in transit (TLS) and at rest.
  • Access controls — role-based access, organization isolation, and least-privilege invitations. Users only see data for organizations they belong to.
  • Session security — automatic session timeouts and CSRF protection on all state-changing requests.
  • Audit trails — compliance-critical actions are recorded in immutable audit logs, supporting our customers' 21 CFR Part 11 workflows.
  • Monitoring — application errors and security events are continuously monitored.
  • Rate limiting & abuse protection — platform-layer edge rate limiting and always-on DDoS mitigation, plus application-layer quotas on our public API.
  • Data retention — configurable retention policies with scheduled cleanup.

Compliance posture

  • 21 CFR Part 11-ready features — DeviceWatch provides immutable audit trails, access controls, and session management to support customers operating under FDA electronic records and signatures requirements.
  • DPA & SIG Lite — a Data Processing Agreement (DPA) is available for enterprise customers, and we complete a SIG Lite (Standardized Information Gathering, Lite) questionnaire on request. Because DeviceWatch monitors public FDA data and does not store PHI, our security risk profile is low, and these two documents cover what most procurement teams need.

Our infrastructure

DeviceWatch is built on enterprise-grade, independently audited providers:

  • Vercel — application hosting
  • Supabase — database & authentication
  • Stripe — payment processing
  • Anthropic (Claude) — AI summarization of public FDA narratives
  • Resend — transactional email

Reporting a vulnerability

If you believe you've found a security issue, please email security@devicewatch.app. We investigate all reports promptly and will keep you informed of our progress.

Questions?

Enterprise customers and procurement teams can request our security whitepaper, a completed security questionnaire, or a DPA at security@devicewatch.app.