Skip to content

IDE Cybersecurity Closure Matrix

Field Value
Baseline Frozen source 91c0e98a9bc9429a0486bebdebffc7d8dbbe300e; designated Build 843 1455cda7ad5d3e164b4a955ea0e3bc725a9996e9
Purpose Concise disposition of study-used cybersecurity controls and operational follow-through
Status Cybersecurity scope and controls accepted under D09; operational items remain where shown
Date 2026-09-08
Control area Current state Remaining action/disposition
Protected local clinical records, migration, backup exclusion, and gated export TV-SEC-001 passed 68/68 at the frozen baseline Complete; accepted under D08 and D09
Build 843 dependency resolution Exact CryptoSwift 1.10.0 and controlled Package.resolved; dependency and crypto/session tests passed Complete; Build 843 approved for IDE submission 2026-09-03
Machine-readable SBOM CycloneDX 1.5 SBOM generated and reconciled to the Build 843 manifest Complete; accepted within D09
Vulnerability review Dated public GitHub advisory review found no matching external-package advisories Accepted manual method for submission; define operational monitoring cadence
License review CryptoSwift attribution, SlideButton MIT, SwiftCharts Apache-2.0, LoopKit/OmniBLE MIT, and G7SensorKit MIT with traced upstream sync base identified Accepted within D09; retain required distributed acknowledgments
Threat modeling Current plan lists study-relevant scenarios and trust boundaries Open; complete and approve a structured worksheet if required by sponsor process
G7 and DASH inherited controls Device/interface boundaries and local implementation are documented Open; retain approved supplier/FDA-cleared-product references for relied-upon controls
Update and patch process Post-approval software change procedure exists Open; approve owner, severity criteria, deployment path, and study communication process
Vulnerability monitoring No approved recurring cadence is recorded Open; assign owner, sources, frequency, and escalation criteria
Incident response General severity and response expectations are documented Open; approve contacts, timing, containment, reporting, and recovery procedure
Cyber labeling and informed-consent assessment Investigational and device-use limitations are present Open; Sponsor/Regulatory determines any cyber-specific labeling or consent content
Scout telemetry Supportive only; local dosing does not depend on Scout; local recovery ZIP is primary software reconstruction evidence Approved scope; retain corroborating sequence records and investigate material gaps; broader cloud/auth/Part 11 deferred
Clinical Settings unlock Subject-scoped, single-use offline verification and secure local state are implemented and tested Complete; accepted under D08 and D09
Broader provider/authentication and commercial cloud Not relied upon for local dosing or official study outcomes under the approved Scout scope Deferred; reopen only if relied-upon study scope expands

Final cybersecurity acceptance is recorded under D09. This matrix preserves the operational follow-through without reopening closed Build 843 dependency work or expanding the accepted supportive-Scout boundary.