IDE Software Risk and Cybersecurity Summary¶
Status: Reviewer summary for the frozen engineering baseline Updated: 2026-09-03
Software Risk Themes¶
The risk analysis concentrates on:
- incorrect or mistimed insulin-delivery decisions
- stale, missing, or degraded CGM or pump state
- backup-basal and masked-fallback exposure during interruptions
- interrupted automatic bolus attribution and exactly-once accounting
- alert or UI behavior that obscures a significant condition or response
- unauthorized Clinical Settings changes or unsafe reset/configuration
- loss, exposure, misassociation, or incomplete transfer of study records
- association with the wrong pump or CGM sensor
Principal Controls¶
- freshness, availability, identity, continuity, and pump-state gates
- reference-host-aligned algorithm input and total-insulin command construction
- persistent request-step identity and evidence-precedence rules
- bounded, conserved fallback replay and explicit assumed-delivered labels
- programmed backup basal and fingerstick-supported CGM-outage safeguards
- alert normalization, precedence, deduplication, persistence, and escalation
- first-save configuration boundary and subject-scoped offline unlock
- G7 replacement acquisition controls; staleness alone never releases the bound
sensor, while
RA-023/D06retain the documented multi-candidate and replacement-state limitations - protected local evidence, backup exclusion, sequenced telemetry, and exact-session recovery export
- controlled traceability from hazards through requirements, design, verification, and evidence
The detailed controls and residual scores are in Risk Analysis version 1.53 and RTM version 1.86.
Cybersecurity Boundary¶
BionicLoop owns the controller app, local storage/export, cloud-client code, logging, application configuration, and embedded-package integration it ships. Dexcom and Insulet own the proprietary device firmware and primary security controls of their cleared products. Algo2015 clinical logic is sponsor- controlled; BionicLoop owns its hosting, build identity, and isolation.
The exact-freeze local-control lane passed 68/68 tests. The current investigational posture removes participant Files sharing/open-in-place, protects and backup-excludes retained records and export staging, gates recovery sharing to the clinical workflow, and isolates recovery artifacts to the selected algorithm session.
Build 843 uses an exactly tracked dependency resolution and passed dependency, crypto/session, core, app, and scoped security verification. Its signed archive, installed identity, and real-Pod operation are recorded.
Scope Limitations¶
The local-control result does not close:
- inherited supplier security evidence
- commercial cloud or broader provider/authentication controls
- Part 11 readiness
- controlled vulnerability/scanner acceptance beyond the documented manual software-composition and advisory method
- commercial or relied-upon cloud transport beyond the clinically approved supportive/optional Scout package boundary
Current Open Items¶
- sponsor-designated acceptance of exact-freeze cybersecurity evidence
- acceptance of the controlled manual composition/advisory method or approved scanner evidence
- inherited-control artifact linkage for DASH, G7, and the Dexcom app
- retained Scout evidence only as corroborating backup unless the study later widens its relied-upon cloud scope
Official study sources are Dexcom Clarity for CGM outcomes, the BionicLoop exported CSV for insulin-delivery outcomes, and staff-entered electronic case-report forms for adverse events and other safety information.
The engineering recommendation remains conditional for investigational use, not a commercial cybersecurity closure.