Cybeats
Cybeats builds SBOM Studio, a software bill of materials management and software supply chain security platform focused on connected and medical devices, operating as a subsidiary of publicly traded Relay Medical Corp.
Visit Website ↗ + Add to CompareOverview
Cybeats builds SBOM Studio, a software bill-of-materials (SBOM) system of record aimed at manufacturers of connected and medical devices. The platform ingests SBOMs and VEX (Vulnerability Exploitability eXchange) documents across a product’s lifecycle, correlates component-level vulnerabilities against known CVEs, and gives device makers a continuously updated view of what open-source and third-party code is actually running in their products. That is a narrower, more regulated problem than generic application security scanning, and it is the company’s whole focus.
The company was founded in Toronto in 2016 by Peter Pinsker, Dmitry Raidman, and Vladislav Kharbash, and was acquired in 2021 by Relay Medical Corp, a publicly traded medical-technology holding company (CSE: RELA), for roughly $7.18 million in cash and stock. Rather than being absorbed and rebranded, Cybeats continued operating under its own name as Relay Medical’s cybersecurity subsidiary, with Relay using the acquisition to build out a dedicated medical-device cybersecurity offering alongside its diagnostics business.
Cybeats’ relevance is tied directly to regulation: FDA premarket cybersecurity guidance for medical devices, the software supply chain provisions of U.S. Executive Order 14028, and the EU Cyber Resilience Act all now push device manufacturers toward maintaining verifiable SBOMs. Cybeats positions SBOM Studio as the compliance and risk-visibility layer that satisfies those requirements without manufacturers having to build SBOM tooling in-house.
As a small subsidiary of a micro-cap public parent, Cybeats’ disclosed customer base and financials are thin, and most public information about the company’s traction comes from Relay Medical’s own investor press releases rather than independent reporting. The underlying technology fit for a real and growing compliance problem is genuine, but the company’s scale and independent validation remain unproven.
Innovation Matrix Assessment
Cybeats has iterated on SBOM Studio since its 2020 launch, adding VEX ingestion and, per a 2024 vendor release, an AI-based analysis layer picked up by a medical device manufacturer customer. Release cadence looks steady for a small team but is not independently tracked.
Operating as a subsidiary of a micro-cap public parent (Relay Medical Corp) gives Cybeats capital access but also means its financials are folded into a small, thinly-traded diagnostics-and-cybersecurity holding company rather than standing on its own revenue base.
Relay Medical's investor communications cite expanding contracts with medical device manufacturers, but there is no independently reported customer count, revenue figure, or growth rate to corroborate the pace of adoption.
SBOM Studio is purpose-built for connected and medical devices rather than being a generic enterprise SBOM tool, aligning tightly with FDA premarket cybersecurity guidance and EU Cyber Resilience Act requirements that are still new enough that few vendors specialize this narrowly.
No independent test, MITRE-style evaluation, or third-party audit of SBOM Studio's detection or correlation accuracy was found. Evidence of effectiveness is limited to vendor press releases naming customer expansions, which is a real but unverified signal.
Software supply chain transparency is a growing, regulator-driven requirement (U.S. Executive Order 14028, FDA premarket cybersecurity guidance, EU Cyber Resilience Act), and medical/IoT device makers specifically are under increasing pressure to produce and maintain SBOMs.
Why CISOs Should Care
CISOs and product security teams at medical device and connected-device manufacturers need a working answer for SBOM and VEX compliance requests from regulators and hospital customers, and Cybeats is one of the few vendors purpose-built for that vertical.
What Makes It Different
Unlike general-purpose software composition analysis tools, Cybeats is scoped specifically to connected and medical devices, and it is backed by a publicly traded medtech parent rather than venture capital, which shapes its go-to-market around healthcare and device manufacturing.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A credible, narrowly-focused SBOM specialist riding real regulatory tailwinds in medical device cybersecurity. The technology fit is sound, but independent validation and disclosed scale remain thin.
Editorial Note: Claims vs. Verified Findings
Cybeats' customer-expansion and AI-feature announcements come from Relay Medical's own investor press releases and have not been corroborated by independent trade press. The 2021 acquisition by Relay Medical for approximately $7.18 million and the company's 2016 founding are independently documented across multiple financial news outlets (Newsfile Corp, GlobeNewswire, Infosecurity Magazine, Nasdaq).
Sources
Alternatives to Cybeats
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…