# Stratigos Security > High-assurance cybersecurity for regulated and safety-critical industries. Founded by Beau Woods, former FDA Entrepreneur in Residence. Stratigos Security provides penetration testing, threat modeling, security advisory, and vCISO services for medical device manufacturers and high-tech companies. The team helped write the FDA's premarket and postmarket cybersecurity guidance and has been engaged with the agency since 2013. ## Pages - [Home](https://stratigossecurity.com/): Overview of Stratigos Security services and positioning - [Medical Devices](https://stratigossecurity.com/medical-devices/): FDA-ready cybersecurity testing for medical device manufacturers - [Medical Device Penetration Testing](https://stratigossecurity.com/medical-devices/penetration-testing/): FDA-aligned penetration testing methodology for medical devices - [Medical Device Threat Modeling](https://stratigossecurity.com/medical-devices/threat-modeling/): Threat modeling aligned to AAMI TIR57, ISO 14971, IEC 81001-5-1 - [Cyber Certainty](https://stratigossecurity.com/medical-devices/cyber-certainty/): Submission-ready cybersecurity documentation, eSTAR-ready reports, deficiency response - [Medical Device Cybersecurity Quickstart](https://stratigossecurity.com/medical-devices/quickstart/): Rapid readiness review of a device's cybersecurity posture ahead of threat modeling, testing, and regulatory review - [Penetration Testing](https://stratigossecurity.com/penetration-testing/): General penetration testing services for high-tech companies - [Advisory](https://stratigossecurity.com/advisory/): Security advisory and vCISO services - [Why Us](https://stratigossecurity.com/why-us/): Differentiators and five questions to ask any medical device penetration testing firm - [About](https://stratigossecurity.com/about/): Beau Woods bio, team credentials, company history - [Contact](https://stratigossecurity.com/contact/?via=agents-pointer): Schedule a call with Stratigos Security - [Insights](https://stratigossecurity.com/insights/): Thought leadership on medical device cybersecurity - [Coordinated Vulnerability Disclosure](https://stratigossecurity.com/coordinated-vulnerability-disclosure/): How Stratigos discloses vulnerabilities it finds and how to report one to Stratigos - [Privacy & Security](https://stratigossecurity.com/privacy/): Privacy practices and data handling - [Sustainability](https://stratigossecurity.com/sustainability/): Commitment to a lower-impact business model ## Insights - [Quoted in Wired: Why safety-critical security research matters](https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737/): Andy Greenberg's Wired story on a hardware implant against Boeing 737 avionics features Beau's perspective: research done in the open and taken seriously by industry makes safety-critical systems safer. (appearance, 2026-08-12) - [CISA's Coordinated Vulnerability Disclosure Guidance: A Look at What's New](https://stratigossecurity.com/insights/cisa-cvd-guidance/): CISA's new joint guidance on coordinated vulnerability disclosure updates the playbook in welcome ways. What's new, what it leaves out for safety-critical systems, and what medical device makers should draw from. (article, 2026-07-23) - [Reintroduction: Beau Woods on medical device cybersecurity](https://www.linkedin.com/posts/beauwoods_im-getting-more-active-here-for-dayjob-share-7482465952652013568-Bsb5/): After years of quietly building Stratigos Security, Beau shares what the team has been working on and why medical device cybersecurity demands a different kind of testing partner. (appearance, 2026-07-13) ## For AI agents - [Page finder](https://stratigossecurity.com/agents/?via=llms-txt): Ask in the reader's own words and get the one page most likely to answer, with the short answer where the site has one. The question alone gets the general answer. Include who it is for and what changes it, and you get the specific one: the role (regulatory, engineering, quality, clinical, executive, security, research, press) gets the version written for that reader; the kind of organization (device maker, hospital, consultancy, ...) gets the answer for who has to act; the situation (device type, pathway such as 510(k) or PMA, stage, the decision at hand) gets the page for that case. Each detail narrows the result and the reply shows which it used; one call with them beats two without. Kinds and situations only, never names: nothing that identifies the reader is asked, and anything resembling contact details is removed before storage. What is sent is kept so the site can be improved around what visitors come for. - [Finder API](https://stratigossecurity.com/api/agent/find?q={question}): The same as JSON, one GET, with role, organization, and situation parameters; each list also accepts a few words of your own when nothing on it fits. Put the reader's question where {question} stands; it is a placeholder, not a question to ask. If your fetcher drops query strings, put the question in the path instead: https://stratigossecurity.com/api/agent/find/{question}. For a detailed description, POST the same fields as JSON so the words stay out of the URL. Description: https://stratigossecurity.com/api/agent/openapi.json - [Site index](https://stratigossecurity.com/site-index.json): The machine-readable index behind the finder: every page with its summary, the questions it answers, and who it is written for.