API-first security platform for healthcare infrastructure. BlueFlow asset management, Tapirx passive device discovery, and VulnFWRD™ AI risk orchestration — MIT-licensed open core you can inspect, extend, and deploy on your own terms.
Use independently or together. Each component exposes a versioned REST API and connects via the pluggable connector framework — designed for maximum flexibility with no vendor lock-in.
Django REST API for healthcare IT asset management. Versioned API at /api/v1/ with full OpenAPI 3 schema, pluggable connector framework, SBOM generation, and role-based access control. Deploy with Docker Compose or install as a Python package.
Free, open-source medical device discovery written in Go. Passively identifies devices from HL7 and DICOM network traffic via SPAN port, live interface, or pcap file — with zero impact on clinical operations. Plugs into BlueFlow as a discovery-type connector.
AI-powered risk orchestration with bidirectional BlueFlow integration. BlueFlow emits structured risk events when vulnerabilities map to assets or Pulse feed items match tracked devices. VulnFWRD returns scored remediation intents — the full closed-loop for healthcare vulnerability management.
Every endpoint lives at /api/v1/ with full OpenAPI 3 schema auto-generated by drf-spectacular. Swagger UI served at /api/v1/schema/ui/.
Each connector implements ConnectorBase — standard pull(), push(), and validate_credentials() methods with Celery task binding. Trigger any connector on-demand via POST /api/v1/connectors/<id>/sync/ or schedule with Celery Beat.
Identifies medical devices from HL7 and DICOM traffic without active scanning or any network disruption. SPAN port or pcap input.
Safe scanning workflows that guard active medical devices. CVE cross-reference against NVD with EPSS and CISA KEV enrichment.
Bidirectional sync with computerized maintenance management systems. Import existing device inventory; export scan scheduling and utilization data.
Push asset context and vulnerability events to SIEM platforms. Enrich alerts with device criticality, ePHI status, and network segment data.
Virta Labs proprietary threat intelligence matched to your specific device inventory. NVD, CISA KEV, and EPSS enrichment for tracked assets.
Async paginated push to any subscriber. UUID job tracking, configurable page size, and full auditing. Powers the VIPER vulnerability intelligence bridge.
Full Docker Compose stack — web, Celery worker, Celery Beat, PostgreSQL, Redis. Auto-migration on container boot. Running in minutes.
Register connectors, deploy Tapirx on a SPAN port, trigger syncs via API. The safe-scanning guard protects active medical devices automatically.
Connect vulnerability scanners, configure the VulnFWRD bridge, enable webhook subscribers. Celery Beat runs scheduled connector syncs.
Built-in RBAC with scoped API tokens. Permissions enforced at the ViewSet level on every endpoint. From read-only leadership dashboards to full security admin control.
Read-only access for leadership and auditors. Export reports in JSON, CSV, SPDX, and CycloneDX formats.
Create and update assets, groups, and tags. For IT teams managing day-to-day device inventory.
Clinical engineering access. Scan management, SBOM generation, ePHI tracking, and maintenance scheduling.
Full platform control. Connector management, webhook configuration, scoped API token issuance, and RBAC administration.
Virta Labs co-authored the world's first research on cardiac implant cybersecurity in 2008. Our founders shaped FDA medical device security guidance, led industry standards bodies, and built the NSF-funded PowerGuard™ malware detection system. Now funded by ARPA-H's UPGRADE program to build hospital-scale digital twins for autonomous vulnerability remediation.
Former federal advisors who shaped national medical device security policies, standards, and regulatory frameworks at FDA, NIST, and HHS. Founded the category through pioneering research.
Co-authored the first peer-reviewed research on cardiac implant cybersecurity. Exposed critical vulnerabilities and drove industry-wide security improvements across major device manufacturers.
Production-grade technology proven through NSF SBIR grants, ARPA-H funding, and enterprise deployments at major health systems across the United States.
Deploy locally. Own your data. Export anytime. We'll align VulnFWRD™ capabilities to your environment and share documentation.
We'll align capabilities to your environment and share API documentation.