The first thing to break in regulated software is often not the software. It is the story of the software - which requirement led to which risk control, which test proved it, which person approved it, and which exact version escaped into the world. Somewhere between a Jira ticket and a 2,000-page regulatory submission, smart engineers become reluctant archivists. Ketryx built a company around rescuing them from that second job.
The Cambridge, Massachusetts company calls its product connected lifecycle management. A less polished description is more useful: Ketryx sits across the development tools a team already uses, watches the work happen, and keeps the evidence connected. Requirements in Jira, code and pull requests in GitHub, tests in CI/CD, hazards in a risk file, approvals in a quality process - the platform turns those scattered objects into a live, traceable model.
That distinction explains the company better than the fashionable AI label. Ketryx is not mainly asking a medical-device engineer to chat with a robot about ISO 13485. It is building the plumbing that gives an AI agent the right project context and gives a human reviewer a deterministic audit trail. The agent may suggest a trace link or draft a change-impact assessment. The controlled workflow still decides whether the product ships.
The problem arrived wearing a lab coat
Erez Kaminski came to the problem from two directions. At Wolfram Research, he worked among people who built Mathematica and Wolfram|Alpha - software tools made for difficult technical work. Later, as head of AI and machine learning for Amgen's medical-device division, he saw how safety-critical software was actually developed. The contrast bothered him. Modern engineering lived in fast, collaborative tools; regulatory evidence was still reconstructed through manual checks, copied fields and aging systems.
There was a personal edge too. Kaminski's mother is a physician who performs cochlear-implant surgery and a patient with a cochlear implant herself. He had watched a device change her life while noticing how difficult it could be to improve the software inside products like it. Manufacturers were not declining updates because nobody cared. They were confronting the high cost and long delay of proving each change safe across different regulators.
In 2021, Kaminski founded Ketryx with Jan Pöschko, a longtime Wolfram infrastructure leader who had helped build Wolfram|Alpha and led Wolfram Cloud development. They recruited Paul Jones, a former FDA official with deep experience in medical-device software rules, and started connecting Jira and GitHub into one traceable lifecycle.
What they actually built
The product is an orchestration layer, not merely a document repository. It pulls items from connected systems into a structured product model. It can enforce that a risk control has an approved test, block a release when a required procedure has not been followed, compile a design history file, generate a traceability matrix, and maintain a software bill of materials. It also covers requirements, configuration, automated test evidence, electronic approvals, system-of-systems architecture and change control.
AI entered this system gradually. Ketryx shipped assisted requirement creation, suggested trace links and generated release notes, then introduced validated AI agents for regulated work. Its current tools can review quality records, flag conflicts, analyze test coverage, draft artifacts and assess the downstream impact of a change. The useful constraint is human-in-the-loop review for safety-critical decisions. Generic models know standards in the abstract; Ketryx argues that its advantage is reading the actual design history, relationships and controls of the product in front of it.
What did it cost?
For the smallest eligible customer, the public number is refreshingly unenterprise: $0 per year. That tier is for pre-market companies that have raised less than $2 million. Startup, Business and Enterprise plans are subscription SaaS, but Ketryx does not publish their prices. Buyers contact sales, which is unsurprising for software that must be configured around a regulated lifecycle and may include implementation expertise. Professional services add quality, regulatory and AI-transformation specialists to the platform.
What failed first - and what changed
Ketryx did not begin with the full platform. Kaminski has described an earlier avenue: AI that processed public product complaints and connected them to known risks and issues. It was related to safety, but it caught the problem late, after products were already in use. The founders kept digging into regulation and product development, guided by large medical-device partners, until the larger opportunity became visible. Complaint intelligence survived as part of the lifecycle; the company moved upstream to the machinery that creates evidence before release.
The second failure was an industry habit: treating compliance as a final exam. Engineering built the product, then another group tried to reconstruct what had happened. Trace links broke, spreadsheets drifted, test results were duplicated into reports, and every change created fresh archaeology. Ketryx's change of mind was architectural. Do not automate the document at the end. Connect the objects at the beginning and let documents fall out of the graph.
The proof lives in release cycles
HeartFlow provides the most visual example. Its monolithic ecosystem contained more than 100,000 items. Working with Ketryx, the cardiovascular software company reorganized that estate as a system of systems, deprecated about 90,000 items and reported a 90 percent reduction in complexity. It kept Jira and GitHub, while Ketryx maintained end-to-end traceability and generated documentation. The implementation took 10 weeks.
Beacon Biosignals had another flavor of the same problem. Manual requirements and traceability work stretched release cycles for its AI and wearable products. Connecting automated tests and software components to the regulated record cut its reported release cycle from four weeks to two and documentation time by 75 percent. Flo Health faced the cultural version: how does a consumer app with hundreds of millions of users add an ISO 13485-aligned quality system without turning its engineers into clerks? Flo says it completed deployment, process mapping and training in 90 days, versus its own estimate of a year, while regulated teams kept shipping biweekly.
These are vendor-published case studies, so the numbers deserve that label. Still, they point to a coherent mechanism. None of the wins came from writing a prettier policy. Each came from reducing duplicate representations of the same work.
Where Ketryx sits - and where it does not
The market around Ketryx is crowded but divided. Greenlight Guru, Qualio, MasterControl, Veeva and ETQ sell quality-management systems. Polarion, Jama Connect, Codebeamer and Matrix Requirements cover requirements and application lifecycle management. Large organizations also assemble their own combination of Jira, GitHub, spreadsheets, scripts and document stores.
Ketryx's wedge is the overlay. It wants to be the connective and enforcement layer across the stack, especially for software-heavy regulated products that change often. That can be an advantage when engineers resist a separate quality tool. It can be a drawback when a buyer wants every CAPA, supplier, training and post-market process consolidated into one replacement suite. Competitors make exactly that critique. The honest choice depends on whether the center of gravity is a broad quality program or a fast-moving engineering lifecycle.
The company has widened beyond medtech on its website, describing support for pharma, biotech, robotics, automotive, aerospace, defense and nuclear energy. The logic travels: a complex system changes quickly, failure has consequences, and proof must cross many tools. But medtech remains the strongest public evidence base, the deepest certification story and the source of most named customers.
Good conditions
Software changes frequently; Jira, Git and CI/CD already matter; requirements, risks and tests live in several systems; quality leaders want continuous evidence; teams can redesign procedures around integrations.
Bad conditions
Releases are rare; the product barely contains software; workflows are not digitized; the organization wants a single replacement suite; or nobody owns the links Ketryx is meant to keep current.
What the reader can copy
Ketryx's most portable lesson has little to do with FDA acronyms. Founders looking at an ugly enterprise workflow should find the artifact everyone must create but nobody wants to own. Then trace it backward. Where was the underlying information born? Who already touched it? Which links become stale? The product opportunity may be a layer that captures those relationships as a side effect of normal work.
The five-part Ketryx playbook
- Start with a mandatory, expensive output - in this case, regulatory evidence.
- Integrate where the raw work already happens instead of demanding a workflow transplant.
- Model relationships, not just documents, so a change can reveal its downstream impact.
- Use AI for drafts, links and review acceleration; preserve deterministic gates for accountable decisions.
- Prove value with elapsed time and cycle frequency, not a vague promise of transformation.
Funding followed the proof. Lightspeed led a $14 million Series A in 2023. Transformation Capital led a $39 million Series B in September 2025, with Lightspeed, MIT's E14 Fund, Ubiquity Ventures and 53 Stations participating. Former Medtronic CEO Bill Hawkins invested and later joined the board. Total funding moved above $55 million. In August 2026, Ketryx announced that Accenture had selected its platform as the continuous compliance technology behind medtech transformation work, pairing a global consultancy's process and adoption machinery with Ketryx's software.
There is a pleasing irony in a company selling automatic evidence trails earning ISO 27001 certification by spending the better part of a year building its own evidence trail. Ketryx acknowledged it. That is also the point. Compliance cannot be wished away, even by compliance software. The worthwhile product is the one that makes the burden proportional to the risk - rigorous where patient safety is involved, quiet everywhere else.
Kaminski once said he wanted to create the most boring software company anyone had built, because important infrastructure tends to become boring. Ketryx is not boring yet. It sits in the noisy collision of AI, medical devices and regulation. But if it succeeds, its work may eventually become invisible: the code is ready, the evidence is ready, and nobody has to schedule a weekend with a spreadsheet.