Cruxi logo
Gov Legal · Workflow Automation

Cruxi

Cruxi is a regulatory submission platform for medical device teams. Specialized AI agents handle device classification, predicate analysis, eSTAR drafting and RTA checks, while a marketplace of 25+ directories connects companies with vetted regulatory consultants and providers.

Active GDPR compliant Free plan Freemium No public API Verified by Guidaio
Overview

What is Cruxi?

Cruxi is a regulatory submission platform for medical device companies, operated by Tipmunk SASU. Its centre of gravity is the FDA 510(k). The product carries a device from first intake through classification, predicate selection, regulatory assessment, evidence planning, eSTAR drafting and final packaging, and claims to produce a complete draft in four to five hours where traditional preparation runs six to twelve months.

The work is done by named, purpose-built agents rather than a general chatbot. NucAgent reads the device description and intended use to pin down product code, regulation number and device class with confidence scores. PreAgent scores candidate predicates on intended use, technological characteristics, performance data and regulatory history, weighing recalls and MAUDE adverse event records so that a predicate with a poor post-market record is not picked by accident. A reasoning agent then works through all 18 eSTAR sections and drafts content. All three run against an FDA database Cruxi maintains itself, covering product codes, the text of 21 CFR, cleared 510(k) devices, guidance documents, recognised IEC and ISO standards, recalls and safety data. That is how the platform justifies its zero hallucinations claim: statements are anchored either in that database or in the user's own uploaded files, with citations you can follow.

The design is deliberately human-in-the-loop. Cruxi never files anything with the FDA, never presses submit in eSTAR and never takes a regulatory decision. Every classification, predicate and drafted section is a recommendation the user accepts, modifies or rejects, and an optional second step routes the finished draft to a vetted FDA consultant for review.

A second business sits alongside the software: a marketplace of more than 25 regulatory directories covering FDA US Agents, EU Authorised Representatives, GDPR Article 27 representatives, eIFU platforms, GUDID tools, testing laboratories and cosmetics compliance, with a request-for-quote system. Fourteen submission types are advertised, but only the 510(k) is fully open: De Novo, PMA, IDE, Q-Submission, Breakthrough, EU MDR, UKCA, Health Canada and TGA are described as in beta and calibration, with access limited to selected groups.

What it does

  • Classify a medical device and return its product code, regulation number, device class and regulatory pathway
  • Identify and score predicate devices to support a substantial equivalence argument
  • Produce a regulatory assessment across all 18 eSTAR sections
  • Draft submission sections with every claim traced back to its source
  • Run automated Refuse to Accept (RTA) readiness checks before filing
  • Map required evidence and generate a device-specific testing matrix
  • Generate and export a complete, correctly formatted 510(k) submission package
Audience

When to use Cruxi / When not to

A quick filter to help you decide if Cruxi is the right fit.

When to use Cruxi

  • Regulatory affairs teams at medical device manufacturers preparing an FDA 510(k) or eSTAR submission
  • Independent regulatory consultants and agencies running several client submissions a month
  • Medtech startups that need submission-grade regulatory work without a full in-house RA department
  • Quality and QA/RA managers building evidence plans, testing matrices and RTA-proof documentation
  • Procurement and project leads sourcing FDA US Agents, EU Authorised Representatives or testing laboratories through the directories

When not to use Cruxi

  • Anyone expecting the tool to file with the FDA or make the regulatory call: it never submits and never decides
  • Teams looking for formal legal, medical or regulatory advice, which the terms of service explicitly exclude
  • Developers wanting programmatic access, since there is no public API, no SDK and no mobile application
  • Individuals, students and hobbyists, as pricing starts at USD 100 per credit and targets funded device programmes
  • Companies whose priority pathway is De Novo, PMA, EU MDR, UKCA, Health Canada or TGA, all still in beta with restricted access
Get started

How to use Cruxi

A typical end-to-end flow, from setup to results.

  1. Start with the free regulatory assessment: no account, no card, roughly a minute for a first read on classification, pathway and timeline
  2. Open the read-only demo project to walk through a real 510(k) end to end before committing anything
  3. Create an account and sign in with a Google account, or with an email and a twelve-character password
  4. Enter your administrative contacts and device intake details: description, intended use and technology
  5. Let the classification agent return the product code, regulation number and device class with its confidence scoring
  6. Review the scored predicate shortlist and choose the device you will argue substantial equivalence against
  7. Work through the regulatory assessment covering all 18 eSTAR sections and the evidence map it produces
  8. Upload and organise your supporting documents against the generated evidence and testing plan
  9. Draft and revise sections in the eSTAR editor, then run the RTA check and the final QA review
  10. Export the complete submission package, and optionally send the draft to a vetted FDA consultant for review
Quick read

Pros & Cons

Pros

  • Genuinely specialised: a complete 510(k) pathway, not a general assistant pointed at regulatory work
  • Answers are anchored in an FDA database Cruxi maintains itself, covering product codes, 21 CFR, cleared devices, guidance, standards, recalls and MAUDE data, rather than model recall
  • Source traceability is a stated design principle, with claims linked back to regulations, public 510(k) summaries or the user's own documents
  • A real free entry point: the quick regulatory assessment needs no account and no card, and project creation is free
  • Prices are published openly, purchased credits never expire, and credits are only deducted once a service completes successfully
  • The trust documentation is unusually candid for a company this size and states plainly what is not done, including the absence of application-layer database encryption and of any zero-retention AI claim
  • Human expert review is available on demand through a vetted consultant network without ever being forced on the user

Cons

  • An unresolved contradiction about where the company actually is: the terms, the privacy policy and the contact page all name a French company registered in Paris, while the Compliance & Contacts page states that Cruxi is headquartered in the United States and not established in the EU
  • The stated legal entity and its Paris trade register number could not be found in the French public registries consulted
  • SOC 2 Type II and HIPAA are claimed once, on the homepage, and appear nowhere in the trust centre that describes itself as verified-only
  • Nine of the fourteen advertised services are in beta with restricted access, so the headline offer is broader than what is actually open
  • No public API, no mobile application and no third-party product integrations
  • No hosting country or region is published, database records are explicitly not encrypted at application layer, and confidential device documents pass through third-party AI subprocessors
  • The company and the domain are very recent, with the domain registered in August 2025 and first archived in December 2025, for work of this consequence
Pricing

Pricing & Plans

A free entry point exists and requires no payment details: the quick regulatory assessment runs without an account, and creating a project after signing in is free. Beyond that, Cruxi is credit-based. The published unit rate is USD 100 per credit, purchasable in any quantity, which makes USD 100 the lowest paid entry point. The cheapest complete service is a single microservice at USD 200, or two credits, while the full 510(k) workflow costs USD 1,000, or ten credits. All prices are quoted in US dollars.

Free
  • quick regulatory assessment with no account and no card
  • plus free project creation after signing in
Full 510(k) workflow
  • USD 1
  • 000
  • or 10 credits
  • covering classification
  • predicate analysis
  • regulatory assessment
  • evidence and testing plan and eSTAR-style draft content
510(k) Regulatory Pathway Assessment and Roadmap
  • USD 300
  • delivered in one day
Starter credit pack
  • 5 credits for USD 500
  • at USD 100 per credit
Professional credit pack
  • 15 credits for USD 1
  • 350
  • at USD 90 per credit
  • a 10% discount
Agency credit pack
  • 40 credits for USD 3
  • 200
  • at USD 80 per credit
  • a 20% discount
Custom credit pack
  • any quantity at USD 100 per credit
Professional Membership
  • USD 500 per month for 50 monthly credits
  • priority support
  • a dedicated account manager
  • advanced analytics and unlimited microservice access
Plan 10
  • Purchased credits never expire
  • membership credits expire at the end of each billing cycle and are consumed before purchased credits
Special offers — Volume discounts on credit packs: Professional at 15 credits for USD 1,350 (10% off) and Agency at 40 credits for USD 3,200 (20% off) · Purchased credits carry no expiry date, and credits are not deducted when a service fails · A launch promotion advertising 90% off for three months, at USD 100 for the full workflow and USD 20 per single service, was valid through 21 May 2026 and is therefore expired, although it was still displayed on the homepage and the product page in August 2026 · No student, jobseeker, non-profit or startup pricing is published
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Cruxi handles your data.

GDPR overview

Cruxi publishes a complete documentary set: a privacy policy effective 20 April 2026, a data processing agreement, a named subprocessor list, a cookie policy and a data subject request page. The in-product controls are concrete, with JSON export of profile, project, workflow, message and consent records, self-service project and account deletion, and separately tracked access, portability, rectification and erasure requests. Cookie consent is collected before any non-essential tag loads for EU and UK visitors, and Tipmunk SASU is named as controller. The homepage claims GDPR compliance outright. One page contradicts all of this: Compliance & Contacts states that Cruxi is not established in the European Union, does not direct services to EU or UK individuals, sits outside GDPR Article 3(2), and has therefore appointed no Article 27 representative. No standard contractual clauses or transfer mechanism are mentioned anywhere.

Who owns the data?

Under the terms of service, users keep their rights in everything they upload or create on the platform. Cruxi processes that content only to deliver the service, operate its infrastructure, support the account and meet contractual or legal obligations. The data processing agreement sets the roles out plainly: the customer is the controller, Cruxi the processor, and Tipmunk SASU is named as controller for platform operations unless a separate written agreement says otherwise. Private project data is not shared with other customers, consultants or partners unless the user explicitly authorises it, and Cruxi states that it does not sell customer data. Responsibility for uploaded content and for the use made of generated outputs stays with the user.

Reuse rights

Users may reuse what the platform produces without asking permission. Classifications, predicate analyses, regulatory assessments, drafted eSTAR sections and the exported package are theirs to edit, hand to a consultant or file with the FDA, and the terms are explicit that reviewing those outputs and deciding how to use them is the user's own responsibility. On Cruxi's side, the declared purposes are running the platform, processing the AI tasks the user requests, billing, fraud prevention, security, troubleshooting and answering support or privacy requests. AI processing is subcontracted to Google Vertex AI / Gemini and to OpenAI. The product FAQ states that device information, documents and submission drafts are not used to train public models, although the trust page stops short of claiming zero-retention AI processing.

Data retention & training

Retention summary
Cruxi publishes no fixed retention period. Workspace, consent and privacy-request records are kept only as long as needed to run the service, fulfil requests, meet security and operational needs and satisfy legal obligations. A monthly scheduled job purges stale inactive projects and accounts, with retention warnings possible before it runs; active subscriptions and memberships are excluded from automatic purge. Users can delete individual projects from the interface, which also cleans up linked workflow artefacts, and delete their account from the in-app Data and Privacy menu. Formal access, portability, rectification and erasure requests are tracked separately from immediate self-service deletion. Cruxi relies on managed-provider backups and promises no self-service restoration after a hard delete. On termination, customer data is deleted or returned according to configuration, customer instructions and legal obligations.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

Cruxi names its infrastructure openly but not its geography. Application hosting, file storage, networking and logging run on Google Cloud Platform; the managed operational database is MongoDB Atlas; AI processing goes to Google Vertex AI / Gemini and to OpenAI; payments run through Stripe; sign-in uses Google identity services. Traffic is served over HTTPS/TLS at the hosting edge and at application entry points. The primary production Google Cloud Storage bucket holding uploaded 510(k) documents and generated submission artefacts is encrypted at rest by default with a customer-managed Cloud KMS key. Cruxi states explicitly that MongoDB records and other application-layer fields are not field-encrypted by its own code and relies on provider-managed encryption there. No hosting country and no region are published anywhere on the site. The site's resolved IP address is a Google anycast node located in the United States, which describes the front end rather than where customer data actually resides.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Cruxi.

  • Unclear jurisdiction: the terms, privacy policy and contact page name a French company in Paris while the Compliance and Contacts page declares Cruxi established in the United States and outside the EU, so a user cannot tell which law governs the contract or where a dispute would be heard
  • The stated legal entity and its Paris trade register number were not found in the French public registries consulted, which is a basic diligence gap before entrusting a multi-million-euro device programme
  • SOC 2 Type II and HIPAA compliance are asserted on the homepage but absent from the trust centre that presents itself as verified-only and from the data processing agreement, so they should be treated as claims rather than facts
  • A polished AI draft can read as complete while a requirement is missing; the promise of a four-to-five hour submission invites teams to skip the human review the vendor itself insists on, and liability for the filing remains entirely human
  • Confidential device documents and drafts transit third-party AI subprocessors, no hosting country or region is published, database records are not encrypted at application layer, and permanent deletion cannot be undone by the user
  • Commercial signals need checking at source: a launch promotion advertising 90% off ran out on 21 May 2026 yet was still displayed in August, and the 4.8 out of 5 rating over 150 reviews is authored by Cruxi itself in the site's structured data
  • Nine of the fourteen advertised submission types are in beta with restricted access, and the company and domain date only from 2025, so capability and continuity both deserve verification before a programme depends on them
Setup

Setup & Integrations

Technical difficulty

Very low. There is nothing to install: Cruxi is a browser-based application reached with a Google account or an email and a twelve-character password. The workflow is guided step by step, from administrative contacts through to export, and no development skills are needed since there is no API, no SDK and no integration to configure. The free assessment takes about a minute and needs no account at all. The real effort is regulatory rather than technical: you must describe your device and its intended use accurately and assemble the supporting evidence. Budget four to five hours for the full workflow.

Deployment

Web app

Integrations

Google Cloud Platform MongoDB Atlas Google Vertex AI Gemini OpenAI Stripe

Supported languages

English
Company

Behind Cruxi

Company name
Tipmunk SASU
Founded
29/12/2025
Country of origin
🇫🇷 France
Headquarters
47 rue Vivienne, 75002 Paris, France
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇱🇹 Lithuania
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does Cruxi actually do?
It prepares FDA regulatory submissions for medical devices, with the 510(k) at its centre. Specialised AI agents classify the device, shortlist and score predicate devices, produce a regulatory assessment across all 18 eSTAR sections, draft the content and package the submission. A separate marketplace of more than 25 directories connects companies with regulatory consultants and service providers.
Does Cruxi submit to the FDA on my behalf?
No. Cruxi never files a submission, never presses submit in eSTAR and never takes a regulatory decision. It produces structured, source-linked drafts that you accept, modify or reject. Accountability for what reaches the FDA stays with you and your designated regulatory owner, and the terms of service exclude legal, medical and regulatory advice.
What does it cost, and is anything free?
The quick regulatory assessment is free and needs no account or card, and creating a project after signing in is free. Paid use runs on credits at USD 100 each. A single microservice costs USD 200, the full 510(k) workflow USD 1,000, and a Professional Membership USD 500 per month for 50 monthly credits.
How long does a submission take?
Cruxi advertises four to five hours for a complete draft, against six to twelve months of traditional preparation, and claims a 50 to 70 percent reduction in preparation time. That covers your side of the work only: the FDA's own standard review time for a 510(k) remains 90 calendar days.
Are my confidential device documents used to train AI models?
According to the product FAQ, no. Device information, documents and submission drafts are said to stay within Cruxi's environment and are not used to train public models. The trust centre is more measured and does not claim zero-retention AI processing, and no customer-facing opt-out control is documented.
Who processes my data?
Cruxi publishes a named subprocessor list: Google Cloud Platform for hosting and file storage, MongoDB Atlas for the database, Google Vertex AI / Gemini and OpenAI for AI processing, Stripe for payments, Google Analytics and Tag Manager for measurement, and Google identity services for sign-in. No hosting country or region is published.
Can I export or delete my data?
Yes. You can export profile, project, workflow, message, consent and privacy-request data as JSON, delete individual projects from the interface and delete your account from the in-app Data and Privacy menu. Formal access, portability, rectification and erasure requests are tracked separately. There is no self-service restore after permanent deletion.
Is there an API or a mobile app?
No. A full review of the site, including a 582-URL sitemap, found no public API documentation, no SDK and no App Store or Google Play listing. Cruxi is a browser-based web application behind authentication, reached with a Google account or an email and password.
Are all fourteen advertised services available?
No. Only the FDA 510(k) is fully open. De Novo, PMA supplements, IDE, Q-Submission, Breakthrough Device Designation, EU MDR technical documentation, UKCA, Health Canada MDL and Australia TGA ARTG are described on the pricing page as in beta and calibration, with access limited to selected groups of professionals.
Who operates Cruxi?
The terms of service, the privacy policy and the contact page all name Tipmunk SASU, a French company with a registered office at 47 rue Vivienne, 75002 Paris. A separate Compliance and Contacts page states that Cruxi is headquartered in the United States and not established in the European Union. This contradiction is unresolved on the site.
Conclusion

Should you pick Cruxi?

Cruxi is one of the more convincing vertical AI products of its kind. The scope is real rather than decorative: a complete FDA 510(k) pathway from device intake to an exported submission package, built on an FDA database the company maintains itself, with named agents for classification, predicate scoring and drafting, and source traceability treated as a design constraint instead of a marketing line. The trust documentation is unusually honest for a company this young, stating not only what is protected but what is not. A free assessment with no account makes it cheap to form your own view.

Against that sits a set of signals worth resolving first. The site cannot keep its own story straight about where the company is: the terms, the privacy policy and the contact page all describe a French company in Paris, while a compliance page insists Cruxi is headquartered in the United States and outside EU law. The named legal entity and its Paris register number could not be found in the French public registries consulted. SOC 2 Type II and HIPAA are claimed on the homepage and nowhere in the verified-only trust centre. Nine of the fourteen advertised services are still in beta, a promotion that expired in May 2026 was still on display in August, and the 4.8 out of 5 rating is self-declared in the site's own markup.

The sensible reading is that the software may well be good while the corporate presentation is not yet trustworthy. For a regulatory team that keeps control, has a consultant validate the output and does its own diligence on the vendor, Cruxi is worth the free assessment. For anyone needing certainty about jurisdiction, certification or data location before uploading confidential device files, those answers are not on the site today.