
Cruxi
Cruxi is a regulatory submission platform for medical device teams. Specialized AI agents handle device classification, predicate analysis, eSTAR drafting and RTA checks, while a marketplace of 25+ directories connects companies with vetted regulatory consultants and providers.
What is Cruxi?
Cruxi is a regulatory submission platform for medical device companies, operated by Tipmunk SASU. Its centre of gravity is the FDA 510(k). The product carries a device from first intake through classification, predicate selection, regulatory assessment, evidence planning, eSTAR drafting and final packaging, and claims to produce a complete draft in four to five hours where traditional preparation runs six to twelve months.
The work is done by named, purpose-built agents rather than a general chatbot. NucAgent reads the device description and intended use to pin down product code, regulation number and device class with confidence scores. PreAgent scores candidate predicates on intended use, technological characteristics, performance data and regulatory history, weighing recalls and MAUDE adverse event records so that a predicate with a poor post-market record is not picked by accident. A reasoning agent then works through all 18 eSTAR sections and drafts content. All three run against an FDA database Cruxi maintains itself, covering product codes, the text of 21 CFR, cleared 510(k) devices, guidance documents, recognised IEC and ISO standards, recalls and safety data. That is how the platform justifies its zero hallucinations claim: statements are anchored either in that database or in the user's own uploaded files, with citations you can follow.
The design is deliberately human-in-the-loop. Cruxi never files anything with the FDA, never presses submit in eSTAR and never takes a regulatory decision. Every classification, predicate and drafted section is a recommendation the user accepts, modifies or rejects, and an optional second step routes the finished draft to a vetted FDA consultant for review.
A second business sits alongside the software: a marketplace of more than 25 regulatory directories covering FDA US Agents, EU Authorised Representatives, GDPR Article 27 representatives, eIFU platforms, GUDID tools, testing laboratories and cosmetics compliance, with a request-for-quote system. Fourteen submission types are advertised, but only the 510(k) is fully open: De Novo, PMA, IDE, Q-Submission, Breakthrough, EU MDR, UKCA, Health Canada and TGA are described as in beta and calibration, with access limited to selected groups.
What it does
- Classify a medical device and return its product code, regulation number, device class and regulatory pathway
- Identify and score predicate devices to support a substantial equivalence argument
- Produce a regulatory assessment across all 18 eSTAR sections
- Draft submission sections with every claim traced back to its source
- Run automated Refuse to Accept (RTA) readiness checks before filing
- Map required evidence and generate a device-specific testing matrix
- Generate and export a complete, correctly formatted 510(k) submission package
When to use Cruxi / When not to
A quick filter to help you decide if Cruxi is the right fit.
When to use Cruxi
- Regulatory affairs teams at medical device manufacturers preparing an FDA 510(k) or eSTAR submission
- Independent regulatory consultants and agencies running several client submissions a month
- Medtech startups that need submission-grade regulatory work without a full in-house RA department
- Quality and QA/RA managers building evidence plans, testing matrices and RTA-proof documentation
- Procurement and project leads sourcing FDA US Agents, EU Authorised Representatives or testing laboratories through the directories
When not to use Cruxi
- Anyone expecting the tool to file with the FDA or make the regulatory call: it never submits and never decides
- Teams looking for formal legal, medical or regulatory advice, which the terms of service explicitly exclude
- Developers wanting programmatic access, since there is no public API, no SDK and no mobile application
- Individuals, students and hobbyists, as pricing starts at USD 100 per credit and targets funded device programmes
- Companies whose priority pathway is De Novo, PMA, EU MDR, UKCA, Health Canada or TGA, all still in beta with restricted access
How to use Cruxi
A typical end-to-end flow, from setup to results.
- Start with the free regulatory assessment: no account, no card, roughly a minute for a first read on classification, pathway and timeline
- Open the read-only demo project to walk through a real 510(k) end to end before committing anything
- Create an account and sign in with a Google account, or with an email and a twelve-character password
- Enter your administrative contacts and device intake details: description, intended use and technology
- Let the classification agent return the product code, regulation number and device class with its confidence scoring
- Review the scored predicate shortlist and choose the device you will argue substantial equivalence against
- Work through the regulatory assessment covering all 18 eSTAR sections and the evidence map it produces
- Upload and organise your supporting documents against the generated evidence and testing plan
- Draft and revise sections in the eSTAR editor, then run the RTA check and the final QA review
- Export the complete submission package, and optionally send the draft to a vetted FDA consultant for review
Pros & Cons
Pros
- Genuinely specialised: a complete 510(k) pathway, not a general assistant pointed at regulatory work
- Answers are anchored in an FDA database Cruxi maintains itself, covering product codes, 21 CFR, cleared devices, guidance, standards, recalls and MAUDE data, rather than model recall
- Source traceability is a stated design principle, with claims linked back to regulations, public 510(k) summaries or the user's own documents
- A real free entry point: the quick regulatory assessment needs no account and no card, and project creation is free
- Prices are published openly, purchased credits never expire, and credits are only deducted once a service completes successfully
- The trust documentation is unusually candid for a company this size and states plainly what is not done, including the absence of application-layer database encryption and of any zero-retention AI claim
- Human expert review is available on demand through a vetted consultant network without ever being forced on the user
Cons
- An unresolved contradiction about where the company actually is: the terms, the privacy policy and the contact page all name a French company registered in Paris, while the Compliance & Contacts page states that Cruxi is headquartered in the United States and not established in the EU
- The stated legal entity and its Paris trade register number could not be found in the French public registries consulted
- SOC 2 Type II and HIPAA are claimed once, on the homepage, and appear nowhere in the trust centre that describes itself as verified-only
- Nine of the fourteen advertised services are in beta with restricted access, so the headline offer is broader than what is actually open
- No public API, no mobile application and no third-party product integrations
- No hosting country or region is published, database records are explicitly not encrypted at application layer, and confidential device documents pass through third-party AI subprocessors
- The company and the domain are very recent, with the domain registered in August 2025 and first archived in December 2025, for work of this consequence
Pricing & Plans
A free entry point exists and requires no payment details: the quick regulatory assessment runs without an account, and creating a project after signing in is free. Beyond that, Cruxi is credit-based. The published unit rate is USD 100 per credit, purchasable in any quantity, which makes USD 100 the lowest paid entry point. The cheapest complete service is a single microservice at USD 200, or two credits, while the full 510(k) workflow costs USD 1,000, or ten credits. All prices are quoted in US dollars.
- quick regulatory assessment with no account and no card
- plus free project creation after signing in
- USD 200
- or 2 credits
- for classification
- predicate search
- regulatory assessment or an RTA check
- USD 1
- 000
- or 10 credits
- covering classification
- predicate analysis
- regulatory assessment
- evidence and testing plan and eSTAR-style draft content
- USD 300
- delivered in one day
- 5 credits for USD 500
- at USD 100 per credit
- 15 credits for USD 1
- 350
- at USD 90 per credit
- a 10% discount
- 40 credits for USD 3
- 200
- at USD 80 per credit
- a 20% discount
- any quantity at USD 100 per credit
- USD 500 per month for 50 monthly credits
- priority support
- a dedicated account manager
- advanced analytics and unlimited microservice access
- Purchased credits never expire
- membership credits expire at the end of each billing cycle and are consumed before purchased credits
Data, GDPR & hosting
A consolidated view of how Cruxi handles your data.
GDPR overview
Cruxi publishes a complete documentary set: a privacy policy effective 20 April 2026, a data processing agreement, a named subprocessor list, a cookie policy and a data subject request page. The in-product controls are concrete, with JSON export of profile, project, workflow, message and consent records, self-service project and account deletion, and separately tracked access, portability, rectification and erasure requests. Cookie consent is collected before any non-essential tag loads for EU and UK visitors, and Tipmunk SASU is named as controller. The homepage claims GDPR compliance outright. One page contradicts all of this: Compliance & Contacts states that Cruxi is not established in the European Union, does not direct services to EU or UK individuals, sits outside GDPR Article 3(2), and has therefore appointed no Article 27 representative. No standard contractual clauses or transfer mechanism are mentioned anywhere.
Who owns the data?
Under the terms of service, users keep their rights in everything they upload or create on the platform. Cruxi processes that content only to deliver the service, operate its infrastructure, support the account and meet contractual or legal obligations. The data processing agreement sets the roles out plainly: the customer is the controller, Cruxi the processor, and Tipmunk SASU is named as controller for platform operations unless a separate written agreement says otherwise. Private project data is not shared with other customers, consultants or partners unless the user explicitly authorises it, and Cruxi states that it does not sell customer data. Responsibility for uploaded content and for the use made of generated outputs stays with the user.
Reuse rights
Users may reuse what the platform produces without asking permission. Classifications, predicate analyses, regulatory assessments, drafted eSTAR sections and the exported package are theirs to edit, hand to a consultant or file with the FDA, and the terms are explicit that reviewing those outputs and deciding how to use them is the user's own responsibility. On Cruxi's side, the declared purposes are running the platform, processing the AI tasks the user requests, billing, fraud prevention, security, troubleshooting and answering support or privacy requests. AI processing is subcontracted to Google Vertex AI / Gemini and to OpenAI. The product FAQ states that device information, documents and submission drafts are not used to train public models, although the trust page stops short of claiming zero-retention AI processing.
Data retention & training
Hosting summary
Cruxi names its infrastructure openly but not its geography. Application hosting, file storage, networking and logging run on Google Cloud Platform; the managed operational database is MongoDB Atlas; AI processing goes to Google Vertex AI / Gemini and to OpenAI; payments run through Stripe; sign-in uses Google identity services. Traffic is served over HTTPS/TLS at the hosting edge and at application entry points. The primary production Google Cloud Storage bucket holding uploaded 510(k) documents and generated submission artefacts is encrypted at rest by default with a customer-managed Cloud KMS key. Cruxi states explicitly that MongoDB records and other application-layer fields are not field-encrypted by its own code and relies on provider-managed encryption there. No hosting country and no region are published anywhere on the site. The site's resolved IP address is a Google anycast node located in the United States, which describes the front end rather than where customer data actually resides.
Things to keep in mind
Risks and trade-offs to weigh before adopting Cruxi.
- Unclear jurisdiction: the terms, privacy policy and contact page name a French company in Paris while the Compliance and Contacts page declares Cruxi established in the United States and outside the EU, so a user cannot tell which law governs the contract or where a dispute would be heard
- The stated legal entity and its Paris trade register number were not found in the French public registries consulted, which is a basic diligence gap before entrusting a multi-million-euro device programme
- SOC 2 Type II and HIPAA compliance are asserted on the homepage but absent from the trust centre that presents itself as verified-only and from the data processing agreement, so they should be treated as claims rather than facts
- A polished AI draft can read as complete while a requirement is missing; the promise of a four-to-five hour submission invites teams to skip the human review the vendor itself insists on, and liability for the filing remains entirely human
- Confidential device documents and drafts transit third-party AI subprocessors, no hosting country or region is published, database records are not encrypted at application layer, and permanent deletion cannot be undone by the user
- Commercial signals need checking at source: a launch promotion advertising 90% off ran out on 21 May 2026 yet was still displayed in August, and the 4.8 out of 5 rating over 150 reviews is authored by Cruxi itself in the site's structured data
- Nine of the fourteen advertised submission types are in beta with restricted access, and the company and domain date only from 2025, so capability and continuity both deserve verification before a programme depends on them
Setup & Integrations
Technical difficulty
Very low. There is nothing to install: Cruxi is a browser-based application reached with a Google account or an email and a twelve-character password. The workflow is guided step by step, from administrative contacts through to export, and no development skills are needed since there is no API, no SDK and no integration to configure. The free assessment takes about a minute and needs no account at all. The real effort is regulatory rather than technical: you must describe your device and its intended use accurately and assemble the supporting evidence. Budget four to five hours for the full workflow.
Deployment
Integrations
Supported languages
Behind Cruxi
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does Cruxi actually do?
Does Cruxi submit to the FDA on my behalf?
What does it cost, and is anything free?
How long does a submission take?
Are my confidential device documents used to train AI models?
Who processes my data?
Can I export or delete my data?
Is there an API or a mobile app?
Are all fourteen advertised services available?
Who operates Cruxi?
Should you pick Cruxi?
Cruxi is one of the more convincing vertical AI products of its kind. The scope is real rather than decorative: a complete FDA 510(k) pathway from device intake to an exported submission package, built on an FDA database the company maintains itself, with named agents for classification, predicate scoring and drafting, and source traceability treated as a design constraint instead of a marketing line. The trust documentation is unusually honest for a company this young, stating not only what is protected but what is not. A free assessment with no account makes it cheap to form your own view.
Against that sits a set of signals worth resolving first. The site cannot keep its own story straight about where the company is: the terms, the privacy policy and the contact page all describe a French company in Paris, while a compliance page insists Cruxi is headquartered in the United States and outside EU law. The named legal entity and its Paris register number could not be found in the French public registries consulted. SOC 2 Type II and HIPAA are claimed on the homepage and nowhere in the verified-only trust centre. Nine of the fourteen advertised services are still in beta, a promotion that expired in May 2026 was still on display in August, and the 4.8 out of 5 rating is self-declared in the site's own markup.
The sensible reading is that the software may well be good while the corporate presentation is not yet trustworthy. For a regulatory team that keeps control, has a consultant validate the output and does its own diligence on the vendor, Cruxi is worth the free assessment. For anyone needing certainty about jurisdiction, certification or data location before uploading confidential device files, those answers are not on the site today.
- Choosing a selection results in a full page refresh.
- Opens in a new window.