Your code ships fast.
Your compliance should too.

With every software release, tracy.md seamlessly updates your technical documentation to align with your code.

check-icon
IEC 62304
check-icon
ISO 14971

For teams building medical device software.

Code review panel showing 'Traceability review PR #248 merged' and three traceability issues with statuses.
4x faster
Preparing for CE-mark
100%
In sync with your code
3x higher
Exit value for a certified device
Problem

Code ships. Compliance docs fall behind.

12–18 months delay
Time is wasted writing documentation instead of building features and going to market.
Lack of in-house knowledge
Your best engineers end up writing technical documentation by hand, killing your velocity. Or money gets burned on regulatory expertise.
AI accelerates the drift
Agentic coding tools (Cursor, GitHub Copilot, Claude Code) ship more code, faster, increasing the gap between code and documentation.
Solution

Code fast. Get compliant faster.

Compliant from day one
The technical file is built as you go with software development. Nothing to reconstruct, and no documentation freeze before you file.
Expertise built in
A clear view of which code change requires a documentation update, linked to the rule of the standard that applies.
Keep pace with your agents
A continuous, automated process inside your development workflow, so documentation stays in sync with every new version of the software.
HOW IT WORKS

From PR merge to regulatory sign-off in minutes.

Start with the device profile.

Tell tracy.md what the medical device is intended for, by who and which safety class applies. This is the one-time part and will be used in every run when analyzing your codebase.

User interface of ECG Monitor product context showing safety class, intended use, medical purpose, users, and patient info.

Connect the codebase.

Connect the repositories that make up the medical device software. tracy.md reads your code base and merge metadata.

Dashboard showing Helix Medical ECG Monitor repositories with status, open PRs, and findings counts.

What changed and needs an update.

tracy.md analyses each code change, identifies what the software does differently, and compares with your current documentation.

Code update for multi-factor sign-in requiring a verified second factor beyond password, with session changes.

A list of records that need your attention.

Anything that no longer matches or is missing gets flagged, ready to get updated.

User interface showing multi-factor sign-in pull requests with status and priority for ECG Monitor software.

Nothing changes without a human.

Every finding is a proposal. Accept it, edit it, or reject it. No record changes until a person signs it off, creating an immutable audit trail for every regulatory decision.

Software interface showing multi-factor sign-in request with approval option and trace details in Helix Medical app.

From reactive to real-time.

Your code changes with every release. Your records change when someone finds the time. tracy.md does the check at the release itself, so the technical file is never behind.

check-icon

Every release, not every audit: the work is continuous rather than reconstructed under deadline.

check-icon

No context gets lost: a change is reviewed while the person who made it still remembers why.

Code review comment noting risk control RC-004 missing MFA reference despite MFA code addition in PR #248.
Code review comment noting risk control RC-004 missing MFA reference despite MFA code addition in PR #248.

Records a reviewer can walk.

Every record in tracy.md has an ID, a status, a version history and how it links to each other, so that a reviewer can walk your documentation in a series of clicks rather than a search through folders.

check-icon

Unique IDs: every record is addressable and filterable, the format reviewers ask for.

check-icon

Links both ways: open a requirement, see the need above it and the tests below it.

check-icon

Gaps are visible: a requirement nothing verifies shows up as a gap before a reviewer finds it.

No black box.

Nothing is suggested without its source. Each finding carries the change that triggered it, the rule of the standard that got triggered, giving you all the tools to verify the outcome.

check-icon

Check it, don’t trust it: the reasoning is on the page, not inside a model.

check-icon

Learn as you build: all in plain-English so no separate training is needed.

Code review comment noting risk control RC-004 missing MFA reference despite MFA code addition in PR #248.

What actually changes.

The first job is getting the technical file built at all. The second is keeping it true once you're certified.

Without tracy.md
Building the technical file
Building the technical file
Code-aware
Building the technical file
Reverse-engineered
Traceability
Traceability
100%
Traceability
Unknown
Consulting cost
Consulting cost
€30k
Consulting cost
€150k
Engineering freeze
Engineering freeze
None
Engineering freeze
6–10 weeks
Exit value at acquisition
Exit value at acquisition
3× higher
Exit value at acquisition
Baseline
Documentation debt
Documentation debt
Zero
Documentation debt
High

Pricing

A seat-based licence that grows as your company grows.

30-day free trial on every plan

Solo
€99
/mo
For early-stage teams. No certification yet and no regulatory hire, so the documentation lands on whoever has time.
check-list
1 seat
Team
€249
/mo
For growth-stage teams. A regulatory lead and a codebase that moves faster than the technical file.
check-list
5 seats
Scale
€499
/mo
For certified companies. The audit is behind you and the between-audit work isn't.
check-list
10 seats
Entreprise
Custom
Deployment, integration and contractual terms shaped around your QMS and your supplier qualification requirements.
check-list
Uncapped seats

Compliance that keeps pace with your code

FAQ

Questions we get asked.

Getting started

How long does setup take?

Connecting a repository is quick. Pointing tracy.md at your existing requirements and risk file is the part that varies, and it depends entirely on how those are stored today. We do that part with you during the onboarding phase rather than leaving you to it.

Do we need to change how we code or deploy?

No. tracy.md connects as a webhook on pull requests into a branch you pick, usually the one you release from, and does its reading outside your pipeline. You can also run it over the whole repository whenever you want, which is how the first baseline gets built. It doesn't gate merges, rewrite branches or sit in your deployment path. Turn it off and your pipeline is exactly as it was.

Is our code and IP secure?

Your code is yours. It is never used to train models, never shared with another customer, and never leaves the environment set out in your contract. Every customer is isolated. tracy.md reads the repository and writes nothing back to it, and you can revoke access at any time. Your security reviewer gets the full architecture and the data processing agreement before you connect anything.

Do we need a regulatory person to use tracy.md?

You need someone who can approve a change to a risk control. On most teams that's a QA or RA lead, sometimes a founder wearing that hat. tracy.md proposes. It has no authority to sign.

We have no documentation yet. Where do we start?

Here, and it is the best place to start from. tracy.md reads the codebase and produces a baseline: the software architecture, the requirements and specifications, the risks and the risk controls it can identify, and the verifications your software already implies. All of it is a draft and all of it is editable. You are reviewing a first pass rather than facing an empty template.

We have no QMS yet. Is that a problem?

No. tracy.md keeps the software records themselves: every record has an ID, a version history, a status and its links to the code and the clause. That is what a reviewer walks through. When you do put a QMS in place, the records move into it as a set that is already structured and already traceable.

Compliance & regulatory

Can auditors or notified bodies object to AI-assisted compliance?

The standards care about whether your process is defined, followed and evidenced. They don't specify which tools produce the evidence. What matters is that a competent person reviewed and approved each item, and that the record shows it. That's why sign-off is always a person, and why every finding carries the change and the clause it came from.

Does tracy.md replace our eQMS?

No. Your QMS stays the system of record. tracy.md works on the software records and the code they describe, and hands the result back. It sits alongside what you already run.

What if a new feature changes our device classification?

That's a judgement call and it stays with your regulatory lead. What tracy.md does is make the change visible: when code lands that touches a claim about intended use or a clinical function, it surfaces it rather than letting it pass unnoticed.