
> SECTOR_01 · LOGISTICS
Supply chains that hold under pressure.
We track the ports, routes and corridors your goods move through, so you see a chokepoint forming weeks before it stops a shipment.

SSX360 builds signing products and delivers scoped cybersecurity services for machine authorization, software provenance, and post-quantum migration. Every report includes evidence reviewers can check offline.
We reply within one business day.
> WHAT_YOU_RECEIVE

> 01_THE_MISSION
SSX360 combines analyst-led services with signing products across the four sectors below. Every service names its scope, and every signed finding arrives with evidence a reviewer can check.

> SECTOR_01 · LOGISTICS
We track the ports, routes and corridors your goods move through, so you see a chokepoint forming weeks before it stops a shipment.

> SECTOR_02 · DEFENSE
Assessments built from public reporting and sensor data, for operators who want a second read on the threat picture from someone who did not build the systems under review.

> SECTOR_03 · FINANCE
We trace who you are exposed to and through which systems, then sign each finding so your risk committee can check it rather than take it on trust.

> SECTOR_04 · CLIMATE
Weather, water and energy stress measured against the assets you actually own, for planning horizons of a quarter or a decade.
> 02_WHO_THIS_IS_FOR
You need to know what automated systems a target operates, where their data came from, and what those systems are authorized to do before your signing date.
You need a signed read on logistics, defense, finance or climate exposure before the board asks why the dashboard stayed green.
You need a second, signed opinion on the threat picture, separate from the vendors who built the systems under review.
Counterparty, market and infrastructure risk needs end-to-end tracing with findings a regulator can read without a sales call attached.
Weather, water and energy stress against real assets, for horizons of a quarter or a decade.
Personal and portfolio risk sits outside the systems a company uses to track its own. You need a scoped review you can act on without waiting for a committee.
A provenance review for an acquirer's deal team before signing. We examine the target's software, data sources, and machine authorization records, then sign the findings inside a live transaction timeline.
T-MINUS 5-7 DAYS →A focused audit of one system, site or counterparty. The gaps we can prove exist, delivered inside a live decision timeline.
T-MINUS 5-7 DAYS →A signed, sector-mapped assessment of your exposure across logistics, defense, finance and climate. One document your board and your auditors both accept.
T-MINUS 2-3 WEEKS →We embed alongside your operation for three weeks, reading the same sector signals and delivering signed findings on a decision cadence. One slot per quarter. The engagement letter names retainer conversion as the exit ramp.
T-MINUS 3 WEEKS →Analyst-run sector coverage with quarterly re-assessment so the picture stays current, for enterprises and individuals alike.
MONTHLY →We reply within one business day. What an engagement costs.
> PRODUCT / USB_SIGNER
The SSX360 USB signer is produced and available through direct contact. It uses an RP2350 USB bridge and an NXP SE050 secure element to sign Matrix Scroll records without exporting the private Ed25519 key.
Ask about the USB signer
Shipping configuration

FEATURED · RPT_001 · 2026-08-11
A visible password pattern does not make a 14-character router key practical to brute-force. Predictable generation and credential reuse are the failures that turn a sticker into access.
[READ_THE_REPORT →]> INTELLIGENCE_LOG
Biweekly field notes across logistics, defense, finance and climate. Free, written for people who have to make the call.
[READ_THE_ARCHIVE →]
> METHOD
Every finding is signed over its exact text, so one changed character breaks the signature. The same check, in the open Matrix Scroll protocol anyone can install, reads a whole run of changes and names the ones carrying no signed record at all, so a gap in the trail gets reported rather than passed over.
[RUN_THE_CONFORMANCE_VECTOR →]> 03_WHAT_IT_RUNS_ON
We build and publish verification software, produce the USB signer, and use the same stack in scoped services. Each capability below names the evidence behind it.
Analysts read logistics corridors, defense open-source reporting, financial counterparties and climate stress indicators. Every engagement uses all four.
Four sectors · analyst-run
Focused audits of one system, site or counterparty, delivered inside a live decision timeline. The signed findings verify against the public key carried in the record.
5 to 7 days · offline verify
Every finding is a signed record whose text is written in one fixed order, so altering any part of it breaks the signature. Ed25519 is the signature scheme, published as RFC 8032, which means any standard cryptography library can check our work. The protocol ships valid, altered and unsigned sample files so you can run that check yourself.
Ed25519 RFC 8032 · fixed encoding
A sector-mapped assessment of exposure that a board and an auditor can both accept as one document.
2 to 3 weeks
> OFFER / PQ_SIGNATURE_INVENTORY
The PQ Signature Inventory identifies where your systems sign records, which algorithms and libraries they use, who owns each surface, and how long each record must remain verifiable. SSX360 ranks the migration work by exposure and delivers a signed inventory your team can review offline.
Fee: Confirmed on the call, once scope is clear.

Long-lived verification
Inventory before implementation.
Identify every signing service, library, key, and record format in scope, with an owner and required verification lifetime.
Separate near-term cryptographic changes from long-lived records whose required verification lifetime exceeds that of today's signature algorithms.
Where the system fits, Matrix Scroll 0.7.0 can attach an ML-DSA or SLH-DSA signature beside Ed25519 during a staged move.
Technical boundary
Matrix Scroll exposes ML-DSA and SLH-DSA through liboqs as an evaluation and migration-planning path. The path lacks CMVP validation. liboqs advises against relying on it in production or for sensitive data.