Skip to content
XRAY_01 · GLOBAL SURFACE · REFRACTED

Post-quantum cybersecurity. Built for evidence.

SSX360 builds signing products and delivers scoped cybersecurity services for machine authorization, software provenance, and post-quantum migration. Every report includes evidence reviewers can check offline.

We reply within one business day.

LOGISTICS MONITORED
DEFENSE MONITORED
FINANCE MONITORED
CLIMATE MONITORED

> WHAT_YOU_RECEIVE

What you actually receive

A signed report
Signed means we attach a cryptographic signature to the exact text of the document. Change one character and the signature stops matching, so you can prove the copy in your hand is the one we issued.
Ed25519, the signature scheme in RFC 8032
Evidence your own people can check
Your reviewers verify the report on their own machines using a free open-source tool, with no account and no key from us. Nothing calls back to SSX360, so the report still holds up if we stop answering the phone.
Offline verification, no network call
Findings ordered by what blocks your decision
We list the gaps we can prove exist, hardest first, measured against the date you have to decide by rather than against a generic severity scale.
One document, plus the evidence behind it

> 01_THE_MISSION

Instability rarely announces itself. It surfaces in the signals first.

SSX360 combines analyst-led services with signing products across the four sectors below. Every service names its scope, and every signed finding arrives with evidence a reviewer can check.

> SECTOR_01 · LOGISTICS

Supply chains that hold under pressure.

We track the ports, routes and corridors your goods move through, so you see a chokepoint forming weeks before it stops a shipment.

> SECTOR_02 · DEFENSE

Situational awareness with evidence attached.

Assessments built from public reporting and sensor data, for operators who want a second read on the threat picture from someone who did not build the systems under review.

> SECTOR_03 · FINANCE

Exposure you can see before it moves.

We trace who you are exposed to and through which systems, then sign each finding so your risk committee can check it rather than take it on trust.

> SECTOR_04 · CLIMATE

Physical risk, quantified for the long view.

Weather, water and energy stress measured against the assets you actually own, for planning horizons of a quarter or a decade.

> 02_WHO_THIS_IS_FOR

Who this is for

  1. Deal teams buying a company

    You need to know what automated systems a target operates, where their data came from, and what those systems are authorized to do before your signing date.

  2. Enterprise risk and continuity teams

    You need a signed read on logistics, defense, finance or climate exposure before the board asks why the dashboard stayed green.

  3. Defense and critical-infrastructure operators

    You need a second, signed opinion on the threat picture, separate from the vendors who built the systems under review.

  4. Financial institutions and counterparties

    Counterparty, market and infrastructure risk needs end-to-end tracing with findings a regulator can read without a sales call attached.

  5. Asset owners facing physical climate risk

    Weather, water and energy stress against real assets, for horizons of a quarter or a decade.

  6. Family offices and high-net-worth principals

    Personal and portfolio risk sits outside the systems a company uses to track its own. You need a scoped review you can act on without waiting for a committee.

> PRODUCT / USB_SIGNER

A finished signer with the key held in silicon.

The SSX360 USB signer is produced and available through direct contact. It uses an RP2350 USB bridge and an NXP SE050 secure element to sign Matrix Scroll records without exporting the private Ed25519 key.

Ask about the USB signer
Product visualization of the SSX360 USB signer enclosure with a verification status display
Product visualization. Supplied units use the documented RP2350 and NXP SE050 signing path; enclosure details may vary.

Shipping configuration

  • 01Completed hardware with RP2350 USB CDC and NXP SE050 secure-element signing.
  • 02Host integration ships in matrixscroll 0.7.0 through the hardware extra and 14-tool MCP server.
  • 03Physical units come from SSX360 through direct contact. PyPI distributes the host software only.

FEATURED · RPT_001 · 2026-08-11

Default router passwords: the pattern is not the weakness

A visible password pattern does not make a 14-character router key practical to brute-force. Predictable generation and credential reuse are the failures that turn a sticker into access.

[READ_THE_REPORT →]

> INTELLIGENCE_LOG

Read it before the disruption.

Biweekly field notes across logistics, defense, finance and climate. Free, written for people who have to make the call.

Free. No sponsorship, no vendor reprints. Unsubscribe in one click.

[READ_THE_ARCHIVE →]

> METHOD

Signal. Verification. Signed record.

Every finding is signed over its exact text, so one changed character breaks the signature. The same check, in the open Matrix Scroll protocol anyone can install, reads a whole run of changes and names the ones carrying no signed record at all, so a gap in the trail gets reported rather than passed over.

[RUN_THE_CONFORMANCE_VECTOR →]

> 03_WHAT_IT_RUNS_ON

What the work runs on

We build and publish verification software, produce the USB signer, and use the same stack in scoped services. Each capability below names the evidence behind it.

Sector signal desk

Analysts read logistics corridors, defense open-source reporting, financial counterparties and climate stress indicators. Every engagement uses all four.

Four sectors · analyst-run

Vulnerability & audit pipeline

Focused audits of one system, site or counterparty, delivered inside a live decision timeline. The signed findings verify against the public key carried in the record.

5 to 7 days · offline verify

Signed evidence records

Every finding is a signed record whose text is written in one fixed order, so altering any part of it breaks the signature. Ed25519 is the signature scheme, published as RFC 8032, which means any standard cryptography library can check our work. The protocol ships valid, altered and unsigned sample files so you can run that check yourself.

Ed25519 RFC 8032 · fixed encoding

Stability Assessment method

A sector-mapped assessment of exposure that a board and an auditor can both accept as one document.

2 to 3 weeks

[FULL_CAPABILITY_REGISTER →]

> OFFER / PQ_SIGNATURE_INVENTORY

A post-quantum migration starts with the signatures you already depend on.

The PQ Signature Inventory identifies where your systems sign records, which algorithms and libraries they use, who owns each surface, and how long each record must remain verifiable. SSX360 ranks the migration work by exposure and delivers a signed inventory your team can review offline.

Delivery
3 to 4 days
Primary output
Signed inventory

Fee: Confirmed on the call, once scope is clear.

Long-lived verification

Inventory before implementation.

  1. 01Current state

    Map the current estate

    Identify every signing service, library, key, and record format in scope, with an owner and required verification lifetime.

  2. 02Migration priority

    Rank the exposure

    Separate near-term cryptographic changes from long-lived records whose required verification lifetime exceeds that of today's signature algorithms.

  3. 03Migration roadmap

    Define the transition path

    Where the system fits, Matrix Scroll 0.7.0 can attach an ML-DSA or SLH-DSA signature beside Ed25519 during a staged move.

Technical boundary

Matrix Scroll exposes ML-DSA and SLH-DSA through liboqs as an evaluation and migration-planning path. The path lacks CMVP validation. liboqs advises against relying on it in production or for sensitive data.