Skip to content

SSX360 products, services, and open protocol

SSX360 builds cybersecurity products and delivers scoped services across logistics, defense, finance and climate. The work covers signed evidence, machine authorization, software provenance, and post-quantum migration.

Signed evidence, clear limits, and verification your reviewers can run offline.

Four sectors we read

Logistics, defense, finance and climate. Each sector gets a continuous signal read and a signed assessment path when exposure needs a decision.

Sector 01

Logistics

See where ports, routes, and suppliers could interrupt a transaction or operation.

Sector 02

Defense

Get a sourced second view of threats affecting critical systems.

Sector 03

Finance

Trace counterparty and system exposure before it reaches the balance sheet.

Sector 04

Climate

Measure weather, water, and energy stress against owned assets.

What we sell and maintain

Products and services are commercial. Matrix Scroll remains open so buyers and reviewers can inspect the protocol and verify records without an SSX360 account.

SSX360

Products and scoped services

Cybersecurity products and services covering signed evidence, machine authorization, software provenance, post-quantum migration, and four-sector risk.

Signet-C and Signet-N

Completed hardware products

A ceremony signer and a resident signer, both available through direct contact. The software console animates status icons. The device display presents the current state only. Qualified customers receive the relevant integration details under the applicable confidentiality terms.

Open

Matrix Scroll

Open protocol and SDK

Apache-2.0 software for creating and verifying portable signed evidence records. Public documentation covers the supported interface and verification workflow.

Open

How products and services are delivered

SSX360 sells products and scoped services. We separate product specifications, service scope, evidence, and commercial terms so a buyer can see exactly what each purchase includes.

Cybersecurity products and scoped services for signed evidence, machine authorization, and post-quantum migration.

  1. 01

    Product and service scope is written separately in each proposal, including what is supplied, what is reviewed, and what remains the buyer's responsibility.

  2. 02

    Reports name the evidence, method, assumptions, and limits behind each material finding.

  3. 03

    Framework alignment is presented as evidence mapping, not a certification claim.

  4. 04

    We publish corrections. A finding we got wrong is amended in public, where everyone who read the original can see the change.

  5. 05

    Service fees are fixed once scope is clear. Product availability and pricing are confirmed through direct contact.

How a correction is issued, and every correction we have issued so far, are on the corrections page.

What every engagement defines

  • Framework mappings connect evidence to named control objectives. They are evidence mapping, not a certification claim. Certification comes from each scheme's accredited assessors.
  • SSX360 sells cybersecurity products and scoped services. Each proposal and report names the product, service, evidence, and limits in scope.
  • Signet-C and Signet-N are completed hardware signers supplied through direct contact. The software console animates status icons. The device display presents the current state only. Public pages do not disclose their internal architecture or customer integration details.
  • The post-quantum software path supports assessment and migration planning, including inventory against Category 5 parameter sets such as ML-DSA-87 used in CNSA 2.0 alignment work. It is not presented as a validated production cryptographic module, CNSA certification, FIPS CMVP validation, NSA approval, or as suitable for protecting sensitive production data.
  • Working with defense and government suppliers is not the same as holding an accreditation. We hold no facility clearance, no CMMC certification and no ITAR registration, and we say so before anyone asks.
  • Matrix Scroll is free under Apache-2.0. Its public verification software can be used without buying an SSX360 service.

Where to start

A first call covers service scope, product fit, and the evidence you need. We explain what the work can establish, confirm USB signer availability when relevant, and quote once the scope is clear.

Where we name a scheme such as PCI DSS, SOC 2 or the EU AI Act, we are describing evidence mapping, not a certification claim. Certification under any scheme named here comes from that scheme's own accredited assessors.

The full scope of what an SSX360 assessment does and does not cover is set out in our legal terms.

Request a call