Skip to content

Capabilities

Choose the proof your decision needs.

Start with what must be reviewed, what evidence your team needs, and how far the verification should go.

The issued mark

The issued mark.

One mark, issued against a named workflow and recorded as SSX-L3.0 in the registry. Scope is named in the registry entry, not implied by the mark.

Post-quantum readiness

SSX-L3.0 / MCV-1.0

Named scope

Applies to the named workflow and upkeep terms recorded in the registry entry.

Will the proof still hold next year?

A scoped review with signed findings, an authorization record for one named workflow, and scheduled upkeep.

What is included

  • Scope, findings and limits signed
  • Authorization record verified over a defined evidence window
  • Deployment and upkeep recorded

Buyer routes

Two common starting points.

Fintech

From workflow review to production proof.

Start with a scoped review of a payment, treasury, wallet, or vendor decision, then verify SSX Terminus controls over a defined evidence period. The mark follows once the workflow carries a maintained authorization record and scheduled review.

M&A

From diligence finding to post-close control.

Review the target and its automated systems before signing, then verify authorization controls for material machine actions after close. The mark follows once the acquired workflow carries a maintained authorization record and scheduled review.

Coverage

What the work touches.

The five spokes name the sectors. The same evidence layer also covers entropy sources, optical benches, field timing, counter-UAS programs, defended cells, adversarial wargames, and program-scale evidence planes. Internals and fees stay in the proposal.

Bench and starter evidence

  • Open provenance

    Matrix Scroll remains Apache-2.0. Signed records from every other engagement ride the same verifier.

  • Entropy sources

    Assessment of random bit sources, including a documented abstention rule when a source must not be treated as certified. Where methods follow NIST SP 800-90B, that is evidence mapping, not a certification claim.

  • Optical detection bench

    Single-photon and time-resolved optical benches for quantum random-number generation and ranging, including lidar programs.

Deployable systems

  • Field network nodes

    Deployable nodes that keep timing, navigation, and communications on a signed evidence path.

  • Precision timing

    Atomic clocks and holdover timing for field systems that must remain accountable when satellite navigation is degraded.

  • Counter-UAS evidence

    Assessment and signed records for counter-unmanned aircraft programs at a named site and evidence period.

Defended cells

  • Area defense

    Evidence for a named defended area: sensors, timing, and the records a reviewer can check after an event.

Program instruments

  • Adversarial wargame

    A scoped service that uses a digital twin as a test instrument against a named threat and evidence period.

  • Accountable evidence plane

    Program-scale capture, bind, batch, and sign for a named decision, with offline verification.

Matrix Scroll, Apache-2.0

Open verification software

  • Available under Apache-2.0 on PyPI and GitHub.
  • Reviewers can verify delivered evidence without an SSX360 account.
  • Public documentation covers the supported interface and verification workflow.

Authorized testing and scoped services

SSX360

  • Authorized penetration testing and scoped cybersecurity services under written rules of engagement.
  • Entropy-source assessment, field timing, counter-UAS evidence, and program-scale records when those systems are in scope.
  • Machine-authorization and provenance work when the decision needs a verifiable record.
  • Each proposal names the scope, method, limits, deliverables, and fixed fee.
  • Reports include an evidence package reviewers can verify without calling us.

Scope

What this surface does not cover

The service boundary matters as much as the finding. Open either panel for the full commercial scope and limits.

Request a call
Boundaries
  • Identity and access management

    SSX360 reviews authorization evidence. It does not replace your identity provider, credential lifecycle, or access-control system.

  • Automation operation

    Our work reviews and verifies records. It does not operate, host, or supervise your automated systems.

  • Third-party certification

    Framework mappings connect evidence to control objectives. Certification remains with each scheme's authorized assessors.

  • Blanket product assurance

    A report or mark applies only to the scope and evidence period written into the delivered record.

Scope and disclosure limits

Where we name a scheme such as PCI DSS, SOC 2 or the EU AI Act, we are describing evidence mapping, not a certification claim. Certification under any scheme named here comes from that scheme's own accredited assessors.

  1. 01

    Public pages describe buyer outcomes, availability, and verification. Implementation details are provided only during qualified scoping and under the applicable confidentiality terms.

  2. 02

    The post-quantum software path is intended for assessment and migration planning, including Category 5 parameter sets such as ML-DSA-87 used in CNSA 2.0 alignment work. It is not presented as a validated production cryptographic module, CNSA certification, FIPS CMVP validation, or NSA approval.

  3. 03

    Hosted features and customer integration details are documented only for the customer and scope that require them.