CYBERSECURITY / SIGNED EVIDENCE

Cybersecurity for
mission systems.

Security assessments, post-quantum signatures, and records your reviewers can verify offline. Each engagement defines the systems, authorization, methods, and evidence required for review.

Explore ML-DSA-87

01 / SIGNATURES & TRUST

Signed records.
Independent review.

Matrix Scroll protocol v2 connects the signature, the record format, and the rules for trusting a signer. Each has a distinct role in the evidence your team reviews.

Matrix Scroll ML-DSA-87, security category 5, protocol v2 signature profile

ML-DSA-87

Post-quantum signatures

SSX360 has adopted ML-DSA-87 for Matrix Scroll protocol v2. Signatures let reviewers check the integrity of signed material against the expected public key.

COSE + JCS

Defined signed bytes

Protocol v2 specifies the bytes covered by a signature using COSE and canonical JSON. Reviewers can check the same record representation across implementations.

SHA-384

Record commitments

SHA-384 record commitments support checking the record content. Signature verification and signer authorization remain separate review steps.

PY / RS / JS

Offline verification

Verifier implementations in Python, Rust, and JavaScript let reviewers check signed material offline using the expected public key and trust policy.

TRUST POLICY

Explicit signer enrollment

The trust policy identifies which signers are authorized for the review. A valid signature is assessed alongside the signer’s authority, source quality, and scope.

ML-DSA is a digital-signature standard specified in FIPS 204. SSX360’s algorithm choice is separate from product certification or cryptographic-module validation.

Read the signature standard

02 / SCOPED SECURITY ENGAGEMENTS

Assessment for your operating environment

Set the assessment around your control systems, communications, and assurance requirements. Agree the testing boundaries and expected evidence before work begins.

OT & INFRASTRUCTURE

Examine the connected site.

Define the control systems, interfaces, access paths, and operational constraints. Agree the scope before active testing begins.

  • Authorized penetration testing
  • Communications and telemetry integrity
  • Machine-authorization review
  • Signed findings and evidence
HARDWARE & SOFTWARE ASSURANCE

Assess hardware and software.

Connect instrument-backed observations, cryptographic provenance, and migration planning to the system your team needs to evaluate.

  • EM and RF characterization
  • Entropy-source assessment
  • Software provenance
  • Post-quantum signature inventory

03 / ACCOUNTABLE EVIDENCE PLANE

From assessment
to a reviewable record.

Accountable Evidence Plane connects assessment work with signed records and offline verification. Define the systems, authorization, evidence period, and review criteria before work begins.

  1. 01 / DEFINE

    Agree the boundary.

    Document the systems in scope, written authorization, operating constraints, and the questions the assessment should answer.

  2. 02 / RECORD

    Preserve the context.

    Deliver findings with the methods, observations, and limitations needed to interpret them. Include signed records where agreed in the engagement.

  3. 03 / VERIFY

    Check the evidence.

    Review the signed material with the verifier, expected public key, and trust policy. Assess the findings against the original scope and source quality.

Explore Accountable Evidence Plane

04 / PROTOCOL & RELATED WORK

Open software and related development

SIGNET PNT-1

The PNT-1 field-unit design applies signed integrity records to positioning, navigation, and timing. Hardware testing and performance validation remain part of the development plan.

Explore SIGNET methods

N.3.X.U.S OS

Hardware interfaces, perception, application logic, field communications, and evidence requirements within one architecture.

Explore N.3.X.U.S OS

Define your next assessment.

Share the operating context and review questions. Methods, deliverables, and acceptance criteria are agreed for each engagement.

Request a briefing.

Prepare a message for mission@ssx360.com, then send it from your email app.

Share your area of interest, general requirements, and the decision your team needs to make.

Keep this first message to general requirements. Arrange confidentiality terms before sharing nonpublic information.

Read our Privacy notice and legal contact information.