Ships today
Fintech change-control evidence
- ✓Ed25519 authorization records on agent-assisted merges
- ✓MCP manifest baselines with drift detection
- ✓Scroll Gate CI — block unsigned changes on protected branches
Enterprise // agentic commerce
Agent Authorization Authority — beside your rail, not instead of it.
Enterprise & authorization partners
Framework mapping
Ed25519
commit envelopes
offline-verifiable proof
local-only
CLI & HOOKS
repo never uploaded
Scroll Gate
PR enforcement
signed vs unsigned
SSX360
control plane
identity · billing · audit
For payment & agentic commerce teams
Tokenization, authentication, and settlement stay on your network. SSX360 is the portable proof layer: signed commits on infrastructure code, CI gates before merge, and (in pilot) bounded agent mandates with human approval records you can verify offline.
Networks tokenize and move money. SSX360 answers who authorized the agent, what limits applied, and whether the change was signed before merge — authorization first, compliance mappings as billing.
Ships today
Pilot program open
Complements agentic payment infrastructure (AP2-style mandates) — we do not process cards or replace network tokens.
Layer 1 · Protocol (Sign)
Matrix Scroll SDK, local Ed25519 signing, and MCP Trust Scanner — the open-source foundation.
Layer 2 · Governance (Trust / Govern)
SSX360 platform, team console, drift alerts, and Scroll Gate CI PR enforcement — the control plane.
Layer 3 · Hardware (Prove)
SE050 physical USB-C device and Authorization Pilot deployments — bench-validated preview, not GA.
Prove which model flagged or cleared a case, under whose authority, months or years later.
Maintain an immutable record of the agent, the inputs, and the human approval behind automated lending.
Attest that identity verification ran exactly as required, backed by cryptographic proof.
Bind money-movement configurations to a scoped, authorized session with a verified human in the loop.
Phase 1 · Hardware Pilot
Deploy physical devices to select engineering teams for hands-on validation in real development environments.
Phase 2 · Platform Integration
Expand across the organization — full fleet-wide enrollment, CI gating, and measurable compliance improvements documented.
Phase 3 · Scale & self-serve
Proven results drive enterprise-wide expansion once warn-mode gates and evidence export are validated.
Three layers — open protocol, CI enforcement, hosted control plane.
Matrix Scroll
Open protocol. Signs commit envelopes locally via CLI, hooks, and MCP — keys never leave the machine.
Scroll Gate
CI enforces signed commits on protected branches before merge — unsigned changes are blocked or flagged.
SSX360
Hosted control plane for identity, billing, policy registry, and audit evidence export.
USB-C hardware possession factor (SE050 preview), merge gates on GitLab or GitHub, and audit export — governed sessions for agents, not developer productivity surveillance.
01 · Sign
Matrix Scroll attaches commit envelopes via hooks, CLI, or MCP when agents touch your codebase.
02 · Gate
Scroll Gate and ssx360 check enforce signatures before merge.
03 · Export
Trust Operations Console: audit ledger, policy registry, and JSON evidence for procurement.
Owns Git repositories, controls permissions, manages project access, and approves merge activities.
Works on assigned repositories with possession-factor sessions — commits, pull requests, and signing recorded with identity and device status.
Monitors security events, reviews audit logs, and performs compliance readiness checks — SIEM export and offline evidence packs, not certification.
Pilot and enterprise deployments scope logging for assessor review — Prometheus / Grafana and SIEM export integrate with your monitoring stack; evidence packs remain offline-verifiable.
Hardware signing · SE050
The NXP SE050 secure element generates its Ed25519 key on-chip and signs under the same RFC 8032 byte contract as the shipping SDK — no verifier changes required. This is a bench-validated PoC available for enterprise pilot evaluation, not a GA or certified hardware product.
Non-exportable keys
The Ed25519 private key is generated inside the SE050 on first boot and never leaves the chip — no USB key-generation path exists.
Browser + CLI verify
Every signature checks out in the matrixscroll.com browser verifier and the matrixscroll CLI under the current byte contract — same verify path as software-signed envelopes.
Bench-validated, Jul 2026
10 acceptance vectors (64–800 B payloads) signed on SE050 hardware and cross-checked against Matrix Scroll before leaving the contractor's bench.
Context: Payments, ledger, and core banking systems under PCI-adjacent change control as agents refactor pipelines.
Fit: Signed commits and Scroll Gate enforcement before merge — machine-readable evidence for internal audit, not payment-rail certification.
Pilot focus
Context: Hyperscale internal repos with continuous integration and AI codegen at scale.
Fit: Signed provenance at commit time bridges AI-assisted changes and zero-trust CI/CD — declared actor and tool metadata in the audit ledger.
Pilot focus
Context: SEC, PCI-adjacent, and federal supplier codebases under software change-control scrutiny.
Fit: Machine-readable verification manifests — auditable proof of which production paths were touched by agents.
Pilot focus
We govern
We do not claim