Legal
SSX360 policies, contact routes and the boundary between this website and a signed engagement.
Policies
Engagements
Assessments, snapshots, pilots and retainers run under their own signed agreement, including scope, confidentiality, liability and reliance terms. That agreement governs the engagement and takes precedence over anything published here.
Reliance
A signed SSX360 report is addressed to the client named on it. Third parties should not rely on a report without a written reliance letter from us. If you have been handed one of our reports during a diligence process and need reliance, contact us before depending on it.
Commercial terms
Product and service boundaries are public. Read the delivery model before engaging us, particularly if your organization appears in our research.
What every engagement defines
- Framework mappings connect evidence to named control objectives. They are evidence mapping, not a certification claim. Certification comes from each scheme's accredited assessors.
- SSX360 sells authorized security testing and scoped cybersecurity services. Each proposal and report names the service, evidence, and limits in scope.
- The post-quantum software path supports assessment and migration planning, including inventory against Category 5 parameter sets such as ML-DSA-87 used in CNSA 2.0 alignment work. It is not presented as a validated production cryptographic module, CNSA certification, FIPS CMVP validation, NSA approval, or as suitable for protecting sensitive production data.
- Working with defense and government suppliers is not the same as holding an accreditation. We hold no facility clearance, no CMMC certification and no ITAR registration, and we say so before anyone asks.
- Matrix Scroll is free under Apache-2.0. Its public verification software can be used without buying an SSX360 service.
Contact
General: mission@ssx360.com. Security reports: mission@ssx360.com.
