Legal
SSX360 policies, contact routes and the boundary between this website and a signed engagement.
Policies
Engagements
Assessments, snapshots, pilots and retainers run under their own signed agreement, including scope, confidentiality, liability and reliance terms. That agreement governs the engagement and takes precedence over anything published here.
Reliance
A signed SSX360 report is addressed to the client named on it. Third parties should not rely on a report without a written reliance letter from us. If you have been handed one of our reports during a diligence process and need reliance, contact us before depending on it.
Commercial terms
Product and service boundaries are public. Read the delivery model before engaging us, particularly if your organisation appears in our research.
Scope of our assessments
- Framework mappings connect evidence to named control objectives. They are evidence mapping, not a certification claim. Certification comes from each scheme's accredited assessors.
- SSX360 sells cybersecurity products and scoped services. Each proposal and report names the product, service, evidence, and limits in scope.
- The completed SSX360 USB signer uses an RP2350 bridge and an NXP SE050 secure element for Ed25519 signing. Physical units are supplied through direct contact. PyPI distributes the host software only.
- Post-quantum signing in Matrix Scroll implements the ML-DSA and SLH-DSA algorithms specified in FIPS 204 and FIPS 205, through liboqs. That is an algorithm implementation, not a CMVP-validated cryptographic module, and we will not describe it as FIPS validated. liboqs itself states that it should not be relied on in production or to protect sensitive data, which is a limit we repeat rather than bury.
- Working with defense and government suppliers is not the same as holding an accreditation. We hold no facility clearance, no CMMC certification and no ITAR registration, and we say so before anyone asks.
- Matrix Scroll is free under Apache-2.0. The software signer, verifier, MCP server, conformance vectors, and USB signer host integration can be used without buying an SSX360 service.
Contact
General: mission@ssx360.com. Security reports: mission@ssx360.com.
