Skip to content

SSX360 verification registry

Every public SSX mark resolves to signed evidence.

An issued Level 1, Level 2, or Level 3 mark carries a unique registry ID. Its entry names the level, subject, scope, criteria version, assessor, dates, status, report digest, and Matrix Scroll signature.

Public entries are published only after the applicable level criteria pass and the holder gives written authorization. Reviews conducted under NDA remain confidential and are not listed. A public mark is valid only when its unique registry URL resolves to a current entry.

  1. L1

  2. L2

  3. L3

Registry publication

Public entries appear only after the verification concludes, the record is signed, and the holder authorizes publication. NDA-bound reviews do not reveal the holder, subject, scope, or status here.

A mark shown without a resolvable entry is not an issued SSX verification mark. Send suspected misuse to our security contact.

Published entries

Publication begins with the first holder-authorized issued record. Confidential reviews remain outside this index.

Registry IDs are assigned at issuance and are never reused.

Check a public mark in three steps

  1. 1

    Follow the registry URL

    Match the ID printed beside the mark to the entry served from ssx360.com/mcv/registry.

  2. 2

    Match scope and date

    Confirm the named subject covers what you are evaluating and that the status is current.

  3. 3

    Verify the signed record

    Download the JSON record and run the open Matrix Scroll verifier offline. A changed byte causes verification to fail.

What each entry contains

Registry ID
Unique identifier printed beside the issued mark
Verification level
Level 1, Level 2, or Level 3 and the criteria version applied
Holder and subject
Organization displaying the mark and the product or workflow reviewed
Verified scope
Systems, actions, period, and exclusions covered by the report
Criteria and assessor
Published criteria version and the named assessor responsible for the conclusion
Dates and status
Verification date, expiry date, and current, expired, or revoked status
Signed record
Report and evidence digests inside an Ed25519-signed Matrix Scroll manifest

A mark can expire or be revoked

A mark that cannot be lost carries little information. The registry keeps past entries visible while changing the status a relying party sees.

  1. Issue

    Verified

    The report passes the applicable level criteria for the named scope and the public entry is signed.

  2. Live

    Current

    The entry displays its scope, method version, assessor, dates, digests, and signature.

  3. 12 months

    Expires

    A new review renews the mark. An expired entry remains visible with its expired status.

  4. Material change or misuse

    Revoked

    The registry keeps the revoked entry visible with its date and reason code.

Mark use

Permitted

  • Describing the verification using the level, criteria version, and scope named in its current registry entry.
  • Stating that MCV-1 was used when the current registry entry names Level 2 or Level 3.
  • Displaying the issued mark with its full registry ID, URL, and expiry date while the entry is current.

Not permitted

  • MCV-1 certified or SSX360 certified.
  • Quantum-proof, fully secure, or organization-wide when the registry entry names a narrower scope.
  • Using the master artwork without an issued registry ID and URL.
  • Cropping, editing, or continuing to display a mark after expiry or revocation.
  • Extending a scoped verification to an organization, portfolio, product, or period not named in the entry.