Privacy // data boundaries
SSX360 privacy
SSX360 uses a local-first signing model and a hosted account portal for identity, billing, entitlement, confirmation, and audit export.
SSX360 privacy
Ed25519
commit envelopes
offline-verifiable proof
local-only
CLI & HOOKS
repo never uploaded
Scroll Gate
PR enforcement
signed vs unsigned
SSX360
control plane
identity · billing · audit
The portal proves access. The desktop does the repo work.
This page summarizes the launch privacy posture for SSX360. It is written for product clarity, not as a substitute for formal legal advice.
Portal data
The hosted portal stores account identity, authentication session state, Stripe customer and subscription references, entitlement state, license ID, device-code records, API key prefixes (never full secrets), provenance metadata, usage metering events, and audit export state.
Local signing data
Commit envelopes, workspace binding, and MCP integration are designed to run on the customer machine through the Matrix Scroll SDK. Private source code should not be uploaded to the portal as part of the normal flow.
Third-party services
SSX360 uses Supabase for hosted auth and entitlement storage, Stripe for checkout and billing, Vercel for portal hosting.
Telemetry
Product telemetry must be explicit and documented before launch use. Telemetry is not a license to upload private source code or hidden repository contents.