Skip to content

SSX360 sells cybersecurity products and scoped services. You get defined deliverables, signed evidence, and verification your reviewers can run.

Products and services with a defined scope.

Choose the completed SSX360 USB signer or a scoped service covering software provenance, machine authorization, post-quantum migration, logistics, defense, finance, or climate risk.

The SSX360 USB signer is a commercial product supplied through direct contact. Matrix Scroll remains free under Apache-2.0, and service proposals name the evidence, limits, and deliverables in scope.

SSX verification levels

Audit. Control. Keep proof current.

L1 records a point-in-time audit. L2 verifies authorization controls over an evidence period. L3 anchors the record in recognized hardware and adds scheduled upkeep.

  1. L1 / AuditSSX-L1.0

    What are we buying, approving, or accepting?

    A scoped fintech or M&A audit with signed findings, an evidence period, and clear limits.

  2. L2 / SSX TerminusSSX-L2.0 / MCV-1.0

    How will the system prove who approved an action?

    Level 1 plus a verified record showing how authorization controls operated for the named workflow.

  3. L3 / Signer + upkeepSSX-L3.0 / MCV-1.0

    How will the approval record stay verifiable in operation?

    Level 2 plus a recognized hardware root of trust, deployment record, scheduled review, and upkeep.

Compare criteria and marks

Provenance Snapshot

L1 / Audit
5 to 7 days

Deal teams buying a company

A provenance review for an acquirer's deal team before signing. We examine the target's software, data sources, and machine authorization records, then sign the findings inside a live transaction timeline.

Deliverables and scope

Covers one target company's automated systems under diligence. Multi-entity or platform-rollup scope is quoted on the call.

What you receive

  • Signed Provenance Snapshot addressed to the named deal team
  • Model provenance: the target's own work, a fine-tune of someone else's, or a wrapper on a third-party API
  • Training-data origin, and which of those claims the data room can evidence
  • Machine authorization: what the system can execute, who or what authorized it, and what record that approval leaves
  • Authorization and evidence-trail gaps ranked by close risk
  • Offline-verifiable evidence package
  • Reliance letter available, so a named lender, insurer or co-investor can rely on the report too

Confirmed on the call, once scope is clear

Scope a Snapshot

SSX Terminus Authorization Solution

L2 / SSX Terminus
Custom delivery

Fintech, payment, treasury, and automation teams

A custom authorization scope for one high-impact automated workflow. SSX360 defines the control requirements, verifies how they operated over an agreed evidence period, and delivers the machine-verifiable record.

Deliverables and scope

Covers one automated workflow and the systems that directly approve, execute, or record its named actions. Delivery and integration scope are confirmed after the Level 1 evidence baseline is clear.

What you receive

  • Signed MCV-1 baseline report
  • Custom SSX Terminus control specification
  • Evidence-window definition for the named actions
  • Machine-verifiable authorization record
  • Acceptance test and offline-verification handoff

Confirmed on the call, once scope is clear

Scope SSX Terminus

Vulnerability & Audit Report

L1 / Audit
5 to 7 days

One system, site or counterparty

A focused audit of one system, site or counterparty. The gaps we can prove exist, delivered inside a live decision timeline.

Deliverables and scope

Covers one system, site or counterparty. Wider scope is quoted on the call. If you go on to commission a Stability Assessment, this fee comes off it, within the window your engagement letter sets out.

What you receive

  • Signed Vulnerability & Audit Report
  • Gap findings ranked by decision urgency
  • Offline-verifiable evidence package

Confirmed on the call, once scope is clear

Request a report

Stability Assessment

FlagshipL1 / Audit
2 to 3 weeks

Enterprises and principals facing multi-sector exposure

A signed, sector-mapped assessment of your exposure across logistics, defense, finance and climate. One document your board and your auditors both accept.

Deliverables and scope

Covers the sectors and systems listed at kickoff. Shared credentials or handoffs between automated systems widen the review and are quoted once the system list is clear.

What you receive

  • Signed Stability Assessment
  • Sector exposure map across logistics, defense, finance and climate
  • Findings ranked by what blocks a decision
  • Evidence package verifiable offline
  • SSX Terminus control specification when machine-authorization gaps are found
  • PQ Signature Inventory included when the systems that sign your records are already in scope

Confirmed on the call, once scope is clear

Scope an assessment

Signer + Upkeep Deployment

L3 / Signer + upkeep
Custom delivery

Production fintech and enterprise workflows

A custom Level 3 scope that anchors the authorization record in a recognized hardware root of trust and adds a scheduled upkeep plan. Signet-C and Signet-N are supported deployment options.

Deliverables and scope

Covers one named workflow, one recognized hardware root of trust, and the upkeep term recorded in the proposal. Additional systems and locations are scoped separately.

What you receive

  • Hardware-root acceptance and attestation record
  • Signet-C or Signet-N supplied when selected for the named workflow
  • SSX Terminus evidence baseline for approved actions
  • Hardware-anchored signing and offline-verification handoff
  • Deployment record and operating guide
  • Upkeep cadence and change-review schedule
  • Cryptographic-transition record when required by the evidence lifetime

Confirmed on the call, once scope is clear

Scope signer deployment

Signer Upkeep

L3 / Signer + upkeep
Monthly

Available after a Level 3 deployment

Scheduled review and upkeep for the recognized hardware root and named authorization workflow, with evidence refreshed as the operating environment changes.

Deliverables and scope

Opens after a completed Level 3 deployment and covers the hardware root, workflow, and review cadence named in the upkeep agreement.

What you receive

  • Hardware-root status and custody review
  • Quarterly MCV-1 re-assessment for the named workflow
  • Authorization-policy and evidence review after material changes
  • Updated verification and cryptographic-transition record
  • Named upkeep schedule and response path

Confirmed on the call, once scope is clear

Discuss signer upkeep

PQ Signature Inventory

L1 / Audit
3 to 4 days

Teams mapping post-quantum signature exposure

A list of every place your systems sign a record today, which algorithm each one relies on, and what moving to the newer post-quantum schemes would touch. Included free inside a Stability Assessment when those systems are already in scope.

Deliverables and scope

Covers the signing systems you nominate. Included free inside a Stability Assessment when they are already in scope.

What you receive

  • Signed PQ Signature Inventory
  • Systems and libraries ranked by migration urgency
  • Offline-verifiable evidence package

Confirmed on the call, once scope is clear

Scope a PQ inventory

Framework mappings show which control objectives our evidence satisfies, written so your reviewers and assessors can check the work against the scheme themselves. That is an evidence mapping, not a certification claim. Certification under any scheme named here comes from that scheme's own accredited assessors.

Four words we use, in plain terms
Provenance
Where something came from and whose hands it passed through. For an automated system, that includes the software it runs, the data it uses, who or what authorized it, and what it may execute.
Evidence package
The files behind the report. Each one is signed, and your reviewers can confirm the signatures on their own machines without an account or a key from us.
Signature surface
Every place your systems sign a record: the code you ship, the pipelines that build it, the documents you have to stand behind later. Knowing the list is what makes a migration plannable.
Reliance letter
A written statement naming a third party, such as your lender, insurer or acquirer, and permitting them to rely on the report as though it had been addressed to them.

How the fee works

The fee is fixed once scope is clear and confirmed on the call. Multi-system or regulated scope can change the quote. The agreed fee and scope remain fixed during delivery unless both parties approve a written change.

We confirm the fee on the call after the systems, evidence, and decision timeline are clear.

Every engagement runs under its own signed agreement. What an assessment does and does not cover is set out in our legal terms.

Request a call

We reply within one business day.