Keys never leave your machine

Identity tools find agents. SSX360 proves authorization.

NHI platforms discover identities, privileges, and risky access. SSX360 signs the authorization record before the agent changes code, calls tools, or takes action - with offline-verifiable Ed25519 proof.

Why SSX360 wins the wedge

Inventory is not authorization. Remediation is not proof.

AI-era identity security tells you which non-human identities exist and where access is over-scoped. Most "full audit trail" claims are still app logs - timestamped activity, not signed proof. SSX360 sits one layer lower: the signed, portable record of who authorized the machine action - before it moved money, filed a claim, or touched a regulated system - and what an assessor can verify without trusting our control plane.

Before action

Sign declared actor, tool, scope, and changed surface before merge or tool drift is accepted.

Offline proof

Verify the record in CLI, browser, or CI with the same RFC 8032 bytes - no SaaS lookup required.

Complements NHI

Keep your NHI inventory, vault, and ITDR stack. Add the authorization record they do not produce.

Built for consequences

Fintech agents moving money, healthcare agents filing claims, tax and credit agents making calls - the actions a regulator or assessor cares about, not general chatbot logging.

How it works

Sign, Trust, Gate, Prove

From local authorization records to offline-verifiable evidence — MCP baselines, CI enforcement, export.

1

Sign

Matrix Scroll CLI, hooks, or MCP attach Ed25519 authorization records — actor, tool, scope. Keys stay local.

matrixscroll hook-install
2

Trust

Scan and sign MCP install-time baselines. Drift detection fails CI when tool surfaces change without re-authorization.

matrixscroll mcp scan -o baseline.json

Try the live scanner →

3

Gate

Scroll Gate runs on every pull request. Missing or tampered authorization records fail CI before merge.

ssx360 check --hosted

Try the simulation →

4

Prove

Export ssx360.evidence-pack.v1 JSON — verify offline. No SSX360 in the trust path.

ssx360 evidence export

Who it's for

MCP-blocked security, agent ops, SOC 2 windows

Pricing ladder

Sign free → Trust → Govern → Prove

Pricing →

Sign

Free

Matrix Scroll SDK — local signing, MCP Trust Scanner

Trust

$499/mo

Agent Trust — MCP baselines, drift alerts, authorization ledger

Govern

$199/mo

Team console — policy registry and audit export

Prove

Paid

Authorization Pilot · Snapshot · Enterprise

Repo contents never leave your machine — see exactly what's hosted →

They receipt the model call. We receipt everything the machine does.

Scan your MCP server