SSX360 / TOOLS

FREE TOOLS · RANKED BY WHAT'S DUE FIRST

Trust must be checkable.

Six working tools for the obligations landing now. Use them in the browser or add them to your agent over MCP. Every result carries a receipt you can verify yourself. No account needed.

#1CRA incident-evidence ledger

CRA Incident Clock

Deadlines, required report content, an awareness record and a verifiable receipt.

Art. 14 reporting live since 11 Sep 2026: 24h / 72h / final-report clocks.

#2Agent/MCP evidence adapter

MCP Evidence Probe

Audit tools/list manifests for injection and questionnaire gaps. Hash-chain every tool call.

Security questionnaires now ask for agent tool-call records. Complements your gateway.

#3C-UAS post-op reporting

C-UAS After-Action Builder

Detection logs into a post-operation report with Remote ID, time-to-notify and IFR clocks.

IFR in force since 1 Jul 2026: 48h post-op report, 6-year audit trail. FEMA-grant fundable.

#4PQ signature evidence

PQ Signature Inventory

Find RSA/ECDSA/EdDSA in certificates, CycloneDX SBOM/CBOMs and configs.

CNSA 2.0 acquisition gate on 1 Jan 2027. FAR PQC rule due Dec 2026.

#5OT evidence integrity

INSM Retention Checker

CIP-015 readiness score plus a Merkle-root attestation over your INSM data manifest.

CIP-015-1 INSM from 1 Oct 2028. R3 requires INSM data to be protected from tampering.

#6Examiner-ready evidence

Examiner Evidence Pack Builder

Map program documents to examiner evidence expectations (NIST CSF 2.0 / CRI Profile functions).

Exam cycles never stop. Bring evidence your examiner can verify offline.

Use them from Claude, Cursor or VS Code

Every tool is a Hugging Face Space running as an MCP server. Click the MCP badge on any Space, or add one to your client config:

{ "mcpServers": { "ssx360-cra": { "url": "https://ssx360corp-cra-incident-clock.hf.space/gradio_api/mcp/" } } }
SOFT · NO SALESVerify a receipt in your browser MID · 30 MINOffice hours: technical, no pitch HARD · FIXED FEEScope an engagement