AIR
Proof Lab
StartEcosystem
Explore (579)Live Systems (52)Pricing
Log InGet API Key✓ Verify It Yourself

Claims Evidence

Tamper-evident, portable, verifiable across the carrier-reinsurer-regulator chain.

This evidence layer powers HATS, H33’s cyber-insurance governance product — continuous, cryptographic proof of which controls were active and how an incident was handled, so a claim is backed by verifiable evidence instead of affidavits.

Cyber insurance claims hinge on what the insured can prove about an incident — when it started, who detected it, what controls were active, what response was triggered. Standard logs are insufficient: they can be edited, lost in vendor changes, or contradicted across systems. H33 produces tamper-evident claims evidence that travels across the carrier, reinsurer, regulator, and litigation chain without losing fidelity at any hop.

The cyber claims evidence problem

Cyber insurance claims have a specific evidentiary structure. The claim depends on facts about an incident: timeline, scope, controls, response. Each downstream party — carrier, reinsurer, regulator, court — has progressively less trust in the insured's internal records. Standard cyber logs do not survive this chain well: the insured's MFA logs can be edited; the SIEM may have been compromised in the incident; the identity provider may have changed vendors; the endpoint detection vendor may have been acquired; the cloud provider may have rotated logs out of retention. By the time the claim reaches the regulator or the courtroom, the evidentiary trail may be incomplete or unverifiable.

What H33 captures at incident time

H33 evidence bundles are generated at the moments that matter: Detection — when an intrusion detection or behavioral system identifies a candidate incident, a bundle captures the detection's basis, the model or rule that fired, the data that triggered it, and the response action that followed. Response — when the IR team takes an action, a bundle captures the action's authority, the policy that justified it, the system state, and the evidence considered. Control assessment — when periodic control assessment runs (MFA usage validation, EDR coverage, patch level), a bundle captures the basis and result. Notification — when timelines start, a bundle captures who knew what, when they knew it, and what triggered the timeline. Bundles are signed by three independent post-quantum algorithm families. They can be anchored to a public chain for time binding. They are stored under the insured's control.

How bundles survive the claims chain

Carrier review. The insured provides bundles supporting the claim. The carrier runs the open-source verifier offline. Verification confirms the bundles are unmodified and the timeline is consistent. Reinsurance handoff. The carrier passes the relevant bundles to the reinsurer. The reinsurer runs the same verifier. No re-investigation required. Regulatory review. A breach notification triggers regulatory scrutiny. The insured provides the bundles. The regulator verifies them. The verification result is binding because the open-source verifier is reproducible. Litigation discovery. A third party brings suit alleging negligence. The insured provides the bundles. Opposing counsel runs the verifier. Both sides agree on what the verifier returns.

The reinsurance modeling angle

Reinsurers consistently report that cyber loss data is insufficient for actuarial modeling. The data is sparse, inconsistent across carriers, hard to verify, and contaminated by selection bias. H33 evidence bundles improve the data substrate. Loss events documented with portable, verifiable evidence are comparable across carriers (the bundle format is standardized), verifiable without re-investigation, resistant to selection bias (generated at incident time, not after-the-fact), time-bound (the anchor proves when the bundle was created), and stable across retention windows.

Use cases

Ransomware claim. An insured organization is hit by ransomware. The H33 bundles document the detection, the timeline of encryption, the response actions, and the eventual restoration. The carrier evaluates offline. The reinsurer confirms the basis. The claim is settled without dispute over evidence authenticity. Business email compromise claim. An employee approves a fraudulent wire. The bundles document the MFA state, the email gateway controls, the policy governing wire approval, and the deviation from policy. Insider data theft claim. The bundles document the user's access scope, the data accessed, the DLP signals, and the access timeline.

Common questions

Does this require changing my incident response process?
No. H33 evidence generation runs in parallel with your existing IR tooling. Bundles are produced as a byproduct of the detection, response, and assessment events that already happen.

Can my carrier accept H33 bundles today?
The bundles are open standard, canonical JSON, with an open-source verifier. Any carrier can accept them. Adoption is a contractual matter, not a technical one.

Does this work with my existing SIEM and SOAR?
Yes. The bundle-generation integration is API-based.

What happens if my SIEM is compromised in the incident?
The bundles produced before the compromise are unaffected. The bundles are signed at generation time and stored separately from the SIEM.

Are the bundles privacy-preserving?
Bundles stay under your control. Only the 32-byte commitment goes on-chain when anchored.

Get Started

Run the demo Download the verifier Download a bundle

Related: Cyber Claim Verification · AI Audit Trails · H33 vs Traditional Audit Logs · Avalanche Evidence Anchoring

H33 Products · Claims Evidence

What this product is

Definition. Claims Evidence is a product that produces portable, tamper-evident evidence bundles for cyber-insurance underwriting and claims adjustment — bundles that travel across the carrier, reinsurer, regulator, and litigation chain without losing fidelity at any hop. It owns the evidence-portability workflow and the cross-chain-survivability outcome. It does not own, redefine, or reimplement the attestation, monitoring, or verification it relies on; it composes them.

Why this exists. Each downstream party trusts the insured's internal records less than the last, and standard logs do not survive that chain. This product exists to give a claim a verifiable evidentiary spine for the specific job of underwriting and adjustment. The evidence supports those decisions; it does not by itself settle a claim or make an insurer compliant.

The product boundary. Claims Evidence owns the cyber-insurance-claims evidence workflow and outcome. It uses H33 mechanisms for evidence, monitoring, and verification; it does not redefine or own those mechanisms.

USES H33-74

H33-74 supplies the portable post-quantum attestation and receipt so a bundle stays verifiable at every hop; only the 32-byte commitment goes on-chain when anchored. The product commits and forwards the fact; it does not produce the attestation primitive.

MONITORED_BY HATS

The continuous operational evidence cyber insurance relies on — which controls were active and how an incident was handled — comes from HATS. The product is monitored by it and packages what it recorded into bundles; it does not perform the monitoring. HATS is the cyber-insurance mechanism; this product uses it.

USES Verification

Verification lets any party — carrier, reinsurer, regulator, opposing counsel — reach the same independent verdict on a bundle offline with the open-source verifier. The product surfaces the verdict; the verifying is owned elsewhere.

GOVERNED_BY Agent-008

Where an autonomous agent acted during the incident, its authority and scope are governed by Agent-008, and the bundle records those governed decisions. The product packages them; it does not perform governance.

Replaceability test

If the signature families or the anchoring chain changed, this would still be Claims Evidence. The evidence-portability workflow and cross-chain-survivability outcome are what it owns. Mechanisms are chosen, not owned.

When to use it

Use Claims Evidence when you need portable, tamper-evident evidence bundles for underwriting or claims adjustment — evidence that must survive handoffs across the carrier, reinsurer, regulator, and litigation chain without re-investigation.

When NOT to use it — use a neighbor instead

To reach an independent verdict on a specific filed or disputed claim, use Cyber Claim Verification. To structurally reduce cyber-claims exposure across a whole book, use Cyber Insurance Claims. For the continuous cyber-insurance monitoring mechanism itself, see HATS.

If you want a mechanism directly

To evaluate the portable-attestation primitive, read H33-74; for the verdict engine, read Verification. This product is the evidence workflow and outcome; those are the building blocks.

Frequently asked questions

Claims Evidence, and how the product composes H33 mechanisms.

What is Claims Evidence and what problem does it solve?

It is a product that produces portable, tamper-evident evidence bundles for cyber-insurance underwriting and claims adjustment, solving the problem that standard logs do not survive the carrier-reinsurer-regulator-litigation chain. It owns the evidence-portability workflow and cross-chain-survivability outcome; it uses H33 mechanisms for the portable attestation, the continuous operational evidence, and the independent verdict rather than reimplementing them. Cryptographic evidence supports underwriting and claims decisions; it does not by itself settle a claim or make an insurer compliant.

Which H33 mechanisms does it use?

It USES H33-74 for the portable post-quantum attestation that carries a bundle across every hop, is MONITORED_BY HATS for the continuous operational evidence of which controls were active, and USES Verification so any party reaches the same independent verdict offline. Agent decisions during an incident are GOVERNED_BY Agent-008. The product composes these; it does not own or redefine them.

Does a verified bundle settle the claim or prove compliance?

No. A verified bundle supports the underwriting or claims decision by proving, independently, what the evidence says. It does not by itself settle a claim or make an insurer or policyholder compliant; the carrier still makes the coverage and settlement decision. The bundle removes disputes over evidence authenticity, not the adjudication itself.

When should I use this versus another product?

Use Claims Evidence for portable evidence bundles for underwriting and the carrier-reinsurer-regulator chain. To verify a specific filed claim, use Cyber Claim Verification. To reduce exposure across a whole book, use Cyber Insurance Claims. For the monitoring mechanism itself, see HATS. To evaluate a mechanism directly, read the H33-74 or Verification hubs.

Next step

See the claim-evidence workflow run on real cyber-insurance data.

View the Evidence Workflow  →