Claims Evidence
Tamper-evident, portable, verifiable across the carrier-reinsurer-regulator chain.
This evidence layer powers HATS, H33’s cyber-insurance governance product — continuous, cryptographic proof of which controls were active and how an incident was handled, so a claim is backed by verifiable evidence instead of affidavits.
Cyber insurance claims hinge on what the insured can prove about an incident — when it started, who detected it, what controls were active, what response was triggered. Standard logs are insufficient: they can be edited, lost in vendor changes, or contradicted across systems. H33 produces tamper-evident claims evidence that travels across the carrier, reinsurer, regulator, and litigation chain without losing fidelity at any hop.
The cyber claims evidence problem
Cyber insurance claims have a specific evidentiary structure. The claim depends on facts about an incident: timeline, scope, controls, response. Each downstream party — carrier, reinsurer, regulator, court — has progressively less trust in the insured's internal records. Standard cyber logs do not survive this chain well: the insured's MFA logs can be edited; the SIEM may have been compromised in the incident; the identity provider may have changed vendors; the endpoint detection vendor may have been acquired; the cloud provider may have rotated logs out of retention. By the time the claim reaches the regulator or the courtroom, the evidentiary trail may be incomplete or unverifiable.
What H33 captures at incident time
H33 evidence bundles are generated at the moments that matter: Detection — when an intrusion detection or behavioral system identifies a candidate incident, a bundle captures the detection's basis, the model or rule that fired, the data that triggered it, and the response action that followed. Response — when the IR team takes an action, a bundle captures the action's authority, the policy that justified it, the system state, and the evidence considered. Control assessment — when periodic control assessment runs (MFA usage validation, EDR coverage, patch level), a bundle captures the basis and result. Notification — when timelines start, a bundle captures who knew what, when they knew it, and what triggered the timeline. Bundles are signed by three independent post-quantum algorithm families. They can be anchored to a public chain for time binding. They are stored under the insured's control.
How bundles survive the claims chain
Carrier review. The insured provides bundles supporting the claim. The carrier runs the open-source verifier offline. Verification confirms the bundles are unmodified and the timeline is consistent. Reinsurance handoff. The carrier passes the relevant bundles to the reinsurer. The reinsurer runs the same verifier. No re-investigation required. Regulatory review. A breach notification triggers regulatory scrutiny. The insured provides the bundles. The regulator verifies them. The verification result is binding because the open-source verifier is reproducible. Litigation discovery. A third party brings suit alleging negligence. The insured provides the bundles. Opposing counsel runs the verifier. Both sides agree on what the verifier returns.
The reinsurance modeling angle
Reinsurers consistently report that cyber loss data is insufficient for actuarial modeling. The data is sparse, inconsistent across carriers, hard to verify, and contaminated by selection bias. H33 evidence bundles improve the data substrate. Loss events documented with portable, verifiable evidence are comparable across carriers (the bundle format is standardized), verifiable without re-investigation, resistant to selection bias (generated at incident time, not after-the-fact), time-bound (the anchor proves when the bundle was created), and stable across retention windows.
Use cases
Ransomware claim. An insured organization is hit by ransomware. The H33 bundles document the detection, the timeline of encryption, the response actions, and the eventual restoration. The carrier evaluates offline. The reinsurer confirms the basis. The claim is settled without dispute over evidence authenticity. Business email compromise claim. An employee approves a fraudulent wire. The bundles document the MFA state, the email gateway controls, the policy governing wire approval, and the deviation from policy. Insider data theft claim. The bundles document the user's access scope, the data accessed, the DLP signals, and the access timeline.
Common questions
Does this require changing my incident response process?
No. H33 evidence generation runs in parallel with your existing IR tooling. Bundles are produced as a byproduct of the detection, response, and assessment events that already happen.
Can my carrier accept H33 bundles today?
The bundles are open standard, canonical JSON, with an open-source verifier. Any carrier can accept them. Adoption is a contractual matter, not a technical one.
Does this work with my existing SIEM and SOAR?
Yes. The bundle-generation integration is API-based.
What happens if my SIEM is compromised in the incident?
The bundles produced before the compromise are unaffected. The bundles are signed at generation time and stored separately from the SIEM.
Are the bundles privacy-preserving?
Bundles stay under your control. Only the 32-byte commitment goes on-chain when anchored.
Related: Cyber Claim Verification · AI Audit Trails · H33 vs Traditional Audit Logs · Avalanche Evidence Anchoring
H33 Products · Claims Evidence
What this product is
Definition. Claims Evidence is a product that produces portable, tamper-evident evidence bundles for cyber-insurance underwriting and claims adjustment — bundles that travel across the carrier, reinsurer, regulator, and litigation chain without losing fidelity at any hop. It owns the evidence-portability workflow and the cross-chain-survivability outcome. It does not own, redefine, or reimplement the attestation, monitoring, or verification it relies on; it composes them.
Why this exists. Each downstream party trusts the insured's internal records less than the last, and standard logs do not survive that chain. This product exists to give a claim a verifiable evidentiary spine for the specific job of underwriting and adjustment. The evidence supports those decisions; it does not by itself settle a claim or make an insurer compliant.
The product boundary. Claims Evidence owns the cyber-insurance-claims evidence workflow and outcome. It uses H33 mechanisms for evidence, monitoring, and verification; it does not redefine or own those mechanisms.
H33-74 supplies the portable post-quantum attestation and receipt so a bundle stays verifiable at every hop; only the 32-byte commitment goes on-chain when anchored. The product commits and forwards the fact; it does not produce the attestation primitive.
The continuous operational evidence cyber insurance relies on — which controls were active and how an incident was handled — comes from HATS. The product is monitored by it and packages what it recorded into bundles; it does not perform the monitoring. HATS is the cyber-insurance mechanism; this product uses it.
Verification lets any party — carrier, reinsurer, regulator, opposing counsel — reach the same independent verdict on a bundle offline with the open-source verifier. The product surfaces the verdict; the verifying is owned elsewhere.
Where an autonomous agent acted during the incident, its authority and scope are governed by Agent-008, and the bundle records those governed decisions. The product packages them; it does not perform governance.
If the signature families or the anchoring chain changed, this would still be Claims Evidence. The evidence-portability workflow and cross-chain-survivability outcome are what it owns. Mechanisms are chosen, not owned.
When to use it
Use Claims Evidence when you need portable, tamper-evident evidence bundles for underwriting or claims adjustment — evidence that must survive handoffs across the carrier, reinsurer, regulator, and litigation chain without re-investigation.
To reach an independent verdict on a specific filed or disputed claim, use Cyber Claim Verification. To structurally reduce cyber-claims exposure across a whole book, use Cyber Insurance Claims. For the continuous cyber-insurance monitoring mechanism itself, see HATS.
To evaluate the portable-attestation primitive, read H33-74; for the verdict engine, read Verification. This product is the evidence workflow and outcome; those are the building blocks.
Frequently asked questions
Claims Evidence, and how the product composes H33 mechanisms.
What is Claims Evidence and what problem does it solve?
It is a product that produces portable, tamper-evident evidence bundles for cyber-insurance underwriting and claims adjustment, solving the problem that standard logs do not survive the carrier-reinsurer-regulator-litigation chain. It owns the evidence-portability workflow and cross-chain-survivability outcome; it uses H33 mechanisms for the portable attestation, the continuous operational evidence, and the independent verdict rather than reimplementing them. Cryptographic evidence supports underwriting and claims decisions; it does not by itself settle a claim or make an insurer compliant.
Which H33 mechanisms does it use?
It USES H33-74 for the portable post-quantum attestation that carries a bundle across every hop, is MONITORED_BY HATS for the continuous operational evidence of which controls were active, and USES Verification so any party reaches the same independent verdict offline. Agent decisions during an incident are GOVERNED_BY Agent-008. The product composes these; it does not own or redefine them.
Does a verified bundle settle the claim or prove compliance?
No. A verified bundle supports the underwriting or claims decision by proving, independently, what the evidence says. It does not by itself settle a claim or make an insurer or policyholder compliant; the carrier still makes the coverage and settlement decision. The bundle removes disputes over evidence authenticity, not the adjudication itself.
When should I use this versus another product?
Use Claims Evidence for portable evidence bundles for underwriting and the carrier-reinsurer-regulator chain. To verify a specific filed claim, use Cyber Claim Verification. To reduce exposure across a whole book, use Cyber Insurance Claims. For the monitoring mechanism itself, see HATS. To evaluate a mechanism directly, read the H33-74 or Verification hubs.