H33-Recovery · Platform & Authority

Your backups are intact. That is not the same as safe to restore.

After a compromise, every copy still passes its checksum and every restore point is still readable. H33-Recovery answers the question your backup product does not ask: which of these artifacts has earned the right to become trusted production state again — and by what evidence?

The demonstration runs the real engines compiled to WebAssembly. Every classification, boundary and refusal is recomputed in your browser — including when you attack it.

The category

Two systems, one backup, two correct answers

Both answers below are about the same artifact, and both are right. They answer different questions, and only one of them governs whether production may consume it.

Traditional recovery asks

Can we restore this backup?

  • checksum valid
  • retention policy satisfied
  • anomaly scan passed
  • object readable

H33-Recovery asks

Can this backup become trusted again?

  • integrity established
  • identity bound by content, not path
  • lineage resolves to a pre-incident anchor
  • authority transition not proven

Integrity is not authority.
An artifact can be perfect and still not be permitted.

The state model

Four states, because two are not enough

Security tooling trains people into a binary: green or red. Enterprise recovery has a third condition that loses more estates than the second, and H33-Recovery names it rather than colouring it green.

ADMISSIBLE

Positive evidence supports admission. The artifact falls inside the interval where trust was positively evidenced.

UNCERTAIN

A known object carrying evidence-bounded uncertainty. Not a failure — no evidence places it inside or outside the compromise.

REFUSED

Positive evidence establishes contamination or invalid authority. The artifact may be intact; its authority is not.

UNKNOWN

Insufficient identity to classify at all. Not a degree of risk — an absence of the basis for judging risk. Absence of proof is not proof of safety.

The trust ladder

Nine rungs, and a seam no engine crosses

Nothing enters above Unknown. Nothing reaches production eligibility without an explicit human promotion decision that the engine cannot manufacture. An agent may discover, analyse and recommend. It may not widen its own authority.

0Unknownasserts nothing
1Discoveredobserved to exist; content commitment recorded
2Identifiedbound to a known identity — not by filename
3ProvenancePartialsome ancestry established; the chain has gaps
4Analyzedstructure, cryptographic state and dependencies characterised
5RecoveryCandidateproposed for recovery — still not trusted
6Validatedsurvived validation in an isolated environment
✗ hard authority seam — a human recovery authority acts here
7AuthorizedForReintroductiona human authority has authorised reintroduction
8ProductionBoundbound into the recovered estate under a new baseline

Compiled invariants

Five rules that cannot be configured off

Not policy, not settings, not a compliance profile. These are compiled into the engine, and no customer configuration, methodology or runtime flag can disable them.

EVIDENCE_REQUIRED_FOR_PROMOTIONUnknown data cannot become trusted without evidence.
PATH_IS_NOT_IDENTITYA filename or path does not establish identity.
AUTHORITY_CANNOT_SELF_WIDENAn agent cannot widen its own authority.
EVIDENCE_IS_APPEND_ONLYOriginal evidence cannot be destroyed.
ACTION_REQUIRES_AUTHORITYRecovery actions require explicit authority.

Temporal boundary engine

It will not tell you when the attack began

That question usually has no evidenced answer, and a recovery system that invents one is worse than a recovery system that admits it does not know. H33-Recovery reconstructs an interval instead, and grades every clock by how much authority it is allowed to have over that interval.

trusted ≤ 08:44   |   uncertain 08:44 → 09:37   |   compromised ≥ 09:37   |   contained 10:16
Attestedmay narrowbounded, causally ordered, replay- and backdate-resistant — the PQ-Time class of source
ThirdPartyImmutablemay narrowprovider control-plane log, object-lock metadata, certificate transparency — not ours to forge, not theirs to revise
TrustedHostmay narrowa host we operate, outside the blast radius at the observed time
AttackerReachablemay never narrowusable as a signal, never as a bound

That last line is the engine's spine. An attacker-reachable clock can widen uncertainty; it can never narrow it. It is why a forged clean attestation, a claim that the compromise started later, an adversary declaring its own containment, and a backdated record all fail to move the boundary — individually or together.

The transition protocol

Evidence sufficiency and authority sufficiency are different failures

A proposed change of standing is a first-class object carrying the requirements it must discharge, each independently resolved. That turns “what evidence is sufficient?” from positioning language into something a machine evaluates — and separates two outcomes that must never read the same.

transition   snapshot-0842  AuthorizedForReintroduction

  identity_binding        SATISFIED
  integrity               SATISFIED
  temporal_admissibility  SATISFIED
  lineage_resolution      SATISFIED
  key_exposure_analysis   SATISFIED
  isolated_validation     SATISFIED
  human_authority         MISSING

  EVIDENCE SUFFICIENT · AUTHORITY INSUFFICIENT

Evidence sufficient, authority insufficient means the artifact is fine and a human should now be asked. Evidence insufficient means asking a human would be premature — you would be escalating a decision nobody can yet make. Conflating them is how a recovery programme burns its incident bridge on questions that have no answer yet.

Where a requirement is missing, the engine also carries what would resolve it — immutable provider event, object-lock metadata, a PQ-Time record — so an uncertain candidate comes with the shortest path to becoming decidable rather than an instruction to go and think about it.

Negative evidence

A refuted claim is not a missing one

Recovery tooling accumulates reasons to trust something. H33-Recovery also models evidence that destroys a previously plausible reading, because an absence and a refutation are not the same finding and must not produce the same response.

UNKNOWNno evidence establishes the architecture
UNVERIFIEDdeclared arm64; nothing measured
CONTRADICTEDdeclared arm64; measured x86-64 — both values known

A contradiction outranks every gap. Reporting “three requirements missing” beside a proven falsehood invites someone to go and collect the three. And a refuted transition offers no resolution path at all, because there is no evidence that repairs a contradiction — offering a list would imply otherwise.

The demonstration

Operate it against a ransomware incident

A governed terminal session against a previously attested estate. You issue every command; the engine answers. Nothing advances on a timer, and every command declares the state it requires, refuses if that state is absent, and leaves a chained evidence record behind.

operator@northwind:~$ h33 mission create --purpose recovery --agent agent-008
operator@northwind:~$ agent-008 reconstruct --boundary
operator@northwind:~$ agent-008 assess --recovery-points
operator@northwind:~$ h33 challenge --inject attestation-clean --source attacker-reachable
  boundary       trusted ≤ 08:44 · compromised ≥ 09:37
  UNCHANGED

Synthetic incident estate. The engines are real and compute live; the incident data is simulated input, and the demonstration says so on every surface that uses it.

Honest boundaries

What is built, and what is not

Every claim on this page corresponds to implemented behaviour or is marked otherwise. The parts that do not exist are named as unavailable rather than pending, because a missing signer is not a queued approval and must never be mistaken for one.

Trust ladder & invariantsimplementedrecovery-core
Temporal boundary reconstructionimplementedrecovery-temporal
Lineage & authority graphimplementedrecovery-graph
Key exposure intelligenceimplementedrecovery-keyintel
Transition & requirement graphimplementedrecovery-transition
Governed agent contractimplementedrecovery-agent
H33-74 anchoring pathnot integratedevidence objects are H33-74-shaped; anchoring is not wired
Post-quantum authorisationnot integratedno signer is wired into the engine
Governed executornot integratednothing in this system restores data

Composition

What H33-Recovery uses

Recovery composes other admitted H33 products rather than absorbing them. Each remains its own product with its own authority; the recovery engine consumes them.

The dependency runs one way and it matters: an estate attested before an incident has a baseline to reconstruct against. An estate with no prior attestation returns UNKNOWN for everything, which is an honest answer and a useless one.

The definition

H33-Recovery proves the chain by which an untrusted or uncertain artifact is — or is not — permitted to become trusted production state.

It does not decide what gets restored. It determines what evidence is sufficient to present a recovery decision, and preserves the boundary where human authority must act. That is an architectural property rather than a detection feature, which is why backup, EDR, SIEM and incident-response tooling do not produce it as a by-product.