About these stories. Composite scenarios drawn from real failure patterns in industry reports, court records, and customer conversations · not attributed to specific people. Structure here matches the format for named customer case studies · when publication permission lands, the composite label is removed and metrics are populated with the customer's own numbers.

Customer scenarios

Why people switch to H33.

Five situations digital life fails to handle · and what H33 does differently. Each ends with the specific workflow that solves the problem.

Guardian recovery · scenario 1

"I found the hardware wallet. The recovery phrase was gone."

A retired engineer stored a 24-word phrase on a paper card in a home safe six years ago. When the family cleaned out the safe last month, the card was gone. Or moved. Or accidentally shredded with a stack of bank statements. Nobody remembers what happened to it.

The hardware wallet is right there on the desk. It powers on, shows the balance, and asks for the phrase to sign a transaction. Without the phrase, the balance is a photograph of a fortune. Chainalysis estimates that between 3 and 4 million Bitcoin are already stranded like this. Every year adds more.

The moment: The wallet works perfectly. The paper card is what died.
What H33 does differently: With H33's guardian recovery, the seed phrase was never generated. Three-to-five people you trust hold cryptographic attestation credentials. A threshold of them attests that you are you, and the wallet unlocks. Nothing paper. Nothing to lose in a house fire.

Result

  • Wallet access restored in minutes, not months
  • Guardian attestations verifiable on-chain
  • No paper artifact needs to survive to preserve custody

The workflow that solves this

How guardian recovery works Seed phrase vs guardian recovery Identity Recovery capability Recover crypto safely · use case
H33 Vault · currently protected
H33 Vault · currently protected

Digital estate · scenario 2

"My father handled everything. Nobody knew where anything was."

The father was 68, healthy, and had not yet gotten around to writing everything down. He assumed there would be time. He owned Bitcoin, some ETH, three insurance policies, an IRA with a brokerage nobody in the family had heard of, and a hardware wallet in a safe deposit box he alone had authority over.

The adult daughter was named executor. She found the hardware wallet but not the seed phrase. She called the exchange; they froze the account. She called the insurance companies; two of the three required a certified death certificate before they would tell her which policies existed. Three months in, she was still trying to identify which assets were part of the estate.

The moment: The assets exist. The people who inherited them cannot reach them.
What H33 does differently: With H33 in place, this ends differently. Beneficiaries are named cryptographically per asset. Life Validation runs continuously. When it lapses, the estate flow activates automatically: executor authority unlocks, beneficiary allocations transfer, every step signed and audit-logged.

Result

  • Executor receives scoped access within 24 hours of dormancy trigger
  • Beneficiary allocations flow automatically per the cryptographic designation
  • Every distribution reconstructable from the signed audit trail years later

The workflow that solves this

Estate planning for crypto What happens when someone dies with Bitcoin How digital beneficiaries work H33 Estate hub Send inheritance documents · use case
H33 Estates · Life Validation + beneficiaries
H33 Estates · Life Validation + beneficiaries

Authority chain · scenario 3

"The wire was legitimate. Proving it 18 months later was impossible."

A mid-sized manufacturing company. A $4.2 million wire went out eighteen months ago to a legitimate vendor. Now a regulatory examination is asking: prove that Jim, the VP of Finance who has since left the company, actually approved this specific amount, to this specific recipient, at this specific moment.

The SIEM has a session log showing Jim was authenticated. SAP has an entry showing the wire was approved. Neither is cryptographic proof that Jim's authentication and Jim's approval were bound to this particular transaction, at this particular version, under this particular policy. The internal audit team's honest answer is 'we believe so.' The regulator's expected answer is 'demonstrate it.'

The moment: Six weeks of forensic reconstruction. A material weakness disclosure in the annual report. Insurance premiums adjust the following year.
What H33 does differently: With H33, every payment ships with its authority chain: who authorized (Jim's biometric-attested identity), under what policy, with what evidence, what preconditions. The chain is portable. Given the receipt hash alone, the auditor reconstructs the exact decision eighteen months later without asking H33 anything.

Result

  • Regulator receives cryptographic proof · not vendor-log reconstruction
  • Auditor reconstructs the decision independently from the receipt hash
  • No material weakness · no premium adjustment · no forensic engagement

The workflow that solves this

Payment Authorization capability Decision Integrity Infrastructure Try the interactive replayer Try the interactive verifier Protect company finances · job
Approve sign-in · payment $25 to Sarah
Approve sign-in · payment $25 to Sarah

Passwordless migration · scenario 4

"The company banned passwords. We still needed people to get into everything."

A software company, 340 employees. In late 2022 they used LastPass Business. When the vault-blob breach was disclosed and offline brute-force became plausible, the security team spent four weeks rotating credentials, chasing employees whose browsers had cached the old passwords, and answering the same question from the board: 'how do we prevent this next time?'

The correct answer is not another password manager. Another vault is another single point of compromise for the same failure class. The correct answer is that sites verify a cryptographic signature. But rolling that out across 340 people, providing recovery when devices die, and handling the last 15% of sites that don't support WebAuthn yet is a real deployment.

The moment: The realization that no incremental fix to password managers addresses the incident class.
What H33 does differently: With H33 as the identity layer, passkeys are owned by the person, recoverable through guardians, and continue signing session actions after login. For the sites that don't yet support WebAuthn, H33-Key holds credentials with authority-based invocation. When a site is compromised, no shared secret about that user was there to leak.

Result

  • 340 employees migrated in under a month · no master-password rotation crisis
  • Recovery load moved from IT ticket queue to guardian attestation flow
  • Nothing site-side to leak in the next breach

The workflow that solves this

Passwordless Authentication Password manager vs self-custody H33 vs 1Password H33 vs LastPass Replace password managers · use case
Approve sign-in · biometric · location bound
Approve sign-in · biometric · location bound

Identity layer · scenario 5

"Passkeys worked. The rest of authentication didn't."

A regional bank's CISO in 2025. Passkeys were finally viable across enough of the customer-facing site set that the bank could commit to a passwordless roadmap. The engineering team started implementing WebAuthn against a handful of relying parties. Six months in, the practical questions kept arriving.

What happens when a customer loses their phone? What happens when they sign a large wire from a new device? How does the bank identify the customer to a call-center agent when there is no password to verify? None of these questions have crisp answers inside a pure WebAuthn deployment. WebAuthn handles the initial credential. It does not handle recovery, cross-device continuity, or the graceful degradation to human channels.

The moment: Passwordless without an identity layer is a partial architecture. The failure modes are all in the parts WebAuthn does not cover.
What H33 does differently: With H33 as the identity layer, passkeys are H33-managed but customer-owned. Guardian recovery handles device loss. Continuous session signing handles the 'is this still the customer' question. The call-center agent verifies identity by requesting a biometric-attested signed challenge — not by asking for a password reset.

Result

  • Passkey adoption reached the target of the roadmap in the projected window
  • Guardian recovery replaced call-center identity verification for lost-device flow
  • Continuous signing eliminated the step-up MFA prompt cadence customers complained about

The workflow that solves this

What is passwordless authentication Passkeys vs password managers Okta vs Passkeys WebAuthn Integration H33 Identity hub
Trusted devices · places · continuous authentication
Trusted devices · places · continuous authentication

Trust status

Runs today. Honest about what's next.

We publish what's shipped and what's coming — the same list on every page.

Runs today

  • SOC 2 Type II Certified
  • ISO/IEC 27001 Certified
  • Vault workflows running in production
  • Cryptographic receipts emitted per action
  • Immutable audit trail · Object-Locked
  • Auth1 · Wallet · Document · Audit APIs
  • Post-quantum primitives (Dilithium + Kyber)
  • Benchmark v12 · 2,293,766 auth/sec

Coming next

  • Public /verify// receipt viewer
  • Public /replay// decision viewer
  • docs.h33.you developer documentation
  • Payment Requests + Rewards adapters

One scenario away from switching.

Every problem above is solvable in the Vault today. Sixty seconds to first login.

Start free See the proof surface