Or you trust one user of a company but not another. Many services give each org a separate subdomain. If they support basic auth for whatever reason then just going to the other organisation will give them a hash of your credentials.
To assume that a user trusts the subdomain because she trusts the domain, is something I find insane.