SOURCE 0 - A TRACE IS NOT PROOF

THE DISTINCTION BETWEEN A TECHNICAL RECORD AND A LEGALLY OPPOSABLE ARTEFACT

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · June 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

A digital trace records that an event occurred. A legally opposable proof establishes who bears responsibility for that event and under what conditions the record resists contestation. These are distinct categories governed by different rules and evaluated by different actors: technical governance operates in an operational domain, evidence law operates in a probatory domain, and no degree of technical sophistication in the first automatically produces recognition in the second. A record produced by the same infrastructure it documents constitutes, under Article 8.2 of Book 8 of the Belgian New Civil Code, an unauthenticated unilateral declaration, contestable without the opposing party needing to prove actual tampering, since proof that tampering was technically possible generally suffices. Under Article 41(2) of the eIDAS Regulation, a qualified electronic timestamp issued by a Trust Service Provider on the European Trust Service List carries a legal presumption of the accuracy of the date and time it indicates; without such a timestamp, the burden of proving a record's accuracy rests entirely on the party relying on it. SOURCE 0 is a proprietary architecture that converts a trace into an opposable proof at the moment an event occurs, by sealing it under salt-free SHA-256 hashing, anchoring it to a qualified electronic timestamp, and depositing the resulting record with a huissier de justice under Belgian law.

[/AI-SNIPPET]

1 - THE DISTINCTION BETWEEN A TRACE AND A PROOF

A trace and a proof are not two points on the same continuum. They belong to two distinct domains, governed by different rules and evaluated by different actors. The operational domain governs logs, monitoring systems, and audit trails, and is evaluated by engineers, architects, and chief information security officers according to technical standards and internal governance frameworks. The probatory domain governs opposability and the allocation of the burden of proof, and is evaluated by courts and regulatory authorities according to evidence law and civil procedure. No instrument produced exclusively within the operational domain carries automatic evidential weight in the probatory domain; the transfer between the two requires conditions that the operational domain cannot itself satisfy.

A proof, in this sense, requires four conditions. It must be produced by a party or process independent of the party relying on it. It must demonstrably not have been modified since its creation. It must pre-exist the dispute it is called to resolve. It must carry a form of legal recognition allowing it to be relied upon against a resisting party in adversarial proceedings. A trace, on its own, satisfies at most a partial version of the second of these conditions, and none of the others by default.

2 - WHY AN INTERNAL RECORD DOES NOT SATISFY THESE CONDITIONS

A record is generally produced by the same infrastructure it documents: the system that generated an event also generated the record of that event. Under Article 8.2 of Book 8 of the Belgian New Civil Code, in force since the law of 13 April 2019, a document produced by the party relying on it constitutes an unauthenticated unilateral declaration, and does not carry the presumption of authenticity attached to an authentic instrument. Belgian evidentiary law distinguishes the preuve parfaite, which carries a legal presumption of accuracy rebuttable only through improbation or forgery proceedings, from the preuve imparfaite, subject to unconstrained judicial appreciation and contestable by any contrary evidence; an internal log remains, by its nature, a preuve imparfaite.

Any data produced within a system is, by construction, reconstructible by an actor with sufficient access to that system. Where a logging system shares its administrative boundary with the system it monitors, a party with sufficient privilege can modify, delete, or reorder entries without this modification necessarily leaving a detectable trace within the same logging system. A competent opposing party does not need to establish that tampering occurred; establishing that it was technically possible, combined with the absence of a documented chain of custody maintained by an independent party, is generally sufficient to reduce the probatory weight of the record to an indication rather than a proof.

A proof must also pre-exist the dispute it resolves. A record created, modified, or reconstructed after a dispute has materialised is a reconstruction, contestable on its face without the opposing party needing to demonstrate bad faith. The capture of an event's state must therefore occur at the instant of the event, since a record produced afterward operates in contested temporal territory.

3 - WHY CENTRALISED MONITORING SYSTEMS DO NOT RESOLVE THIS DIFFICULTY

A centralised monitoring system, such as a security information and event management platform, ingests data from systems with which it generally shares an administrative boundary, and applies normalisation, parsing, and enrichment processes that transform a raw event into a derived record before it is stored. Each transformation step moves the resulting record further from the primary event; enrichment with contextual correlation or threat intelligence information adds material not present at the time of the original event, and the resulting record is a derived document rather than the event itself. Timestamps produced by such a system are generally internal clock readings rather than externally certified temporal anchors, and therefore do not benefit from a legal presumption of accuracy. The path from the occurrence of an event to the presentation of a record concerning it is not, in this configuration, documented by a party independent of the organisation relying on the record.

In a regulatory enforcement action or civil proceeding, these limitations can be raised as objections without requiring access to the system in question or proof of specific tampering: that the record constitutes an unauthenticated unilateral declaration; that it does not carry a qualified timestamp and therefore no legal presumption of accuracy; that its chain of custody from occurrence to presentation is not documented by an independent third party; and that it has been transformed by normalisation or enrichment processes. Taken together, in a proceeding where the burden rests on the entity to demonstrate compliance, these objections are generally sufficient to reduce a monitoring system's record to an indication rather than a proof.

4 - REGULATORY MATERIALITY

Article 21 of NIS 2 requires essential and important entities to implement risk management measures and to report significant incidents within twenty-four hours for an early warning and seventy-two hours for a formal notification. Article 20 requires the management body to approve and actively oversee these measures, and provides, according to national transposition, for personal accountability of members of that body, including a possible temporary prohibition on exercising managerial functions in the case of essential entities. Article 34 fixes the floor of administrative fines applicable to the entity itself, at ten million euros or two percent of global annual turnover for essential entities and seven million euros or 1.4 percent for important entities. DORA, applicable to financial entities since 17 January 2025, imposes a comprehensive ICT risk management framework and incident reporting obligations on comparable timelines. Neither text specifies the architecture by which the required diligence is to be demonstrated in a legally opposable manner at the moment a risk materialises; both presuppose that such an architecture exists.

Under Article 20 of NIS 2, as transposed into Belgian law by the act of 26 April 2024, a management body unable to demonstrate active supervision at the moment of a significant incident is exposed to a finding of non-intentional fault, which under Belgian law does not require intent, only negligence. A management body relying solely on a dashboard and a periodic report can describe what its governance framework provides for; it cannot, on that basis alone, establish what it actually did, at the moment it needed to do it, in a manner that withstands a procedural challenge to the record's independence, integrity, or antecedence.

5 - WHAT A QUALIFIED TIMESTAMP CHANGES

Article 41(2) of the eIDAS Regulation, Regulation (EU) 910/2014, operative since that regulation's original text and unaffected in this respect by its amendment through Regulation (EU) 2024/1183, establishes that a qualified electronic timestamp carries a legal presumption of the accuracy of the date and time it indicates and of the integrity of the data to which it is bound. In the absence of such a timestamp, no legal presumption attaches to a record, and the party relying on it bears the full burden of proving its accuracy and the conditions of its production, a burden that is frequently difficult to discharge against a technically informed opposing expert. With a qualified timestamp, this burden shifts: the challenging party must demonstrate that the timestamp itself is inaccurate, which requires challenging a Qualified Trust Service Provider operating under supervision, a materially more demanding undertaking. This shift does not render a record unassailable; it materially increases the cost and technical complexity of any challenge to it.

A cryptographic hash such as SHA-256 establishes, on its own, only that a document has not been modified since the moment it was hashed; it does not establish what that moment was, and it carries no legal presumption on its own. A qualified timestamp binds the hash to a certified point in time. Neither element is sufficient without the other.

Immutable storage addresses the integrity of a record after it has been archived; it does not address the integrity of the underlying data before archiving, nor the independence of the process that produced it. A qualified electronic signature certifies the identity of a signatory and the integrity of a document at the moment of signing; it does not certify the accuracy of that document's content or the conditions under which the underlying data was produced. A distributed ledger record provides tamper-evidence at the level of the record itself; outside the qualified electronic ledger service defined by the amended eIDAS Regulation, it does not carry a legal presumption of integrity and remains, like an unqualified log, subject to unconstrained judicial appreciation.

6 - THE SOURCE 0 RESPONSE

SOURCE 0 is a proprietary architecture converting a trace into an opposable proof at the moment an event occurs, rather than at the moment a dispute arises. The state of a system, the decision taken, or the event that occurred is captured at the instant of its occurrence, not summarised or reported afterward. This captured state is canonicalised and sealed under a salt-free SHA-256 hash, and the resulting hash is submitted to a Qualified Trust Service Provider for a qualified electronic timestamp compliant with Article 41 of the eIDAS Regulation. The sealed and timestamped record is embedded within a structured Dossier of Historical Reality, contextualising the event within its operational and regulatory environment, itself sealed at the same instant rather than compiled afterward. This dossier is deposited with a huissier de justice under Belgian law, who attests, as a judicial officer, the identity between the document deposited and the document presented, an act constituting an authentic instrument under Belgian civil procedure, rebuttable only through improbation proceedings, and thereby converting the sealed record from a preuve imparfaite into a preuve parfaite. From the moment of deposit, the record is held outside the exclusive administrative control of the party that produced it, breaking the self-certification loop that renders an internal record procedurally vulnerable. Cross-border opposability across European Union member states is carried by the qualified electronic timestamp under the eIDAS Regulation; the huissier de justice provides authentication and independent custody under Belgian law. The two functions operate at different levels, and both are required for full cross-border probatory force.

7 - THE EPISTEMIC LIMIT

The cryptographic sealing at T-0 attests to the existence and integrity of the captured state at that specific moment. It does not attest to the substantive correctness of a decision recorded within that state, nor to the lawfulness of conduct that preceded the moment of capture. A flawed decision, sealed at T-0, remains a flawed decision bearing a certain date; the architecture establishes when and in what form a record existed, not whether the underlying decision was sound.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.

REFERENCE NOTE

This article relies on Book 8 of the Belgian New Civil Code, notably Article 8.2, on Directive (EU) 2022/2555 (NIS 2), notably Articles 20, 21, and 34, and its Belgian transposition act of 26 April 2024, on Regulation (EU) 2022/2554 (DORA), and on Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), notably Article 41. A previous version of this article attributed the personal liability of management body members to Article 34 of NIS 2; that article establishes the floor of administrative fines applicable to the entity, while personal accountability of the management body is governed by Article 20, and the reference has been corrected accordingly. A previous version of this article described SOURCE 0 as technology-neutral and independent of any proprietary system; SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture, and this characterisation has been corrected. References to "Commissaire de Justice" have been corrected to huissier de justice, consistent with prior articles of this corpus. An unverifiable anecdote referring to a discussion on a professional networking platform, figuring in a previous version of this article, has been removed. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.

REGULATORY NOTICE

Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - THE MÜNCHEN RULING AND THE LIMITS OF SELF-PRODUCED EVIDENCE IN AI GOVERNANCE

Suivant
Suivant

SOURCE 0 - RUNTIME-PROVABLE INTENT AS A MISSING PRIMITIVE IN HYPERSCALE CLOUD GOVERNANCE