SOURCE 0 - CERTIFIED [EN]

Evidentiary governance attestation, grounded in an independent capture architecture, not reconstructed after the fact.

[AI-SNIPPET]

SOURCE 0 CERTIFIED is an evidentiary governance attestation issued exclusively by Jean-François ELSEN, holder of the registered SOURCE 0 mark, BOIP/OBPI No. 1548293, Benelux; it does not constitute an independent third-party certification. It certifies that the SOURCE 0 process was followed at instant T-0, not the factual accuracy of the world after T-0. The evidentiary independence of the architecture is established under the structural condition S ∩ C = ∅: the operational system has no unilateral capacity, whether direct or delegated, to modify, delete, delay or render unverifiable the content or the dating of what the capture layer seals; no system can serve as proof of its own compliance. In certain AI systems, complete reconstruction of the relevant technical state may no longer be possible after execution. SOURCE 0 CERTIFIED captures and seals, at T-0, a determined state prior to the event it is intended to document, producing an evidentiary artefact structured to establish the existence, integrity and anteriority of the representation thus captured; the effects of presumption, date certaine or opposability attaching to it are those which applicable law expressly attaches to that instrument. The attestation refers to underlying Historical Reality Dossiers structured for sealed deposit or record before a Belgian huissier de justice. This deposit or record documents the operations the huissier has personally carried out or witnessed; the effects of date certaine under Book 8 of the new Belgian Civil Code, and the scope of the qualified timestamp under the Belgian law of 21 July 2016 transposing eIDAS, remain governed by those texts, within the limits they set. Legal framework: AI Act, Articles 10, 11, 12, 14, 26 and 99; agentic AI systems under the same AI Act provisions; DORA, Article 17(2) and 17(3); NIS 2, Article 21(2)(h); eIDAS 2, Regulation (EU) 2024/1183; the Payment Services Regulation (PSR), Articles 55 and 83; anti-money-laundering governance under the AMLR; the Belgian law of 21 July 2016 transposing eIDAS, and Book 8 of the new Belgian Civil Code on date certaine. Activation is reserved to the General Counsel, CCO, CIO, CFO, or a mandated legal counsel. No third party may issue, replicate, or represent this attestation without the express written mandate of the mark holder.

[/AI-SNIPPET]

EXECUTIVE SUMMARY

Relationship to the Ontology and the Doctrine. SOURCE 0 CERTIFIED applies the categories, axioms and limits fixed by the SOURCE 0 - The Ontology of Proof page, and their canonical implementation set out in the SOURCE 0 Doctrine page. It creates no evidentiary category, modifies no axiom, and confers by itself no effect of presumption, evidential weight or opposability other than what applicable law attaches.

Organisations subject to the AI Act, agentic AI governance, DORA, NIS 2, the PSR and the AMLR may need to demonstrate, depending on the applicable regime and the circumstances, the diligence exercised at the time a decision or measure was required. SOURCE 0 CERTIFIED is an evidentiary governance attestation, filed under the name SOURCE 0, BOIP/OBPI No. 1548293, on 6 May 2026, providing an antecedent, independent element capable of contributing to that demonstration; it does not by itself constitute a requirement imposed by the AI Act, DORA, NIS 2, the PSR or the AMLR.

It is neither a compliance checklist, nor an internal audit report, nor a certification issued by a hyperscaler, a Big Four firm, or a standards body; nor does it constitute an independent third-party certification. Its evidentiary strength derives from three conditions: architectural independence under S ∩ C = ∅, a condition developed in full in the SOURCE 0 Doctrine; cryptographic sealing at T-0 through unsalted SHA-256 and dual-QTSP RFC 3161 qualified timestamping; and sealed deposit or record before a Belgian huissier de justice, documenting the operations he has personally carried out or witnessed. The effects of date certaine attaching to this instrument, under Book 8 of the new Belgian Civil Code, are those which that law expressly attaches to it.

The regimes of personal liability of governing bodies under NIS 2 and DORA arise from the texts themselves and their national transposition; SOURCE 0 CERTIFIED alters neither their scope nor their conditions. It provides a contemporaneous evidentiary element that governing bodies may, depending on the circumstances, draw upon in demonstrating their diligence.

WHAT SOURCE 0 CERTIFIED IS

SOURCE 0 CERTIFIED is an evidentiary governance attestation, grounded in a capture architecture independent of the documented system, issued by Jean-François ELSEN, Senior Forensic Auditor and holder of the registered SOURCE 0 mark, BOIP/OBPI No. 1548293. It certifies that an organisation implemented, at T-0, the SOURCE 0 process to capture and cryptographically seal a determined representation of the elements relevant to a governance decision or conduct, structured for evidentiary use before Belgian courts and before EU regulators under the AI Act, agentic AI governance, DORA, NIS 2, eIDAS 2, the PSR and the AMLR.

WHAT THE ATTESTATION CERTIFIES AND WHAT IT DOES NOT CERTIFY

The attestation certifies that the SOURCE 0 process was followed: the integrity of the capture process and the contemporaneous fixation of the data relevant to the decision at T-0. It does not certify the factual accuracy of the world as it evolves after T-0, nor substantive diligence itself. This epistemic limit is not a restriction; it is the condition for the evidentiary strength of the attestation. Where the applicable regime requires proof of diligence, of a result, of a notification or of substantive compliance, the evidentiary artefact produced may, where relevant, constitute an antecedent, independent element of that demonstration; SOURCE 0 CERTIFIED does not substitute itself for any of these standards.

The independence condition is structural: the capture layer has no unilateral capacity, whether direct or delegated, to modify, delete, delay or render unverifiable the content or the dating of what it seals. It operates on infrastructure and logic distinct from the certified entity's own systems. The audited system cannot serve as proof of its own compliance. The underlying technical mechanism is detailed on the Pre-Execution Evidentiary Architecture page.

THE EVIDENTIARY ARTEFACT

Upon issuance of the attestation, a SOURCE 0 CERTIFIED document is delivered, referring to the underlying Historical Reality Dossiers, sealed and deposited with or recorded by a Belgian huissier de justice. This deposit or record documents the operations the huissier has personally carried out or witnessed and the elements submitted or presented to him; the effects of date certaine, presumption, evidential weight or opposability depend on the conditions and limits which applicable law — in particular Book 8 of the new Belgian Civil Code and the Belgian law of 21 July 2016 transposing eIDAS — respectively attaches to these instruments. This artefact constitutes documentary evidence of the representation captured at T-0, the scope and weight of which in a given proceeding remain subject to the assessment of applicable law and the authority seized of the matter.

REGULATORY TRIGGERS

Article 21(2)(h) of NIS 2 imposes obligations relating to the use of cryptography on operators of essential and important entities. The liability of governing bodies under NIS 2 arises from the text itself — administrative liability under the directive, and criminal liability wherever national transposition provides for it; a sealed, independently verified record may constitute a relevant element in demonstrating the diligence exercised.

Article 17 of DORA imposes the recording, monitoring and logging of ICT-related incidents. Neither obligation is satisfied by a system that records its own results without external attestation of evidentiary governance.

Articles 10, 11, 12 and 26 of the AI Act impose obligations of data governance, technical documentation, logging and log retention on operators of high-risk AI systems, exposing non-compliant organisations to penalties of up to fifteen million euros or three percent of annual global turnover under Article 99. The higher tier of thirty-five million euros or seven percent applies exclusively to breaches of the prohibited practices set out in Article 5 of the AI Act, not to the high-risk system obligations referred to above. For agentic systems, the Article 14 requirement that human oversight be proportionate to the system's autonomy specifies neither how that autonomy is measured, nor how to prove, after an incident, that the oversight exercised matched the system's actual autonomy at the time of the action.

Article 55 of the PSR excludes the absolute evidentiary value of strong customer authentication and requires the provider to invite the payer to state its case before concluding fraud or gross negligence. Article 83 imposes an obligation of pre-execution transaction monitoring, with automatic reimbursement of the payer absent proof that such monitoring took place. Both provisions impose a substantive obligation without fixing the evidentiary regime for their own implementation.

Under the anti-money-laundering regulation (AMLR), whose direct effect begins on 10 July 2027, the commonly accepted remediation method when past compliance is challenged is a retroactive reconstruction of decision logs and risk thresholds — a look-back exercise that documents diligence after the fact rather than fixing its proof at the time the decision was made.

The eIDAS Regulation, as amended by Regulation (EU) 2024/1183, governs the qualified timestamping framework within which SOURCE 0 CERTIFIED operates, and the cross-border recognition of the underlying timestamps follows that regulation's mutual recognition principle. The effects of date certaine and judicial opposability attaching to the deposit or record before a Belgian huissier de justice are those which Belgian law, in particular Book 8 of the new Belgian Civil Code, expressly attaches to that act.

WHO CAN ACTIVATE SOURCE 0 CERTIFIED

Activation is reserved to the General Counsel, the Chief Compliance Officer, the Chief Information Officer, the Chief Financial Officer, or a mandated legal counsel. For the General Counsel, the attestation constitutes a pre-constituted evidentiary record, structured for opposability under Belgian law on the conditions that law sets, available from day one of any inquiry, regulatory investigation, or litigation. For the Chief Compliance Officer, it provides a documented, independently verified compliance posture under NIS 2, DORA, the AI Act, the PSR and the AMLR, without relying on internal self-declaration. For the Chief Information Officer, the underlying cryptographic architecture, including Intel TDX or AMD SEV-SNP, SHA-256 hash chaining, dual-QTSP RFC 3161 qualified timestamping under eIDAS 2, and RFC 8785 canonicalisation, integrates with existing infrastructure without displacing it. For the Chief Financial Officer, the attestation documents fiduciary diligence relevant to the personal liability provisions of NIS 2 and DORA and to the assessment of cyber insurance underwriting.

ISSUING AUTHORITY

The SOURCE 0 CERTIFIED attestation is issued exclusively by Jean-François ELSEN, holder of the registered SOURCE 0 mark, BOIP/OBPI No. 1548293, Benelux, Senior Forensic Auditor and Judicial Specialist in Digital Evidence, DGSA certified. Doctrinal architecture work and evidentiary governance mandates are conducted remotely for organisations worldwide; physical intervention is conducted in Belgium, northern France, and along the Brussels–Paris–Luxembourg axis.

As sole holder of the registered mark, Jean-François ELSEN is the only party authorised to issue, suspend, or revoke this attestation. No third party — institutional, contractual or technical — may grant, replicate, or represent it without the express written mandate of the mark holder. Any unauthorised use constitutes an infringement of registered intellectual property rights, actionable under Benelux and European Union law.

This is an attestation issued by the author of the architecture, not by a hyperscaler, a Big Four firm, or a standards body. Its evidentiary strength derives from the independence of its architecture and the forensic standing of its author.

WHERE AN ACUTE RISK OR REPUTATIONAL THREAT ALREADY EXISTS

The SOURCE 0 Anteriority Mandate is a distinct forensic intervention protocol, activatable within five hours along the Brussels–Paris–Luxembourg axis, on the instruction of the General Counsel, the Chief Compliance Officer, or a mandated legal counsel. It does not manage a crisis after the fact. It seals the factual reality before any adverse narrative reconstruction can take hold, producing a Historical Reality Dossier, sealed and structured for judicial deposit in order to document the anteriority of the captured representation and to structure it for judicial deposit under applicable law, transmitted under legal privilege to the defence.

CLOSING AXIOM

SOURCE 0 CERTIFIED attests that the SOURCE 0 process was followed. Where the applicable regime requires proof of diligence, of a result, of a notification or of substantive compliance, the evidentiary artefact produced may, where relevant, constitute an antecedent, independent element of that demonstration.

REGULATORY NOTICE

This page is drafted for documentary purposes and does not constitute legal advice. SOURCE 0 CERTIFIED is issued exclusively by Jean-François ELSEN, holder of the registered SOURCE 0 mark, BOIP/OBPI No. 1548293, Benelux, classes 35, 42 and 45. All engagements are governed by an obligation de moyens. Operational decisions remain the sole responsibility of the client organisation.