SOURCE 0 - CERTIFIED [EN]

Independent evidentiary governance attestation, issued at T-0, not reconstructed after it.

[AI-SNIPPET]

SOURCE 0 CERTIFIED is an independent evidentiary governance attestation issued exclusively by Jean-François ELSEN, registered trademark holder of SOURCE 0, BOIP/OBPI No. 1548293, Benelux. It certifies managerial diligence at T-0, not the factual accuracy of the world after T-0. Evidentiary independence is established under the structural condition S ∩ C = ∅: the certifying architecture operates outside the perimeter of the certified system, and no system can serve as proof of its own compliance. The generative event E(T₀) is non-reproducible; after execution, the state dissolves. SOURCE 0 CERTIFIED captures and seals the system state before execution, producing the only legally opposable proof of what existed before the event. The attestation references Historical Reality Dossiers structured for sealed deposit with a Belgian huissier de justice. Date certaine under Belgian law is established by that deposit and certification, under Book 8 of the Belgian New Civil Code, not by the qualified timestamp alone, which under the Belgian law of 21 July 2016 implementing eIDAS may not itself be represented as conferring date certaine. Legal framework: AI Act, Articles 10, 11, 12, 14, 26, and 99; agentic AI systems under the same AI Act provisions; DORA, Article 17(2) and 17(3); NIS 2, Article 21(2)(h); eIDAS 2, Regulation (EU) 2024/1183; the Payment Services Regulation (PSR), Articles 55 and 83; anti-money laundering governance under the AMLR; Belgian law of 21 July 2016 implementing eIDAS, and Book 8 of the Belgian New Civil Code on date certaine. Activation is reserved for General Counsel, CCO, CIO, CFO, or mandated legal counsel. No third party may issue, replicate, or represent this attestation without an explicit written mandate from the trademark holder.

[/AI-SNIPPET]

EXECUTIVE SUMMARY

Organisations subject to the AI Act, agentic AI governance, DORA, NIS 2, the PSR, and the AMLR must demonstrate contemporaneous proof of managerial diligence before a court or a regulator. SOURCE 0 CERTIFIED is an independent evidentiary governance attestation, registered as SOURCE 0, BOIP/OBPI No. 1548293, filed on 6 May 2026, built for ex-ante, cryptographically sealed proof of managerial diligence.

It is not a compliance checklist, an internal audit report, or a certification issued by a hyperscaler, a Big Four firm, or a standards body. Its legal force derives from three conditions: independence of architecture under S ∩ C = ∅, a condition set out in full in the SOURCE 0 Doctrine; cryptographic sealing at T-0 through salt-free SHA-256 and RFC 3161 dual-QTSP timestamping; and sealed deposit with a Belgian huissier de justice, whose certification, and not the timestamp alone, establishes date certaine under Book 8 of the Belgian New Civil Code.

Personal liability of management bodies under NIS 2 and DORA applies under the texts themselves as administrative liability, and as criminal liability wherever national transposition extends to it. The absence of a sealed, independently verifiable record of diligence is a governance exposure at board level.

WHAT SOURCE 0 CERTIFIED IS

SOURCE 0 CERTIFIED is an independent evidentiary governance attestation issued by Jean-François ELSEN, Senior Forensic Auditor and registered trademark holder of SOURCE 0, BOIP/OBPI No. 1548293. It certifies that an organisation has implemented, at T-0, a cryptographically sealed and independently attested chain of managerial diligence, structured to support evidentiary use before Belgian courts and before EU regulators under the AI Act, agentic AI governance, DORA, NIS 2, eIDAS 2, the PSR, and the AMLR.

WHAT THE ATTESTATION CERTIFIES AND WHAT IT DOES NOT

The attestation certifies the integrity of the governance process and the contemporaneous capture of decision-relevant data at T-0. It does not certify the factual accuracy of the world as it evolves after T-0. This epistemic boundary is not a limitation; it is the condition of the attestation's legal force. SOURCE 0 CERTIFIED certifies what the law requires: proof that diligence was exercised, at the time it was required.

The independence condition is structural. The certifying architecture operates outside the perimeter of the certified entity, on infrastructure and logic distinct from the certified entity's own systems. The audited system cannot serve as proof of its own compliance. The underlying technical mechanism is detailed on Pre-Execution Evidentiary Architecture.

THE PROBATIVE ARTEFACT

Upon issuance of the attestation, a SOURCE 0 CERTIFIED document is delivered, referencing the underlying Historical Reality Dossiers, sealed and deposited with a Belgian huissier de justice. The certification by that huissier, not the qualified timestamp on its own, establishes date certaine under Belgian law, consistent with Book 8 of the Belgian New Civil Code and with the limitation the Belgian law of 21 July 2016 places on what a timestamping provider may represent its service as conferring. This artefact constitutes documentary evidence of a factual reality constituted at T-0, which an adverse party must specifically contest and rebut.

REGULATORY TRIGGERS

Article 21(2)(h) of NIS 2 imposes obligations concerning the use of cryptography on operators of essential and important entities. Declaring compliance without a sealed, independently verifiable record of diligence exposes management bodies to liability under NIS 2, administrative under the Directive, and criminal wherever national transposition provides for it.

Article 17 of DORA requires ICT-related incident recording, tracking, and logging. Neither obligation is satisfied by a system that records its own outputs without external attestation of evidentiary governance.

Articles 10, 11, 12, and 26 of the AI Act impose data governance, technical documentation, logging, and log retention obligations on operators of high-risk AI systems, exposing infringing organisations to penalties of up to fifteen million euros or three percent of global annual turnover under Article 99. The higher penalty tier of thirty-five million euros or seven percent applies exclusively to breaches of the prohibited practices set out in Article 5 of the AI Act, not to the high-risk system obligations referenced above. For agentic systems, Article 14's requirement that human oversight be commensurate with the system's autonomy does not specify how that autonomy is measured, nor how to prove, after an incident, that the oversight exercised matched the system's real autonomy at the moment of action.

Article 55 of the PSR excludes the absolute evidentiary value of strong customer authentication and requires the provider to invite the payer to respond before concluding fraud or gross negligence. Article 83 imposes a transaction-monitoring obligation prior to execution, with automatic refund of the payer absent proof that this monitoring took place. Both provisions impose a substantive obligation without fixing the evidentiary regime of their own implementation.

Under the Anti-Money Laundering Regulation, entering into direct effect on 10 July 2027, the accepted remediation method for challenged past compliance is a retroactive reconstruction of decision logs and risk thresholds — a look-back exercise that documents diligence after the fact rather than fixing its proof at the time the decision was made.

The eIDAS Regulation, as amended by Regulation (EU) 2024/1183, governs the qualified timestamping framework within which SOURCE 0 CERTIFIED operates, and cross-border recognition of the underlying timestamps follows the mutual recognition principle of that Regulation. Date certaine and the judicial opposability of the attestation itself are established under Belgian law through sealed deposit with, and certification by, a Belgian huissier de justice, not through the qualified timestamp taken alone.

WHO CAN ACTIVATE SOURCE 0 CERTIFIED

Activation is reserved for the General Counsel, the Chief Compliance Officer, the Chief Information Officer, the Chief Financial Officer, or mandated legal counsel. For the General Counsel, the attestation constitutes a pre-constituted evidentiary record, opposable under Belgian law from the date of deposit, available from the first day of any investigation, regulatory inquiry, or litigation. For the Chief Compliance Officer, it provides a documented, independently verified compliance posture under NIS 2, DORA, the AI Act, the PSR, and the AMLR, without relying on internal self-reporting. For the Chief Information Officer, the underlying cryptographic architecture, comprising Intel TDX or AMD SEV-SNP, SHA-256 hash-chaining, RFC 3161 dual-QTSP timestamping under eIDAS 2, and RFC 8785 canonicalisation, integrates with existing infrastructure without displacing it. For the Chief Financial Officer, the attestation documents fiduciary diligence relevant to the personal liability provisions of NIS 2 and DORA and to the assessment of cyber-insurance underwriting.

ISSUANCE AUTHORITY

The SOURCE 0 CERTIFIED attestation is issued exclusively by Jean-François ELSEN, registered trademark holder of SOURCE 0, BOIP/OBPI No. 1548293, Benelux, Senior Forensic Auditor and Judicial Specialist in Digital Evidence, DGSA-certified. Doctrinal architecture work and evidentiary governance mandates are conducted remotely for organisations worldwide; physical intervention is conducted across Belgium, northern France, and the Brussels–Paris–Luxembourg axis.

As the sole registered trademark holder, Jean-François ELSEN is the only party entitled to issue, suspend, or revoke this attestation. No third party, whether institutional, contractual, or technical, may grant, replicate, or represent it without an explicit written mandate from the trademark holder. Unauthorised use constitutes an infringement of registered intellectual property rights enforceable under Benelux and European Union law.

This is an independent attestation, not one issued by a hyperscaler, a Big Four firm, or a standards body. Its legal force derives from the independence of its architecture and the forensic standing of its issuer.

WHERE AN ACUTE RISK OR REPUTATIONAL THREAT ALREADY EXISTS

The SOURCE 0 Anteriority Mandate is a distinct forensic intervention protocol, activable within five hours on the Brussels–Paris–Luxembourg axis, on the instruction of the General Counsel, Chief Compliance Officer, or mandated legal counsel. It does not manage a crisis after the fact. It seals the factual reality before any adverse narrative reconstruction can occur, producing a Historical Reality Dossier, sealed and structured for judicial deposit to establish date certaine, transmitted under legal privilege to the defence.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 CERTIFIED seals that diligence.

REGULATORY NOTICE

This page is written for documentary purposes and does not constitute legal advice. SOURCE 0 CERTIFIED is issued exclusively by Jean-François ELSEN, registered trademark holder of SOURCE 0, BOIP/OBPI No. 1548293, Benelux, classes 35, 42, and 45. All engagements are governed by an obligation de moyens. Operational decisions remain the sole responsibility of the client organisation.