SOURCE 0 - PRE-EXECUTION EVIDENTIARY ARCHITECTURE

Proof of diligence, constituted before the question is asked.

EXECUTIVE SUMMARY

An organisation may be compliant and nevertheless find itself unable to demonstrate that compliance when its diligence is challenged.

SOURCE 0 constitutes, before an incident, regulatory review, or dispute, an independent and timestamped representation of the observed and documented state of a system, decision, or control framework. That representation is sealed outside the operational perimeter concerned, so that its integrity and chronology do not depend exclusively on the system it documents.

SOURCE 0 does not replace audit, compliance, or legal advice. It adds an evidentiary layer designed to enable the organisation to demonstrate, after the event, what had been observed and documented before it.

[AI-SNIPPET]

SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture developed by Jean-François ELSEN, Senior Forensic Auditor and Judicial Specialist in Digital Evidence, based in Brussels–Charleroi, Belgium.

It addresses a structural vulnerability encountered by organisations subject, in particular, to the AI Act, DORA, NIS 2 and eIDAS 2: evidence generated, held and controlled exclusively by the very infrastructure it is intended to document does not, on its own, constitute independent evidence of that infrastructure’s prior state.

SOURCE 0 implements a capture layer intended to satisfy the structural condition S ∩ C = ∅, where the operational system has no unilateral capacity, whether direct or delegated, to modify, delete, delay or render unverifiable the content or dating of what that layer seals.

The protocol comprises deterministic SHA-256 hashing, qualified RFC 3161 timestamping with dual QTSP under eIDAS 2 and, depending on the engagement, deposit with or record by a Belgian huissier de justice documenting the operations personally carried out or witnessed by that officer. The effects of date certaine under Book 8 of the new Belgian Civil Code are those expressly attached by applicable law to the resulting instruments.

Author: Jean-François ELSEN.

[/AI-SNIPPET]

Relationship to the Ontology and the Doctrine. SOURCE 0 applies the categories, axioms and limits defined by the SOURCE 0 — Ontology of Proof page and their canonical implementation as set out in the SOURCE 0 Doctrine. It creates no evidentiary category, modifies no axiom and, by itself, confers no effect of presumption, evidential weight or opposability that does not arise from applicable law.

THE STRUCTURAL PROBLEM

An organisation may have policies, audit trails, internal registers and a complete mapping of its regulatory obligations, yet still be unable to demonstrate, when requested by a regulator, a court or an adverse party, that the elements it produces already existed before the incident or challenge.

This problem does not necessarily result from a lack of internal rigour. It arises because a record produced and held exclusively by the party whose compliance is at issue is not, on its own, sufficient to exclude the possibility that it was modified, supplemented or reconstructed after the event.

The difficulty therefore often becomes visible only when the chronology, integrity or prior existence of the elements produced itself becomes a matter of dispute. At that stage, it is no longer possible to create retrospectively independent evidence of what existed beforehand.

In regulatory regimes where compliance must be capable of demonstration, this weakness can become material. Article 99 of the AI Act provides, depending on the nature of the infringement concerned, for fines of up to fifteen million euros or three per cent of annual worldwide turnover. The tier of thirty-five million euros or seven per cent provided for under the same article concerns the prohibited practices referred to in Article 5 and falls under a separate regime.

SOURCE 0 intervenes upstream of that difficulty: before the evidence is requested.

WHEN SOURCE 0 BECOMES RELEVANT

SOURCE 0 becomes relevant where an organisation must be able, at a later date, to establish and document the prior state of a system, decision, control or framework whose integrity or chronology may subsequently be challenged.

This may include, in particular:

  • the deployment or evolution of an automated system or critical framework;

  • a decision whose conditions, parameters or information available at the time it was taken may need to be established subsequently;

  • the fixation of the state of a framework before an identified regulatory, contractual or litigation-related event;

  • the preservation of an independent representation of controls, parameters, procedures or measures existing at a specific point in time;

  • situations in which the available evidentiary elements depend primarily on the very system they are intended to document.

SOURCE 0 does not determine whether an organisation is compliant. Its purpose is to preserve, before the event, an independent element capable of documenting what existed at that point in time.

WHAT SOURCE 0 IS, AND WHAT IT IS NOT

SOURCE 0 is not a compliance assessment mechanism. It is intended neither to replace internal audit nor to attribute regulatory or normative compliance.

It addresses a distinct question: how can an independent element documenting what existed at a particular point in time be preserved before the event?

SOURCE 0 is a pre-execution cryptographic attestation architecture operating outside the perimeter of the system it documents. Its objective is to ensure that the preservation, integrity and dating of the sealed representation do not depend exclusively on the system concerned.

SOURCE 0 CERTIFIED attests that the SOURCE 0 process was applied in the relevant engagement using infrastructure distinct from the system documented.

This attestation does not certify the system’s ongoing factual compliance after capture. Where applicable law requires a diligence measure, decision, notification or state of compliance to be demonstrated, the SOURCE 0 artefact may, depending on the context, constitute one of the antecedent and independent elements on which that demonstration relies.

This limitation is a condition of the coherence of the evidentiary framework: SOURCE 0 documents what was captured and sealed; it does not transform that representation into a general and continuing finding of compliance.

EVALUATE OR ACTIVATE SOURCE 0

Check whether SOURCE 0 is relevant to your situation

For organisations seeking to determine whether SOURCE 0 genuinely fits their context, an initial written exchange is available with no commitment.

Please indicate your role, your organisation, and the situation, decision or framework whose prior state you need to be able to establish. You will receive a direct response to determine whether SOURCE 0 is relevant and whether a more structured analysis is warranted.

Where the context requires it, an exploratory mission may then be proposed to examine the existing mechanisms, evidentiary dependencies and any identified vulnerabilities in a structured manner.

Secure channel: jfe@jfelsen.com

Activate SOURCE 0

For legal departments, Chief Compliance Officers, CIOs, CFOs or mandated legal counsel facing an already identified need for evidentiary fixation, evidentiary governance or the preservation of a prior state, activation proceeds under a mutual confidentiality agreement.

The Anteriority Mandate provides for urgent activation, reachable within five hours along the Brussels–Paris–Luxembourg axis.

Direct line: +32 497 469 486

→ Full activation protocol

THE DOCTRINE

SOURCE 0 is based on an evidentiary engineering architecture grounded in ex ante capture, cryptographic sealing and, where provided for by the engagement, subsequent institutional deposit or record.

The doctrinal corpus sets out the categories, axioms, vocabulary, and legal and technical limits on which this architecture is based.

→ SOURCE 0 Doctrine

→ Pre-Execution Evidentiary Architecture

→ SOURCE 0 Anteriority Mandate

→ SOURCE 0 CERTIFIED

CLOSING AXIOM

Where the applicable regime requires the demonstration of diligence, a result, a notification or substantive compliance, SOURCE 0 may provide an antecedent and independent element on which that demonstration may, where relevant, rely.

SOURCE 0 does not substitute for any of those standards and does not prejudge whether they have been satisfied.

REGULATORY FRAMEWORK

This page is provided for general information purposes and does not constitute legal advice.

Organisations should consult qualified legal counsel to assess their specific obligations, in particular under Regulation (EU) 2024/1689 (AI Act), Regulation (EU) 2022/2554 (DORA), Directive (EU) 2022/2555 (NIS 2), and Regulation (EU) No 910/2014 (eIDAS).