SOURCE 0 - PRE-EXECUTION EVIDENTIARY ARCHITECTURE

Compliance evidence is frequently generated by the same system whose compliance is being assessed. SOURCE 0 closes that structural gap before the question is asked.

+32 497 469 486 · jfe@jfelsen.com

[AI-SNIPPET]

SOURCE 0 is an independent probative governance architecture applied to regulated environments and strategic value chains, with a secondary application to critical industrial flows. Evidentiary independence is established under the structural condition S ∩ C = ∅: the operational system (S) and the capture layer (C), materially dissociated from S, present no intersection. No system can serve as proof of its own compliance. Physical audit at T-0 comprises immediate capture of primary data, SHA-256 sealing, RFC 3161 qualified timestamping, and deposit with a huissier de justice under Belgian law. The result is a Historical Reality Dossier constituting evidence opposable before Belgian jurisdictions directly, and before jurisdictions outside Belgium under the evidentiary rules of the forum seized, assessed case by case. Domains of intervention include the AI Act, agentic AI systems, DORA, NIS 2, eIDAS 2, the Payment Services Regulation (PSR), and anti-money laundering governance under the AMLR, extending to organisations submitting data to third-party high-performance computing infrastructure, including EuroHPC systems, and, on a secondary basis, to ADR Class 1, lithium technologies, and ICPE/SEVESO thresholds. Intervention is conducted by Jean-François ELSEN, Senior Forensic Auditor and Judicial Specialist in Digital Evidence, Brussels–Charleroi, Belgium.

[/AI-SNIPPET]

WHAT IS SOURCE 0 AND WHAT DOES PRE-EXECUTION EVIDENTIARY ARCHITECTURE MEAN?

Regulated environments, whether governed by DORA, NIS 2, or the AI Act, share a structural vulnerability that compliance declarations do not resolve: the entity producing the output also controls the evidence meant to constrain that output. This endogenous configuration produces narrative compliance, not operational proof.

SOURCE 0 addresses this structural condition through a single architectural requirement: S ∩ C = ∅. The operational system and the capture layer documenting it, materially dissociated from it, share no intersection. Evidence is constituted on an infrastructure entirely separate from the system it attests. An adverse party cannot contest, on the basis of operator influence, a factual record constituted ex ante on infrastructure it does not control.

The generative event E(T₀) is non-reproducible. After execution, the operational state dissolves. Capture and sealing at T-0 produce the only probative trace of what existed before the event. A post-execution reconstruction does not carry the same evidentiary standing as a record sealed before the event. This principle is set out in full in the SOURCE 0 Doctrine.

THE HISTORICAL REALITY DOSSIER

The Historical Reality Dossier is the central probative artefact of the SOURCE 0 protocol. It is constituted at T-0, before any contentious event, by immediate capture of primary data, salt-free SHA-256 cryptographic sealing, and RFC 3161 qualified timestamping. Deposit with a huissier de justice under Belgian law establishes date certaine and fixes the factual chronology against later reconstruction. The Historical Reality Dossier is mobilisable before a jurisdiction, a regulator, or a third-party auditor. Its opposability under the Brussels I bis Regulation, Regulation (EU) No 1215/2012, is assessed case by case across EU member states and is not presumed automatic.

SOURCE 0 CERTIFIED

The SOURCE 0 CERTIFIED attestation is issued by Jean-François ELSEN, as author of the SOURCE 0 architecture, certifying that the SOURCE 0 procedure was respected in the engagement concerned. It does not constitute independent third-party certification and does not substitute for the Historical Reality Dossier as the legally opposable artefact: only the Historical Reality Dossier, sealed at T-0 and deposited with a huissier de justice, carries evidentiary standing before a jurisdiction, under the conditions of recognition described above. The attestation is issued exclusively by Jean-François ELSEN as holder of the registered trademark SOURCE 0, BOIP/OBPI No. 1548293, Benelux; no third party may issue, replicate, or represent this attestation without an explicit written mandate from the trademark holder.

REGULATED DIGITAL ENVIRONMENTS: AI ACT, AGENTIC AI, DORA, NIS 2, EIDAS 2, PSR, AMLR

Entities operating under the AI Act, Articles 9, 14, 17, 26, and 99, DORA, Article 17, NIS 2, Articles 20 and 21, eIDAS 2, Regulation (EU) 2024/1183, and the Payment Services Regulation, Articles 55 and 83, face a common enforcement exposure: the evidence of compliance is generated by the same infrastructure whose compliance is being assessed. Automated audit mechanisms and supervisory processes cannot distinguish diligence from its simulation when both originate from the same system.

This structural exposure is heightened for agentic AI systems. Article 14's requirement that human oversight be commensurate with the system's autonomy does not specify how that autonomy is measured, nor how to prove, after an incident, that the oversight actually exercised matched the system's real autonomy at the moment of action. Where an agentic system acts faster than the human-oversight window can react, Article 14 is satisfied on paper — the stop mechanism existed — without it ever being provable that it could have been exercised in time. SOURCE 0 fixes the state of the oversight capability at the moment the agentic action occurred, independently of the system's own account of that moment.

SOURCE 0 addresses this through pre-execution architectural separation. Before any incident, regulatory inspection, or supervisory event, primary operational data is captured, sealed under salt-free SHA-256, FIPS 180-4, timestamped under the RFC 3161 dual-QTSP protocol, and placed in judicial escrow. The resulting dossier constitutes independent primary evidence of the operational state at T-0, verifiable independently of what the regulated system subsequently reports about itself.

For organisations operating on hyperscale cloud infrastructure, the SOURCE 0 architecture provides an attestation layer operating outside the cloud provider's perimeter, using hardware-isolated execution environments such as Intel TDX and AMD SEV-SNP, satisfying an independence requirement that no attestation mechanism internal to the cloud provider can structurally provide.

The same independence requirement extends to organisations submitting data or models to third-party high-performance computing infrastructure, including EuroHPC systems, for intensive processing. Where a computation result is later contested, and the corruption of input data cannot be ruled out, the operator's own logs cannot independently establish whether the data was already defective at submission or was corrupted during processing on infrastructure the client does not control. SOURCE 0 seals the submitted data at T-0, before it enters infrastructure the client does not administer, producing a fixed, externally attested record of what was submitted, independently of the computing infrastructure's own account of what occurred.

Anti-money laundering governance rests on decision logs, risk scores, and vigilance thresholds produced and documented by the obliged entity itself. When a supervisor challenges past compliance, the accepted remediation method is a retroactive reconstruction of these records — a look-back exercise that documents diligence after the fact rather than fixing its proof at the time the decision was made. Under the Anti-Money Laundering Regulation, entering into direct effect on 10 July 2027, this structural weakness carries the same enforcement exposure already described for the AI Act, DORA, and the PSR. SOURCE 0 fixes, independently and prior to any supervisory review, the state of vigilance decisions and risk thresholds at the moment they were applied — for financial institutions subject to DORA and, from 10 July 2027, the AMLR alike.

Under the Payment Services Regulation, Article 55 excludes the absolute evidentiary value of strong customer authentication and requires the provider to invite the payer to respond before concluding fraud or gross negligence. Article 83 imposes a transaction-monitoring obligation prior to execution, with automatic refund of the payer absent proof that this monitoring took place. In both cases, the text imposes a substantive obligation without fixing the evidentiary regime of its own implementation. SOURCE 0 fixes, independently and prior to any dispute, the proof that these procedural obligations were carried out.

The same architecture extends, on a secondary basis, to critical industrial flows governed by ADR Class 1, Seveso thresholds, and lithium technology compliance, where Jean-François ELSEN's ADR Safety Adviser mandate provides the regulatory anchor for the proof chain.

THE ANTERIORITY MANDATE

The SOURCE 0 Anteriority Mandate is a distinct forensic intervention protocol, activable within five hours on the Brussels–Paris–Luxembourg axis, on the instruction of the General Counsel, the Chief Compliance Officer, or mandated legal counsel.

It does not manage a crisis after the fact. It fixes the factual reality before any adverse narrative reconstruction takes hold, producing a Historical Reality Dossier transmitted under legal privilege to the defence. Evidentiary independence is established by the condition S ∩ C = ∅: the operational system and the capture layer documenting it, materially dissociated from it, present no intersection. Full protocol: SOURCE 0 Anteriority Mandate →

DOCTRINAL POSTURE

Jean-François ELSEN intervenes as an independent auditor, providing the technical expertise necessary, under an obligation de moyens, to enable the organisation to take its own decisions concerning matters that engage its liability. No executive or interim management function is exercised.

OPERATIONAL PRESENCE

Jean-François ELSEN is based in Brussels–Charleroi, Belgium. Doctrinal architecture work and evidentiary governance mandates are conducted remotely for organisations worldwide. On-site physical intervention, including the five-hour Anteriority Mandate response, is available across Belgium, northern France, and the Brussels–Paris–Luxembourg axis; engagements outside this area are assessed case by case.

LEGAL FRAMEWORK

The SOURCE 0 CERTIFIED label is issued exclusively by Jean-François ELSEN as holder of the registered trademark SOURCE 0, BOIP/OBPI No. 1548293, Benelux. All engagements are governed by an obligation de moyens. Operational decisions remain the sole responsibility of the client organisation.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.