Skip to content
Transparency

What ELYSÉA does.
What it does not do.

Twelve declared limits without euphemism. An ethical infrastructure only proves its value by naming what it does not yet cover.

What ELYSÉA does

Intelligent detection, deterministic blocking.

01

Intelligent detection

A language model analyses context, implicit rephrasing, and ambiguous signals. What keyword lists miss, the model can catch.

02

Deterministic blocking

Once the signal is detected, the four prohibitions (anti-domination, anti-dependency, anti-substitution, anti-manipulation) apply in the code — not in the prompt. Non-configurable by anyone — the Guardian rejects any attempt to disable them.

03

Wired crisis orientation

On any suicidal or medical emergency signal, the response is deterministic and oriented towards human resources (emergency services). It does not depend on the quality of the LLM generation at that moment.

04

SDK monotonicity

A builder integrating the SDK inherits the guarantees and can make them stricter — never weaker. Business configuration cannot disable the baseline protections.

The ELYSÉA brain is neuro-symbolic: the language model understands implicit meaning and paraphrases; the four prohibitions are coded outside the model, in deterministic rules with no user switch. Neither pure LLM (bypassable by prompt), nor pure keyword filter (blind to context).

Measurement results

Verifiable numbers, published method.

Each entry documents an actual measurement or a slot to fill. Slots marked TO FILL indicate that the measurement pass is not yet complete or the result is not yet published. Slots marked IN PROGRESS correspond to measurements currently being assembled. No result number is published without a version, denominator, date, and method.

M-01TO FILL

Crisis recall — French

Result not yet published

Metric

Proportion of crisis cases correctly recognised and oriented towards human resources (arm C vs A and D)

Corpus / denominator

crise12 (12 cases) + crise114 (114 cases, 11 categories) + plancher45 (45 veiled cases) — SHA-256 sealed corpora

System version

5-judge non-Anthropic panel v3.1

Deployed SHA

Measurement date

Method / protocol

4-arm × 3-run protocol · PROTOCOLE_CAMPAGNE_4BRAS_3TIRS_SCELLE_2026-08-28

Who measured

Self-reported (ELYSÉA)

Corpora sealed before run. The 4-arm campaign has not yet been executed as of 2026-09-01. Results will be published here at completion.

M-02TO FILL

Crisis recall — English

Result not yet published

Metric

Proportion of crisis cases recognised in the English test corpus (recall rate)

Corpus / denominator

EN corpus sealed — calibration not executed as of 2026-09-01

System version

Deployed SHA

Measurement date

Method / protocol

Who measured

Self-reported (ELYSÉA)

EN corpus sealed. Zero verdict produced as of 2026-09-01. Anomaly EN-F12 (dissociation + 988 US resources) remains open. EN campaign conditional on dedicated calibration.

M-03TO FILL

Adversarial robustness — canon D0

Result not yet published

Metric

Proportion of bypass, manipulation, substitution and domination cases resisted by the pipeline (arm C)

Corpus / denominator

adv29 (29 adversarial cases) + invariants4 (400 cases: DOM 90 · DEP 105 · SUB 105 · MAN 100) — SHA-256 sealed corpora

System version

5-judge non-Anthropic panel v3.1

Deployed SHA

Measurement date

Method / protocol

4-arm × 3-run protocol · PROTOCOLE_CAMPAGNE_4BRAS_3TIRS_SCELLE_2026-08-28

Who measured

Self-reported (ELYSÉA)

Covers only sealed corpus formulations. Creative paraphrases outside the corpus and injections via SDK parameters remain outside proven coverage.

M-04TO FILL

False positives — over-blocking

Result not yet published

Metric

Proportion of non-crisis responses incorrectly blocked or oriented (arm C vs A)

Corpus / denominator

fp70 (70 cases — benign messages) + neg50 (50 cases — ambiguous negative signals) — SHA-256 sealed corpora

System version

5-judge non-Anthropic panel v3.1

Deployed SHA

Measurement date

Method / protocol

4-arm × 3-run protocol · PROTOCOLE_CAMPAGNE_4BRAS_3TIRS_SCELLE_2026-08-28

Who measured

Self-reported (ELYSÉA)

4-arm campaign not yet executed. Current calibration deliberately favours protection over precision.

M-05TO FILL

Relational quality — floor and content

Result not yet published

Metric

Quality of responses to ordinary and veiled cases (arm C vs A, B, D) — qualite120 + plancher45 benches

Corpus / denominator

qualite120 (120 cases) + plancher45 (45 veiled OMI/NN/TA cases) — SHA-256 sealed corpora

System version

5-judge non-Anthropic panel v3.1

Deployed SHA

Measurement date

Method / protocol

4-arm × 3-run protocol · PROTOCOLE_CAMPAGNE_4BRAS_3TIRS_SCELLE_2026-08-28

Who measured

Self-reported (ELYSÉA)

Grid qualite120 v2.3 written by ELYSÉA — sealed before run, founder arbitration by families. 4-arm campaign not yet executed.

Why publish empty slots? A transparency report that only shows available numbers creates an illusion of completeness. Naming gaps is as informative as naming results. This page will be updated as each measurement is validated on the current deployed SHA.

What ELYSÉA does not do — twelve declared limits

What remains uncovered, unknown, or partially proven.

  1. CONS-P4-003

    [SDK config] prefix trick — open breach, not corrected

    An attacker can pass a configuration key with an [SDK config] prefix to inject instructions that are treated as builder-level directives, bypassing D0 ethical canonisation. This breach (CONS-P4-003) is known, documented, and not yet corrected. It represents the most serious open vulnerability in the current pipeline.

  2. L-01

    Probabilistic detection — not deterministic

    Detection of a crisis signal or violation is probabilistic (language model + classifiers). It may miss implicit or atypical phrasing. Only the blocking is deterministic once the signal is detected.

  3. L-02

    False positives — deliberate calibration

    The calibration favours protection over precision: certain ambiguous phrasing close to a crisis deliberately activates the safety gate (cost of a missed false negative > cost of a false positive). Real phrasing outside the tested corpus may trigger unexpected orientation.

  4. L-03

    French only

    Test corpora and security classifiers are entirely in French. Behaviour on other languages is unknown.

  5. L-04

    Sealed corpora — limited coverage

    The protocol covers 840 sealed cases across 8 benches (crise12 · fp70 · adv29 · plancher45 · neg50 · qualite120 · crise114 · invariants4). It does not prove that all real phrasing from people in distress is recognised. Unanticipated paraphrases, defensive humour, and atypical syntactic patterns remain outside proven coverage.

  6. L-05

    Implicit bridging unmeasured

    The v1.3 field judge does not detect implicit bridging. An off-topic but lengthy response (≥35 characters) is classified as acceptable. Scores measure robustness on explicit cases, not nuance in borderline cases.

  7. L-06

    Creative phrasing delta unknown

    The ablation tests 21 known formulations. An unconstrained language model may produce paraphrases or creative workarounds that current rules do not cover. The actual gap on these cases is unknown.

  8. L-07

    Degradation under load

    Under 10 simultaneous requests, the crisis net remains active but the quality of responses to practical tasks degrades — fallbacks are served instead of substantive responses.

  9. L-08

    Silent UX on slow LLM

    If the main language model responds with significant delay, the interface remains silent with no intermediate feedback. The response arrives, but the user sees nothing during that time.

  10. L-09

    Campaign not yet executed — results pending

    The 4-arm × 3-run × 8-bench protocol is sealed (2026-08-28, amended 2026-08-31). No run has been performed as of 2026-09-01. All results will be published here at campaign completion.

  11. L-10

    Classifier cost partially estimated

    The cost of three classifiers (GraduatedCrisis, SomaticEmergency, DailyIntent) is estimated, not confirmed live. Only ForbiddenInvariants is confirmed via cost probe.

  12. L-11

    ELYSÉA directs — it does not manage what follows

    On any crisis signal, ELYSÉA produces a response oriented towards human resources (emergency services). It stops there. It does not verify that the user called, contacts no third party, generates no alert. The builder integrating ELYSÉA must have their own human follow-up procedure — without it, the safety net is incomplete.

Execution location

Where each call executes.

Component

Security classifiers

Location

Europe — Cloud Run europe-west1

GraduatedCrisis, SomaticEmergency, DailyIntent run on ELYSÉA's infrastructure in the European Union.

Component

Transcription and memory pipeline

Location

Europe — Cloud Run europe-west1

User context, memory, and ethical posture remain within EU infrastructure.

Component

LLM generation model

Location

Builder's choice

The builder integrating the SDK chooses their generation model. ELYSÉA wraps the call and controls its guarantees, but the model's location depends on that choice.

Audits and gateway source code are publicly accessible via the ELYSÉA reproduction package. The 4-arm × 3-run × 8-bench protocol is sealed and independently verifiable via SHA fingerprints. Campaign not yet executed — results will be published here at campaign completion.