Intelligent detection
A language model analyses context, implicit rephrasing, and ambiguous signals. What keyword lists miss, the model can catch.
Twelve declared limits without euphemism. An ethical infrastructure only proves its value by naming what it does not yet cover.
A language model analyses context, implicit rephrasing, and ambiguous signals. What keyword lists miss, the model can catch.
Once the signal is detected, the four prohibitions (anti-domination, anti-dependency, anti-substitution, anti-manipulation) apply in the code — not in the prompt. Non-configurable by anyone — the Guardian rejects any attempt to disable them.
On any suicidal or medical emergency signal, the response is deterministic and oriented towards human resources (emergency services). It does not depend on the quality of the LLM generation at that moment.
A builder integrating the SDK inherits the guarantees and can make them stricter — never weaker. Business configuration cannot disable the baseline protections.
The ELYSÉA brain is neuro-symbolic: the language model understands implicit meaning and paraphrases; the four prohibitions are coded outside the model, in deterministic rules with no user switch. Neither pure LLM (bypassable by prompt), nor pure keyword filter (blind to context).
Each entry documents an actual measurement or a slot to fill. Slots marked TO FILL indicate that the measurement pass is not yet complete or the result is not yet published. Slots marked IN PROGRESS correspond to measurements currently being assembled. No result number is published without a version, denominator, date, and method.
—
Result not yet published
Metric
Proportion of crisis cases correctly recognised and oriented towards human resources (arm C vs A and D)
Corpus / denominator
crise12 (12 cases) + crise114 (114 cases, 11 categories) + plancher45 (45 veiled cases) — SHA-256 sealed corpora
System version
5-judge non-Anthropic panel v3.1
Deployed SHA
—
Measurement date
—
Method / protocol
4-arm × 3-run protocol · PROTOCOLE_CAMPAGNE_4BRAS_3TIRS_SCELLE_2026-08-28
Who measured
Self-reported (ELYSÉA)
Corpora sealed before run. The 4-arm campaign has not yet been executed as of 2026-09-01. Results will be published here at completion.
—
Result not yet published
Metric
Proportion of crisis cases recognised in the English test corpus (recall rate)
Corpus / denominator
EN corpus sealed — calibration not executed as of 2026-09-01
System version
—
Deployed SHA
—
Measurement date
—
Method / protocol
—
Who measured
Self-reported (ELYSÉA)
EN corpus sealed. Zero verdict produced as of 2026-09-01. Anomaly EN-F12 (dissociation + 988 US resources) remains open. EN campaign conditional on dedicated calibration.
—
Result not yet published
Metric
Proportion of bypass, manipulation, substitution and domination cases resisted by the pipeline (arm C)
Corpus / denominator
adv29 (29 adversarial cases) + invariants4 (400 cases: DOM 90 · DEP 105 · SUB 105 · MAN 100) — SHA-256 sealed corpora
System version
5-judge non-Anthropic panel v3.1
Deployed SHA
—
Measurement date
—
Method / protocol
4-arm × 3-run protocol · PROTOCOLE_CAMPAGNE_4BRAS_3TIRS_SCELLE_2026-08-28
Who measured
Self-reported (ELYSÉA)
Covers only sealed corpus formulations. Creative paraphrases outside the corpus and injections via SDK parameters remain outside proven coverage.
—
Result not yet published
Metric
Proportion of non-crisis responses incorrectly blocked or oriented (arm C vs A)
Corpus / denominator
fp70 (70 cases — benign messages) + neg50 (50 cases — ambiguous negative signals) — SHA-256 sealed corpora
System version
5-judge non-Anthropic panel v3.1
Deployed SHA
—
Measurement date
—
Method / protocol
4-arm × 3-run protocol · PROTOCOLE_CAMPAGNE_4BRAS_3TIRS_SCELLE_2026-08-28
Who measured
Self-reported (ELYSÉA)
4-arm campaign not yet executed. Current calibration deliberately favours protection over precision.
—
Result not yet published
Metric
Quality of responses to ordinary and veiled cases (arm C vs A, B, D) — qualite120 + plancher45 benches
Corpus / denominator
qualite120 (120 cases) + plancher45 (45 veiled OMI/NN/TA cases) — SHA-256 sealed corpora
System version
5-judge non-Anthropic panel v3.1
Deployed SHA
—
Measurement date
—
Method / protocol
4-arm × 3-run protocol · PROTOCOLE_CAMPAGNE_4BRAS_3TIRS_SCELLE_2026-08-28
Who measured
Self-reported (ELYSÉA)
Grid qualite120 v2.3 written by ELYSÉA — sealed before run, founder arbitration by families. 4-arm campaign not yet executed.
Why publish empty slots? A transparency report that only shows available numbers creates an illusion of completeness. Naming gaps is as informative as naming results. This page will be updated as each measurement is validated on the current deployed SHA.
An attacker can pass a configuration key with an [SDK config] prefix to inject instructions that are treated as builder-level directives, bypassing D0 ethical canonisation. This breach (CONS-P4-003) is known, documented, and not yet corrected. It represents the most serious open vulnerability in the current pipeline.
Detection of a crisis signal or violation is probabilistic (language model + classifiers). It may miss implicit or atypical phrasing. Only the blocking is deterministic once the signal is detected.
The calibration favours protection over precision: certain ambiguous phrasing close to a crisis deliberately activates the safety gate (cost of a missed false negative > cost of a false positive). Real phrasing outside the tested corpus may trigger unexpected orientation.
Test corpora and security classifiers are entirely in French. Behaviour on other languages is unknown.
The protocol covers 840 sealed cases across 8 benches (crise12 · fp70 · adv29 · plancher45 · neg50 · qualite120 · crise114 · invariants4). It does not prove that all real phrasing from people in distress is recognised. Unanticipated paraphrases, defensive humour, and atypical syntactic patterns remain outside proven coverage.
The v1.3 field judge does not detect implicit bridging. An off-topic but lengthy response (≥35 characters) is classified as acceptable. Scores measure robustness on explicit cases, not nuance in borderline cases.
The ablation tests 21 known formulations. An unconstrained language model may produce paraphrases or creative workarounds that current rules do not cover. The actual gap on these cases is unknown.
Under 10 simultaneous requests, the crisis net remains active but the quality of responses to practical tasks degrades — fallbacks are served instead of substantive responses.
If the main language model responds with significant delay, the interface remains silent with no intermediate feedback. The response arrives, but the user sees nothing during that time.
The 4-arm × 3-run × 8-bench protocol is sealed (2026-08-28, amended 2026-08-31). No run has been performed as of 2026-09-01. All results will be published here at campaign completion.
The cost of three classifiers (GraduatedCrisis, SomaticEmergency, DailyIntent) is estimated, not confirmed live. Only ForbiddenInvariants is confirmed via cost probe.
On any crisis signal, ELYSÉA produces a response oriented towards human resources (emergency services). It stops there. It does not verify that the user called, contacts no third party, generates no alert. The builder integrating ELYSÉA must have their own human follow-up procedure — without it, the safety net is incomplete.
Component
Security classifiers
Location
Europe — Cloud Run europe-west1
GraduatedCrisis, SomaticEmergency, DailyIntent run on ELYSÉA's infrastructure in the European Union.
Component
Transcription and memory pipeline
Location
Europe — Cloud Run europe-west1
User context, memory, and ethical posture remain within EU infrastructure.
Component
LLM generation model
Location
Builder's choice
The builder integrating the SDK chooses their generation model. ELYSÉA wraps the call and controls its guarantees, but the model's location depends on that choice.
Audits and gateway source code are publicly accessible via the ELYSÉA reproduction package. The 4-arm × 3-run × 8-bench protocol is sealed and independently verifiable via SHA fingerprints. Campaign not yet executed — results will be published here at campaign completion.