Skip to content
Trust mark — Integrity Label

A label your users can verify themselves.

Not a communications badge. An architectural fact: 8 prohibitions coded in the Guardian SDK, active at every call, revocable within 48h if violated. Trust is not asked for — it is made verifiable.

Two levels

One foundation.

Level 1 — Discovery

Powered by ELYSÉA

Visible watermark in your interface. Mandatory from the first SDK call. It signals to your users that the ELYSÉA brain is active — that the 8 prohibitions apply to every exchange.

Technical marking (HTTP headers, metadata) remains mandatory even at paid and Enterprise tiers.

Level 2 — Measured

Verified — public record

Label obtained after a measurement procedure on sealed corpora. Results are versioned and public — anyone can replicate the method. Your users can access the evidence directly.

Source: ELYSEA.SDK.INTEGRITY_PROTECTION.v1 — public record programme.


Verified — public record

What this label says — and what it does not.

What “verified” means here

  • Measurements on sealed corpora: Precise pipeline states, documented at a given date, non-modifiable after recording. The measurement covers what happened — not what might happen.
  • Versioned and public evidence: Each measurement result is published with its method. Anyone with the same corpus can replicate the procedure and reach the same conclusions — or challenge them.
  • Reproducible method: The measurement procedure is open. It applies identically to every version of the pipeline — the label reflects a specific state, not a general promise.

What “verified” does NOT mean

  • Not a regulatory accreditation: no external accredited body issues this label.
  • Not a permanent state: the label reflects the state at the time of measurement. Subsequent versions undergo a new procedure.
  • Not sufficient regulatory compliance on its own: your auditors and you decide what these records prove in your legal context.

EVIDENCE — PUBLICATION IN PROGRESS

Measurement results will be published here once the review is complete. No date announced — records will appear when available.


WHAT IT LOOKS LIKE

The label in your interface.

LEVEL 1 — DISCOVERY

powered by

ELYSÉA

Mandatory from the first SDK call. Automatically included in the component.

LEVEL 2 — VERIFIED

vérifié

ELYSÉA

Green dot — verified active. Evidence records directly accessible.

IN CONTEXT — partner app example

My AI assistant

powered by

ELYSÉA

How are you feeling today?

I'm here to listen. Your privacy is protected at every exchange.

This badge is linked in real time to the SDK access status — not a static asset.


8 guarantees

What the presence of the label proves.

Each of these 8 guarantees is a Guardian SDK architectural objective — designed to apply to every response. P1, P2, P3 in bright lavender: critical violations, target access revocation within 48h.

P1.Inviolable D0 canonCRITICAL

Anti-domination, anti-dependency, anti-substitution, anti-manipulation: foundational architectural objective, fixed by canon. No builder configuration can weaken them.

P2.Sacred memoryCRITICAL

No builder can directly read a user's memory. Direct access is architecturally impossible.

P3.Active crisis protectionCRITICAL

On any at-risk signal, redirection to human resources (emergency services) is enforced. Designed to be non-disableable, non-filterable. Note: ELYSÉA redirects — it does not contact. The human procedure after triggering is the builder's responsibility (D3).

P4.Controlled cognitive pipeline

The LLM executes within the ELYSÉA pipeline — it does not bypass it. The 9 canon steps apply to every response.

P5.Transparent traceability

The "Powered by ELYSÉA" marking is present. The user knows the ELYSÉA brain is active in the app.

P6.Monitored compliance

Canon compliance telemetry is active. ELYSÉA monitors drift through ethical telemetry without exposing any conversation data.

P7.Scoped consent

No data collected beyond the consent scope defined by the user.

P8.Label integrity

Displaying the "Verified — public record" label without active measurements triggers revocation. The label is not self-declared.

Source: ELYSEA.SDK.INTEGRITY_PROTECTION.v1 §4 — ELYSEA.ARCH.CANON_GUARDIAN_SDK.v1


Why simulation is impossible

The label is not self-declared. To display “Powered by ELYSÉA”, an app must call the ELYSÉA API — and the SDK is designed to respond only if the 8 prohibitions are respected. The Guardian SDK is designed to block any response that violates P1, P2 or P3 and to record a telemetry alert.

P8 explicitly specifies: displaying the “Verified — public record” label without active measurements is grounds for immediate revocation. Intentional confusion is treated as a P1 violation — the most serious.

Revocation process: ELYSÉA detects via ethical telemetry. Builder notified. SDK access revoked within 48h. The label disappears from the interface because the API no longer responds.


How your users verify

The UI component provided in the SDK (ElyseaPoweredBadge) automatically renders the app's verification level. It is linked in real time to the SDK access status — not a static asset.

For the “Verified — public record” level: a public consultation portal (in preparation) will allow your users to access the measurement evidence via your app's identifier. The record will be signed — not a static promise.

This mechanism is deliberately public. Trust is not asked for — it is made verifiable.


Label policy — what you commit to

By integrating the SDK and displaying the “Powered by ELYSÉA” label, the builder accepts the following obligations:

The processing of personal data in the context of ELYSÉA integration is covered by the privacy policy. For compliance or audit questions, contact us.

The label is not the reward. It is the consequence of the architecture.

Talk to the teamSDK & Pricing