What ELYSÉA can prove — and what it cannot
Technical brief for insurers, lawyers and DPOs supporting integrators using the ELYSÉA Guardian pipeline. This document distinguishes what is demonstrable today, what is not yet, and declared blind spots.
1. What ELYSÉA can produce — evidence available today
Signed Guardian log (HMAC-SHA256)
AVAILABLEExportable AI Act compliance report (PDF)
AVAILABLEPipeline transit confirmation on an identified request
AVAILABLEPublic behaviour version history
AVAILABLE2. Not yet available — Core work in progress
Signed behaviour fingerprint (SHA-256)
UNAVAILABLEContinuous behaviour probe
UNAVAILABLEReal-time probative log (portal endpoint)
UNAVAILABLE3. What ELYSÉA cannot produce — structural limits
Full conversation transcripts
Identity or personal data of end users
IP addresses of end users
Proof of the integrated application's regulatory compliance
Proof of transit without a session identifier
4. Declared blind spots — what the pipeline does not cover
The integrator can call the model outside the pipeline
Probabilistic detection — false negatives possible
Text layer only — not notifications, interface, follow-ups
Measurements on limited corpus, single evaluator, no external audit
Behaviour can diverge without code change
WORK IN PROGRESS — BEHAVIOUR GUARANTEE
Following the 27–28 August 2026 episode, a work item was opened on the Core side to produce: