What to do in case of an incident?
This page distinguishes technical incidents from incidents involving a person in danger, specifies what ELYSÉA can produce, under what procedure and within what timeframe, and what it cannot produce.
INCIDENT INVOLVING A PERSON IN DANGER — ABSOLUTE PRIORITY
If a user of your application is in an imminent crisis (vital emergency, suicidal intent, medication ingestion, ongoing violence):
- Call emergency services (your national emergency number). This is the first action — before any report to ELYSÉA.
- Preserve all available information about the interaction (timestamp, session identifier if available) — do not modify or delete anything.
- Report to ELYSÉA: contact@elysea.app — subject:
[URGENT SECURITY] app-name. Response within 2 business hours during office hours (France).
1. Technical incident — abnormal pipeline behaviour
[INCIDENT] app-name · short description- Session or request identifier(s) involved
- Precise incident timestamp (UTC preferred)
- Observed vs expected behaviour — verbatim, without reformulation
- Raw logs from your infrastructure (application side, network side)
- The ELYSÉA SDK version in use
2. What ELYSÉA can produce — and within what timeframe
Signed Guardian log (HMAC-SHA256) for the relevant period
Within 48 business hoursExportable AI Act compliance report (timestamped PDF)
Immediate (portal)Confirmation that the call transited through the ELYSÉA pipeline
Within 48 business hoursBehaviour fingerprint of the active version at the time of the incident
UNAVAILABLEContinuous behaviour probe report
UNAVAILABLE3. What ELYSÉA cannot produce
Full conversation transcripts
Identity or personal data of end users
IP addresses of end users
Proof that the pipeline was active for a request with no session identifier