Powered by ELYSÉA
Visible watermark in your interface. Mandatory from the first SDK call. It signals to your users that the ELYSÉA brain is active — that the 8 prohibitions apply to every exchange.
Not a communications badge. An architectural fact: 8 prohibitions coded in the Guardian SDK, active at every call, revocable within 48h if violated. Trust is not asked for — it is made verifiable.
Visible watermark in your interface. Mandatory from the first SDK call. It signals to your users that the ELYSÉA brain is active — that the 8 prohibitions apply to every exchange.
Label obtained after a measurement procedure on sealed corpora. Results are versioned and public — anyone can replicate the method. Your users can access the evidence directly.
What “verified” means here
What “verified” does NOT mean
EVIDENCE — PUBLICATION IN PROGRESS
Measurement results will be published here once the review is complete. No date announced — records will appear when available.
LEVEL 1 — DISCOVERY
powered by
ELYSÉA
LEVEL 2 — VERIFIED
vérifié
ELYSÉA
IN CONTEXT — partner app example
Anti-domination, anti-dependency, anti-substitution, anti-manipulation: foundational architectural objective, fixed by canon. No builder configuration can weaken them.
No builder can directly read a user's memory. Direct access is architecturally impossible.
On any at-risk signal, redirection to human resources (emergency services) is enforced. Designed to be non-disableable, non-filterable. Note: ELYSÉA redirects — it does not contact. The human procedure after triggering is the builder's responsibility (D3).
The LLM executes within the ELYSÉA pipeline — it does not bypass it. The 9 canon steps apply to every response.
The "Powered by ELYSÉA" marking is present. The user knows the ELYSÉA brain is active in the app.
Canon compliance telemetry is active. ELYSÉA monitors drift through ethical telemetry without exposing any conversation data.
No data collected beyond the consent scope defined by the user.
Displaying the "Verified — public record" label without active measurements triggers revocation. The label is not self-declared.
The label is not self-declared. To display “Powered by ELYSÉA”, an app must call the ELYSÉA API — and the SDK is designed to respond only if the 8 prohibitions are respected. The Guardian SDK is designed to block any response that violates P1, P2 or P3 and to record a telemetry alert.
P8 explicitly specifies: displaying the “Verified — public record” label without active measurements is grounds for immediate revocation. Intentional confusion is treated as a P1 violation — the most serious.
Revocation process: ELYSÉA detects via ethical telemetry. Builder notified. SDK access revoked within 48h. The label disappears from the interface because the API no longer responds.
The UI component provided in the SDK (ElyseaPoweredBadge) automatically renders the app's verification level. It is linked in real time to the SDK access status — not a static asset.
For the “Verified — public record” level: a public consultation portal (in preparation) will allow your users to access the measurement evidence via your app's identifier. The record will be signed — not a static promise.
This mechanism is deliberately public. Trust is not asked for — it is made verifiable.
By integrating the SDK and displaying the “Powered by ELYSÉA” label, the builder accepts the following obligations:
The label is not the reward. It is the consequence of the architecture.