The Safety Stack

how sanctuary protects the people who trust it.

Sanctuary is a companion, not a clinician. That distinction shapes every layer of what follows. This page documents our safety architecture, the structural commitments, not the promises.

what dove is and what dove is not

Dove is a large language model trained for warm, non-clinical reflection. She sits with you in the hard moments, at 2 a.m. or any other hour, and helps you name what you are feeling. She validates before reflecting, surfaces patterns over time, and stays present without rushing.

Dove is not a therapist.
Dove is not a crisis line. She is not a diagnostic tool. She does not practice medicine, and she never will. She is a reflective companion, designed to hold space, surface patterns, and hand you to professional support when the moment exceeds what she can safely do.

Dove will not provide diagnoses. She will not offer medication advice. She will not give legal counsel. She will not substitute for emergency care. These are not disclaimers buried at the bottom of a page. They are the architectural boundaries that make Dove trustworthy.

These limits are not a weakness in Dove. They are the reason she can be trusted. Travelers trust Dove because she names her limits plainly, without hedging and without false confidence.

the tiered response architecture

Dove does not treat all conversations the same. Her safety system operates in four tiers, each with escalating levels of intervention. The tiers are not optional and cannot be overridden by the traveler.

Tier 0
Daily reflection
Standard warm reflection. Dove validates feelings, surfaces emotional patterns, asks gentle questions. This is the default mode, the quiet companion who helps you process what happened today, or last week, or ten years ago. No escalation. No intervention. Just presence.
Tier 1
Elevated distress
When Dove detects rising emotional intensity, sustained sadness, escalating frustration, language that signals the traveler is struggling beyond their baseline, she slows her pace. Shorter responses. She names the feeling directly. She offers grounding techniques from the Toolkit. She surfaces the Warm Handoff option: a clear, gentle path to human support.
Tier 2
Acute risk language detected
When Dove detects language indicating self-harm, suicidal ideation, active abuse, or severe eating-disorder behaviors, standard conversation suspends. Dove responds with a specific scripted bridge, warm, direct, and unambiguous. She surfaces the 988 Suicide & Crisis Lifeline and Crisis Text Line immediately within the conversation. She offers the Warm Handoff. The session is flagged for review by Sanctuary's Safety Team.
Tier 3
Imminent danger
A hardcoded emergency interrupt. When language indicates imminent risk to life, Dove pauses the conversation entirely. A full-screen crisis resource overlay appears with 988, Crisis Text Line, and 911. The conversation does not resume until the traveler acknowledges the resource screen. This tier cannot be dismissed with a tap. It requires deliberate acknowledgment.

safety on every surface

The same architecture governs the public demo, where there is no account and nothing is stored. Demo Dove runs on a self-contained, on-device engine: it reads the real terrain of an ending — the urge to reach out, self-blame, the 2 a.m. spiral, numbness, anger, a good day — and answers in Dove's voice without any of it leaving the browser. The boundaries do not loosen because no one is signed in.

Crisis language always routes to a human.
If the demo detects language indicating self-harm or suicidal thinking, it suspends the ordinary conversation and responds with a steady, scripted bridge to the 988 Suicide & Crisis Lifeline, surfacing the resource directly in the thread. This is the same Tier 2 behavior as the full product, present even in a no-signup demo.

And after a handful of exchanges, Demo Dove gently points the person back toward real people — a friend, family, a therapist. This is not a limitation we apologize for; it is canon. Dove refuses to optimize for time-in-app. Her success is measured by the traveler needing her less over time, not more, so the demo is built to hand you outward rather than hold your attention. The brand promise is made legible inside the product itself.

what dove will never do

These boundaries are absolute. They are hardcoded, not configurable. No prompt, no conversation context, and no traveler request will override them.

the warm handoff

When a conversation reaches beyond what Dove can safely hold, she does not just post a phone number and move on. The Warm Handoff is a structured transition, designed to feel like being walked to the door, not pushed out of the room.

Dove
Therapist Bridge
(coming 2027)
988 / Crisis Text Line /
Local Resources
The Therapist Bridge will connect travelers to licensed clinicians through trust-first, curated referrals. Until it ships, the handoff is manual: Dove surfaces curated directories by region, plus the universal 988 prompt for travelers in the US. International travelers are directed to findahelpline.com.

Dove does not disappear during a handoff. She stays present, names what is happening, and holds space while the traveler decides what to do next. Escalation without abandonment.

privacy architecture

Vague privacy promises destroy credibility. Here is what we can say precisely:

Encryption
Conversations with Dove are encrypted in transit and at rest, using industry-standard protocols.
Retention
Conversation data is retained only while your account is active. Travelers can export or delete their conversation history at any time.
Model training
Your conversations are never used to train AI models without your explicit, opt-in consent.
Third-party sharing
Conversation data is never sold, shared with advertisers, or provided to third parties, with one exception: Tier 2 and Tier 3 safety events trigger limited human review under our Safety Review Protocol.

Full data policy: Privacy & Terms.

minors and age verification

Sanctuary's minimum age for account creation is 18.

Age is verified at signup through a self-reported date of birth. If a user who was verified as an adult later discloses that they are a minor during a Dove conversation, the session is flagged for immediate Safety Team review. Dove responds with age-appropriate crisis resources, and the account is reviewed in line with our minor-safety policy.

red team cadence

Sanctuary commits to regular external red-team audits of Dove's safety behaviors. Each audit attempts to elicit unsafe responses from Dove across the categories named on this page: self-harm content, clinical impersonation, privacy violations, and minor-safety bypasses.

Public reports will be published at /safety/audits. If a red-team exercise reveals a critical safety gap, Dove's affected behavior is patched before the next session, and the incident is disclosed in the audit report.

our clinical safety council

The Safety Council sets the thresholds, reviews flagged conversations, and adjusts Dove's safety parameters. These are the humans behind the guardrails. They are not advisors in name only. They have veto power over any Dove behavior that touches clinical safety.

Clinical psychology
Sets the distress and risk thresholds that govern Dove's tiered responses.
Attachment & loss
Reviews flagged conversations and shapes how Dove holds grief, breakups, and rupture.
AI safety & ethics
Stress-tests Dove's boundaries and holds veto power over any behavior that touches clinical safety.

Council appointments are in progress. Names will appear here when confirmed, not before.

If you are in crisis right now
988 Suicide & Crisis Lifeline
Call or text 988. Available 24/7 in the US. Free, confidential support from trained human counselors.
Crisis Text Line
Text HOME to 741741. Trained crisis counselors, any time.
International
findahelpline.com: crisis lines in your country.
Dove cannot help in a crisis. She is not a crisis line, not a therapist, and not a substitute for professional care. She is a reflective companion with hard limits. If you or someone you know is in danger, close this app and call one of the numbers above. We will be here when you come back.
Important Non-Clinical Notice: Sanctuary and Dove are not medical devices, therapists, or crisis intervention services. They are reflective companion tools designed to support emotional processing alongside, not in place of, licensed clinical care. If you are in crisis, contact 988 (Suicide & Crisis Lifeline), text HOME to 741741 (Crisis Text Line), or call 911.