Trust is a product feature
Decision support with humans in charge, review-only proctoring, least-privilege access and a complete audit trail — by design.
Role-based access
Eight built-in roles with module-level permissions from Super Admin to Report Viewer. Editable without code.
Complete audit trail
Configuration and security changes are logged with before/after snapshots, actor and IP. Secrets are redacted.
Encrypted secrets
Provider API keys are encrypted at rest and only the last four characters are ever displayed.
Kiosk isolation
Candidate kiosks use short-lived, signed, session-scoped tokens — no staff access, no navigation away.
Built to assist people — never to replace their judgment
These principles are enforced in the product, not just written in a policy.
01
AI never auto-rejects
Scores and recommendations are decision support. No candidate is rejected by an algorithm.
02
No accent penalty
Evaluation focuses on content and clarity — accents, dialects and code-switching are never penalised.
03
Humans make the final call
Authorised reviewers see the evidence and own every hiring decision, with notes and an audit trail.
04
No clinical inference
We assess job-relevant competencies only — never personality disorders, health, emotion or protected traits.
05
Keys never in the browser
AI provider keys are encrypted at rest and used server-side only. Candidates' browsers never see them.
Signals for reviewers — never automatic penalties
The kiosk records integrity signals with timestamps. Critical signals notify staff in real time; none of them changes a score.
| Signal | Severity |
|---|---|
| Camera disconnected | critical |
| Microphone disconnected | critical |
| Candidate not detected | warning |
| Multiple persons/voices | warning |
| Unexpected session interruption | warning |
| Network disconnection | warning |
| Network restored | info |
| Window lost focus | warning |
| Exited full-screen | warning |
| Application/session tampering signal | critical |
| Operator paused session | info |
| Operator resumed session | info |
| Operator terminated session | critical |
| System check overridden | warning |
- Window lost focus10:42:18
- Exited full-screen10:42:21
- Network disconnection10:47:03
- Network restored · answer re-sent10:47:09
- System check overridden by operator10:31:55
Signals never change scores — a reviewer decides what they mean.
Least privilege, out of the box
Eight roles with module-level permission levels — none, limited, view, operate, edit, full. Admins can tailor every role without code.
Every change and every AI call, accounted for
Configuration and security changes are written to the audit log with before/after snapshots. Every evaluation stores its prompt version, provider, model, latency and cost.
- AI provider keys encrypted at rest; only the last 4 characters are shown
- Correlation IDs on every error for fast, precise support
- Kiosks use short-lived, session-scoped signed tokens
Activated evaluator prompt v4
Neha (Assessment Mgr) CONFIGURATION
Rotated OpenAI key ••••7Q2c
Arjun (Super Admin) SECURITY
Evaluated Q12 via evaluator v4 · 0.9s
AI Engine AI
Adjusted score 62 → 70 with note
Kavita (Reviewer) REVIEW
Keep what you need, for as long as you need it
Retention windows are organisation settings, so your policy — not ours — decides how long candidate data lives.
Answer audio
180 days
Default — configurable per organisation
Transcripts & evaluations
365 days
Kept for audit and calibration
Kiosk access codes
12 hours
Single-session, device-bound
Audit & activity logs
Retained
Before/after snapshots, secrets redacted
Talk to us about your security review
We’ll walk your InfoSec and HR teams through access control, data flows and the AI governance model.