Tenant isolation
Multi-tenant architecture with hard isolation at the database and API layer. Your content, candidates, and results never cross a tenant boundary.
When the auditor, the client, or the candidate questions a result, the answer has to hold up. Here's the architecture that makes sure it does.
Multi-tenant architecture with hard isolation at the database and API layer. Your content, candidates, and results never cross a tenant boundary.
Granular permissions per evaluator: who can create exams, view results, manage questions, run shortlisting — controlled per role, per tenant.
Every score, every violation, every certificate carries an immutable, time-stamped record — built for compliance, dispute, and audit.
Billing and AI-usage records are written once and never updated. A full transaction history for every credit, debit, and refund.
Token-based authentication with role-scoped JWTs. Guest candidate links are time-bounded, single-purpose, and revocable.
Webcam evidence, screen recordings, and certificates are stored in encrypted S3-compatible object storage with signed access URLs.
Strict for a high-stakes certification, lenient for a practice quiz — every layer is logged, severity-classified, and reviewable by a human before any auto-fail.
Live monitoring with face-api.js detection of no-face / multiple faces.
Candidate-consented screen capture stored as exam evidence.
Browser devtools, console, and view-source detection with auto-submit.
Tab changes, window switches, and focus loss timestamped per session.
Mandatory fullscreen with violation logging on exit.
Audio detection during exam to catch verbal cheating.
Coverage, certifications, expiry, and recert workflows are tracked continuously — not assembled the week before the auditor lands.
Every shortlist, score, and certificate has the evidence behind it: violation logs, time analysis, category breakdown, the rubric used.
Per-tenant retention policies on candidate data, proctoring evidence, and assessment records — your jurisdiction, your rules.
Working towards SOC 2 Type II and ISO 27001. Regional data residency available on enterprise plans. For a current security questionnaire, customer reference architecture, or data-processing addendum — talk to our team.
Tell us what your procurement team needs — questionnaire, DPA, reference architecture, pen-test summary — and we'll get it to you fast.