Feature Cheating detection, fraud prevention and image proctoring
Detect sophisticated fraud and misuse of AI with telemetry, pattern analysis and full monitoring.




Our ecosystem of deep integrations makes it easy to streamline your hiring processes.










The integrity system is the set of features that records what happens during an assessment so the reviewer can tell a legitimate result from an attempt at fraud. It logs an event trail from start to finish: device, browser and approximate location, tab switches and window focus loss, exiting full screen, number of monitors, opening developer tools, copy and paste actions along with the copied content, text entered without going through the clipboard, pauses and connection drops. With the webcam on, it also records the ID photo and periodic photos during the test. All of this becomes a timeline with a screen recording, where each event jumps to the exact moment in the video.
In the Integrity tab of each assessment, in three groups. Assessment: hide score, shuffle questions and hide titles. Browser: copy-and-paste logging, tab-exit monitoring, full-screen mode, second-screen detection and screen recording. Camera: mandatory webcam with periodic photos, AI image analysis and photo ID at the start. Each feature is enabled individually, and the recommendation is proportionality. An auto-graded technical test calls for browser controls and photo ID; a certification with market value calls for the full camera setup; a personality test calls for almost nothing. The more features you enable, the more friction for the candidate, so turn on what the risk of the role justifies.
With the webcam on, the platform takes a photo at the start for identification, then one every 20-30 seconds during the test. Without AI analysis, these photos are just a visual record for a reviewer to look at. With analysis on, each photo is checked for six situations: person not looking at the screen, more than one person, no person, face partially visible, phone detected and capture failure. The reading is cautious by design: a photo without a face proves nothing on its own, so absence only starts to count after two photos in a row, and any candidate interaction within the 20-30 second window cancels the reading, because an empty chair doesn't move the mouse. Photos count by density, not individually: a single flagged image doesn't change the classification of the whole attempt.
It's a label per attempt, with four levels (none, low, medium, high), that helps the reviewer prioritize what to look at first. Each event gets a weight based on its severity: high is worth 15 points, medium 5, low 1, neutral 0.5. Repetitions of the same event within 30 seconds get a multiplier. The sum becomes a score from 0 to 100 that falls into bands: up to 25 none, up to 50 low, up to 75 medium, above that high. Three rules adjust the calculation: a single severe event outside the photos already moves the attempt to high; proctoring photos count by proportion, not individually; and events that happen when there is no content on screen, such as in the waiting room, are downgraded, because they only pose a risk while the candidate has a question in view.
Yes, at two levels. The ready-made profiles (standard, strict and light) change how much each signal weighs: in the light profile, for example, window focus loss no longer scores and leaving the tab drops to medium; in the strict profile, everything goes up. If no profile fits, you can adjust signal by signal. Two safeguards are built in to keep results comparable: the criteria are frozen at the start of each attempt, so all candidates in the same process are evaluated by the same rules even if the configuration changes midway; and before applying a change, you can simulate its impact on attempts that have already ended and see how many would change category.
The system was designed with these cases in mind, and the documentation is explicit about the caveats. Drinking water: a photo without a face doesn't score, only episodes of continuous absence do, and interaction cancels them. Dictation and accessibility tools: they produce text in blocks, so this case weighs less than an insertion that would be impossible by keyboard. VPN, corporate network and mobile internet: they shift the location, which is approximate and informational, not scored. Second monitor: detection only works in Chrome with permission, and undetermined situations are not logged, to avoid a false "single monitor". Developer tools: heuristic detection, with possible false positives in browsers with unusual extensions. That's why the high category means "look first", never "reject".
No, and that's a product rule, not a configuration option. The severity indicator prioritizes the review; the decision to disqualify is always made by a person, after looking at the timeline, the video and the content of the events. There are two reasons. The first is fairness: the absence of an event doesn't prove the action didn't happen, and the presence of an event doesn't prove fraud. The second is data protection law: disqualifying someone through a solely automated decision gives the candidate the right to a review (e.g., Article 20 of Brazil's LGPD and Article 22 of the GDPR), and an integrity signal alone doesn't support that decision. The recommendation is to record the reason for disqualification in the result and give the candidate a chance to explain.
Yes. When starting an assessment with integrity features, the browser asks for the corresponding permissions (camera, full screen, monitor detection), and the candidate can only proceed after granting them. With the warning option on, they get an alert the first time they leave the tab. Transparency is part of the strategy: a candidate who knows there's a recording behaves differently, and the company fulfills its duty to inform. The recommendation is to state in the invitation which features are active and why, and to ask for headphones and a quiet environment when camera and audio are on. Fewer surprises mean fewer drop-offs and fewer disputes.
Photos, screen recordings and events are linked to the candidate's attempt, with access restricted to the company's authorized users. The company is the data controller and defines the legal basis, which is usually legitimate interest with a documented proportionality test (why this role justifies these features), as well as the retention period. Coodesh acts as the data processor and does not use this material to train models. Deleting the workspace removes the data within 30 days. Before turning on the camera in a process, it's worth aligning with your DPO on the notice text for candidates, how long images are kept and who can access them.