Capability matrix

    Every signal. Every OS. Documented.

    ScreenComply ships in two deployment modes — a Browser-Based API for asynchronous upload analysis and a Desktop Agent for real-time OS monitoring. Coverage by operating system is below. Most institutions deploy both for end-to-end integrity.

    Full support  ·  Partial / heuristic  ·  Not supported (OS constraint)  ·  Not applicable

    Section 1 · Browser-Based API

    Server-side upload API. Every OS, no install.

    Candidates or customers POST a file — video, audio, image, document, or code — over HTTPS and receive structured JSON in return. No OS-resident component runs on the candidate's device. Every Section 1 capability is supported on every OS; real-time alerts are N/A in this mode by design (post-session analysis).

    CapabilityWinMacLinuxAndroidiOSNotes
    Video analysisBehavioral intelligence from session recordings
    Absence / leaving frame detectionFlags frames where no face, body, or human is detected. Timestamped in API response.
    Secondary device detection (monitor, phone)Model identifies phones or additional screens based on object detection and gaze divergence off equilibrium.
    Mobile phone detection (specific signal)Dedicated phone-in-frame classifier with position and handling-gesture signals. Directly addresses the 'second screen' vector.
    Sustained gaze divergenceCombines head pose and on-screen gaze vector. Flags extended periods of off-screen attention. Single glances are filtered; threshold is configurable.
    Anomalous behaviorSurfaces statistically unusual patterns not covered by specific detectors (off equilibrium) — e.g. erratic head movement, repeated out-of-frame gestures, or atypical shoulder activity.
    Writing on paper detectionDetected via head-down pitch, shoulder/arm movement pattern, and gaze adjustment.
    Typing / keyboard use detectionDetected via head-down pitch, shoulder/arm movement pattern, and gaze adjustment.
    'Pretending to engage' composite flagIndicator of passive presence without active attention or participation, derived from gaze divergences, body-language changes, and other tested indicators.
    Remote assistance suspicionUses audio context synchronized with gaze patterns — flags when the user is reading while answering a question.
    Continuous face identity consistencyRe-verified facial embeddings throughout the session — catches mid-session candidate swaps (proxy handoff).
    Full behavioral timeline (multi-track heatmap)Per-frame data across all tracked signals returned as structured JSON and rendered in the dashboard.
    AI verdict summaryPlain-English summary with top findings, risk flags, and overall behavioral score. Intended for human reviewer consumption.
    Identity verificationConfirming who is taking the assessment
    Photo ID capture and face matchPre-session photo-ID capture matched against live candidate image. Match score and ID document hash included in audit log.
    Liveness check (anti-photo, anti-loop, anti-deepfake)Challenge-response plus 3D liveness (facial geometry + rPPG) to defeat photo, recorded-video, and live-deepfake spoofs.
    Deepfake & AI content detectionUpload video, audio, image, document, or code
    Video deepfake detectionFrame-level AI classifier with temporal consistency checks. rPPG and 3D liveness signals integrated.
    AI-generated image detectionImage upload endpoint. GAN fingerprint analysis (DCT spectral signatures) plus metadata/EXIF consistency checks.
    AI-generated document detectionDocument upload endpoint. Perplexity, burstiness, and semantic-drift classifiers calibrated against RAID. Covers GPT, Claude, and Gemini outputs.
    AI-generated code detectionCode-specific classifier analyzing stylistic consistency, variable-naming entropy, comment cadence, and commit-like structure. Beta — calibration ongoing for Codility's question bank.
    Audio deepfake / voice clone detectionAudio upload endpoint. Vocoderprint detection plus micro-pause and breathing-cadence analysis.
    Audio & transcriptSpeaker analysis from uploaded audio or video
    Speech-to-text transcriptionFull timestamped transcript returned in API response.
    Speaker diarizationMulti-speaker labeling (SPEAKER_00, SPEAKER_01, …) with timestamps.
    Unexpected second voice detectionFlags additional speaker during a solo session — primary integrity signal for off-camera coaching.
    Ambient audio environment analysisDetects background TV, audible second keyboard, ambient conversation — broader than second-voice detection.
    Earpiece / whisper-coaching detectionLow-volume directed speech and micro-response-timing patterns indicative of earpiece coaching. Beta.

    Section 2 · Desktop Agent

    Native code on the candidate's device.

    Coverage varies by OS because the relevant OS APIs vary. Where a capability is limited on mobile, pair the Browser-Based API path — many mobile gaps are covered behaviorally by post-session video and audio analysis in Section 1.

    CapabilityWinMacLinuxAndroidiOSNotes
    AI coding assistant detectionPurpose-built for technical assessment integrity
    Browser extension enumerationSession-start inventory of installed and active browser extensions. Blocklist covers Copilot, Cursor tab, GPT-in-browser variants, and 120+ AI assistants.
    Desktop AI app detection (Cluely, Cursor, Interview Coder, etc.)Process-list scanning against a continuously-updated AI-assistant signature database. Includes named 'invisible' overlay tools.
    Overlay / always-on-top window detectionDetects transparent and always-on-top windows invisible to screen share (the Cluely vector). Enumerates window z-order and compositor flags at the OS level.
    Proxy / remote-access detectionPreventing 'someone else takes the test'
    Remote access tool detectionDetects TeamViewer, AnyDesk, Chrome Remote Desktop, Parsec, RustDesk, Splashtop, and similar. Both running-process and active-session signals.
    Input-source integrity (local vs. remote keyboard/mouse)Validates input events originate from physical peripherals on the local machine, not a remote driver. Defeats silent remote takeover.
    Process & application monitoringWhat is running on the machine
    General cheating-tool detectionProcess list scanned against known blocklist (answer overlays, auto-typers, LeetCode companions). List updated continuously.
    Unauthorized background app detectionFull process snapshot at session start plus continuous polling; unlisted apps flagged per admin policy.
    Screen recording / capture software runningDetects OBS, Camtasia, native OS screen-capture APIs, and mirroring drivers running concurrently.
    Virtual machine / sandbox detectionDetects whether the agent is running inside a VM to prevent environment spoofing. Hypervisor-flag and timing-based probes.
    Session behavior monitoringWhat the user is doing during the session
    Tab switching / window focus lossEvery focus-loss event logged with timestamp and destination app or URL.
    Secondary device sniffing (network side)Detects network traffic or display signals from secondary connected devices on the local network.
    Multi-monitor enumeration (OS-level)Queries OS directly for connected displays — stronger signal than behavioral gaze inference alone.
    USB / external storage insertionOS-level device event; immediate alert and log entry.
    Clipboard / paste-event monitoringPaste events into the assessment window logged distinctly from general clipboard activity. Content capture optional by privacy policy.
    Keystroke dynamics / typing cadenceRhythm and inter-key timing analysis distinguishes natural typing from paste-and-modify patterns. Content not captured.
    Network traffic anomaliesUnusual outbound connections flagged; threshold configurable by admin.
    Environment & device integrityPre-session and cross-stage verification
    VPN / proxy / geolocation consistencyVPN and anonymizing-proxy detection; geolocation compared to candidate-declared location and prior sessions.
    Machine fingerprint continuitySame-device verification across multi-stage test flows. Flags device changes between screening and final assessment.
    Pre-session environment scanGuided room/desk scan at session start. Optional per policy — may be required for high-stakes assessments.

    Cross-OS realities

    How each platform fits into a deployment.

    Key framing points for procurement and security review. Each OS has a different native depth, and our deployment model is designed to maximize integrity within the constraints of the platform — not pretend they don't exist.

    Windows

    Windows remains the most comprehensive platform for our desktop agent — every Section 2 signal is supported. For organizations issuing corporate Windows laptops, ScreenComply provides a full-spectrum integrity suite with native depth across every category.

    macOS

    Privacy-first design. Advanced permissions such as Accessibility entitlements for keystroke dynamics are optional. Standard deployment provides comprehensive coverage; additional protections can be enabled where the highest signal integrity is required.

    Linux

    Coverage closely aligned with macOS. Full support for overlay analysis on X11; Wayland support is evolving as compositor protocols stabilize. Ensures technical candidates on Linux are monitored with professional-grade integrity checks.

    Android

    Transparent, permission-based approach. Clear onboarding grants Accessibility Service and package-analysis permissions at install. All security signals are captured accurately and ethically through our optimized candidate workflows.

    iOS

    ScreenComply uses a Tiered Assessment Model with five Advanced Security Modes that adapt to BYOD or fully-managed environments. Where platform restrictions limit background process analysis, posture is preserved through managed configurations, containerized data protection, and our native companion experience.

    Combined Mode (recommended)

    Pairing the desktop agent with the browser-based API addresses gaps in any single platform — identity verification, gaze divergence, and audio analysis carry over even where native OS APIs are restricted. Real-time catches the brazen; post-processing catches the subtle.

    Talk to an engineer

    Need this matrix mapped to your assessment program?

    We'll walk through your candidate device mix, your assessment formats, and the specific signals that matter for your integrity posture. Typical response within two business days.