Hiring integrity guide
How to Catch Interview Cheating
You catch interview cheating by watching for the device-level footprint of assistance rather than trying to read a candidate's face. Hidden copilots, overlay windows, remote-control sessions, and injected input all leave observable traces on the operating system even when they are invisible on the call. ScreenComply captures those traces live, and analyzes recorded sessions afterward, then produces an evidence-linked report for human review.
Behavioral tells are a starting point, not proof
Interviewers often notice something before a tool does: answers that arrive after a consistent pause, phrasing that reads aloud rather than speaks, eyes tracking a fixed region of the screen, or a sudden shift in fluency between conversational and technical portions of the interview.
These observations are useful for deciding to look closer, but they are weak grounds for a decision on their own. Nervousness, accents, connection lag, and neurodivergence all produce similar surface behavior. The point of technical detection is to replace impressions with evidence.
Why browser-based proctoring misses modern AI assistants
Most proctoring tools are built as browser extensions or lockdown browsers. They can see the tab, the page, and sometimes the webcam, but their visibility ends at the edge of the browser process. Modern AI assistance does not live inside the browser.
Tools such as invisible interview copilots and always-on-top answer overlays run as native desktop applications. They render above every other window, are frequently excluded from screen capture and screen share, and never touch the exam tab. A lockdown browser can be perfectly locked down while an assistant quietly reads the question and displays an answer on the same screen.
The same gap applies to remote-control software, virtual machines, injected keyboard input, and a second device sitting off camera. None of these leave a trace inside the browser, which is why a session can look clean in a browser-only tool and still be assisted end to end.
- Native overlay applications draw above the browser and are often invisible to screen sharing and screen recording.
- Remote-access tools let another person drive the machine without any browser-visible signal.
- Virtual machines and sandboxes let a candidate run the assessment in a controlled environment with helpers outside it.
- Synthesized or injected keyboard input can type answers that were never physically typed.
- A second phone, tablet, or monitor off camera leaves nothing at all in the browser.
What device-level detection actually sees
Detecting AI assistance reliably requires observation at the layer where the assistance runs: the operating system. ScreenComply pairs a browser-based API with an optional desktop agent that inspects the environment around the assessment rather than only the page inside it.
The agent enumerates running processes and browser extensions against a continuously updated list of AI assistants, answer overlays, and interview-copilot tools. It looks for always-on-top and transparent windows, remote-access sessions, virtualization, screen-capture drivers, additional connected displays, and USB storage events. It checks whether keyboard input originates from local physical hardware, and it records focus changes, clipboard events, and typing cadence patterns that distinguish composition from paste-and-modify behavior.
No detection system is perfect, and ScreenComply does not claim to catch every form of assistance. The goal is different and more useful: gather corroborating, timestamped signals so a human reviewer can make an informed, defensible decision instead of guessing from a webcam thumbnail.
- Process and extension enumeration against a maintained AI-assistant list.
- Overlay and always-on-top window detection, including windows excluded from screen share.
- Remote access, virtual machine, and screen-capture detection.
- Multi-monitor enumeration queried from the operating system, not inferred from gaze alone.
- Input-source integrity, clipboard and paste events, and typing-cadence analysis.
- Network and secondary-device signals on the local network.
Live detection and post-session analysis
Two things matter for catching assistance: seeing it while it happens, and being able to re-examine the session afterward. Live detection surfaces restricted processes, overlays, remote access, and input anomalies during the interview itself, so an interviewer can decide whether to probe further in the moment.
Recorded-session analysis covers asynchronous and video interviews. It examines the recording for behavioral and audio-visual anomalies, including indicators of synthetic or manipulated media and off-camera coaching, then merges those findings into the same report structure.
How audit-ready integrity reports work
A detection is only useful if it can be explained to someone who was not in the room. Every ScreenComply session produces a structured integrity report: an executive verdict with a risk level, a chronological evidence timeline, and the underlying signal detail behind each entry.
Each entry is timestamped and tied to the specific observation that produced it, so a reviewer can see what was detected, when it happened, and how strong the signal was. Reports are written in non-accusatory, factual language, because the institution or employer makes the decision, not the software.
Reports can be exported to PDF and shared with a secure link, which is what makes them usable in academic-integrity hearings, HR reviews, and compliance audits. Retention is configurable, including tiers that minimize or eliminate stored artifacts for privacy-sensitive programs.
- Executive verdict with a graded risk level rather than a pass/fail guess.
- Chronological, timestamped evidence timeline linked to underlying signals.
- Human-review-by-design framing: factual observations, not accusations.
- PDF export and secure sharing for hearings, HR files, and audits.
- Configurable retention, up to zero-retention operating modes.
Where to go next
Frequently asked questions
What are the signs someone is using AI in an interview?
Common indicators include a consistent lag before every answer, spoken text that reads like written prose, eye movement fixed on one screen region, and — on the device side — an overlay window or restricted process running during the session.
Can you detect invisible interview copilot tools?
Named desktop assistants and overlay tools are detected through process enumeration and always-on-top window inspection, including windows configured to be excluded from screen capture. No system catches everything, so findings are presented as evidence for review.
How do you catch a proxy candidate?
Signals include remote-access sessions, input that does not originate from local physical hardware, machine-fingerprint discontinuity across interview stages, and, in recorded analysis, indicators of manipulated or synthetic video.
What should I do when an interview is flagged?
Review the evidence timeline, look for corroboration across independent signals, and follow a consistent internal process. Treat the report as documentation supporting a human decision, not as a verdict.
Can flagged interviews be used in a hiring dispute?
Reports are exportable to PDF with timestamped, evidence-linked findings, which is what makes them usable in HR review and audit. How they are used in a dispute is a matter for your own policy and counsel.
ScreenComply is under contract with the State of Montana. SOC 2 Type 2 examination in progress.
See a session, a detection, and a report
A short walkthrough of live detection, Detect versus Prevent mode, and the integrity report your reviewers would actually receive.