Skip to content
Security

Recorded openly. Isolated by default.

What we record, how each round is kept separate, and who can see the result. Written for the person on your team who has to sign off on a new hiring tool.

Responsible use of scores

A PraxisAI score is evidence for a person to weigh, not a decision. The product is built so a human stays in the loop and candidates know what is happening.

Deterministic and explainable
Bug-fix rounds are scored by fixed, published rules from the recording, with the evidence behind every number. The method, weights and known limitations are on the scoring page.
Human decision
Every hiring report carries a reminder that scores support human judgment and are not meant to be the sole basis for a decision. Nothing rejects a candidate automatically.
Candidate notice
Before they start, candidates are told what is recorded, that an automated tool scores the round, that a person decides, and how to ask for an accommodation or an alternative assessment.
Candidate copy
Candidates get their own copy of the report with a factual summary and coaching. Your verdict wording, risks and interview questions stay with your team.

How recording works

A round happens in a browser-based VS Code. Everything the candidate does with the AI agent passes through our proxy, which is how it can be measured and capped.

Agent traffic
Every prompt, agent step, tool call and token count is logged by the model proxy, with timestamps.
Workspace activity
Edits, files read, terminal commands and test runs are captured from the editor and the container.
Focus and paste signals
Leaving the tab for a long time and pasting large blocks of text are recorded as events. Their content outside the workspace is never captured; there is no screen or webcam recording.
Told up front
Candidates see exactly what is recorded on the page they join from, before they start.

Isolation of sandboxes

Each round gets its own environment, created for it and torn down after it.

One container per round
A separate container and workspace per session, checked out at the task's commit. Candidates never share a filesystem or a process.
Hidden tests stay hidden
The grading tests and reference fix are kept outside the candidate's environment and are applied only at grading time.
Bounded agent
Each round has a hard token limit, set by the hiring team on the link and enforced at the proxy. A round cannot spend beyond it.
Time-boxed
The environment closes when the timer ends; the work is graded as it stood.

Data handling and access

Candidate data is stored to produce the report and is shown only to the people entitled to it.

Who sees a report
The candidate, and members of the hiring team whose link the round came through. Platform staff access it only to operate and support the service.
Database posture
Every table has row-level security switched on with no public policies; only server code holding a secret key can read or write. No database key ever reaches a browser.
Sign in
Hiring teams and candidates sign in with Google or a one-time link sent to their email. Team membership is granted by email by an owner of the team.
Retention and deletion
Ask us at info@praxisai.site to export or delete a candidate's data or your team's data.

Have a security questionnaire?

Send it to info@praxisai.site or through the contact form. We answer honestly, including where we are still early: we do not yet hold a SOC 2 report or an independent bias audit. You can also see exactly what a hiring team receives in the sample report, and how it is scored in the scoring method.

See it on your own hiring loop.

Tell us about the roles you hire for and the assessment format you want to improve.