Case study 11 / 26
TalentSentinel
Live AI job interviews in the browser — follow-up questions grounded in what the candidate said — ending in a transcript and an evidence-backed assessment.
- Status
- Working build
- Domain
- ai · web · security
- Source of claims
- Private repository README (reviewed). Source and deployment are not public.
A candidate joins with camera and microphone; an AI interviewer asks one question at a time, adapts difficulty and generates follow-ups from the candidate's answers over a WebSocket session with speech per turn. The report scores technical, communication and confidence, and is explicitly framed as decision support, not a hiring decision.
01/The problem
Screening interviews are slow and inconsistent. An AI interviewer can run them at scale — but only if it treats the candidate's words as evidence rather than instructions, and is honest that its verdict can be wrong.
02/The system
A candidate joins with camera and microphone; an AI interviewer asks one question at a time, adapts difficulty and generates follow-ups from the candidate's answers over a WebSocket session with speech per turn. The report scores technical, communication and confidence, and is explicitly framed as decision support, not a hiring decision.
03/Scope
- 01A stateful, turn-based interview over WebSocket with text-to-speech per turn and faster-whisper speech recognition.
- 02Provider-abstracted AI (Ollama, OpenAI, Anthropic, Gemini, OpenRouter) — swapping providers is configuration.
- 03Structured reports: technical, communication and confidence scores, strengths and weaknesses, and a hire/hold/no-hire recommendation.
- 04A strictly layered backend — routes, services, repositories — with JWT access tokens and rotated, hashed refresh tokens.
- 05Uploads size-capped before reading, content-type allowlisted and owner-checked on download; rate limiting on auth, interviews and uploads.
04/Engineering
Prompt injection is a threat model
Candidate speech is treated as content to assess, never as instructions; the system prompt says so and free-text input is length-capped.
Fails closed in production
Startup refuses SQLite, wildcard CORS and weak JWT secrets in production, so a misconfigured deployment cannot boot insecure.
Audit findings stay fixed
Regression tests cover each vulnerability found in a production-readiness audit — path traversal, cross-tenant access, upload limits, CSV injection, RBAC.
05/Interface
Interface screenshots of this commercial product are not public. The visual above is an abstract representation of its modules — not the product itself.
06/Tech stack
- FastAPI
- Python 3.13
- SQLAlchemy 2 (async)
- Celery
- Redis
- PostgreSQL
- React 19
- TanStack Start
- WebSockets
- faster-whisper
07/Result
Verified outcomes
- Backend and frontend test, lint and type suites run in CI on every push.
Known limitations
- Assessments are decision support, not hiring decisions, and can carry bias.
- Privacy and terms pages are templates awaiting legal review.
08/Links
Private commercial codebase — no public links.
Next case study
Restro POS →