Skip to content
→ All work

Case study 11 / 26

TalentSentinel

Live AI job interviews in the browser — follow-up questions grounded in what the candidate said — ending in a transcript and an evidence-backed assessment.

Status
Working build
Domain
ai · web · security
Source of claims
Private repository README (reviewed). Source and deployment are not public.

A candidate joins with camera and microphone; an AI interviewer asks one question at a time, adapts difficulty and generates follow-ups from the candidate's answers over a WebSocket session with speech per turn. The report scores technical, communication and confidence, and is explicitly framed as decision support, not a hiring decision.

01/The problem

Screening interviews are slow and inconsistent. An AI interviewer can run them at scale — but only if it treats the candidate's words as evidence rather than instructions, and is honest that its verdict can be wrong.

02/The system

A candidate joins with camera and microphone; an AI interviewer asks one question at a time, adapts difficulty and generates follow-ups from the candidate's answers over a WebSocket session with speech per turn. The report scores technical, communication and confidence, and is explicitly framed as decision support, not a hiring decision.

03/Scope

  1. 01A stateful, turn-based interview over WebSocket with text-to-speech per turn and faster-whisper speech recognition.
  2. 02Provider-abstracted AI (Ollama, OpenAI, Anthropic, Gemini, OpenRouter) — swapping providers is configuration.
  3. 03Structured reports: technical, communication and confidence scores, strengths and weaknesses, and a hire/hold/no-hire recommendation.
  4. 04A strictly layered backend — routes, services, repositories — with JWT access tokens and rotated, hashed refresh tokens.
  5. 05Uploads size-capped before reading, content-type allowlisted and owner-checked on download; rate limiting on auth, interviews and uploads.

04/Engineering

Prompt injection is a threat model

Candidate speech is treated as content to assess, never as instructions; the system prompt says so and free-text input is length-capped.

Fails closed in production

Startup refuses SQLite, wildcard CORS and weak JWT secrets in production, so a misconfigured deployment cannot boot insecure.

Audit findings stay fixed

Regression tests cover each vulnerability found in a production-readiness audit — path traversal, cross-tenant access, upload limits, CSV injection, RBAC.

05/Interface

Interface screenshots of this commercial product are not public. The visual above is an abstract representation of its modules — not the product itself.

06/Tech stack

  • FastAPI
  • Python 3.13
  • SQLAlchemy 2 (async)
  • Celery
  • Redis
  • PostgreSQL
  • React 19
  • TanStack Start
  • WebSockets
  • faster-whisper

07/Result

Verified outcomes

  • Backend and frontend test, lint and type suites run in CI on every push.

Known limitations

  • Assessments are decision support, not hiring decisions, and can carry bias.
  • Privacy and terms pages are templates awaiting legal review.

08/Links

Private commercial codebase — no public links.

Next case study

Restro POS →