Security
Careers, credentials and money live here.
That is the threat model we design against. This page describes the controls in plain language — what is live in production today, and what is roadmap.
A one-time, human-reviewed account identity check is live today. For exam registrations (e.g. IELTS), a live selfie, a short live verification video and a live identity-document capture are required before admission — human-reviewed, never an automated pass/fail. On exam day, a fresh live selfie and liveness check confirm the same candidate is starting the attempt, again human-reviewed. During the exam itself, tab switches, window focus, fullscreen exit/restore, network changes and copy/paste are monitored and logged for human review — no automated pass/fail. Automated face-matching and computer-vision analysis are not configured; repeated biometric checks before ordinary hiring-assessment attempts remain on our roadmap, not live yet.
TOTP-based multi-factor with one-time recovery codes; required for employer admins and platform staff.
TLS in transit, encryption at rest for identity documents, media answers and payment records.
Active session list, per-device sign-out, and automatic invalidation on password or MFA change.
Privileged actions — score overrides, permission changes, credential revocations — are logged and reviewable.
Payments flow through NOWPayments; ELAREH never holds private keys. Addresses display exactly, always LTR.
Your controls
Security you can see
Security settings are written for people, not auditors: every session visible, every device nameable, every alert explained with a next step.
- Firefox · Lagos, Nigeria
This device · signed in 2 h agoCurrent - Safari · Lagos, Nigeria
Phone · signed in 3 d ago - Chrome · Unrecognised location
Blocked pending your confirmation
Examination security
Integrity without theatre
High-stakes results need protection — and candidates need dignity. Monitoring scope is disclosed before consent, signals are reviewed by people, and no one is ever auto-labelled a cheat by a model.
How proctoring worksResponsible disclosure
Found something?
Report vulnerabilities to [email protected]. We commit to acknowledgement within 72 hours, no legal action for good-faith research, and credit where wanted.
A PGP key and full disclosure scope are not published yet — write to the address above and we'll coordinate directly.
Security questions before a pilot?
We answer security questionnaires as part of every enterprise conversation.