SkillCort Trust Center
SkillCort Public Governance Report
A sanitized, versioned view of verified governance controls and documented limitations, bound to a source governance manifest version and hash.
- Public Trust Statement
- v1.8.0
- Source governance manifest
- v1.6.0
- Last verified
- 5 August 2026
- Status
- Closed with documented limitations
Report actions and source hash
Source manifest SHA-256: e94f722bc45ac881b621355a87d1c412b1b3078979b63249c406520f6be149f7
Executive summary
SkillCort's governance core is closed with documented limitations. Human evaluators own scores and human users own workflow decisions; AI outputs are advisory, provenance is recorded, outcome history is versioned, and incident and pause controls are active. Several candidate-facing and automation capabilities are not yet active and are listed openly below.
Verified control areas
| Area | Status | Summary |
|---|---|---|
| Human outcome ownership | Verified | Authorized human evaluators own scores, and human users own workflow decisions. Outcome changes are recorded. |
| AI provenance | Verified | Where AI is used, the model identity and relevant configuration context are recorded, and AI generations can be traced to their configured context. |
| Versioned score and decision history | Verified | Score and decision changes are kept in an append-only history, and direct writes to outcome tables are restricted. |
| Incident and pause controls | Verified | Critical AI functions can be paused, and incidents can be routed for review. A pause stops the AI provider call and never scores or rejects a candidate. |
| Candidate AI disclosure | Verified | Candidates are informed when AI is used in an assessment. |
| In-app governance notification delivery | Verified within controlled scope | In-app governance notification delivery has been verified in production within a controlled scope. |
| Data retention execution | Verified | Per-workspace retention windows are enforced automatically for monitoring media AND for assessment records (responses, scores, notes, decisions — 24-month default, organization-configurable). Operational logs and organization offboarding follow published schedules, executed by the same daily automation. |
| Consented proctoring capture | Verified | Camera, screen, and microphone capture are each turned on per assessment by the organization and are disclosed to the candidate on the consent screen before the exam starts. Nothing is captured unless the organization enables it. |
| Human-only identity comparison | Verified | For ID-verified sessions an organization may attach a reference photo of the candidate. It is stored privately, disclosed to the candidate on the consent screen, and shown only to a human reviewer beside the session selfie and photo ID. The reference photo is never fed to automated matching, and the organization can remove it at any time. (Separately and only when a delivery requires ID verification, a disclosed face-verification service may compare the session selfie with the captured ID photo — see AI Governance.) |
Current limitations
| Area | Status | Summary |
|---|---|---|
| Candidate acceptance/decline | Not active | Candidate-facing AI participation acceptance and decline controls are being implemented and are not currently active. |
| AI-free alternative | Not guaranteed | SkillCort does not guarantee or automatically create an AI-free alternative assessment. An organization may choose to offer a separate process. |
| Candidate appeal workflow | In progress | A structured in-product candidate appeal flow is in progress. Candidates can raise concerns through the hiring or certifying organization. |
| Notification worker | Deployed, disabled | The notification delivery worker is deployed but disabled and runs only under explicit configuration. |
| Detection scheduler | Not active | Scheduled automated detection is not active. |
| Email governance delivery | Not active | Email delivery of governance notifications is not active. |
| Active-session withdrawal enforcement | Deferred | Enforced withdrawal from an in-progress live session is deferred to a future implementation. |
| Realtime event-level provenance | Deferred | Event-level provenance for realtime sessions is deferred. |
| Extended point-in-time recovery | Not enabled | Backups run daily. Extended point-in-time recovery is not currently enabled. |
| AI-assisted proctoring review | Auto on review-open, human-adjudicated | AI helps scan a session's webcam images, screen images and microphone recording, and points to moments worth a closer look — on the webcam, for example no face, more than one person, a phone, or earphones; on the screen, for example an AI-assistant window, a search engine, a messaging app or a remote-control tool; in the audio, transcribed speech segments such as the question being read aloud or dialogue patterns — speaker identity is never claimed, and the reviewer listens to the actual recording. Notes never quote personal or private content. The scan starts automatically when a reviewer opens the session for review; it never runs unattended, never makes or changes a decision, and every flagged moment carries an explicit human verdict (confirmed or dismissed) recorded with the reviewer and time. This analysis runs on OpenAI models; the reviewer, verdicts and recordings stay within SkillCort. |
| Legal documents | In preparation | SkillCort's Terms, Privacy Notice, Data Processing Addendum and related legal documents are being prepared and are not yet generally available. |
Evidence approach
Statuses above reflect different kinds of evidence:
- Verified — production evidence exists for the stated scope.
- Controlled validation — verified within a bounded, controlled scope.
- Architecture in place — the design exists but is not yet active in production.
- Not active / deferred — the capability is not currently available or enforced.
This report does not expose internal evidence packs or operational detail.
Version history
- Trust Statement v1.8.0Product-data retention execution verified; limitation retired
- Source manifest:
- v1.6.0
- Source verified:
- 5 August 2026
Automated retention execution now covers assessment records (responses, scores, evaluator notes, decisions — 24-month default, organization-configurable), operational logs, and organization offboarding (30-day export window, then deletion from active systems with backup-cycle aging), alongside the existing monitoring-media sweep. Governance limitation L-13 (broad retention execution not active) is retired in manifest v1.6.0 with production evidence; the published privacy policies and Terms of Use state the same schedule.
- Trust Statement v1.7.0Third-party AI providers named; avatar provider changed
- Source manifest:
- v1.5.0
- Source verified:
- 3 August 2026
The third parties behind AI-guided assessment sections are now named to candidates and on this site: OpenAI processes candidate speech (understanding and the interviewer's voice) and powers the AI-assisted proctoring review; HeyGen generates the interviewer's on-screen presenter and receives only the interviewer's lines — never candidate audio or camera. The per-question interviewer clip renderer moved from D-ID to HeyGen; that path renders authored question text only and carries no candidate data. Governance risk R-12 (third parties not yet named) is retired in manifest v1.5.0.
- Trust Statement v1.6.0Source manifest updated; AI review production verification recorded
- Source manifest:
- v1.4.0
- Source verified:
- 2 August 2026
This statement now binds to governance manifest v1.4.0. The manifest records that the human-adjudicated AI review surfaces (webcam, screen, audio, ID name-check) have each been exercised by reviewers on real production sessions, with the runs held in the provenance ledger. No public control, limitation or consent statement changes — the source binding and verification date are refreshed.
- Trust Statement v1.5.0AI review extended to the microphone recording
- Source manifest:
- v1.3.0
- Source verified:
- 26 July 2026
The human-adjudicated AI review now also transcribes a session's microphone recording (when the organization enabled mic capture and the candidate consented) and flags speech segments worth listening to — the question read aloud, dialogue or answer-dictation patterns. Speaker identity is never claimed, the reviewer always listens to the actual audio, every flag receives an explicit human verdict, and notes never quote personal content. The candidate consent screen names AI-assisted transcription in lockstep.
- Trust Statement v1.4.0AI review extended to screen captures
- Source manifest:
- v1.3.0
- Source verified:
- 26 July 2026
The human-adjudicated AI review now also scans a session's screen captures — flagging visible AI-assistant windows, search engines, messaging apps, remote-control tools and unrelated windows. Same guarantees as the webcam review: runs only in reviewer context, never decides, every flag human-adjudicated; AI notes never quote personal message content.
- Trust Statement v1.3.0AI webcam review runs on review-open; per-flag human verdicts
- Source manifest:
- v1.3.0
- Source verified:
- 26 July 2026
The AI webcam scan now starts automatically when a reviewer opens a session (previously click-to-run). It still never runs unattended and never decides: each flagged moment receives an explicit, audited human verdict — confirmed or dismissed.
- Trust Statement v1.2.0Identity reference photo disclosure
- Source manifest:
- v1.3.0
- Source verified:
- 26 July 2026
Discloses the org-provided identity reference photo: candidate-notified on the consent screen, human-reviewer comparison only, never fed to automated matching, org-removable at any time.
- Trust Statement v1.1.0Proctoring capture and AI-assisted review disclosure
- Source manifest:
- v1.3.0
- Source verified:
- 21 July 2026
Names microphone capture (organization-enabled, candidate-consented) alongside camera and screen, and discloses staff-triggered, human-in-the-loop AI review of webcam images that never makes an automated decision.
- Trust Statement v1.0.0Initial public publication
- Source manifest:
- v1.1.0
- Source verified:
- 20 July 2026
Public publication of verified governance controls and documented limitations.
Change triggers
This report is reviewed when:
- A material governance control changes
- A new AI provider or model is introduced
- Candidate acceptance/decline behavior changes
- Candidate appeal behavior changes
- Score or workflow decision ownership changes
- Recording, proctoring or biometric processing changes
- Scheduler, email or retention automation changes
- A legal or consent document is published
Public-safe disclaimer
This report describes verified SkillCort product controls and documented limitations. It is not a legal opinion, regulatory certification, or guarantee of customer compliance.
Public Trust Statement v1.8.0 · source governance manifest v1.6.0 · last verified 5 August 2026.
More in the Trust Center
- AI GovernanceWhere SkillCort uses AI, and where AI does not have final ownership.
- Human Decision ControlPeople own assessment outcomes; AI outputs stay advisory.
- Candidate RightsWhat the candidate experience is today, described honestly.
- Security & PrivacyHow SkillCort approaches privacy-by-design, access, retention and backups.
- AccessibilityThe accessibility target and current state, without overstating conformance.
Public Trust Statement v1.8.0 · source governance manifest v1.6.0 · last verified 5 August 2026 · Closed with documented limitations.