System overview

An exam-proctoring layer, operated by the university.

Examlens records what happens during an online exam session — camera, browser state, lockdown events — and returns one signed integrity report per attempt. It is deployed and operated by the institution itself. No third-party proctoring vendor sits in the data path.

System record
System
Examlens
Role
Proctoring layer for BEZ (Blended Assessment System)
Institution
Management & Science University
Status
Proof of concept — live
Modes
sdk_bez · standalone
Contract
HMAC-SHA256, signed both ways, 5-minute replay window
Deployment
Single tenant — one instance per institution, run by the institution
Sign in to the consoleView the integration surface

Accounts are issued by an administrator — there is no self-registration.

Integration surface

Four endpoints, one callback.

The entire contract between the host exam system and Examlens. Nothing else crosses the boundary — Examlens never receives a question, an answer, or a mark.

EndpointCalled byPurposeAuth
POST /api/sdk/startSDKOpen a proctoring session for an attemptHMAC
POST /api/sdk/snapshotSDKUpload a camera frame, every 15sSession token
POST /api/sdk/eventSDKReport lockdown events, batched every 5sSession token
POST /api/sdk/finalizeSDKClose the session and compute the verdictSession token
POST proctoring_callback.phpExamlensDeliver the signed report back to the host systemHMAC

On the host side the integration is a single include on the exam page. The student never leaves it.

Host system owns
Student authentication, exam definition, question content, rendering, grading, gradebook, and the final academic decision.
Examlens owns
Camera capture, fullscreen and lockdown enforcement, snapshot storage, integrity scoring, reviewer console, and the evidence pack.
Integrity model

Four verdicts. A human always decides.

The verdict is a triage aid — it ranks attempts so a reviewer looks at the right ones first. It is never an accusation, never a grade, and always overridable.

Clean

No signal crossed a threshold. Nothing to review.

Minor

Isolated low-weight events. Usually benign.

Suspicious

Repeated or clustered signals. Queued for review.

Severe

Strong evidence. Escalated to the top of the queue.

Face presence
No face in frame, or a face that no longer matches the baseline captured at session start.
Multiple people
More than one face detected in a snapshot.
Secondary devices
Phones or second screens visible in frame.
Browser lockdown
Fullscreen exits, tab switches, copy/paste, right-click, devtools shortcuts.

Every signal is timestamped against a snapshot. Each attempt can be exported as a single PDF evidence pack for academic-integrity proceedings.

Operating notes

Constraints worth knowing before evaluation.

Browser only

No installer, no desktop agent. Camera, fullscreen, and detection all run in the student's existing browser.

No per-attempt fee

The only marginal cost is optional AI assists initiated by an admin, at roughly $0.0002 per click.

Consent first

The camera prompt is explicit, and the student is told what is recorded before the session starts.

Heuristic, not certified

Thresholds are tunable. No catch-rate claim is made, and every verdict can be overridden by a reviewer.

No SSO yet

In SDK mode identity comes from the host system. Examlens issues no student credentials of its own.

Not an LMS

No courses, transcripts, or curriculum delivery. It runs next to the institution's LMS, not instead of it.

Single tenant

One deployment, one institution. No multi-university provisioning, billing, or plan gating exists.

Proof of concept

No SLA, no SOC 2, no incident runbook, no test suite. Scope is stated plainly so evaluation is about the real thing.