Approved-origin navigation
Top-level navigation is restricted to approved ProctorEdge origins using centralized URL policy checks.
Installable exam browser for controlled ProctorEdge exam access, time-bound launch links, and minimized session-event logging.
ProctorEdge Browser is the installable application candidates use to open authorized exam links. It keeps navigation inside approved origins, blocks unsafe browser behaviors, and produces minimized audit events for review.
The browser controls behavior inside the ProctorEdge application. Stronger production assurance such as signed release trust, backend attestation, update enforcement, and full owner dashboards are planned platform layers around the browser.
From installation to controlled launch, every step is designed to keep exam access inside approved ProctorEdge boundaries.
The candidate installs the approved ProctorEdge Browser before the scheduled exam slot.
The candidate receives a ProctorEdge-controlled exam URL during the activation window, such as one hour before the exam.
Normal browsers should show instructions only. The real exam starts only after ProctorEdge Browser and the backend approve the launch.
The browser applies approved navigation, popup, download, certificate, shortcut, permission, and recovery controls.
For Live+ sessions, Secure Browser can launch the Candidate Companion with the shared exam session token — enabling proctor chat and session status without leaving the controlled exam environment. Companion apps are in active development; see Live Proctoring for the full platform story.
Local browser enforcement for navigation, popups, downloads, certificates, shortcuts, permissions, and minimized event logging.
Top-level navigation is restricted to approved ProctorEdge origins using centralized URL policy checks.
Unmanaged child windows and external popup escapes are denied by default.
Downloads are cancelled in the current secure-browser scope to reduce uncontrolled file movement.
Certificate errors are rejected and routed to safe local recovery views.
Browser and debug shortcuts are blocked in exam mode where Electron can enforce them.
The browser records structured security events without passwords, answers, raw keystrokes, page content, or personal files.
Some high-assurance capabilities require platform and backend support beyond the local browser shell. They should be planned and verified before being treated as production controls.
| Capability | Status | Why it matters |
|---|---|---|
| Signed production installer | Planned | Allows candidates and backend services to trust approved browser builds. |
| Signed updates and minimum-version enforcement | Planned | Prevents outdated or unapproved builds from starting exam sessions. |
| Backend launch-token validation | Planned integration | Binds candidate, provider, voucher, exam, time slot, and browser session. |
| Owner event dashboard | Planned integration | Lets authorized owners and reviewers inspect attempt timelines from backend records. |
| Device and environment risk signals | Future review | Must be privacy-reviewed, tested, disclosed, and treated as review signals. |
The same exam URL behaves differently depending on whether it is opened in a normal browser or ProctorEdge Browser.
If the candidate opens the exam link in Chrome, Edge, Firefox, or another normal browser, the page should show installation and opening instructions and must not deliver exam content.
If the candidate opens the link inside ProctorEdge Browser, the backend can validate the launch token, schedule, candidate, voucher, app version, and policy before returning the approved exam route.
Use ProctorEdge Browser with a provider workflow, scheduled attempt, time-bound launch link, and owner-visible event review plan.