Associate Software Developer, since May 2026
The Secure Browser, from the interface to the operating system.
Talview's Secure Browser enforces an online exam's rules on a candidate's computer. I joined as an intern in September 2025 and became an Associate Software Developer in May 2026. Select a layer in the drawing, or scroll.
Interface
Electron and React
The part a candidate sees. The app is an Electron shell with a React interface, and I built both the interface and what surrounds it.
- Electron and React
- Electron is the app framework and React is the UI library, built with Rsbuild. I compared Electron and Tauri on more than ten criteria, and Electron won.
- Four installers
- The app is packaged for Windows and macOS as EXE, MSI, MSIX and DMG installers.
- Custom PDF viewer
- A PDF viewer I built into the app.
- Custom CSPs
- Content security policies written for the app, to limit what its pages can load.
- Domain blocking
- Blocklisted and whitelisted domains, with 25+ approved domains in the exam policy.
- Deep link launch
- A custom protocol, so the app can be launched from a link.
- Remote proctoring
- Twilio video and nut.js, running at the Electron level, with device control and monitoring at 30 to 40 ms latency.
Native agent
A C++ sidecar on Windows and macOS
A web page cannot see processes or devices. The agent can. It runs next to the Electron app as a C++ sidecar, and I took it from prototype to a background service.
- Sidecar
- A C++ process that runs beside the app. On Windows it is a service, and on macOS it is a daemon.
- Named pipes and Unix sockets
- The app and the agent talk over named pipes on Windows and Unix sockets on macOS.
- Configurable policy
- Every feature can be turned on or off in the configuration. The processes to restrict are whatever the configuration lists, any number of them. The default list has 30. A configuration can also be updated during an active session, when an update arrives with new settings.
Operating system
12+ security controls on low-level OS APIs
Where an exam's rules are enforced. I built 12+ security controls on low-level OS APIs, in the C++ agent.
- Process killing
- Any process that the configuration restricts is ended.
- Virtual machine detection
- The agent detects when the exam is being run inside a virtual machine.
- Screenshot and recording prevention
- The exam screen cannot be captured by screenshots or screen recording.
- Mirroring and extended displays
- Screen mirroring and extended displays are detected and blocked.
- Keyboard shortcut blocking
- Shortcuts that would leave the exam or reach other apps are blocked.
Prototype to release
From the first intern build to a shipped product
The Secure Browser started as an internship prototype and is now the product I work on full time.
- First version
- As an intern I built the first version with Electron, React and a custom C++ native agent. That prototype is what the team later hardened.
- Prototype to release
- I carried the Secure Browser from prototype through in-house alpha testing to release.
- Today
- Associate Software Developer since May 2026, working across the interface, the agent and the OS controls.