# Anti-cheat & proctoring

Every test picks one of three levels. Signals are surfaced to you; nothing
auto-disqualifies a student — you judge.

| Level | What it does |
| --- | --- |
| **light** | Server-side timing, one submission, resume-safe autosave |
| **standard** (default) | + per-student question & option shuffling, tab/app-switch counting, paste discouragement, submission metadata |
| **heavy** (Pro) | + required fullscreen where the platform supports it, webcam snapshots on a timer and on tab-switch, consent screen |

## What this honestly cannot do

No online proctoring can stop a second phone on the desk, a person sitting
off-camera, or a determined impersonator. Heavy mode **deters and documents**
— snapshot timelines and integrity counts let you confront anomalies — but it
is evidence, not prevention. We would rather tell you this than sell you
certainty that does not exist.

## Data care

Snapshots are compressed, visible only to the test's organizer, and deleted
after 30 days. Students consent on-screen before the camera starts; by
enabling heavy mode you confirm you are entitled to collect this from your
students (for minors, that responsibility is yours as the institution).
Timing is enforced by the server clock — a student's device clock changes
nothing. Embedded players cannot force fullscreen, so heavy tests downgrade
to standard inside embeds and you are warned at publish.
