The Control Journal
GuidesSeptember 5, 20268 min read

Does a Remote Interview Show Where You Actually Are?

Your IP is logged by the assessment platform, the video call, and the employer's fraud review. What each layer sees about your location, as of September 2026.

CControl Editorial Team

Your location is not proctored, but it is recorded. A coding assessment logs the IP address you connect from and notices when it changes mid-test. A video interview logs your IP, your resolved geographic location, and your network type in the meeting platform's admin records. Neither is watching you the way a webcam proctor is. Both feed a review that, since 2026, is looking much harder at whether candidates are where they say they are.

This article is about the location layer of remote hiring: what each system observes, why employers sharpened these checks in 2026, and which ordinary situations — a corporate VPN, a coworking network, a week of travel — produce the same signal as the fraud the checks were built to catch. It is a separate question from whether a platform can confirm who you are, which is covered in this guide to identity verification in remote technical hiring, and separate again from what your machine reveals, covered in what each layer can observe about a virtual machine.

What an assessment platform records about your network

Assessment vendors treat the IP address as a consistency check, not a location check. The stated purpose is to notice that the person who opened the test is the person who finished it.

Codility documents an IP Check that "matches the IP address to ensure that the candidate is completing a Codility test from the same device and location," and flags a session when "a candidate opens and completes a Codility CodeCheck test from a different IP or switches IP addresses mid-test" (Codility, How Codility Detects Fraud In Online Code Testing). The suspicion being tested is forwarding — that the link was handed to someone else — not geography.

CodeSignal describes the same signal as context rather than evidence, listing "IP tracking and location signals to add context when reviewing potential integrity concerns" alongside its Suspicion Score, which the company says analyzes "solution similarity, telemetry, and copy-paste activity" (CodeSignal, Cheating Detection & Fraud Prevention).

HackerRank is the useful contrast. Its test integrity documentation describes copy-paste capture, tab-proctoring windows, webcam snapshots, and AI plagiarism analysis — and does not describe network or location signals at all (HackerRank, Test Integrity). The absence matters: proctoring coverage and location coverage are different products, and a platform can be aggressive at one while indifferent to the other. For the full set of signals one vendor stacks together, see this breakdown of what Codility's integrity stack detects.

None of these systems geolocates you as a feature. They record an address, and someone else decides what it means.

What the video call records

A live interview leaves a more detailed trace than most candidates assume, though not to the interviewer.

Zoom's meeting dashboard exposes three participant fields to account administrators: "IP Address: IP address of the device the participant is or was connecting from," "Location: Geographical location of the participant," and "Network Type: Network type of participant. For example, wired, WiFi, or 4G" (Zoom, Dashboard for meetings and webinars).

The person conducting your interview does not see those fields during the call. They sit in the administrative record of the account that hosted the meeting, retrievable later by whoever has admin rights — which, in a hiring context, is the employer. A recruiter comparing an application that says Ohio against a dashboard row that resolves to Warsaw is not doing forensics. They are reading a report.

Why employers started checking in 2026

The controls that catch legitimate candidates were designed for a specific, documented fraud.

In April 2026 the Department of Justice announced sentences for two U.S. nationals who "managed and operated 'laptop farms' intended to deceive victim employers into believing they had hired U.S.-based IT workers," hosting hundreds of employer-issued computers at their residences and connecting them "to hardware devices designed to allow for remote access (referred to as keyboard-video-mouse or 'KVM' switches)." The scheme placed North Korean IT workers at more than 100 U.S. companies using the stolen identities of at least 80 Americans (U.S. Department of Justice, April 15, 2026).

The defensive playbook that followed is explicit about location. Counsel at Skadden advising employers on the pattern recommends binding corporate laptops to verified identities and "restricting access by geography or Autonomous System Number (ASN)," analyzing "login patterns to identify workers logging in from suspicious or frequently changing locations, or multiple workers logging in from the same IP address," sending work equipment "only to the address listed on the worker's identity documents," and preventing workers from installing "unauthorized software — particularly VPNs or remote access tools — onto work laptops unless preauthorized" (Skadden, June 8, 2026).

Read that list as a candidate and the shape of the problem is clear. Frequently changing locations, an IP shared with another applicant, a VPN in the path, and an address that does not match your documents are the four things being looked for. A remote worker with a normal life produces at least one of them regularly.

The mismatches that flag an honest candidate

Each of these is unremarkable in isolation and indistinguishable, at the log level, from the pattern above.

An always-on corporate VPN. If you are taking an assessment on a machine your current employer manages, your traffic may exit through a data center in another country, and you may not be permitted to turn it off. Your IP will not resolve anywhere near you.

A network handoff mid-test. Home Wi-Fi drops, the phone hotspot takes over, and the session now has two IP addresses. Codility names this scenario itself, cautioning that when a check returns a flag "it is not a guarantee that the candidate has cheated (e.g. your candidate had connection issues, so they had to switch from their home network to a mobile network)."

A shared address. Coworking spaces, university networks, apartment buildings behind carrier-grade NAT, and households with two people job-hunting can all put two candidates on one IP. That is the "multiple workers logging in from the same IP address" signal, arriving innocently.

Travel. Interviewing during a trip means your location contradicts your application, your timezone contradicts your IP, and your interview slots sit at odd local hours. Nothing about this is dishonest, and all of it looks like drift.

A privacy VPN you forgot about. Consumer VPNs that launch at boot are common, and they place a commercial ASN between you and the assessment for no reason connected to the interview.

What a flag actually does

Less than the word suggests, and more than nothing.

A location flag is a line item on a report a human reads after the fact. It does not stop the assessment, and on its own it establishes only that two addresses differed. Codility's own guidance is that a single flag is not proof and recommends contacting the candidate when there is uncertainty. CodeSignal frames its location signals as context for review rather than as findings.

What it can do is combine. A changed IP alongside a paste burst alongside a webcam gap is a pattern; a changed IP alone is a home internet connection. The practical risk is not the flag but the silence around it — a candidate is rarely told which signal ended a process, which is why it is worth removing the avoidable ones. What happens after a flag is raised is covered in more detail in what happens when a coding assessment flags you.

What to do before a remote assessment or interview

Decide your answer to "where will you be working from" before anything is logged, not after. The location question in remote hiring is usually a right-to-work, tax, and payroll question, and it becomes an integrity question only when the answer changes.

Then reduce the noise:

  • Disconnect a consumer VPN for the assessment unless you have a specific reason to keep it. Check whether it launches automatically.
  • If a corporate VPN cannot be disabled, say so in advance, in writing, to the recruiter. A pre-recorded explanation is worth far more than one offered after a flag.
  • Finish on the network you started on. If a handoff happens anyway, mention it in the same message thread rather than hoping nobody looks.
  • Expect the check to continue past the interview. Equipment shipping to your document address and right-to-work verification arrive later in the process, and a location stated loosely early is harder to correct then.
  • If you are traveling, treat it as a scheduling disclosure rather than a secret. Employers reschedule for travel routinely; they do not overlook a contradiction discovered in a log.

What this does not settle

The location layer says nothing about competence, and it is weak evidence even about location. IP geolocation databases place addresses at the level of a city or a carrier's aggregation point, not a residence, and mobile networks routinely resolve hundreds of kilometers from the device. A VPN defeats it entirely for anyone who wants it defeated, which is precisely why the serious version of this check moved to hardware possession and device binding rather than IP.

That is also the boundary of what candidates should read into the 2026 enforcement wave: the controls are aimed at identity and employment fraud, not at how you prepared. They belong to a different part of the process than proctoring, and they are reviewed by different people.

Where a desktop assistant fits, and where it does not

Control is a desktop AI interview assistant for Windows and macOS that runs as a native overlay, transcribes the conversation in real time, and stays out of supported screen captures without taking focus from the window being shared. Those properties concern what is visible on your screen. They have no bearing on the network layer described here: an overlay does not change your IP address, your resolved location, or the meeting platform's admin record, and no desktop tool should be understood as addressing them.

The narrower point matters more. When an assessment moves out of the browser into a lockdown application, that class of tool is the target rather than a bystander — HackerRank's Desktop App Mode documentation states that it "blocks the use of other applications during the test," names AI assistants among them, and prevents virtual machines, screen sharing, and remote access. If you are being asked to install one, read what a desktop lockdown assessment installs and watches before you agree, and plan for an unassisted session.

The short version

Assessment platforms log your IP to check consistency, meeting platforms log your IP and resolved location for administrators, and employers now compare both against what you told them, because a documented fraud pattern taught them to. None of these systems proves where you are and none of them is proctoring. The exposure is a mismatch you did not explain: a VPN, a network change, a shared address, or a trip. Say the true thing early, keep your connection boring for an hour, and the layer stops mattering.

If you want to see how a desktop assistant behaves before you rely on one, Control's free allowance covers the first five messages and two minutes of voice, which is enough for a dry run outside a real interview.

Continue exploring