Inspiration
The hackathon brief named it exactly: generative AI broke trust in hiring on both sides at once. A role that used to draw 30 applicants now draws 500, many templated by the same AI tools, some carrying hidden prompt-injection text aimed at the screening software. On the other side, candidates have no way to tell a real offer from a deepfake recruiter call or a look-alike domain. With a background in AppSec and offensive security, this read less like an HR problem and more like an identity and integrity problem — the kind we already had the tools for.
What it does
GoldenGate is a trust triage layer for the hiring funnel. On the candidate side, it deduplicates applications into one golden record per person, routes ambiguous matches to an LLM tie-breaker, cross-checks each candidate's claimed history against their public footprint, and scans raw resume files for prompt-injection attempts. On the employer side, it reuses the same matching engine to catch typosquatted domains and checks business registration and email authentication. Every result ships with evidence, not a silent score.
How we built it
A blocking step narrows 500 applications down before any pairwise comparison runs. Jaro-Winkler and Levenshtein score name, email, and phone; cosine similarity on resume embeddings adds a fourth signal. Composite scores above 75 auto-merge, below 60 stay distinct, and the gray zone goes to Claude for a structured same/different/uncertain call. A verification agent built on Tavily and Solari checks public and LinkedIn presence, wrapped in Prism for bias and explainability monitoring. The employer side reuses the fuzzy matcher against known-good domains, plus WHOIS age and SPF/DKIM/DMARC checks.
Challenges we ran into
The hardest problem wasn't detection — it was avoiding false flags on honest candidates who simply used AI to polish a resume. Tuning the weight split (45/25/20/10 across name, email, phone, resume) and the 60–75 gray-zone band took real iteration. Prompt-injection detection also had to run on the raw file structure, not the rendered text an LLM would see, which meant a separate pass entirely.
Accomplishments that we're proud of
A full working pipeline end to end in one day — not a mockup, an actual dashboard: 40 applications ingested, 31 resolved to unique candidates, 8 duplicate groups merged, 138 pairs routed for review. The same entity-resolution core does double duty across two very different verification problems, and every flag comes with an audit trail a recruiter can actually inspect.
What we learned
String similarity alone misses real duplicates that an LLM catches instantly by reasoning about content, not characters. And trust tooling only works if it's legible — a silent score gets ignored or distrusted; a flag with evidence gets acted on.
What's next for GoldenGate
Hardening the employer side into a full typosquat and outreach-verification product, expanding the confidence-signal set beyond LinkedIn, cutting LLM cost on the tie-break step, and integrating as a real plug-in layer on top of an existing ATS instead of a standalone tool.
Built With
- claude
- cosine
- jarowrinkler
- python
- similarity

Log in or sign up for Devpost to join the conversation.