Trust · for IT and security teams

Network requirements

Every host and port a Hireanex interview needs, so your team can allowlist the service on a filtered corporate network.

Describes what the product connects to today. Candidates join from a browser link and never install anything. Interviewers use the same browser room plus the dashboard. If your filter still blocks Hireanex after you apply this list, email admin@hireanex.com with your filtering vendor and we will help.

Last updated: September 30, 2026

Quick fixes for candidates

If the interview link will not open, one of these usually gets you in within a few minutes:

  • Try a personal phone or computer. Join from a device your employer does not manage, on home Wi-Fi or a mobile hotspot.
  • Switching networks on a work laptop may not help. Work devices often carry a security agent that filters web traffic on any network, including a phone hotspot, so the same block follows the device.
  • Ask your IT team to allowlist the hosts below. Send them this page: hireanex.com/network-requirements.

Hosts to allowlist

All HTTPS and WSS traffic uses TLS on port 443. The LiveKit wildcard *.livekit.cloud covers the signalling host and the TURN hosts listed separately below.

HostProtocol and portPurposeCandidateInterviewer
hireanex.com
www.hireanex.com
HTTPS 443The web application: pages, scripts, fonts, the self-hosted video-background engine (/mediapipe/) and the error-reporting relay (/monitoring).RequiredRequired
api.hireanex.com
HTTPS 443, WSS 443The Hireanex API: session state, the pre-join network check (/health), and the interviewer's live assist and transcription WebSockets under /ws/.Required (HTTPS)Required (HTTPS and WSS)
uscreen-production-l2v6xcom.livekit.cloud
WSS 443Video call signalling (LiveKit Cloud). Covered by the wildcard *.livekit.cloud.RequiredRequired
*.turn.livekit.cloud
TCP 443 (TURN over TLS)Media relay when UDP is blocked.RequiredRequired
*.host.livekit.cloud
UDP 3478TURN over UDP, which helps establish media connectivity.RecommendedRecommended
LiveKit media servers (any host)
UDP 50000–60000, TCP 7881Direct WebRTC audio and video: the best quality and lowest latency.RecommendedRecommended
*.r2.cloudflarestorage.com
HTTPS 443Recording playback in the dashboard and on shared report links, through signed URLs that expire after one hour.Not neededRequired for playback
download.hireanex.com
HTTPS 443Installer download for the Secure Interview Check desktop app. Only relevant when your organization has that module enabled.Only with Secure Interview CheckNot needed
useuscreen.com
www.useuscreen.com
api.useuscreen.com
recordings.useuscreen.com
HTTPS 443Legacy domains from the previous product name. useuscreen.com redirects to hireanex.com (HTTP 308); the API and recordings hosts are kept for older links.OptionalOptional
  • Speech-to-text audio from the interviewer's browser goes to api.hireanex.com over WSS (/ws/deepgram-stream). The browser never connects to the transcription provider directly.
  • Error reporting is relayed through hireanex.com/monitoring. The browser does not connect to sentry.io, and the application works identically if reporting is blocked.
  • Fonts and the MediaPipe WebAssembly engine are served from hireanex.com. No public CDN, analytics or tag manager is loaded. The application's Content Security Policy allows outbound connections only over https: and wss:.
  • Interview invitations and reminders are sent from noreply@hireanex.com. Add hireanex.com to your mail-filter allowlist so they are delivered.

Video calls: UDP and TCP fallback

Live audio and video run over WebRTC through LiveKit Cloud. The signalling connection is a secure WebSocket on port 443; the media itself prefers UDP.

  • UDP allowed (UDP 50000–60000 to the media servers, or at least UDP 3478 to *.host.livekit.cloud): calls take the direct path with the best quality and lowest latency.
  • UDP blocked: the browser falls back to TURN over TLS on TCP 443 (*.turn.livekit.cloud). The call still works, with higher latency and a slower join. Hireanex automatically retries a failed join in relay-only mode with a longer connection budget for exactly this case.
  • UDP and TCP 443 to *.turn.livekit.cloud both blocked: the call cannot connect.

LiveKit's own firewall guidance is the canonical reference: docs.livekit.io/home/cloud/firewall.

What a blocked network looks like

A URL filter that has not categorized hireanex.com typically produces one of these symptoms while every other site loads normally:

  • Chrome or Edge shows ERR_SSL_PROTOCOL_ERROR, “This site can't provide a secure connection”, or a “Not a secure connection” warning on hireanex.com.
  • The invitation link opens a blank page or a vendor block page, or times out.
  • The page loads but the room never connects: the pre-join network check reports “offline”, or the call stays on “Connecting” and fails.

A quick way to tell a filter from an outage: on the same device and network, open google.com. If Google loads and hireanex.com does not, the network is not down: a filter is singling out Hireanex, and allowlisting the hosts above is the fix. Our live service status is at hireanex.com/status.

Web filter categories

At the time of writing, Hireanex is classified as Online Meetings by Cisco Talos, Computer-and-Internet-Info (Low Risk) by Palo Alto Networks, and Business by FortiGuard. If your web filter still blocks hireanex.com or api.hireanex.com, tell us which filtering vendor you use and we will file the categorization review with them.

Checking from the filtered network

Run these from a machine on the filtered network. The examples are for Windows; on macOS and Linux use curl instead of curl.exe.

nslookup hireanex.com
curl.exe -v https://hireanex.com

Expected on an open network:

  • nslookup returns public addresses (currently 216.150.1.193 and 216.150.16.193).
  • curl.exe -v completes the TLS handshake (TLS 1.3, with a certificate issued for hireanex.com) and returns HTTP/2 200 or a redirect.

Signs of a block:

  • nslookup returns no address, a private address, or the filter's own sinkhole address.
  • curl.exe -v fails during the handshake (for example schannel errors, SSL_ERROR_SYSCALL or Connection reset), shows a certificate issued by the filtering appliance rather than for hireanex.com, or returns an HTTP 403 block page.

Repeat the curl.exe -v check against the API and the video host to confirm each one separately:

curl.exe -v https://api.hireanex.com/health
curl.exe -v https://uscreen-production-l2v6xcom.livekit.cloud

Need help?

Email admin@hireanex.com with the symptom you see and your filtering vendor. For how we protect the data that crosses these connections, see our Security page.