Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

    English (US)
    MX Spanish (Mexico)
    CA French (Canada)
    US English (US)
    • Home
    • Management Tools
    • Security

    reCAPTCHA protection on widgets

    Written by Kat Holtz

    Updated at August 20th, 2026

    Contact Us

    If you still have questions or prefer to get help directly from an agent, please submit a request.
    We’ll get back to you as soon as possible.

    Please fill out the contact form below and we will reply as soon as possible.

    • Getting Started
      Setting up your calendar Managing your alerts Additional Settings
    • Daily Processes
      Candidate Inbox Candidate Profile My Calendar/Calendars Browser Extension My Jobs Approvals Engine Manual and Common Scheduling Practices Form I-9 processes Troubleshooting Forms & Offers
    • Candidate and User Engagement
      Campaigns Conversation Builder Surveys Channels Talent Community Voice Web Management Analytics & Reporting Data Privacy Career Sites
    • Management Tools
      Job Management Scheduling Security Journeys Content Management System (CMS) Multiple Brands Workflows Users, Roles and Permissions Data Feeds Location Management Lookup Tables Assistant Messaging Company Information Client Setup System Attributes Integration Center
    • Contextual AI
      Knowledge Training Library
    • Conversational Events and Campus
      Conversational Events Campus Events
    • Employee Communications
      Communications App Employee Management
    • Release Notes
      2025 2026
    • Workday Feature Descriptions
    + More

    Table of Contents

    Use cases Configuration Step #1: Ensure compliance to Content Security Policy (CSP) Step #2: Enable or disable reCAPTCHA How reCAPTCHA works Where reCAPTCHA is active Data privacy and collection

    Our reCAPTCHA protection is enabled by default across all client web widgets. This comprehensive security layer ensures your defenses are fully maximized against bot traffic and abuse, leading directly to cleaner candidate data and a more secure hiring flow.


    Use cases

    This robust protection layer ensures the integrity of your talent pipeline by:

    • Cleaner Candidate Database: Significantly reducing the number of fake or bot-driven candidate profiles created through conversational applications.
    • Secure Conversations: Guaranteeing that candidates engaging with Olivia are human, and protecting against disruptive platform abuse.
    • Wider Coverage: This enhanced protection is now active across all applicable widget instances by default.

    Configuration

    Step #1: Ensure compliance to Content Security Policy (CSP)

    For reCAPTCHA to work, the client's IT or Security team must allow traffic to the following Google domains in their CSP header. If they don't, reCAPTCHA won't load and they won't have the protection.

    • www.google.com (Main service domain)
    • www.gstatic.com (Used to load necessary scripts and images for the widget)

    Learn more about this in Google’s CSP configuration guide.

    Step #2: Enable or disable reCAPTCHA

    reCAPTCHA is enabled by default. Only users with full access to Client Setup can enable or disable reCAPTCHA  in your account. If needed, contact your Company/Account Admin or CS Representative for assistance.

    To enable/disable reCAPTCHA:

    1. Select the All Apps menu in the upper-left corner of the header and then Settings in its drop-down menu.
    2. When the Settings page opens, select Client Setup under the Paradox Tools section.
    3. Client Setup will then open. Scroll down to and open the Data Privacy section from the left panel.
    4. Under Enhanced Security, enable or disable the Enable reCAPTCHA setting.
    5. In the lower-right corner, select Save. 

    How reCAPTCHA works

    Your browser does not support HTML5 video.

    Our implementation uses Invisible reCAPTCHA, meaning the security check runs silently in the background, offering robust protection without interrupting the candidate experience.

    1. Silent Check: When a candidate starts a key action (like beginning an application), the system analyzes their behavior to calculate a risk score.
    2. Seamless Experience: If the check confirms the user is human, they continue the conversation instantly—they will see nothing.
    3. Visual Challenge (Only if Suspicious): If suspicious activity is detected, a simple visual challenge (like selecting images) will appear. The candidate must complete this to proceed.

    Where reCAPTCHA is active

    This protection is active whenever the widget (the collapsible chat window) is used.


    Data privacy and collection

    reCAPTCHA collects data solely to assess risk. Paradox does not store this information.

    Clients should be aware that the following data is shared directly with Google for the purpose of the security check:

    • IP Address
    • Device and Browser Information (OS, resolution, etc.)
    • User Behavior Patterns (mouse movements, scrolling)
    • Cookies (including the necessary _GRECAPTCHA cookie)

    We recommend clients refer to Google’s privacy policy and applicable Service Specific Terms.

    Was this article helpful?

    Yes
    No
    Give feedback about this article

    Related Articles

    • Tracking pixels

    Copyright 2026 – Paradox.

    Knowledge Base Software powered by Helpjuice

    Expand