Table of Contents
Our reCAPTCHA protection is enabled by default across all client web widgets. This comprehensive security layer ensures your defenses are fully maximized against bot traffic and abuse, leading directly to cleaner candidate data and a more secure hiring flow.
Use cases
This robust protection layer ensures the integrity of your talent pipeline by:
- Cleaner Candidate Database: Significantly reducing the number of fake or bot-driven candidate profiles created through conversational applications.
- Secure Conversations: Guaranteeing that candidates engaging with Olivia are human, and protecting against disruptive platform abuse.
- Wider Coverage: This enhanced protection is now active across all applicable widget instances by default.
Configuration
Step #1: Ensure compliance to Content Security Policy (CSP)
For reCAPTCHA to work, the client's IT or Security team must allow traffic to the following Google domains in their CSP header. If they don't, reCAPTCHA won't load and they won't have the protection.
- www.google.com (Main service domain)
- www.gstatic.com (Used to load necessary scripts and images for the widget)
Learn more about this in Google’s CSP configuration guide.
Step #2: Enable or disable reCAPTCHA
reCAPTCHA is enabled by default. Only users with full access to Client Setup can enable or disable reCAPTCHA in your account. If needed, contact your Company/Account Admin or CS Representative for assistance.
To enable/disable reCAPTCHA:
- Select the All Apps menu in the upper-left corner of the header and then Settings in its drop-down menu.
- When the Settings page opens, select Client Setup under the Paradox Tools section.
- Client Setup will then open. Scroll down to and open the Data Privacy section from the left panel.
- Under Enhanced Security, enable or disable the Enable reCAPTCHA setting.
- In the lower-right corner, select Save.
How reCAPTCHA works
Our implementation uses Invisible reCAPTCHA, meaning the security check runs silently in the background, offering robust protection without interrupting the candidate experience.
- Silent Check: When a candidate starts a key action (like beginning an application), the system analyzes their behavior to calculate a risk score.
- Seamless Experience: If the check confirms the user is human, they continue the conversation instantly—they will see nothing.
- Visual Challenge (Only if Suspicious): If suspicious activity is detected, a simple visual challenge (like selecting images) will appear. The candidate must complete this to proceed.
Where reCAPTCHA is active
This protection is active whenever the widget (the collapsible chat window) is used.
Data privacy and collection
reCAPTCHA collects data solely to assess risk. Paradox does not store this information.
Clients should be aware that the following data is shared directly with Google for the purpose of the security check:
- IP Address
- Device and Browser Information (OS, resolution, etc.)
- User Behavior Patterns (mouse movements, scrolling)
- Cookies (including the necessary _GRECAPTCHA cookie)
We recommend clients refer to Google’s privacy policy and applicable Service Specific Terms.