Table of Contents
Paradox continuously works to provide you and your team a safe and secure experience while using the platform.
Security updates
The following are security measures added to the Paradox Platform.
Employee login identifier
To avoid security issues around a login identifier that belongs to multiple companies, the following updates were implemented:
- If an employee record is created and its email is later updated manually, an error message will display when the updated email address is already registered by an employee from another company. Users will then need to enter in a different email address.
- Email addresses that are included in an User Data Feed file but are already tied to an employee from another company will cause the file import to fail.
- Paradox Admins can add a user with the same login email to a new company, but any other user cannot.
Preventative measures
SMS pumping fraud
In order to prevent a SMS Pumping Fraud issue, all non-local phone numbers except US, CA, and UK phone numbers will be blocked from sending out SMS notifications. A new SMS Country Whitelist selector on the backend allows your team to select the countries that can be sent SMS messages without a phone number configured on your account.
Employee email address update
Users with full access to Roles and Permissions and users with impersonating access will come across a security measure when updating the email address or phone number for any user with access to 2+ CEM accounts.
For example:
- User A has a login email (created from the "job email" which is what's editable in the UI) of usera@gmail.com. This login email has access to 3 CEM accounts.
- User B has a login email of userb@gmail.com. This login email has access to 1 CEM account.
- User B attempts to update the email address usera@gmail.com of User A’s Employee record to be userb@gmail.com.
With this update, an Update User Details error will display when User B attempts to save User A’s updated Employee record. Action will then need to be taken to allow the update to be made.
Process to update the email address
When a user profile is updated for a user who has access to 2+ CEM accounts, the following will take place depending on how that Employee record is updated:
-
Manually from the CEM:
- When an email address is updated and the record is saved, an error will display and a verification code will be sent to the existing login.
- Roles and Permissions:

- My Profile (for themselves or another user)

- Roles and Permissions:
- The user who’s email address was updated will then need to open the automated Olivia Alerts email sent to the existing login’s email address to view the verification code sent.

- The user will then need to provide this information to the user updating their email address so that they can enter the verification code in the CEM and click the Yes, Make the Changes button to finalize the update.
- When an email address is updated and the record is saved, an error will display and a verification code will be sent to the existing login.
- Public API: The request will be rejected with an Unable to update user due to multi-account access error.
-
User Feeds (Data Feeds):
- If sync_user_email is enabled, the file will display an Unable to update user due to multi-account access error.
- If sync_user_email is not enabled, then the email will be updated on the user profile (UI only), but it will not be authorized until an admin manually goes in and edits the user profile.
Resolve locked out employee issues
If you have a user who is logged out of their active profile due to not having access to their existing login email, then contact your CS Representative or support team for assistance.
System verification
To keep up with modern security practices, there are system verification requirements when a candidate or user enters a secure page that they must log in to.
If a candidate or user enters the wrong verification code five times into the field of the Secure Login page, then they are sent a new verification code and their previous verification code will be invalid.
Candidates and users can request up to 20 codes in a four hour period. To prevent unauthorized access, the account will be temporarily locked after 20 incorrect verification code attempts within four hours.

Below is a list of the secure pages that this system verification process is applied to:
-
User-Related Functionalities:
- Basic User Portal Login
- Basic User Login for Employee Dashboard
- Login with 2FA
- Employee Landing Site Verification
- User Profile Email Security Update Process
- Interview Feedback
- Event Roster
-
Candidate-Related Functionalities:
- Form
- Offer
- Resume
- Document
- View Candidate Data
- PREF Page
- Expire Link
- Video Security
Additional multi-factor authentication practices
Users/Candidates may also have to enter a verification code to access the CEM or specific links within their conversation for additional security. Learn more below: