Pipeline Defender

Security Monitoring for the
Recruiting Pipeline

Continuous threat detection, permission auditing, and compliance monitoring for your recruiting pipeline. Know when something is wrong before damage is done.

Up to 38*
Detection Rules
40+
API Endpoints
4
SIEM Forwarders

* Coverage varies by platform and tier — see Plans.

AUDIT DETECT ALERT REPORT

Pipeline Defender continuously monitors your ATS for insider threats, hiring fraud, and permission drift — visibility into the security blind spot most ATSes leave open. Purpose-built for the recruiting pipeline, not a generic security tool adapted to it.

The Problem

Your ATS Is an Unmonitored Attack Surface

Your recruiting pipeline handles sensitive PII, compensation data, and executive hiring details. No SSPM tool monitors it. Pipeline Defender changes that.

// 01
Insider Data Exfiltration

Recruiters leaving for competitors export candidate databases. Admin accounts access compensation data, interview notes, and EEO records without oversight.

  • Bulk report exports detected
  • API-based data extraction flagged
  • Off-hours PII access monitored
  • Permission escalation tracked
// 02
Nation-State Hiring Fraud

North Korean operatives submit hundreds of AI-generated applications per day using synthetic identities. They've successfully placed workers at hundreds of companies including security firms — per DOJ indictments and CISA advisories.

  • Mass application source detection
  • Rapid profile modification patterns
  • Candidate deletion burst detection
  • Post-hire data access monitoring
// 03
Compliance & Audit Gaps

Most ATS platforms retain audit logs/events for only 30 days. Most compliance frameworks require 1+ year. Without long-term retention, you're flying blind during audits.

  • 365+ day audit log/event retention
  • SOC 2 evidence & GDPR data access log
  • Permission snapshot history
  • Exportable compliance reports
How It Works

Connect. Monitor. Defend.

Pipeline Defender connects to your ATS via API and begins continuous monitoring. First results appear within minutes.

01
Connect

Connect your ATS via OAuth or API key — credentials you generate yourself, no enterprise procurement required. We validate read-only access and begin ingesting your audit log history. All data encrypted at rest in a private, tenant-isolated vault.

02
Ingest

We poll your ATS audit log/events every 5 minutes and capture a fresh permission snapshot. Events retained for 365+ days — your own data, exportable any time.

03
Detect

Detection rules analyze every event. Threat Detection: 26 single-event rules + 8 behavioral pattern detectors + 4 DPRK fraud playbook rules = 38 total. Coverage varies on other platforms — see Plans.

04
Alert

Alerts delivered via Slack, Teams, PagerDuty, or generic webhook. Forward events to Splunk, Datadog, or Sentinel. Triage from the dashboard.

Detection Engine

Up to 38 Detection Rules

26 single-event rules fire immediately. 8 behavioral pattern detectors analyze event batches. 4 DPRK / fraud playbook rules catch nation-state hiring fraud.

Platform note

Full 38-rule coverage on Greenhouse (with Greenhouse Audit Log add-on) SmartRecruiters Threat Detection delivers 14–23 rules (some rules unavailable due to missing actor IP and certain event types). Lever ships the Identity Watch tier only (9–12 rules — no DPRK fraud playbook, no advanced exfiltration patterns). See the per-platform matrix in Plans.

Critical (4)

System takeover and mass data loss.

  • Bulk candidate deletion
  • SSO configuration changed
  • Two-factor authentication removed
  • GDPR policy deleted
High (6)

Privilege abuse and integration tampering.

  • API key created or permissions changed
  • Revoked API key re-enabled
  • Permission escalation (bulk user/org policy)
  • Bulk user deactivation
  • BI connector changed
  • HRIS integration changed
Medium (13)

Data movement and workflow changes that need a second look.

  • Webhook created, changed, or deleted
  • Vendor support account access
  • Bulk candidate import
  • Scheduled report created
  • Offer letter downloaded
  • User permission changed
  • Agency recruiter access changed
  • Confidential job modified
  • Approval workflow changed
  • Candidate deleted
Low (3)

Routine activity worth tracking for audit trails.

  • Off-hours PII access (timezone-aware)
  • Report exported
  • Offer created
Pattern Detectors (8)

Behavioral analysis across event batches catches threats that no single event reveals.

Available on Greenhouse. SmartRecruiters coverage varies (see matrix). Not available on Lever or other platforms.

Bulk API Data Extraction

Detects high-volume programmatic data access indicative of exfiltration via API.

PII Access Velocity

Flags users viewing an unusually high number of candidate profiles.

Report Export Burst

Catches multiple report exports in a short window — a pre-departure exfiltration signal.

Multi-IP Login Detection

Identifies users logging in from 4+ distinct IPs, indicating credential sharing or compromise.

Off-Hours Activity Concentration

Detects concentrated activity outside business hours suggesting unauthorized access.

API Key Data Access

Detects significant data access by API keys rather than interactive users.

Webhook Lifecycle Anomaly

Detects create-then-delete webhook patterns used to cover up data exfiltration.

IP Allowlist Enforcement

Alerts on activity from non-approved IP addresses or CIDR ranges.

DPRK / Fraud Playbook (4)

Based on CISA advisories on nation-state hiring fraud patterns.

Available on Greenhouse. SmartRecruiters coverage varies (see matrix). Not available on Lever or other platforms.

Mass Application Source

Detects 20+ applications from a single source — coordinated fraud indicator.

Rapid Profile Modifications

Detects candidates modified 5+ times — profile tailoring to match job requirements.

Candidate Deletion Burst

Detects rapid multi-candidate deletions — evidence destruction pattern.

Post-Hire Data Access

Detects newly permissioned users immediately accessing sensitive data.

Access Intelligence

Find the Access Risks You're Missing

Pipeline Defender scans all your ATS users, detects permission changes, scores your security posture, and runs structured access review campaigns.

Permission Audit — included in all PD tiers. Works on every supported ATS platform.

!
Permission Auditing

Dormant accounts, over-permissioning, excessive admins, disabled users with active permissions, agency access scope, and confidential job access.

!
Health Score & Change Detection

0-100 permission health score with letter grade. Detects new users, deactivations, admin promotions, permission grants and revocations between audits.

!
Access Reviews & Role Comparison

Structured approve/revoke campaigns for periodic reviews. Role comparison with outlier detection flags users with more access than their peers.

Access Control

Three Roles. Clear Separation.

Pipeline Defender ships with three built-in roles so security teams can detect and respond while administrators retain control of configuration. Roles are additive — Analyst includes everything in Viewer; Admin includes everything in Analyst.

Role 01 ·

Viewer

Read-only access across the entire product.

  • See the security dashboard
  • Browse the alert feed
  • Drill into events and the audit log/events
  • Review user-permission audit results
  • Subscribe to email alert notifications

Security observers, compliance leads, and executives. SOC 2 auditors and external reviewers. HR partners who own the ATS but don't operate the security tooling day-to-day.

Role 02 ·

Analyst

Everything a Viewer can do, plus day-to-day operational actions.

  • Acknowledge and resolve alerts
  • Run on-demand permission audits
  • Trigger event ingestion during incidents
  • View & export SOC 2 / GDPR reports
  • Validate custom detection rule effectiveness

SOC analysts, IT security engineers, detection engineers, and compliance analysts who pull SOC 2 / GDPR reports on a schedule.

Role 03 ·

Admin

Full configuration and operational control of the product.

  • Manage org settings, users, and API keys
  • Configure Slack, Teams & PagerDuty webhooks
  • Connect SIEM (Splunk, Datadog, Sentinel)
  • Manage IP allowlist & rotate encryption keys
  • Deactivate ATS users in response to alerts

Security leads / CISOs, IT administrators owning SaaS lifecycle, and Heads of People Operations who own the ATS account. Recommend keeping Admin small — typically 2 to 4 people.

Separation of duties

The person operating the security tool isn't the same person who configures it. An Analyst can detect and respond, but cannot disable detections or change webhook destinations to hide alerts. Every Admin action is logged to an immutable audit trail — queryable and exportable for SOC 2, ISO 27001, and NIST 800-53 evidence. SSO with attribute-based role mapping is available on the Identity Watch and Threat Detection tiers.

See full capability matrix
Capability Viewer Analyst Admin
Read access
See the security dashboard
See alerts and audit events
See user-permission audit results
Operational
Acknowledge and resolve alerts
Run an on-demand permission audit
Trigger event ingestion
View and export compliance reports
Administrative
Manage organization settings
Add, edit, or remove user accounts
Manage API keys
Configure Slack / Teams / PagerDuty webhooks
Configure SIEM (Splunk, Datadog, Sentinel)
Manage the IP allowlist
Deactivate ATS users in response to alerts
Connect or reconnect your ATS
Rotate encryption keys
Plans

Three Tiers. Pick What Your ATS Supports.

Permission Audit works on every supported ATS. Identity Watch and Threat Detection unlock real-time detection where your ATS exposes an audit feed — coverage varies by platform.

Permission Audit

Access governance for the recruiting pipeline. Point-in-time snapshots of users, roles, and permissions, with change detection between audits. No real-time event monitoring.

  • Permission auditing (dormant, over-permissioned, excessive admins)
  • Permission change detection
  • Permission health score (0-100 with letter grade)
  • Role comparison with outlier detection
  • Access review campaigns (approve/revoke workflows)
  • Agency access & confidential job monitoring (Greenhouse only)
  • Scheduled audits (daily, weekly, monthly)
  • SOC 2 evidence reports & GDPR data access logs
  • Slack, Teams & PagerDuty notifications
  • REST API with OpenAPI documentation
  • Multi-instance ATS support
  • RBAC (admin, analyst, viewer)

Available on: Greenhouse, SmartRecruiters, Lever, Teamtailor, Ashby, BambooHR, Workable.

Identity Watch

Real-time alerts on identity and credential events. Catch credential theft, privilege escalation, and unauthorized exports before damage is done.

Includes everything in Permission Audit, plus

  • Real-time audit log/event ingestion
  • ~12 identity & credential rules: logins (success/fail), password changes, user lifecycle, role/permission changes, API key & OAuth credential lifecycle, SSO configuration changes
  • Off-hours activity detection (timezone-aware)
  • Security posture scoring with trend analysis
  • Browser desktop notifications

Available on: Greenhouse, SmartRecruiters, Lever. Rule count varies by platform — Greenhouse 12, SmartRecruiters ~10, Lever ~9.

* Requires audit log/events API access from your ATS

Platform Permission Audit Identity Watch Threat Detection
Greenhouse ✓ (12 rules) ✓ (26 rules — full 38)
SmartRecruiters ✓ (~10 rules) ✓ (~13 rules + partials)
Lever ✓ (~9 rules) — (no candidate events)
Teamtailor
Ashby / BambooHR / Workable

Rule-by-rule coverage for each tier and platform is documented in our capability matrix — ask us for the current version.

Coming Soon

Secure Your Pipeline

Pipeline Defender is currently in development. Join the waitlist to get early access on your platform of choice.

Built for the recruiting pipeline