Big Security Breach detected, but the team is not acting on it at all.
We were using this tool, until we found a serious security breach. We reported this to the support team a week ago, and have not heard back from them ever since.
Honestly, if this kind of threat to the whole tool is not being taken seriously, I don´t want to use that tool anymore.
For the record, this is the message that went out to Gappeo.
"I hope this message finds you well. We have recently discovered a critical security breach in the ATS platform provided by your team that requires immediate attention.
The issue involves candidates who complete an assessment and exit the platform being able to re-enter and access all assessments taken by other candidates. This not only poses a significant threat to the confidentiality of our assessment process but also compromises the integrity of the platform and the fairness of candidate evaluations.
We kindly request your urgent investigation into this matter and a swift resolution to prevent further unauthorized access. Please let us know the steps you will take to address this and any interim measures we can implement to mitigate the risk while the issue is being resolved."
Adi_A
Jan 7, 2025Dear najef11,
Thank you for sharing your feedback. I’d like to clarify that our system is completely robust, and thousands of candidates and companies rely on our platform daily for their assessments.
The incident you mentioned pertains to a user who logged in as the admin of their account. Naturally, an admin has the ability to view all candidates and their scores, as this is an essential feature for managing assessments.
To address your concerns, I invite you to test our system yourself. Here’s a test link: https://app.gappeo.com/candidate-invite-test/MTU1NXw3NDU=. Please complete the test and let us know if you’re able to see the list of all candidates without admin privileges. 😊
We always encourage double-checking tools before publishing reviews, as it ensures accurate representation and constructive feedback. Should you have any further concerns or questions, feel free to reach out.
Best regards,
Adi