Paradox
United States · www.paradox.ai · 25 vendors
Paradox offers conversational recruiting software, powered by its AI assistant Olivia, to automate tasks such as candidate screening, interview scheduling, and answering candidate questions. The company aims to streamline the hiring process, enabling recruiting and talent acquisition teams to focus more on human interaction and less on administrative software tasks.
Resilience scores
- Digital Sovereignty: 88
- Digital Resilience: 8
- Financial Resilience: 8
Disruption prediction
Paradox has an estimated 40% probability of disruption in the next 6 months.
16 of Paradox's 25 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Embedly — United States
- HubSpot, Inc. — Technology — United States
- and 22 more
Services catalogue
2 services in catalogue across 2 categories; runs on 25 sub-vendors.
- Conversational AI
- Paradox
Insights
Last updated 2026-08-04 · revision 1
25 direct vendors, 329 subvendors
Direct vendors by controlling owner country (sample)
- United States: 22
- Hong Kong: 1
- Denmark: 1
Subvendors by controlling owner country (sample)
- Canada: 11
- Unknown: 2
- United States: 226
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Paradox exhibits high migration readiness, primarily driven by its modern and cloud-centric internal tech stack, including AWS and DigitalOcean Spaces. This existing adoption of cloud infrastructure significantly reduces the effort and complexity associated with further migration or optimization. The mention of "open API" in its key technologies suggests a modular architecture, which is highly conducive to migrating services independently and integrating them effectively in new environments. The ambiguity of "Total Vendors: 0" makes a precise assessment of vendor lock-in challenging; however, if vendors are indeed utilized for the "Total Services: 29", the "Vendor Geographic Diversity" across 4 unique countries (United States, Australia, Hong Kong, Denmark) implies a potentially diversified vendor landscape, which can mitigate some migration complexities associated with vendor concentration. Critical data gaps include specific regulatory environment details, data residency requirements, and financial stability information, which would be essential for a comprehensive migration strategy and funding assessment. Despite these unknowns, the current technological foundation positions Paradox very well for future migrations.
Compliance
9 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Compliant
Paradox has publicly confirmed ISO 27001 certification on its official security page. ISO 27001 is an internationally recognized standard for Information Security Management Systems (ISMS), requiring third-party certification by an accredited certification body. The certification demonstrates that Paradox has implemented a systematic approach to managing sensitive company and customer information. Risk is Low because the certification is publicly confirmed and represents ongoing third-party verification. Continued compliance requires annual surveillance audits and triennial recertification. Post-Workday acquisition, the scope and certification body may have evolved, but the public commitment to ISO 27001 remains.
Evidence: https://www.paradox.ai/legal/security
PDPA — Assessment Required
Paradox has confirmed clients in Singapore (Singtel, UOB) and Australia (Wendy's NZ, Sobeys Canada), indicating active operations in APAC markets. Singapore's Personal Data Protection Act (PDPA) and Australia's Privacy Act 1988 (with the Australian Privacy Principles) apply to organizations collecting personal data of residents in those jurisdictions. Paradox's platform processes candidate personal data in these markets. The Workday privacy policy references APEC Cross-Border Privacy Rules (CBPR) System certification, which provides a framework for APAC data transfers. Risk is Medium because Paradox has APAC clients and processes APAC resident data, but the specific compliance status for each jurisdiction's data protection law is not publicly documented.
Evidence: https://www.paradox.ai/case-studies/singtel, https://www.paradox.ai/case-studies/uob, https://www.workday.com/en-us/privacy.html
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an international assurance standard used primarily for non-financial assurance engagements, often applied in the context of sustainability reporting, privacy assessments, or controls reporting outside the US (where SOC 2 is the US equivalent). Paradox has SOC 2 Type II (the US-equivalent assurance framework) and ISO 27001. For EU/international clients, some may request ISAE 3000-based assurance reports (e.g., ISAE 3402 for service organizations, which is the international equivalent of SOC 1). No public evidence of ISAE 3000 or ISAE 3402 reports was found. Risk is Low because Paradox's SOC 2 Type II and ISO 27001 certifications largely satisfy the assurance needs that ISAE 3000 would address, and ISAE 3000 is not a mandatory regulatory requirement for Paradox's industry.
Evidence: https://www.paradox.ai/legal/security
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 8/10
Paradox demonstrates strong financial resilience despite the absence of publicly disclosed audited financials. As a private venture-backed company, it raised approximately $93 million in disclosed funding across multiple rounds, including a $40M Series B in 2020 and a reported $200M Series C in 2022 at a ~$1.5 billion valuation. Growth signals are robust: revenue grew >720% from 2020 to 2023, implying a ~90-100% CAGR, and the company was named to the Inc. 5000 for five consecutive years and Deloitte Technology Fast 500 for four consecutive years. The October 2025 acquisition by Workday (NASDAQ: WDAY) substantially strengthens Paradox's resilience profile. Workday held over $8 billion in cash and marketable securities, eliminating any refinancing or liquidity risk for Paradox. Paradox also benefits from a blue-chip enterprise customer base with sticky SaaS contracts across Chipotle, 7-Eleven, McDonald's franchisees, Marriott, GM, Nestlé, and others, along with significant transaction scale (32 million interviews projected for 2025, roughly one in ten U.S. interviews). Risks include customer concentration in cyclical hourly-labor industries (QSR, retail, hospitality), AI regulatory exposure (EEOC, NYC AEDT, Illinois, Colorado laws), competitive pressure from HireVue, iCIMS, Phenom, Eightfold, and embedded AI in Workday/Oracle/SAP, and probable historical operating losses typical of high-growth SaaS. Integration risk with Workday is also material, particularly for customers on competing HCM platforms.
Key strengths: Acquired by Workday (Oct 2025), a well-capitalized parent with >$8B in cash, ~$93M+ in disclosed venture funding raised (Series B $40M, Series C ~$200M), >720% cumulative revenue growth 2020-2023 (~90-100% CAGR), Blue-chip enterprise customer base with sticky SaaS contracts, 32 million interviews scheduled in 2025 (~1 in 10 U.S. interviews), Five consecutive years on Inc. 5000; four on Deloitte Fast 500, ISO 27001 and SOC 2 Type II certified, Strong partner ecosystem (Workday, SAP SuccessFactors, Indeed, ZipRecruiter)
Risk factors: Customer concentration in cyclical hourly-labor industries (QSR, retail, hospitality), AI regulatory risk (EEOC, NYC AEDT, state-level automated employment decision laws), Competitive pressure from HireVue, iCIMS, Phenom, Eightfold, and embedded AI in HCM suites, Probable historical operating losses given high-growth SaaS profile, M&A integration risk with Workday, especially for SAP/Oracle HCM customers, No public financial disclosure limits transparency
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.