Security audit
Pipeworx ashby
Security checks for vulnerabilities and agentic risk
Overview
Review carefully: this remote Ashby connector can access sensitive candidate and hiring data, but the artifacts do not explain authentication, permission scope, or data handling by the gateway.
Before installing, confirm who operates gateway.pipeworx.io, how it authenticates to Ashby, whether access is read-only or can modify ATS records, what data it stores or logs, and whether its permissions are limited to the jobs and candidate records you intend to use.
Static analysis
No suspicious patterns detected.
