cd /news/ai-products/an-ai-notetaker-left-181874-meeting-… · home topics ai-products article
[ARTICLE · art-104438] src=machinebrief.com ↗ pub= topic=ai-products verified=true sentiment=↓ negative

An AI Notetaker Left 181,874 Meeting Records Open for Six Months

A security researcher found that tl;dv, an AI meeting recorder used by over 2 million people, left 181,874 meeting records exposed for six months after the flaw was reported on January 28, 2026. The vulnerability, which allowed any authenticated user to access all meeting data, was not fixed until July, and the company's CTO never responded to the researcher. The exposure included 84,312 unique users and 35,003 email domains, with government domains across 23 countries, and the researcher was able to join calls he was not invited to, including one hosted by the Malaysian Ministry of Education.

read3 min views6 publishedAug 20, 2026

AI meeting recorder tl;dv, used by over 2 million people, shipped its Firestore meetings collection without tenant isolation. Any free-tier signup could…

A security researcher found that an AI meeting recorder used by more than two million people had left its entire meetings database open to anyone who signed up, and the hole stayed open for half a year after it was reported.

tl;dv, an AI note-taking tool that joins your calls and transcribes them, shipped its Cloud Firestore meetings collection without tenant isolation. Any authenticated user - including a free-tier signup with no payment attached - could query every meeting record on the platform.

The Scale of the Exposure #

The numbers are the kind that turn a bug into a breach disclosure. 181,874 meeting records. 84,312 unique users. 35,003 email domains. Government domains across 23 countries. Roughly a thousand live recordings at any moment.

Each record carried the creator's email, the conferencing provider, timestamps, recording status, and a conference ID. That last field is what transforms a metadata leak into an access problem: the conference ID reaches the underlying Google Meet or Teams room. The researcher reports joining calls he was never invited to, including one hosted by the Malaysian Ministry of Education.

Six Months of Silence #

The disclosure timeline is the part that should worry anyone running a vendor review process. The flaw was reported January 28, 2026. It was still unfixed in July. The company's CTO never replied to the researcher. A separate internal employee-directory API was reachable with no authentication at all.

This isn't a company that shipped a bug and rushed to fix it. It's a company that shipped a bug, got told about it, and then did nothing for months. That distinction is the whole lesson.

The SOC 2 Problem #

tl;dv holds SOC 2 certification, and that's the takeaway most people are drawing from this story, correctly. A point-in-time attestation does not tell you whether a vendor answers the phone when a researcher finds a hole.

SOC 2 Type I is a snapshot. SOC 2 Type II, evaluated over six to twelve months, is the minimum bar for anything recording your calls. And even Type II wouldn't have caught this on its own - the test is whether controls exist, not whether they actually stop a determined attacker from reading your meeting transcripts.

Why AI Notetakers Are a Special Risk #

AI meeting recorders are a worse-than-average category for this kind of failure. They don't just store your name and email. They store the full content of your conversations - strategy, hiring decisions, product roadmaps, compensation discussions. A notetaker leak is a transcript leak, and a transcript leak is a map of everything your company says behind closed doors.

The AI angle compounds it. These tools aren't passive recorders anymore. They summarize, they extract action items, they build searchable memories of every call. That added intelligence makes the stored data more valuable to an attacker, and the attack surface for getting at it keeps growing.

The vendor lesson is blunt: before you let an AI into your meetings, ask what happens when the researcher finds the hole, not whether the hole exists. Every vendor has holes. The ones that matter are the ones who fix them when told.

Sources: Security researcher bobdahacker disclosure, August 2026; AI Tools Recap daily briefing, August 16, 2026; tl;dv platform records.

Get AI news in your inbox

Daily digest of what matters in AI.

── more in #ai-products 4 stories · sorted by recency
── more on @tl;dv 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/an-ai-notetaker-left…] indexed:0 read:3min 2026-08-20 ·