Your AI Notetaker Left 181,874 Meetings Open

A researcher told tl;dv about its open Firestore in January. It's August, 181,874 meetings are still exposed. See the AI notetaker audit to run today.

Scott Armbruster
11 min read
Your AI Notetaker Left 181,874 Meetings Open

On August 4, a security researcher published a writeup titled tl;dv (Too Lazy; Didn’t Validate): 181,874 Meetings Left Wide Open, documenting a missing database rule in tl;dv, the AI meeting notetaker that records and summarizes calls on Zoom, Google Meet, and Microsoft Teams. Any authenticated tl;dv user could pull every meeting record on the platform. All 181,874 of them, spanning 84,312 users and 35,003 email domains.

The records carried creator email addresses, conferencing provider, timestamps, recording status, and the conference ID. That last field is the one that should make your stomach drop. A conference ID is a joinable room.

The researcher reported it to tl;dv on January 28, 2026. As of the public disclosure in August, it was still open.

Six months. That number matters more than the 181,874.

Quick Verdict

QuestionThe Answer
What broke?A missing tenant-isolation rule on the meetings collection in tl;dv’s Cloud Firestore database.
Who could exploit it?Anyone with a tl;dv account. Free tier included. No exploit chain, no privilege escalation.
What was exposed?181,874 meeting records: creator emails, provider, timestamps, recording status, and joinable conference IDs.
How many users and domains?84,312 users across 35,003 email domains, per the researcher’s analysis.
Live calls too?Yes. Roughly 1,000 meetings sat in status: recording at any moment, meaning a thousand live rooms with exposed IDs.
Could you actually get in?The researcher reported roughly an 80% success rate joining calls while impersonating the notetaker bot.
Who’s on the list?Government bodies in 23 countries, universities including UC Berkeley and University of Tokyo, and corporate domains including HubSpot.
When was it reported?January 28, 2026, to the CEO and CTO directly. Follow-ups ran through July 22.
Was it fixed?Not as of the August 4 public disclosure.
What’s tl;dv’s response SLA?Its own security page advertised a 24-hour security response.
Compliance postureSOC 2 Type I only, no HIPAA, per third-party reviewers.
What do you do?Find out who at your company installed it, today.

What is the tl;dv Firestore vulnerability?

The tl;dv Firestore vulnerability is a missing tenant-isolation rule in the platform’s Cloud Firestore database. Any authenticated tl;dv user could request a Firebase token and query the shared meetings collection, returning every meeting record across every customer account rather than only their own. It exposed creator emails and live, joinable conference IDs.

There is no clever tradecraft in that sentence. That’s the point.

This Is a Configuration Line, Not a Zero-Day

Firestore security rules are the access control layer for the database. You write them. Google’s documentation is explicit that rules default to restrictive and that you own the logic separating one customer’s data from another’s. The standard pattern is a few lines checking that the requesting user’s ID matches the document’s owner field.

That check was absent on the collection holding every meeting on the platform.

I want to be careful here, because I’ve written plenty about how hard security is at small companies and I don’t want to pretend otherwise. Misconfigurations happen. Firebase makes it genuinely easy to ship fast and forget the rules file. What separates a bad afternoon from a six-month incident is what happens after someone tells you.

Here’s the timeline the researcher published: initial contact January 28 to the CEO and CTO. Follow-ups January 29 through February 19, answered with vague reassurance. Then nothing from March 6 through July 22. The company’s security page promised a 24-hour response. The gap between that promise and roughly 180 days of silence is the actual finding.

The Live-Call Problem Is Worse Than the Data Dump

Most breach coverage stops at the record count. Records are historical. You rotate credentials, you notify, you move on.

An exposed conference ID for a call happening right now is a different category of problem, because the exposure is happening in real time and the affected party is in the room. The researcher’s testing found that joining as something that looked like the notetaker bot worked about 80% of the time. Which makes sense. Everyone on a Zoom or Meet call has been trained to see a participant named after a recording tool and think “oh, someone turned on the notetaker.”

Nobody asks. That’s the whole social engineering payload. It doesn’t need a payload.

Think about what runs on those calls at a 30-person company. Comp discussions. Term sheets. The client renewal where you talk honestly about the account. A vendor negotiation where your walk-away number gets said out loud. None of that is in a database you’d audit. It’s in a live room that a stranger could join because a database rule was missing.

Government bodies in 23 countries were in that dataset. So were UC Berkeley and the University of Tokyo, and corporate domains including HubSpot. The researcher also found a separate unauthenticated API on a tl;dv World Cup prediction app leaking employee names and corporate emails, which tells you something about the general engineering hygiene.

The Compliance Badge Did Not Help

tl;dv’s marketing has carried security assurances for years. Third-party evaluators are more specific: Fellow’s comparison of tl;dv alternatives states that tl;dv holds only SOC 2 Type I certification and does not offer HIPAA compliance, and flags that as disqualifying for many teams.

The Type I versus Type II distinction is worth ten seconds of your attention because it’s the single most misunderstood item in SaaS procurement.

SOC 2 Type ISOC 2 Type II
What it testsControls as designed, at one point in timeControls as operated, over 6-12 months
The question it answersDid you write the policy?Did you follow it?
Catches a missing Firestore rule?Only if it existed on audit dayMore likely, through sampled evidence over time
What regulated buyers requireRarely acceptedStandard minimum

A Type I report is a photograph. A Type II report is a film. Neither one would necessarily have caught this specific rule, and I’d be overselling if I claimed otherwise. But the six-month non-response is precisely the kind of operational failure a Type II examination is built to surface, because Type II asks whether your incident response process actually ran, not whether you documented one.

Which is the broader lesson I keep coming back to. A compliance badge is evidence about a vendor’s process discipline, not a guarantee about your data. I made this argument about subprocessors in Your Software Vendors Are Running AI on Your Data, and this incident is the same failure wearing a different logo.

The Real Exposure: Nobody Approved This Tool

Here’s what I think most owners will get wrong reading this. They’ll check whether the company pays for tl;dv, find no invoice, and close the tab.

Wrong question. AI notetakers are the single most viral category of workplace software I’ve seen since Dropbox. One person installs a free tier to stop taking notes in client calls. The bot shows up in every meeting they join. Within a quarter, it’s recording conversations involving people who never agreed to anything and never saw a vendor form.

There’s no procurement event. There’s no invoice. There’s a browser extension and a calendar integration, and now a third party holds a transcript of your leadership meeting.

I covered the general shape of this in Shadow AI: The Hidden Cost (And How to Fix It), where unsanctioned AI use added roughly $200K to average breach costs. Meeting notetakers are the worst version of that pattern, for three reasons that stack:

  • The data is unstructured and maximally sensitive. Nobody redacts a conversation.
  • Consent is fuzzy. The person who installed it isn’t the person whose salary got discussed.
  • Retention is invisible. Ask anyone at your company how long tl;dv keeps recordings. Nobody knows.

How do you audit your AI notetakers this week?

Seven steps. An office manager can do the first four without engineering help.

  1. Check your calendar for bot participants. Open the last 30 days of meetings and look at attendee lists for anything named after a recording tool. That list is your real inventory, not the expense report.
  2. Pull your Google Workspace and Microsoft 365 third-party app permissions. Admin console, app access control. Every tool with calendar or meeting scope is listed there, including the free ones nobody expensed.
  3. Ask the direct question in writing. One Slack message: “Does anyone use an AI notetaker on work calls?” Amnesty framing gets honest answers. Blame framing gets silence and continued use.
  4. Find out what’s recorded and what’s retained. For each tool discovered, get the retention period, the storage region, and who inside your company can access the archive. If nobody can answer in ten minutes, that’s your finding.
  5. Rotate anything discussed on an exposed call. Not credentials. Positions. If a negotiation number, a comp band, or an acquisition conversation ran through tl;dv this year, assume it’s readable and decide whether that changes anything.
  6. Write a one-page notetaker policy. Approved tools, meetings where recording is prohibited, and a rule that all participants get told. Two hundred words is plenty.
  7. Set a vendor-response test. Before approving any AI tool touching conversations, email its security contact a question and time the reply. A vendor that takes eight days to answer a sales-adjacent security email will not answer your breach notification faster.

Step seven is the one I’d fight for. Response latency is the most predictive vendor-risk signal available to a small business, and it’s free to measure.

My Read

Three things I think are true here.

The disclosure process is the product feature nobody evaluates. Every buyer asks about encryption. Almost nobody asks what happens when a stranger emails you a vulnerability. tl;dv had an advertised 24-hour SLA and, by the researcher’s account, went dark for months. You can’t audit that from the outside before you buy. You can test it, which is why step seven exists. The same reasoning drove my read on dev tooling vendor risk: the counterparty’s behavior under pressure is the thing you’re actually buying.

Free-tier AI tools carry enterprise-grade blast radius now. The economics broke somewhere around 2024. A tool costing nothing can hold your board conversations, and the vendor’s incentive to fund a security team scales with revenue per user, which on a free tier is roughly zero. That’s not a moral failing. It’s arithmetic, and it’s why the governance question is which tools touch which conversations, not which tools cost money.

Meeting content is the least protected sensitive data in most companies. You have a policy for customer records. You have a policy for financial data. You almost certainly have nothing written down about the recording of the call where you discussed both. I flagged rogue agents and data exposure as top SMB threats in The 3 AI Security Threats Every SMB Needs to Defend Against. Ambient meeting capture belongs on that list, and it’s the one with the lowest awareness relative to actual exposure.

A fair objection: this is one vendor’s mistake and the category isn’t inherently broken. True. AI notetakers deliver real value, and I’m not telling you to rip them out. Recall and searchable transcripts genuinely change how a small team operates. The move is to pick one, approve it deliberately, check that it has a Type II report and a security contact who answers, and shut the other four off.

The uncomfortable part is what this says about the wider market. Hundreds of AI tools shipped in the last two years on Firebase and similar platforms, built fast by small teams under investor pressure to grow. Tenant isolation is a rules file that one engineer writes in an afternoon and nobody reviews again. tl;dv is the one that got a researcher’s attention. It is not plausibly the only one that got it wrong.

Your Next Step: Open your calendar right now and scan the last 30 days of meetings for a bot participant you didn’t invite. If you find one, you’ve identified an AI vendor holding your company’s conversations that never went through a single approval step. Send one email to that vendor’s security address asking two questions: what’s your retention period, and what’s your vulnerability disclosure process. Time the reply. That timestamp tells you more about your risk than any badge on their homepage.


Related Reading:

TAGS

AI notetaker security risktl;dv data breachAI meeting assistant vendor riskAI notetaker vendor audit small businessFirestore tenant isolation vulnerability

SHARE THIS ARTICLE

What is this worth in your business?

The free Build Audit is 30 minutes. You leave with a ranked list of the automations worth doing in your business, whether or not we build them.