Who is recording your meetings, and who else can read them
Somebody in your business has probably added an AI notetaker to a meeting. It joins the call as a participant, records it, transcribes it, and emails round a summary. It is genuinely useful, it costs almost nothing, and nobody had to ask permission to start using it.
That means a third party now holds recordings of your sales calls, your job interviews, your appraisals, and the meeting where you discussed the thing you have not announced yet. Which raises a question most businesses have never asked: how good is that third party, and how would you know?
Here is one answer.
What the researcher found
On 4 August, a security researcher writing as BobDaHacker published findings on tl;dv, an AI meeting recorder with more than two million users that drops a bot into Google Meet, Zoom, and Teams calls.
The platform stored its meeting records in a database where one collection had no separation between customers. Any signed-up user, on a free account, could query every meeting on the entire platform. Not the video, and not the transcript, but for each meeting: the organiser's email address, timestamps, and the conference ID, which is the joining code for the call itself.
The researcher counted 181,874 meeting records belonging to 84,312 users across 35,003 email domains. Government meetings from 23 countries. Universities including Berkeley and the University of Tokyo. Named corporate customers.
The part that should make you sit up is the live one. Roughly 1,000 of those records at any given moment were meetings currently in progress, with a working joining code attached. The researcher demonstrated it by joining two calls he had no business being in, including one with more than 150 participants. Nobody invited him. As he put it, the database did.
Separately, he found that of 27,334 meetings he sampled, more than 1,000 had been left publicly viewable, exposing 715 attendee email addresses.
The failure that matters is not the technical one
A missing database rule is a mistake, and a fixable one. The researcher notes that the platform applied the correct restrictions to every other collection: users, chats, transcripts, teams, organisations. They just missed one.
What turns a mistake into a story is what happened next. He reported it on 28 January 2026. He got a same-day reply from a co-founder promising the CTO would pick it up. The CTO never responded. He followed up in January, February, March, and July. The reply in February was that the team was on it. After that, silence. When he published in August, he reported that the flaw was still open.
Meanwhile the company's security page carried six compliance badges: SOC 2, UK GDPR, the EU AI Act, EU hosting, AES-256 encryption, and a founder commitment video. Underneath them sat a line promising that the security team responds to reported issues within 24 hours.
That gap is the lesson, and it generalises well beyond one company. Compliance badges tell you a supplier passed an assessment on a particular day against a particular scope. They do not tell you whether anyone answers the phone when something is actually wrong. Those are different questions, and only one of them protects you.
Why this lands on you, not just on them
If your staff record client calls, interviews, or internal meetings on a platform like this, then in UK data protection law you are the controller and that platform is your processor. You decided the recording would happen. That makes the consequences yours to explain.
Practically, that means three things.
You are required to use processors that offer sufficient guarantees about their security, and to have a written contract covering it. "A member of the sales team signed up with a company card" does not meet that bar, and in most businesses that is exactly how the notetaker arrived.
If the data does leak, the notification duty is yours. You would be the one telling clients that the recording of your conversation with them sat in a database any stranger with a free account could enumerate.
And the content is often the sensitive kind. Interview recordings contain candidate personal data. Appraisals contain performance data about your staff. Client calls contain your client's confidential information, frequently covered by a contract you signed promising to look after it.
What to do about it
Find out what is actually recording. Ask around, then check. Look at the participant lists in recent calendar invitations for bot accounts, and ask your IT provider what has been connected to Microsoft 365 or Google Workspace. Most businesses find at least one tool nobody formally approved. This is the same shape as any other shadow IT problem, and the fix starts with an honest inventory.
Decide what is allowed to be recorded at all. The simplest control here is not technical. Interviews, disciplinary meetings, and anything covered by a client confidentiality clause are reasonable things to keep off automated recording entirely. Write the rule down, tell people, and you have removed the worst of the exposure without buying anything.
Check the supplier's disclosure route before you need it. Find the security contact on their site. It is a fair question to ask a supplier directly: who receives security reports, and what is your response time? A company that cannot answer that quickly is telling you how the bad day will go.
Read the badges for what they cover. A SOC 2 report has a scope and a date. Ask which one applies, and when it was last done. Certification is worth something, but it is evidence about a process, not a guarantee about today.
Turn off public sharing by default. Where a tool offers a "anyone with the link" option for recordings, check what your default is. More than 1,000 meetings in this case were publicly viewable because somebody, at some point, ticked a box.
Keep a list of who holds your data. If you cannot name every third party holding your business conversations, you cannot assess them, cannot notify anyone when one of them has an incident, and cannot answer a client who asks. The list is dull to make and it is the thing that makes every other question answerable.
How Steelwise can help
Working out which third parties hold your data, what they promised, and which of those promises you would actually want to test is the kind of review we do. Get in touch.
Further reading
- ICO: Controllers and processors sets out who is responsible for what, and what a processor contract has to contain.
- ICO: Employment practices and data protection covers recording and monitoring in a staff context.
- NCSC: Supply chain security guidance on assessing the suppliers you depend on.