The AI meeting recording platform tl;dv left 181,874 meeting recordings publicly accessible due to a security flaw in its Firestore database, according to a report published on August 4, 2026. The platform, which serves over 2 million users and integrates with Google Meet, Zoom, and Teams, failed to isolate tenant data, exposing sensitive content including sales calls and internal strategy sessions.
The vulnerability stems from the way tl;dv authenticates users. After signing up, users receive a Firebase token that allows querying the Firestore database. However, the 'meetings' collection lacked tenant isolation, enabling any authenticated user to access every meeting record on the platform. The exposed data included creators' email addresses, conference IDs, and meeting transcripts. The security researcher who reported the issue in January 2026 noted that the company’s CTO did not respond to repeated emails over six months.
This exposure highlights significant risks in AI-powered meeting transcription services, which handle confidential business information. tl;dv is backed by investors and endorsed by LinkedIn sales influencers, making the breach notable in the AI SaaS sector. The incident underscores the importance of robust data isolation and security practices in cloud-based AI applications, especially those dealing with sensitive corporate communications.
As of August 2026, the Firestore database remains unsecured, leaving all 181,874 meetings accessible. The researcher’s report on bobdahacker.com details the technical aspects of the flaw and the lack of response from tl;dv’s leadership.