Your AI notetaker sits in every client meeting. Who approved it?
A widely used AI notetaker left one database collection without a tenant-isolation rule, exposing 181,874 meeting records across 84,312 users, including live calls a stranger could join. The vendor held SOC 2, GDPR and EU AI Act compliance the whole time. The lesson for a professional services firm is not that custom-built software is safer, because it is not. It is that with a vendor you wait on someone else's timeline, and with something you own the clock is yours. Most firms should still buy the commodity layer and own only the connective tissue and the privileged data. The urgent part is simpler: find out which AI tools are sitting in your client meetings, and who approved them.
In January a security researcher found that one of the more widely used AI notetakers, the kind that drops a bot into your Zoom, Meet and Teams calls, had left a single database collection without a tenant-isolation rule. Any signed-up user, including anyone on a free account, could query every meeting record on the platform.
That came to 181,874 meeting records, 84,312 users, 35,003 email domains. Each record carried the creator's email address and the conference ID of the call. About a thousand of those meetings were, at any given moment, still recording, which meant their conference IDs were live, working links.
The researcher used one. He walked into a government department's call with 157 people on it. Nobody invited him. The database did.
The part that should worry you is not the bug #
Bugs happen. This one was mundane. Every other collection on that platform was locked down correctly: users, transcripts, recordings, notes, teams, all returning a clean refusal. One was missed.
Here is what makes it worth your attention. That vendor's security page carries SOC 2, GDPR and EU AI Act compliance, EU hosting, AES-256 encryption, and a written promise that its security team responds to reports within 24 hours.
Every one of those badges was accurate. None of them caught this.
If your defence for the AI tools in your client meetings is that the vendor has certifications, that defence has now been tested in public. Compliance attests to having a process. It does not attest to the absence of the specific mistake that matters to you.
The disagreement you are not part of #
The researcher reported it on 28 January and says it was still open in July.
The company disputes that. Its position is that there were two distinct vulnerabilities rather than one long-ignored bug: the first was identified through its penetration testing vendor and a responsible disclosure, then fixed and formally validated. A second route to the same data was found later and closed within 24 hours. It is removing the underlying database technology from its stack, and it will provide a signed attestation from its pen-test vendor to customers who ask.
I am not going to adjudicate that, and I am deliberately not naming the vendor here. The point of this piece is not that one company got caught. It is the position their customers were put in, which is the same position most firms are in right now with tools they have never assessed.
Because notice where that leaves an accounting firm whose client calls were in that collection. Two parties are publicly disagreeing about how long your clients' meeting data was reachable, and you are not one of them. You did not see the disclosure. You did not weigh the fix. You would learn about it, if you learned at all, from a news article.
That is the actual exposure. Not the missing rule. The fact that your firm's answer to "what happened to our data" is "we are waiting to hear as well."
So should you build your own instead? #
I want to give you the honest version of this, because I have a commercial interest in the answer and you should be able to see me handling that.
I recently published a piece about auditing my own systems, where I found six endpoints of my own that would have let a stranger send email as me. Custom-built. By someone who does this for a living. Knowing exactly how it worked.
So I am not going to tell you that custom means safer. My own evidence says otherwise, and the failure was the same shape as the notetaker's: every piece built properly for its own job, and nobody asking what the whole thing would accept.
What custom actually gives you is not safety. It is the timeline.
My six doors were found by me and closed by me inside the same month. There was no vendor to email. No disclosure queue. No CTO not replying. No compliance page to reassure me while nothing happened. When the answer to "who is fixing this" is a person you can call, the clock is yours.
That is a real advantage and it is worth paying for. It is just a different advantage from the one people claim when they say custom is more secure.
When off-the-shelf is the right answer, which is often #
Most of the time, buy.
You should not be building your own video conferencing, your own accounting software, your own email. Those are solved, the vendors are better at it than you will be, and the alternative is a maintenance burden with no upside. Anyone who tells a twenty-person firm to build its own everything is selling hours.
The build case gets stronger as three things become true: the workflow is genuinely specific to how your firm operates, the data involved is sensitive enough that you need to be able to answer for it yourself, and the thing sits close enough to your revenue that being locked to a vendor's roadmap and pricing is a strategic risk rather than an annoyance.
That last one is worth watching over the next couple of years. A lot of AI tooling is currently priced below what it costs to run, because the industry is buying market share with investor money. Assume those prices rise. Design so that a price rise is a decision rather than an emergency.
For most firms this lands in the middle. Buy the commodity layer. Own the connective tissue, the client data, and anything that carries privileged information. That split is how I structure a build. The mistake is not choosing wrong. The mistake is not choosing.
The question to ask on Monday #
Here is the thing I would actually do this week, and it costs nothing.
Ask who approved the AI tools that sit in your client meetings.
In most firms the honest answer is that nobody did. A notetaker got switched on by whoever set up the calendar, it was useful, it spread, and it now attends conversations about client finances, disputes, valuations and personal circumstances. It was never assessed, because it never arrived through a process that includes assessing things. It arrived through convenience.
That is not a technology problem and no tool will fix it. It is a governance gap, and it is the same gap in a firm of fifteen and a firm of a hundred and fifty.
You are the one who has to sit in front of a client and explain it. Not the vendor. Not the researcher. Not whoever installed it.
So make a list. Every AI tool that touches a client conversation, who approved it, what it stores, where, and what happens if it is wrong. If you cannot fill in the columns, you have found your answer, and the fix starts with the list rather than with buying anything.
The honest footnote #
I do not think that vendor is unusually bad. I think they got caught doing something close to universal, which is shipping fast and finding out later. My own audit says the same about me.
The lesson I take from it is not that vendors are careless or that custom is virtuous. It is that somebody has to be accountable for the whole picture, on a timeline you control, and that job does not get done by default. Not by a compliance badge, and not by a smart person building carefully.
Questions people ask me about this #
Should we stop using AI notetakers?
For most firms, no. The value is real and banning them tends to push people onto something worse that nobody can see. The useful step is to pick one, approve it deliberately, check what it stores and where, turn it off for the meeting types where it does not belong, and tell clients it is running. An approved tool with known limits beats three unapproved ones.
Is custom-built software more secure than off-the-shelf?
Not inherently, and anyone who tells you otherwise is selling. Vendors have security teams, audits and far more eyes on their code than a custom build gets. What custom gives you is control of the timeline and the ability to answer for it yourself, because there is no disclosure queue between you and the fix. That is a different benefit from safety, and for privileged client data it is often the one that matters.
Does SOC 2 compliance mean our data is safe?
SOC 2 attests that a company follows defined security processes and has been audited against them. It is meaningful and it is worth asking for. It does not certify that any particular bug is absent, which is why a compliant vendor can still leave a database collection open. Treat certifications as a floor, not an answer.
What should a small firm actually do about this?
Write the list. Every AI tool that touches a client conversation, who approved it, what it stores, where it is hosted, and how you would find out if something went wrong. Most firms have never written it down, and the writing is where the surprises turn up. It takes an hour and needs no budget.