Last week I saw a post on HN that made my back go cold: tldv (the AI tool lots of us use to auto-record meetings and generate notes) had over 181,000 meeting recordings, transcripts, and conversation logs fully exposed on the public internet. No password. No authentication. Anyone with the link could just listen in. I clicked through to check — not even a login popup. Just a complete product review meeting sitting right there, with names, company, salary numbers, everything. This wasn't someone getting "targeted." The front door was wide open.

So what is this thing? tldv is one of those AI meeting note tools that's exploded in popularity over the last couple years. A lot of remote teams, freelance consultants, and product folks I know use it to auto-record Zoom and Google Meet, write up notes, extract action items, even sync into Notion and CRMs. The deal is: you let it join your meeting, it listens for you, takes notes for you, summarizes for you. Basically you're handing all your most sensitive one-on-ones, client calls, and internal decision meetings over to a third-party AI to keep safe. What leaked was an Elasticsearch instance underneath it — an engineer forgot to add authentication. Like welding a safe's door shut but leaving the whole safe sitting in the yard.

The replication cost here is weird because you're not "replicating" — you're avoiding risk. Money: switching tools is basically free. Most SaaS like tldv have free tiers that work fine, so swapping platforms costs nothing extra, though migrating your history might have some export/import overhead. Time: 1–3 days is enough to run through "audit — migrate — notify the people involved." Technical barrier: very low, but you need someone who can export old data and audit permission settings. First step I'd suggest: tonight, go check every AI tool's backend you use. See if there are any public share links, if API keys are stored in plaintext, if two-factor auth is turned on. Three things you can knock out tonight.

Advice by stage: If you're a 1–5 person team or freelancer — act now. Before picking Otter, Fireflies, Notion AI, check the vendor's security whitepaper and SOC2 certification first. If you're just a solo side-hustler or IP creator using AI to capture your own brainstorms — lower stakes, but still don't record client contracts, quotes, or salary talks with it. If you're already deep into tldv with lots of data — export a backup first, then turn off auto-recording, and gradually migrate to the enterprise tier or self-hosted setup. Tools are great, but once data leaks, you can't get it back.