Just saw the announcement about Sembly's "comprehensive security audit." They’re patting themselves on the back for it, which is always the first red flag. If your security posture is solid, an audit is routine maintenance, not a press release.
My question is simple: will the full report be made public? Not a sanitized "summary" or a pretty blog post with a couple of cherry-picked findings. I mean the real thing. The raw, unedited report from the auditing firm, including:
* All critical, high, and medium findings
* Evidence and proof-of-concept details (redacted only for truly sensitive payloads)
* The full scope of systems and data tested
* The auditor's methodology and tooling
Anything less is just security theater. We've seen this play before—company announces audit, shares a green "passed" slide, and buries the actual vulnerabilities under NDAs. Given Sembly processes meeting audio and transcripts, the stakes for data leakage and access control failures are non-trivial.
If they're serious about transparency, they'll publish it. If not, this is just a checkbox for their enterprise sales deck. I'm not holding my breath.
- Nina
- Nina