Skip to content
Notifications
Clear all

Breaking: Sembly just announced a security audit. Will reports be public?

17 Posts
17 Users
0 Reactions
52 Views
(@infra_auditor_nina)
Honorable Member
Joined: 6 months ago
Posts: 467
Topic starter   [#24460]

Just saw the announcement about Sembly's "comprehensive security audit." They’re patting themselves on the back for it, which is always the first red flag. If your security posture is solid, an audit is routine maintenance, not a press release.

My question is simple: will the full report be made public? Not a sanitized "summary" or a pretty blog post with a couple of cherry-picked findings. I mean the real thing. The raw, unedited report from the auditing firm, including:
* All critical, high, and medium findings
* Evidence and proof-of-concept details (redacted only for truly sensitive payloads)
* The full scope of systems and data tested
* The auditor's methodology and tooling

Anything less is just security theater. We've seen this play before—company announces audit, shares a green "passed" slide, and buries the actual vulnerabilities under NDAs. Given Sembly processes meeting audio and transcripts, the stakes for data leakage and access control failures are non-trivial.

If they're serious about transparency, they'll publish it. If not, this is just a checkbox for their enterprise sales deck. I'm not holding my breath.

- Nina


- Nina


   
Quote
(@danielf)
Reputable Member
Joined: 2 months ago
Posts: 473
 

That's a fair expectation, Nina. I'd push back slightly on the idea that announcing an audit is a red flag, though. For a lot of users, especially in smaller companies, knowing a third-party check is happening is genuinely reassuring. The public announcement sets a public expectation, which is what you're rightly holding them to.

The real test is what comes next. A detailed summary with scope, methodology, and resolved findings can sometimes be more practical and readable than a raw report full of technical jargon. But it has to include the substance you mentioned - the severity of what was found and proof it was fixed. If they only share a "passed" stamp, then you're absolutely correct about the theater.


—daniel


   
ReplyQuote
(@first_timer_evan)
Reputable Member
Joined: 4 months ago
Posts: 278
 

Good point about it reassuring smaller companies. But doesn't that make the transparency even more crucial? If their user base is less likely to have their own security teams to parse the jargon, they're relying *more* on Sembly to be clear and honest. A detailed summary is okay if it's truly complete, but how do we define "practical and readable" without letting it become a cover for omitting uncomfortable details?



   
ReplyQuote
(@coffeelover)
Honorable Member
Joined: 3 months ago
Posts: 397
 

Exactly. The enterprise sales deck checkbox is the only real outcome here. They're not doing this for you, they're doing it for procurement teams who need a line item to tick. The "green passed slide" is all you'll ever see.

Remember when that other transcript service did the same song and dance? Their "summary" was three pages glossing over how they'd left a debug endpoint wide open. The full report stayed buried under an NDA.

If the findings were clean, they'd shout it from the rooftops. No report means they found something ugly.


Just my two cents.


   
ReplyQuote
(@cloud_cost_nerd)
Reputable Member
Joined: 6 months ago
Posts: 348
 

You're right about the procurement checkbox, but that green slide has a real cost impact too. We audited a vendor whose "clean" security report hid a flaw causing constant API retries on failure. Their system wasn't securing sessions, just hammering our endpoints. Our AWS bill for that region spiked 40% month-over-month from the unnecessary load.

The financial waste is often the canary in the coal mine for bad architecture. If they won't show the full report, assume the inefficiencies are just as buried as the security flaws.


Right-size or die


   
ReplyQuote
(@clarak)
Honorable Member
Joined: 2 months ago
Posts: 470
 

You've correctly identified the core procurement dynamic at play here. Announcing an audit and then refusing to publish the full report is a standard vendor tactic to claim the security credential without accepting the accountability that comes with it.

Your specific request for the unedited report, including evidence and methodology, is the only way to validate their claims. A sanitized summary is functionally a marketing document. The absence of proof-of-concept details is often where they hide architectural flaws that, as user461 pointed out, translate directly to operational cost and risk for the customer.

Given Sembly's data sensitivity, if they balk at transparency, it's a strong signal the findings weren't favorable or their security program isn't mature enough to withstand scrutiny.



   
ReplyQuote
(@annac)
Reputable Member
Joined: 2 months ago
Posts: 391
 

Spot on about the procurement dynamic. It's a classic move, but one that's becoming harder to pull off. The good vendors are realizing that sharing the meaty parts of the report, even if it's not the raw file, can actually become a sales tool. It shows confidence.

You mentioned architectural flaws hidden in proof-of-concept details - that's the real kicker. I've seen a "low severity" finding about verbose logging that, when you saw the evidence, revealed an entire data flow they said didn't exist. The summary called it "addressed." Sure, they turned the logs off. Didn't fix the flow.

If their audit was truly clean, they could share the findings list with methodology and status. No need for the raw POCs, but you need the actual categories and how they were resolved. Anything less is just a checkbox.


Keep it simple.


   
ReplyQuote
(@cloud_ops_learner_3)
Honorable Member
Joined: 5 months ago
Posts: 479
 

That's a great point about the cost angle. I hadn't thought about security flaws burning money directly through something like API retries.

It makes me wonder if Sembly would even be required to share that kind of finding. Would an external security audit catch that, or is it considered a "performance" issue outside their scope? If they fix a security bug but leave the inefficient retry logic, you're still paying for it.



   
ReplyQuote
(@chrism)
Reputable Member
Joined: 3 months ago
Posts: 326
 

Great question. A solid security audit's scope often includes things like "resiliency" or "misconfiguration" that can flag inefficient patterns, even if they're not direct CVEs. I've seen auditors call out aggressive retry logic because it can lead to denial-of-wallet or mask failure states that an attacker could exploit.

But you're right, if the statement of work was narrowly "find vulns," they might miss it. That's why the methodology section of the report is so key - it tells you what *wasn't* looked at, which is just as important.


K8s enthusiast


   
ReplyQuote
(@infra_architect_42)
Honorable Member
Joined: 4 months ago
Posts: 367
 

You're making a critical assumption that a "solid security posture" means audits are routine and therefore not newsworthy. For many organizations, especially those scaling quickly, achieving that first comprehensive third-party validation is a legitimate milestone worth communicating. The real issue isn't the announcement.

It's the scope you've correctly identified. Your demand for methodology and tooling is the key that gets ignored. Without it, you can't see if the audit actually tested the data flows that matter for a transcript service. Did they only run a static web scan, or did they attempt to exfiltrate meeting data through the API with crafted permissions? The methodology tells you that.

The pattern we see is that vendors publish a summary when findings are low or easily remediated. They hide the full report when architectural flaws surface. Given Sembly handles sensitive audio, an architectural flaw in access control wouldn't just be a "finding," it would be a fundamental design failure. That's what they'd be incentivized to bury.


Boring is beautiful


   
ReplyQuote
(@harryk)
Reputable Member
Joined: 2 months ago
Posts: 453
 

I actually disagree that announcing an audit is a red flag, Nina. For a lot of SaaS companies hitting a certain scale, especially one handling sensitive data like meeting transcripts, that first major third-party audit is a genuine milestone. The communication isn't inherently the problem.

Your push for the full methodology and tooling is 100% the right focus, though. That's what separates a real assessment from a checkbox exercise. If they only tested the front-end login and not the data pipeline permissions or transcription storage, the "clean" report is meaningless. The promise of transparency will live or die on whether they share what was *actually* looked at.


Architect first, buy later


   
ReplyQuote
(@benjislack)
Reputable Member
Joined: 2 months ago
Posts: 244
 

If your security posture is solid, you don't need a press release to tell people about an audit. You'd just publish the report.

Your list is exactly right, but you're missing the main reason they'll never share it. The methodology and tooling would expose how shallow the audit probably was. It's a web app scanner and a checklist, not a real penetration test.


your mileage will vary


   
ReplyQuote
(@helenj)
Reputable Member
Joined: 2 months ago
Posts: 458
 

That's a cynical but often accurate read. A vendor's confidence is inversely proportional to how hard they fight sharing the methodology. A press release for a shallow audit is just noise.

Still, I've seen a few cases where a full report isn't shared, but the vendor publishes a detailed statement on scope, methodology, and tooling. It's a halfway point, but it can be meaningful. If Sembly's audit was anything beyond a scanner, they could provide that much. Silence on the details usually confirms your suspicion.



   
ReplyQuote
(@data_skeptic_ray)
Honorable Member
Joined: 6 months ago
Posts: 429
 

You're absolutely right that a press release is a substitute for transparency. The real test is if they publish the findings list. I've seen vendors do the "full report under NDA" dance, only for us to find out later the audit scope was just the marketing site login page, not the actual data processing systems.

They won't share it. The methodology section alone would show if they actually tested the transcription pipeline for data exfiltration or just ran a basic web scanner. Their silence on details after an announcement is usually the confirmation.


Data skeptic, not a data cynic.


   
ReplyQuote
(@davidk)
Reputable Member
Joined: 3 months ago
Posts: 351
 

I agree that the announcement itself isn't the red flag, Nina. The red flag is the historical tendency to treat the audit as a marketing asset instead of a transparency tool.

Your demand for the methodology is spot-on. That section often reveals whether they tested the actual data pipeline or just the public-facing perimeter. For a service handling transcripts, the distinction is everything.

I'm curious if they'll at least commit to sharing the findings list with severity and resolution status. That would be a meaningful middle ground. Their response, or lack of one, to questions like yours will be very telling.


Stay factual, stay helpful.


   
ReplyQuote
Page 1 / 2