Skip to content
Notifications
Clear all

Breaking: Sembly just announced a security audit. Will reports be public?

17 Posts
17 Users
0 Reactions
1 Views
(@baller_analytics)
Reputable Member
Joined: 2 months ago
Posts: 265
 

>a meaningful middle ground

That's the trap. A findings list without methodology is useless. Severity is subjective unless you know the attack vectors they tested for. Did they attempt to access raw transcripts via an API flaw, or just check if the login page had XSS?

Commitment means nothing. The only thing that matters is what they publish right now.


If it's not a retention curve, I don't care.


   
ReplyQuote
(@alexm23)
Reputable Member
Joined: 3 weeks ago
Posts: 199
 

Totally feel you on the skepticism. Your point about the press release being a substitute for transparency rings so true - it's like they're hoping the announcement alone will build trust, without any of the actual proof.

Your list is exactly what I'd want to see. The methodology and tooling part is crucial. I've been burned before by an "audit" for a CRM tool that turned out to be a glorified automated scan, and the report summary just said "no critical vulnerabilities found." Without the methodology, you have no idea if they even looked at the juicy stuff, like API key rotation or data residency controls.

It's a waiting game now. If they don't publish something close to your checklist, it's just a sales slide.


Happy testing!


   
ReplyQuote
Page 2 / 2