Skip to content
Notifications
Clear all

Just found a major flaw in Sembly's security model for confidential client calls.

1 Posts
1 Users
0 Reactions
4 Views
(@martech_ops_sarah)
Trusted Member
Joined: 4 months ago
Posts: 30
Topic starter   [#4450]

Hey everyone. I've been using Sembly for about six months now to help with client meeting transcriptions and summaries, mostly for our marketing strategy syncs. It's been a huge time-saver for creating follow-up emails and action items. However, something happened last week that has me seriously reconsidering its use for any call with sensitive or confidential information.

I was on a call with a high-value client, discussing their upcoming product launch details, target audience segments, and some not-yet-public pricing strategy. Like I always do, I had Sembly running in the background. After the call, I went to review the transcript and noticed something odd in the "Key Points" section. It correctly pulled out action items, but it also generated a bullet point summarizing the confidential pricing model with a specific percentage discount tier we discussed.

That wasn't the alarming part. The alarming part was when I clicked into the "AI Insights" section. Sembly had auto-generated a suggested email draft "to follow up on the discussed pricing." This draft, meant for me, *contained the specific discount figure in plain text*. If I had accidentally sent that without thorough review—which is easy to do when you're rushing—that confidential data would have been in the client's inbox.

This exposed two major issues in their security model for me:
1. **Lack of configurable data redaction:** There's no way to tell Sembly, "Hey, when you see numbers that look like prices or percentages, blur them out or flag them for manual review." It processes everything with the same level of openness.
2. **Overly prescriptive AI actions:** The tool isn't just transcribing; it's actively creating outputs (emails, summaries) designed to be used with minimal editing. When those outputs contain sensitive data, it creates a huge risk of unintentional leakage. It assumes all meeting content is safe to repurpose.

I've worked with other platforms (like Gong for sales, which has more granular controls) and in my HubSpot/Salesforce workflows, I'm used to being able to tag fields as "confidential" or restrict data flow. Sembly feels like it's built for internal team meetings, not for agency or consultant conversations where client IP is paramount.

Has anyone else run into this? I'd love to hear how you're handling it. For now, I've stopped using it on any client call and I'm manually transcribing the sensitive ones, which defeats the whole purpose. I'm wondering if there's a setting I've missed or if this is just an inherent risk with the current product design.

~Sarah


Data is the new oil


   
Quote