2025 AssemblyAI — indirect exposure via Granola app API key
Data compromised
Meeting transcripts (text)
Technical writeup
Hard-coded AssemblyAI API key in Granola macOS Electron app. Accessible via unauthenticated /get-feature-flags endpoint. Tenable researcher demonstrated: key allowed enumeration of /transcript API to download text transcripts for other Granola users. ~300 alpha users affected. Granola revoked key within minutes. No audio accessible, only text transcripts.
Root cause
Third-party (Granola) hardcoded API key; unauthenticated endpoint