>gabes/the letter
movetuesday2026-08-04

every conversation your support bot has ever had is written down somewhere. a researcher just found 3.7 million of them sitting in the open.

no password, no encryption, names and addresses included. the vendor left the door open. your name goes on the notice.

a researcher found 3.7 million chat transcripts, call recordings and phone transcriptions in three unsecured databases tied to sears home services, dating 2024 to 2026, with customer names, physical addresses, emails and phone numbers inside. the condition is ordinary and it is probably yours: you put a bot in front of customers, the bot writes down every conversation, and the writing lives on infrastructure you have never looked at and cannot audit. the cost does not land on the vendor. the name on the breach notice is yours, and the customer reading it has never heard of the company that actually left the door open. the advice going around is to ask for the vendor's soc 2, which tells you they have a process, not where your transcripts sit or how long they are kept.

do the version that holds: this week, send two questions in writing to every ai vendor that touches a customer conversation. where are transcripts and recordings stored, and what is the retention period. then set retention to the shortest window your business can work with, and get it into the contract at renewal. a vendor who will not answer those two in writing has already answered them.