Meetily is a desktop meeting recorder that keeps everything local. It captures your microphone and the computer's audio together, so it works with Zoom, Meet, Teams or anything else without a bot joining the call, and transcribes live with Whisper or NVIDIA's Parakeet running on your machine. When the meeting ends it writes a summary with the model you choose: a local Ollama model by default, or Claude, Groq, OpenRouter, OpenAI or any OpenAI-compatible endpoint. You can also import an existing recording and re-transcribe it with a different model or language.
It is a single Tauri app with a Rust backend and a Next.js interface, using Metal and CoreML on Macs and Vulkan on Windows. Builds are offered for Apple Silicon Macs and 64-bit Windows; Linux users build from source.
Meetily is made by Zackriya Solutions, MIT-licensed, with about 31,400 stars and version 0.4.1. The free Community Edition sits beside a paid Meetily PRO built on a separate codebase, with more accurate transcription, custom templates, PDF and DOCX export and automatic meeting detection. The speaker diarization mentioned in the repository's description is listed in the README as a PRO feature, not part of the free app.
- Repository: github.com/Zackriya-Solutions/meetily
- Licence: MIT (MIT License)
- Language: Rust. Stars: 31.4K. Forks: 3,430. Last push: Sep 15, 2026.
- Scan: safe, Sep 10, 2026, commit a2cb62e
Who it is for
Consultants, lawyers, clinicians and other professionals who cannot send meeting audio to a cloud note-taker, and anyone who dislikes AI bots joining their calls.
Getting started
1. macOS on Apple Silicon, with Homebrew
brew install --cask meetily2. Windows: run the x64 installer from the releases page. Linux: build from source
git clone https://github.com/Zackriya-Solutions/meetily && cd meetily/frontend && pnpm install --frozen-lockfile && ./build-gpu.shSummaries need a language model: install Ollama for fully local summaries, or add an API key for Claude, Groq, OpenRouter or OpenAI, in which case the transcript is sent to that provider. The Windows build needs a CPU with AVX2, and CUDA acceleration only comes with a source build. Recording other people may require their consent where you live.
Safety scan
We cloned Zackriya-Solutions/meetily at commit a2cb62e on Sep 10, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious code patterns and no bare-IP URLs across 536 files and about 113,000 lines of Rust and TypeScript.
- One committed binary: frontend/vs_buildtools.exe, 4.5 MB, a Windows executable carrying Microsoft's code-signing certificate chain, which matches the Visual Studio Build Tools bootstrapper. It arrived in an October 2025 release commit and nothing in the code refers to it. It plays no part in the app you install, but if you need the build tools, download them from Microsoft.
- We read the analytics code. Meetily uses PostHog, and AnalyticsProvider.tsx sets analyticsOptedIn to false for new installs and resets it to false once for older installs, so nothing is sent until you switch it on. Transcripts go off the machine only if you choose a cloud model for summaries.
- 114 known advisories (3 critical, 42 high). frontend/pnpm-lock.yaml holds 77, including two Next.js 14 criticals that concern a running Next server; Meetily builds Next as a static export inside Tauri, so no Next server runs. Nine sit in backend/requirements.txt, the older Python server with Docker scripts, which the self-contained desktop app does not use, and 28 in Cargo.lock, none critical.
- Eight workflows, none using pull_request_target, and none of the 28 third-party actions pinned to a commit. The six installer scripts all belong to that Python backend and none uses sudo or pipes a download to a shell. Licence and contributing guide present; no security policy, Dependabot or CodeQL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | 1 Cargo build script. 6 installer scripts |
| Committed binaries | 1 executable or compiled object committed; listed under the raw findings. |
| CI workflows | 8 workflows. None use pull_request_target. 28 of 28 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 21 distinct hosts referenced from source; most often huggingface.co, github.com, api.github.com, stackoverflow.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 114 advisories across 1,527 pinned packages: 3 critical, 42 high, 43 moderate, 12 low, 14 unrated. Cargo.lock: 855 packages, 28 advisories; backend/requirements.txt: 10 packages, 9 advisories; frontend/pnpm-lock.yaml: 662 packages, 77 advisories. |
| Project hygiene | Has licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Installer scripts (6)
- backend/install_dependancies_for_windows.ps1, 197 lines; talks to bun.sh, chocolatey.org, github.com, vcredist.com
- backend/run-docker.ps1, 1,566 lines; talks to huggingface.co
- backend/run-docker.sh, 2,009 lines; talks to huggingface.co
- backend/setup-db.ps1, 338 lines
- backend/setup-db.sh, 369 lines
- backend/start_with_output.ps1, 925 lines; talks to api.github.com, github.com
Committed binaries (1)
frontend/vs_buildtools.exe: PE (Windows executable), 4 MB
Worst known vulnerabilities (24 of 114)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-2xp9-vwfh-vxw4 | critical | next@14.2.35 | Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used |
| GHSA-p293-qw3h-jr36 | critical | next@14.2.35 | Next.js: Unauthenticated Remote Code Execution on windows-hosted servers |
| GHSA-w7jw-789q-3m8p | critical | shell-quote@1.8.3 | shell-quote quote() does not escape newlines in object .op values |
| RUSTSEC-2026-0194 | high | quick-xml@0.37.5 | Quadratic run time when checking a start tag for duplicate attribute names |
| RUSTSEC-2026-0195 | high | quick-xml@0.37.5 | Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service |
| RUSTSEC-2026-0194 | high | quick-xml@0.39.4 | Quadratic run time when checking a start tag for duplicate attribute names |
| RUSTSEC-2026-0195 | high | quick-xml@0.39.4 | Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service |
| GHSA-82j2-j2ch-gfr8 | high | rustls-webpki@0.101.7 | rustls-webpki: Denial of service via panic on malformed CRL BIT STRING |
| GHSA-2jrp-274c-jhv3 | high | pydantic-ai@0.2.15 | Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling |
| GHSA-5rvq-cxj2-64vf | high | python-multipart@0.0.20 | python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service |
| GHSA-pp6c-gr5w-3c5g | high | python-multipart@0.0.20 | python-multipart has Denial of Service via unbounded multipart part headers |
| GHSA-wp53-j4wj-2cfg | high | python-multipart@0.0.20 | Python-Multipart has Arbitrary File Write via Non-Default Configuration |
| GHSA-3pq3-5fj3-cg6v | high | axios@1.16.1 | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| GHSA-542g-h47m-68v8 | high | axios@1.16.1 | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization |
| GHSA-c29m-xwm3-cm6r | high | axios@1.16.1 | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| GHSA-gcfj-64vw-6mp9 | high | axios@1.16.1 | Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning |
| GHSA-m8m8-qj5v-23w3 | high | axios@1.16.1 | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection |
| GHSA-mghh-pgcx-3jjj | high | axios@1.16.1 | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location |
| GHSA-x97p-jq2g-jp4f | high | axios@1.16.1 | Axios: Prototype Pollution Gadget in axios toFormData Options |
| GHSA-3jxr-9vmj-r5cp | high | brace-expansion@2.1.0 | brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@2.1.0 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-mh99-v99m-4gvg | high | brace-expansion@2.1.0 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@2.1.0 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-rgw5-rvv9-x895 | high | brace-expansion@2.1.0 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
By the numbers
| Stars | 31.4K |
|---|---|
| Forks | 3,430 |
| Contributors | 20 |
| Commits | 661 |
| Open issues | 202 |
| Open pull requests | 154 |
| Releases | 12 |
| Latest release | v0.4.1 |
| Licence | MIT |
| Main language | Rust |
| Project age | 1 year |
| Last push | Sep 15, 2026 |
| Tracked files | 536 |
| Lines of code | 113.4K |
| Checkout size | 47 MB |
Lines by language: Rust 48.6K, TypeScript 32.1K, C/C++ header 9,263, Shell 4,676, PowerShell 4,019, Markdown 3,475.
Questions
Is Meetily free?
The Community Edition is MIT-licensed and free, with local transcription and AI summaries. Meetily PRO is a separate paid product with more accurate models, custom summary templates, PDF and DOCX export, automatic meeting detection and team deployment. Cloud summary providers bill you for their API use; Ollama costs nothing.
Does Meetily join my meetings as a bot?
No. It records system audio and your microphone directly on your computer, so other participants see no extra attendee. That also makes it your job to tell people they are being recorded.
Does Meetily send my audio to the cloud?
No. Recordings, transcripts and transcription models stay on your machine. The only thing that leaves is the transcript text sent for summarizing, and only if you pick a cloud provider instead of a local Ollama model.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
