[HN Gopher] Delve - Fake Compliance as a Service
___________________________________________________________________
Delve - Fake Compliance as a Service
Author : freddykruger
Score : 479 points
Date : 2026-03-19 19:08 UTC (1 days ago)
(HTM) web link (deepdelver.substack.com)
(TXT) w3m dump (deepdelver.substack.com)
| ersshh wrote:
| Forbes 30u30 pipeline remains undefeated.
|
| How did none of this come up during diligence? Feels like a prime
| example of too good to be true.
| sebmellen wrote:
| Trust me, you can lie and get away with it if you go through YC
| and dropped out of a top university. Garry Tan blocked me on X
| for pointing this out. It's a big club, and you ain't in it!
|
| Fortunately, some of the old-YC spirit seems to be alive here
| on HN still.
| jvwww wrote:
| They likely barely had a product when they applied to YC.
| It's more interesting as to why this wasn't discovered (if it
| is even true) when they were raising their Series A.
| allovertheworld wrote:
| You mean from the beginning? They could've just done it
| properly initially then moved to this scam process later
| rithdmc wrote:
| > How did none of this come up during diligence?
|
| The article states that, "Even though we knew we'd technically
| be lying about our security to anyone we sent these policies to
| for review ... we decided to adopt these policies because we
| simply didn't have the bandwidth to rewrite them all manually."
| latchkey wrote:
| This is the next one...
|
| https://x.com/HotAisle/status/2035024494663016532
| duped wrote:
| Dishonesty is high signal for VC
|
| Like no one characterizes it like that, but this is the same
| business where you can tell a story about hiring a bunch of
| college friends to pretend to be your employees so a client
| comes to your "office" and thinks you're a legitimate business.
| And instead of looking in horror at how casually you'll lie to
| get business it's seen as scrappy and whimsical.
| ManuelSuarez wrote:
| https://www.reddit.com/r/soc2/comments/1q7u90o/real_or_fake_...
| halamadrid wrote:
| This was such as interesting read, but I found this link via
| LinkedIn rather than hackernews.
|
| I would have expected this to be somewhere at the top right now
| given how deep the article digs and evidence seems legit.
| sebmellen wrote:
| I think it may be getting (intentionally?) suppressed from the
| homepage. Given this is a YCombinator website, I wouldn't rule
| that out.
|
| Regardless, it's been an ongoing issue. I know a few involved
| companies -- it takes basically 5 days to get a SOC 2 Type 2
| report through Delve. And, of course, they market this way too:
| "SOC 2 in days". Unbelievable.
| instalabsai wrote:
| Surprised/not surprised that this is getting buried from the
| homepage
| sebmellen wrote:
| I just got blocked by another YC founder (and potential
| investor in Delve?) for refuting his handwavey argument
| that "all compliance companies do this" [0] -- this is
| beyond just marketing, it is active and blatant/intentional
| fraud. I don't see how it can be defended. But in that
| sense it is a major crisis for anyone who invested in the
| company.
|
| [0]: https://x.com/kobyjconrad/status/2034843865396506864
| dang wrote:
| It got downweighted by HN's voting ring detector. Mods
| didn't touch it, except to place the story on the frontpage
| once we knew it existed.
| browningstreet wrote:
| It's a trending story on X. Was surprised there was no meaty
| discussion here on HN.
| andrewflnr wrote:
| I see the submission time as an hour ago, so it actually
| looks like it got a second-chanced, i.e. boosted by the site
| admins.
| dang wrote:
| That's correct - you can see from
| https://news.ycombinator.com/submitted?id=freddykruger that
| this post was actually submitted 23 hours ago. The
| timestamp at the top of the thread is relativized to fit
| the second-chance pool (https://hn.algolia.com/?dateRange=a
| ll&page=0&prefix=true&que...).
| dang wrote:
| In case anyone hasn't seen my other posts about this:
|
| (1) I had no idea this story existed and woke up to claims
| that I was obviously* suppressing it.
|
| (2) I looked into it and found that no moderator had touched
| either of the two submissions of the story, but that both
| submissions had set off HN's voting ring detector. (Whether
| there was a voting ring or not, I don't know - that software
| isn't perfect. It has held up well over the years though.)
|
| (3) We merged the two discussions and placed the merged
| thread on the front page.
|
| (4) Why? Because we moderate HN less, not more, when YC or a
| YC startup is part of a story: https://hn.algolia.com/?dateRa
| nge=all&page=0&prefix=false&qu.... This is literally the #1
| principle of moderation in the sense that it was the very
| first thing that pg drilled into me: https://hn.algolia.com/?
| dateRange=all&page=0&prefix=true&que....
|
| * https://quoteinvestigator.com/2018/11/18/know-trouble/
| muglug wrote:
| TIL that voting ring detection exists
| dang wrote:
| HN would be an entirely different place if people could
| just arrange to get their stuff upvoted onto the front
| page! We've spent hundreds of hours working on this over
| the years. Still not perfect of course.
| sebmellen wrote:
| My theory is that a lot of people may have looked for a
| story like this on the home page and then searched
| 'Delve' to see if anything was submitted recently and
| then upvoted one of those recently submitted posts.
| x0x0 wrote:
| in some slacks there are regular requests to upvote
| stuff.
| moomoo11 wrote:
| I miss 2010s YC until like 2017 ish when crypto sort of just
| caused a massive decline across the board.
|
| I guess it is great if you're a grifter/scammer or looking to
| just sell off to a FANG.
| srikar_alter wrote:
| agreed
| gsibble wrote:
| How does this not reach the front page?
| slackfan wrote:
| It does, but it's also a takedown of a YC-backed company.
|
| Really great vetting there, guys.
| stuckkeys wrote:
| LOL -For a good minute the comments were not visible. Someone
| is playing RR.
| dang wrote:
| We were in the process of merging the threads. Actually
| tomhow had correctly merged them, but I misinterpreted
| which submission had been first and undid that. Then
| corrected my mistake.
|
| Had you checked the other thread during that "good minute",
| you'd have seen that all the comments were intact.
| nedwin wrote:
| It's on the front page for me?
| dang wrote:
| We just found out about this story and the submissions of it.
| It looks like it didn't make the front page because it set off
| HN's voting ring detector.
|
| Mods didn't touch either thread except (1) we merged the
| duplicate discussions and (2) we rolled back the voting ring
| penalty so that the story would be on the frontpage.
|
| This is in keeping with the principle that we moderate stories
| less, not more, when YC or a YC startup is part of the story.
| That's been the case since the beginning, and I've posted about
| it dozens of times: https://hn.algolia.com/?dateRange=all&page=
| 0&prefix=false&qu....
| sebmellen wrote:
| Respectfully, I think there may be an issue with your voting
| ring detection, which is that if multiple people try to
| submit the same article and are redirected to an existing
| post and they upvote it, that might be setting off the voting
| ring alert. Can you check that?
|
| I would imagine that's what happened here.
| dang wrote:
| That's definitely not what happened here. The data would be
| quite different in that case.
|
| Edit: 10% of the votes came from resubmissions of the URL.
| The other 90% came from other sources.
| sebmellen wrote:
| Curious to know! I submitted the duplicate article and
| most definitely did not work with any voting ring.
| ohyoutravel wrote:
| All this evidence seems pretty legit. I found this on LinkedIn
| and came here to post, but noticed it had already been posted.
| Surprised I didn't see it on HN front page.
| sebmellen wrote:
| It is being suppressed by @dang, I believe they may have a
| policy that allows suppression for bad YC-related news.
| tomhow wrote:
| Moderators didn't see it, and our policy is the precise
| opposite of this - see https://hn.algolia.com/?dateRange=all&
| page=0&prefix=false&qu... or, for more color, https://hn.algo
| lia.com/?dateRange=all&page=0&prefix=true&que....
|
| We've restored it to the front page now.
| sebmellen wrote:
| Yes, but your team claimed this set off "voting ring"
| behavior [0] and it was suppressed for nearly a day because
| of that. I am very curious how you determine what is, or is
| not, "voting ring" behavior. I believe Dang is responding
| in another thread about that.
|
| [0]: https://news.ycombinator.com/item?id=47457689
| dang wrote:
| Obviously we don't publish how HN's voting ring detector
| works. If we did, it would quickly stop working.
|
| What matters in this case is (1) it's a software penalty
| that has nothing to do with the content of a story, (2)
| moderators didn't touch the submissions or even know they
| existed, and (3) once we did know that they existed, we
| merged the threads and placed the story on the frontpage
| - that is, we went out of our way to give this story
| _more_ attention, not less - in keeping with the
| principle explained here: https://hn.algolia.com/?dateRan
| ge=all&page=0&prefix=false&qu....
| laidoffamazon wrote:
| Major red flag with this should have been that their expensive
| marketing predicated heavily on them being MIT dropouts instead
| of any expertise in the space
| AFF87 wrote:
| I remember having sales calls with them and the vibe was that it
| was "cheap and quick"... exactly what you want for your
| compliance
| LambdaComplex wrote:
| > No custom tailoring, no AI guidance, no real automation. Just
| pre-populated forms that required you to click "save".
|
| I hate that I've become this cynical, but it's gotten to the
| point where reading the "no x, no y, just z" construct makes me
| assume that writing is AI generated (and then I immediately stop
| caring about reading it)
| fantasizr wrote:
| there needs to be a fund with an ethos of "move slowly and do
| things accurately"
| sunir wrote:
| The fund is called customers. The independent regulator is
| called the AICPA. It really comes down to who is paying
| attention
|
| SOC2 is as useful as a privacy policy at protecting your data.
| It's all humans following human incentives.
| Spivak wrote:
| The value of SOC2 is that it does take _some_ experience to
| be able to plausibly fake the evidence which weeds out people
| that truly have no idea what they 're doing. It also provides
| a blueprint of the stuff you should be doing if you actually
| care.
|
| But beyond that it's not worth a whole lot.
| fantasizr wrote:
| yeah it's funny to see some defense of this practice as
| "well the whole thing is pointless anyway so nothing is
| lost by defrauding folks". Pretty hollow argument
| DANmode wrote:
| There are a few, roughly.
|
| Like the best options in most categories, they don't spend a
| bunch of money or time on brand presence, advertising.
|
| _You_ simply find _them_.
| neutronicus wrote:
| The United States military?
| hrimfaxi wrote:
| Slow is smooth and smooth is fast.
| gmerc wrote:
| Well now we know how Cluely and friends can claim to be SOC2
| compliant.
| rvz wrote:
| Notice how none of Delve's affiliates on X are posting anything
| after that Substack post. Probably their lawyers told them not to
| say anything further.
|
| What does that tell you about the scam that was unveiled?
|
| Not good.
| JimDabell wrote:
| The only thing it tells us is that they have received competent
| legal advice. Any counsel is going to tell you to shut up
| regardless of whether you are in the right or wrong.
| claudiug wrote:
| wow, cannot imagine now companies that tool the compliance, and
| get deals just to be fake. uff...
| resiros wrote:
| This seems like a hit job by a competitor. Really ruthless.
|
| > Two months ago, an email went out to a few hundred Delve
| clients informing them that Delve had leaked their audit reports,
| alongside other confidential information, through a Google
| spreadsheet that was publicly accessible.
|
| Who leaked the audit reports? Who sent this email? Who is taking
| the time to write this analysis and kill the company?
|
| In my opinion, the majority of the points in the article are no
| news. A compliance saas that offers templates for policies, all
| of them do. The AI is a chatbot, well who thought.
|
| I think the main point is the collusion between delve and the
| auditors. Is the evidence for that clear?
| sebmellen wrote:
| Hit piece or not, the blatantly fraudulent behavior displayed
| by Delve is reprehensible.
|
| And they didn't even try. Read this management assertion for
| one of the (known) affected companies:
|
| > _We have prepared the accompanying description of Cluely,
| Inc.,_ system titled "Cluely is a desktop AI assistant to give
| you answers in real-time, when you need it." _throughout the
| period June 27, 2025 - September 27, 2025(description), based
| on the criteria set forth in the Description Criteria DC
| Section 200 2018 Description Criteria for a Description of a
| Service Organization's System in a SOC 2 Report (description
| criteria)._
|
| > _The description is_ intended to provide users with
| information about the "Cluely is a desktop AI assistant to
| give you answers in real-time, when you need it." that _may be
| useful when assessing the risks arising from interactions with
| Cluely, Inc. system, particularly information about the
| suitability of design and operating effectiveness of Cluely,
| Inc. controls to meet the criteria related to Security,
| Availability, Processing Integrity, Confidentiality and Privacy
| set forth in TSP Section 100, 2017 Trust Services Principles
| and Criteria for Security, Availability, Processing Integrity,
| Confidentiality and Privacy (applicable trust services
| criteria)._
| cyrusradfar wrote:
| There's no need for some conspiracy.
|
| It's a juicy story to talk about that hits a lot of checkboxes
| that make it viral -- 1. the hustle culture
| they promoted online was gross 2. they followed the 30u30
| Forbes pattern like Liz Holmes, FTX, etc. 3. they're a
| YC co, so their's plenty of popular voices supporting them
|
| The 3rd isn't to slight the program but folks definitely slam
| any companies that seem to be in the moral gray area as a proof
| the program is nihilistic and a net negative. People like to
| shove mistakes in the face of "successful" folks like
| investors/VCs.
|
| Finally, the security and compliance community is litigious by
| their nature and this startup, in general, was a net negative
| for a lot of people who do fractional / consulting work in
| security.
| sebmellen wrote:
| What's more surprising to me, as a layperson, is that I found
| this out and investigated their shady auditor network in late
| December. It didn't take much work.
|
| Insight Partners invested in a 32 MILLION DOLLAR ROUND
| without any apparent shred of due diligence. What does that
| say about the VC market writ large?
| emilycg wrote:
| The key problem is the audits and the auditors. I have
| independently verified for our vendors that they have the same
| templated SOC2 as all of the leaked reports, which is
| concerning because that shows the auditors did not actually
| validate the controls.
|
| SOC2 is supposed to give you an INDEPENDENT evaluation of the
| compliance of a company "are they doing what they say they are"
|
| If the SOC2 report is just a pre-populated template, it is
| meaningless.
|
| It doesn't really matter the motivation of the "DeepDelver" -
| this has implications across all companies that rely on these
| vendors that have been "assessed" by Delve.
| OsrsNeedsf2P wrote:
| Really curious what you're going to do, going forward. Will
| you be rejecting compliance certified with Delve? Will you be
| forcing your vendors to redo compliance?
| sebmellen wrote:
| Delve did not even try to fake the reports well. They could have
| used AI tooling to write somewhat plausible Assertions of
| Management, but they just dropped in clear form submissions to
| the reports they provided. Here is an example from Cluely:
|
| > _We have prepared the accompanying description of Cluely, Inc.,
| system titled "Cluely is a desktop AI assistant to give you
| answers in real-time, when you need it." throughout the period
| June 27, 2025 - September 27, 2025(description), based on the
| criteria set forth in the Description Criteria DC Section 200
| 2018 Description Criteria for a Description of a Service
| Organization's System in a SOC 2 Report (description criteria)._
|
| > _The description is intended to provide users with information
| about the "Cluely is a desktop AI assistant to give you answers
| in real-time, when you need it." that may be useful when
| assessing the risks arising from interactions with Cluely, Inc.
| system, particularly information about the suitability of design
| and operating effectiveness of Cluely, Inc. controls to meet the
| criteria related to Security, Availability, Processing Integrity,
| Confidentiality and Privacy set forth in TSP Section 100, 2017
| Trust Services Principles and Criteria for Security,
| Availability, Processing Integrity, Confidentiality and Privacy
| (applicable trust services criteria)._
|
| I mean, just re-read this sentence:
|
| > _The description is intended to provide users with information
| about the "Cluely is a desktop AI assistant to give you answers
| in real-time, when you need it." that may be useful_
|
| It makes no sense at all.
|
| Someone implemented the code to automate this report mill, and
| didn't think to even smooth it out with an LLM! There was clear
| intent here.
|
| To imagine that an auditor reviewed and stamped this as a
| coherent body of work beggars belief.
| biggletiddies wrote:
| Cluely and HockeyStack are scam companies too.
|
| Cluely did the ChatGPT wrapper to cheat on interviews then sold
| the customer data to recruiters. The whole company promise is a
| scam, and useless since we have LLMs.
|
| HockeyStack held contests for people to win cars etc and never
| delivered. They also lied about having revenues and a product
| when they had nothing built. Along with Greptile they were doing
| 7day weeks of unpaid labor from "trial periods".
|
| Scams all around.
| porridgeraisin wrote:
| Wait what's the greptile story?
| buttsack wrote:
| It says right there, 7-day work weeks (no days off).
|
| Also they were part of the cohort forcing workers to stay
| minimum until 9PM.
|
| Like every AI company, their "product" is a Next.js website,
| OPENAI_API_KEY, and a Stripe checkout page.
| porridgeraisin wrote:
| Ah ok. What's with the "unpaid labour" part?
| buttsack wrote:
| It's also in the original post. Greptile, HockeyStack,
| and others from that cohort of 20-year old founders out
| of YC were having software engineer candidates come in
| day-in and day-out, staying until 9PM under the threat of
| being rejected if they left earlier.
|
| They were not paid at all, they were working long-term on
| a "trial period". And yes it's very illegal. I was there
| and saw it first-hand.
|
| The guys they had on trial periods - though I'm sure they
| were very intelligent - were not really firing on all
| cylinders if you know what I mean.
| calderwoodra wrote:
| Greptile is an awesome product, not sure where the scam is
| there
| frenchie4111 wrote:
| wow you guys really delved into this
| suriya-ganesh wrote:
| I've gone through this process and is this not a failure from the
| institute that are giving away these certifications for a fee
| without any due diligence?
|
| intermediaries like delve have only amplified this failure.
|
| it was obvious to anyone who was involved in this industry that,
| all of this is just security theatre with nothing really to back
| it up.
| stringtoint wrote:
| Love the depth of this post.
|
| We were actually looking at it as well recently (we're using
| Drata). I was thinking "Cool, this looks like the next cool step
| forward". The claims didn't sound out of the world in my ears.
|
| Every time an issue like this appears I wonder how many more
| undiscovered frauds are out there.
| egorfine wrote:
| Compliance is something that no one ever wants and everybody
| hates. Not a single founder wakes up in the morning thinking to
| themselves: "oh I wish I could make my company XYZ-123
| compliant!"
|
| Thus providing compliance is really just paying someone to shift
| responsibility.
|
| The regulator can ask whether you are compliant. You can present
| certificate from Delve or someone else and that's the end of it.
| Duhck wrote:
| When I worked in cybersecurity I had a similar realization. No
| one cared about security posture. They cared about insurance
| policies. People hired us to shift blame instead of improve
| security posture. this is not terribly different
| bjackman wrote:
| One of my FAANG security projects incidentally helped with
| some compliance efforts (I made very sure it was incidental,
| constantly said things like "I am thrilled that I can help
| you guys achieve your goals but I wanna be clear that I don't
| give a shit about compliance and I won't be allowing it to
| influence the direction of my product" in meetings, it must
| have been extremely annoying to work with me).
|
| At some point I was asked to look over the documents for the
| compliance definition and it was really hilarious. I had to
| give my engineering perspective on which aspects of the
| requirements we were and weren't meeting.
|
| But they were stuff like "you must have logs". "You must
| authenticate users". "You must log failed authentication
| attempts".
|
| Did we fulfill these requirements? It's a meaningless
| question. Unless you were literally running an open door
| telnet service or something you could interpret the questions
| so as to support any answer you wanted to give.
|
| So I just had to be like "do you want me to say yes?" and
| they did, so I said yes. Nothing productive was ever achieved
| during that engagement.
| leeter wrote:
| This is why I've said for years: If you want to drive best
| practices and policy with companies you can only do it with
| liability. Particularly non-insurable and non-tax deductible
| liability. If a company can't offload civil or criminal
| penalties to their insurance company and take the tax write
| down, they suddenly start caring about it.
|
| That said, this should be used sparingly; as it embeds a
| behavior deep. If that behavior later no longer makes sense
| it can be extremely costly to change it later.
| robocat wrote:
| > Particularly non-insurable and non-tax deductible
| liability
|
| Too often liabilities exceed assets, or the liabilities are
| externalised.
|
| Liability doesn't work as an incentive for many risks. For
| uncommon but extreme risks, it can be better to roll the
| dice on company failure than regularly pay low amounts for
| mitigation.
|
| It is especially effective to ignore liabilities when a
| company has poor profitability anyways.
|
| And then you see major companies sidestep the costs of
| their liabilities (plenty of examples after security
| failures, but also companies like Johnson&Johnson).
| wccrawford wrote:
| I think it's subtly different than that.
|
| Companies _do_ want to be secure. They try, and they often
| fail because it 's _hard_.
|
| They hire auditors to find problems _and_ to shift blame. But
| since they only have 30 days to fix the problems that are
| found, it 's going to see a _lot_ like they only care about
| shifting the blame. Because at that point, they only care
| about passing that audit.
|
| Right after that, though, they start caring about security
| again.
|
| How do I know? 19 years experience going through those audits
| on the company side. For 11 months of the year, it was clear
| the boss cared about security. For that 1 month during the
| 'free retest' period, they only cared about passing that
| audit.
| Muromec wrote:
| Not a single person wakes up in the morning thinking they wish
| to pay taxes and rent and do the laundry the other stuff that
| has to be done. I would be nice to smoke weed and play video
| games all day and order the deliveries.
|
| Some things just have to be done.
| egorfine wrote:
| > thinking they wish to pay taxes
|
| Wellll this is not always the case. I have moved from a
| shithole country to a nice one and oh boy I am crying in
| gratitude every month that I pay taxes. Because it is every
| day that I can see my money working for me in the
| environment.
|
| But your point stands.
| Muromec wrote:
| As a person who moved to a high-tax country I understand
| the sentiment. It's usually lost on the people who were
| always there paying those taxes. Somehow it often doesn't
| click that they get something in return.
|
| The same applies to all the audit and bureaucracy stuff.
| Does it do something? If you don't feel it does, does it
| mean it's not? I don't know really, but I hope somebody is
| rotating their key material as they provided in their
| security posture.
| kakacik wrote:
| There are well-used tax money, then there are stupidly
| burned tax money on ie buying favors of some part of
| population before elections, financing blindly without any
| checks social security programs that get abused to no end,
| or simply plain old corruption.
|
| I love bringing Switzerland up to annoy most of
| western/northern Europeans since their success is so
| obvious and undeniable while going in very different
| direction than most of Europe. Low to low-medium taxes, yet
| state budgets are frequently in positive numbers, there is
| no end to money spend on infra projects, train infra, but
| also rather strong social programs (just not ridiculously
| bad as mentioned above), top notch free healthcare and
| education. VAT taxes are 2-8% instead of 20-23% in all
| countries around. Country simply works(TM) because
| population is not hard comfort-zone-addicted and entitled
| bunch of spoiled whiny kids, they work relatively hard and
| it brings results, consistently and long term. They don't
| work more than americans nor asians, but thats enough for
| their prosperity.
|
| Do you think lets say a heavy tax burden in say Italy, or
| even France (not even going more into southern or eastern
| EU since that would be a small book) is really used well
| and efficiently? I visit those places frequently and it
| certainly doesn't seem that way. Random examples - Italy
| has garbage everywhere, people drive to highway stops to
| drop it there (so the wind blows it all around).
| Infrastructure seems like from 80s, with added age. From
| people dealing with bureaucracy there - its stuck in 19th
| century, direct approach will get you often nowhere. France
| - most communist state in western Europe, heck in _all_
| Europe, sans Belarus maybe. Yet if you talk to people, they
| are constantly pissed off at government, never happy with
| society or state they live in. I don 't blame them,
| listening to French colleagues complain is often rather sad
| experience. Not something you read in travel guides, do
| you.
| KPGv2 wrote:
| It doesn't hurt that Swiss immigration is very difficult
| to get through, and they have all that Holocaust money no
| Nazi or dead Jewish victim is ever going to come claim.
| hermanzegerman wrote:
| Well let's see how good that Swiss Model would work as a
| big normal state, and not as a small tax haven, smaller
| than the State of Baden-Wurttemberg living off those
| surrounding states (siphoning up wealthy people, who got
| rich in those countries, and also their academics, that
| they didn't have to pay the education for)
| Muromec wrote:
| >Low to low-medium taxes, yet state budgets are
| frequently in positive numbers
|
| >because population is not hard comfort-zone-addicted and
| entitled bunch of spoiled whiny kids
|
| I'm not sure why would I need lower taxes in exchange for
| more work. This somehow feels like a scam.
| tfrancisl wrote:
| Maybe no one wakes up wanting to deal with compliance, but it
| you found a company that has legal or moral obligations to be
| compliant with these standards, you sure have signed yourself
| up for it. Passing the responsibility off to some other company
| is, quite simply, irresponsible.
| egorfine wrote:
| Problem is, compliance is often detrimental to the cause. You
| want to encrypt users' data at rest? Illegal. You must store
| users data in a way prescribed by the law and it is extremely
| cumbersome, outdated and insecure.
| egorfine wrote:
| > Passing the responsibility off to some other company is,
| quite simply, irresponsible.
|
| Then do not pass the responsibility. But here's the trick:
| the regulator would like to see an audit done by a firm and
| purchasing audit services is exactly that: passing
| responsibility. So legally you can't be compliant unless you
| passed responsibility.
| tfrancisl wrote:
| These compliance companies are not primarily tasked with
| auditing, as this article makes very clear. Delve is in
| control of the auditing process in a way that is
| inappropriate and unusual for this industry. The work that
| the company with these obligations should be doing
| themselves is generating the Section 3 description and the
| controls. The auditor then independently verifies their
| compliance with the controls. Thats a clear delineation of
| responsibilty, IMO
| bedatadriven wrote:
| I don't want to work wherever you do your thing. Software as a
| service means you provide a service, and you should take your
| responsibility to protect your customer's data super seriously.
| Compliance frameworks are one useful tool among many to support
| this effort. It helps us identify gaps, identify risks, make
| improvements. It also give us a way to communicate what we do
| to our partners. The behavior described in the medium post is
| fraud, pure and simple.
|
| I am a founder, and my ambition includes meeting the highest
| possible standards for my customers.
| xtracto wrote:
| I've done a mix of SOC2, ISO27001 and PCI L1 for 3 different
| startups. 2 of them b2b. All certified 100% and fully
| compliant.
|
| The problem with the current frameworks is that the
| "controls" are so asinine and auditors so hard headed, that
| getting certified becomes a matter of "checking the box" .
|
| Particularly most of those frameworks REQUIRE maintaining so
| much paper red tape that make a 10 person startup want to
| kill themselves. And in addition the costs are stupid high
| for startups that are just "starting up".
|
| On the flip side, how many large companies have we seen that
| have all the SOCs, ISOS and whatnot certifications, and they
| get pwn3d and their data stolen or exposed.
|
| It tells you that a place being certified doesn't guarantee
| shit.
|
| The reality is that large companies ask for certs as a CYA
| mechanism: the "security" department of LargeCo, asks for the
| compliance cert so that when shit hits the fan, they can say
| "not my fault, they told me they were compliant"
|
| The good thing is that with the new Bullshit generators (llm)
| this certifification/compliance process will collapse.
| solatic wrote:
| > Not a single founder wakes up in the morning thinking to
| themselves: "oh I wish I could make my company XYZ-123
| compliant!"
|
| Somehow I doubt that you are in the B2B/Enterprise space. When
| you're pitching demos and you hear from people "we really wish
| we could buy your product but we can't because Finance won't
| approve the expenditure unless you get XYZ-123", and you hear
| that over and over again because that is the real-world
| industry that you live in, then you better believe that there
| are founders who wake up in the morning wishing that.
|
| You clearly have no understanding of what compliance does.
| Compliance does not "shift responsibility". Compliance is you
| demonstrating to your customers that you give enough of a shit
| that you're willing to pay the table stakes to sit at the
| table. You can complain that the game has table stakes, but all
| worthwhile games have them.
| kobieps wrote:
| This
| throwaway2016a wrote:
| There is a lot of serious allegations in here. But some of these
| complaints apply to most SOC 2 compliance services. For example:
| it points out that Delve provides pre-filled documents and
| encourages you to accept them as is. In my experience that is
| typical. I have seen companies just rubber stamp pre-created
| documents that describe IT processes that do not accurately
| reflect actual policy because the MBA[1] running the project
| didn't want to pull in IT and had no idea what any of it meant.
|
| [1] No offense to MBA, just using it as a placeholder for:
| business stakeholder with no IT background.
| hrimfaxi wrote:
| Giving you template device management policies is one thing,
| it's a whole other thing to say you don't have to have board
| meetings and generating fake minutes.
| throwaway2016a wrote:
| 100%, accepting pre-generated board meeting notes is
| egregious. This whole thing is awful and I am in no way
| defending it. The opposite, I think other compliance as a
| service companies also need to be scrutinized as well.
| x0x0 wrote:
| If you aren't either having the minimal meetings or written
| consents per the requirements for the delaware C, something
| outside Delve's hands has gone off the rails...
| whatinthenote wrote:
| Doesn't seem like a problem with SOC 2 compliance, seems like a
| problem where a company appointed someone who is not suited to
| handle a SOC 2 project.
|
| As for the pre-filled stuff, that's what other SOC 2 companies
| mean when they try to sell you "compliance in a box." Not that
| bad if the company is starting from scratch (<1 year), but not
| realistic for a company that has an existing IT footprint.
|
| However, the allegations here is that it is fraud. An "AI"
| company acting as a front for certification mills.
| latchkey wrote:
| I've been talking about this for a while now. For those of you
| thinking... Oh, I use a "good" company... think otherwise.
|
| https://x.com/HotAisle/status/1946302651383329081
|
| The whole thing is a racket.
| stuckkeys wrote:
| Great write up. What makes this interesting...I thought it was
| cool what they were doing...but also seemed too good to be true.
| I went ahead a booked a demo call with them. Great personas. Very
| friendly. Can't say they had all the answers, but they did bring
| a CISO on the last meeting, which seemed a bit scripted. They
| also never disclosed any breaches, even after I asked them.
| Yikes. Good luck to the orgs that went through all that process.
| Muromec wrote:
| The only job of a test is to fail, so if you never see the page
| red it's not doing anything. It's refreshing to see this being
| called out instead of going with the flow because "everyone is
| doing so".
| hintymad wrote:
| Question: how likely is it that a number of 20-year olds have the
| passion of solving the problem of compliance auditing? I can
| hardly imagine that I'd even be interested in taking a look at
| the domain. It's just... so mundane. Or maybe the alpha-type
| overachievers don't care about the domain but the opportunity?
| wmf wrote:
| Solving boring problems has been conventional startup wisdom
| for a long time. And a "mundane" startup might be more
| interesting than traditional high-paying jobs like
| finance/law/consulting.
| https://www.joelonsoftware.com/2007/12/06/where-theres-muck-...
| busseio wrote:
| I work for a firm that develops custom software in regulated
| industries, and we have brilliant software & data engineers in
| their 20's working on compliance auditing, and more
| specifically "Compliance Management System health monitoring."
|
| We've be able to use a lot of AI-assisted engineering and AI in
| the software to solve longstanding business challenges in this
| space.
|
| I won't make assumptions about where you're located, but on the
| East Coast US it is big business among banks, utilities,
| healthcare, etc.
| hardwaregeek wrote:
| I wonder if it's almost like a new version of management
| consulting. You hire/invest in a bunch of smart 20-somethings
| who seem generally intelligent with the idea that they'll
| "disrupt" an industry with their from-first principles
| approach. Do the 23 year old McKinsey consultants particularly
| care about their work? No, but the McKinsey name is a fast way
| to gain clout and access to executives. Ditto the YC name
| ohmahjong wrote:
| I'm in the industry (albeit not a 20-year old), and agree that
| the domain itself is incredibly dry.
|
| The tech is quite interesting, thankfully.
|
| From a customer perspective it's interesting - compliance sucks
| so much that even a slight improvement/automation goes a long
| way
| laidoffamazon wrote:
| The problem may not be "intellectually interesting" to them at
| all, but building B2B SaaS does appeal to them from a
| lifestyle/prestige/pedigree perspective and will probably get
| them an exit to become a Venture investor even if they fail.
| jazzyjackson wrote:
| I think there are lots of 20 year olds with a passion for
| making money
| poupdich wrote:
| Perhaps more relevant is how much can a 20-year old possibly
| know about your business, or any business
| victorbjorklund wrote:
| I'm currently working on a KYC compliance startup. Loads of fun
| both technically and also KYC in it self. Most things can be
| fun and interesting to someone.
| imaurer wrote:
| vibe compliance
| fareesh wrote:
| A lot of startups move fast with a small team.
|
| You build something great and big corporation X wants to buy a
| subscription but you need to be certified.
|
| Much of this is a good checklist but some of it is very european.
|
| "Where is the risk register to track controls in your 7 person
| company?"
|
| Now instead of doing what your team does best, you are doing
| paperwork theater for frameworks designed for a 100,000 employee
| enterprise.
|
| You are documenting things nobody will read, making up processes
| that don't exist and translating the operations of a lean company
| into bureaucratic language.
|
| What's needed is a variant of these standards for small teams,
| which is proportionate and pragmatic.
| ljm wrote:
| Maybe you suouldn't be hacking due diligence if your team isn't
| ready for it
| ceejayoz wrote:
| Isn't ready for, or doesn't need?
|
| I had to have meetings with... myself, at times, for
| compliance reasons.
| phyzix5761 wrote:
| What is the purpose of a business though? To make profits for
| its owners. If the profit lies in doing all this corporate
| theater then that's the business. A company that focuses only
| on providing a service and product but ignores how their
| customer needs to use said service and product is going to go
| out of business.
| eikenberry wrote:
| That is "a" purpose of a business, but not the primary
| purpose. The primary purpose of business is to provide a
| service or product people want. You can want profits all day
| long but if you don't have something people want you don't
| have a business.
| throttlebody wrote:
| I would argue that profits are a result of what you do and
| not the purpose... Obviously intertwined but that's why its
| important to pick something you like
| IgorPartola wrote:
| Exactly this. But my question here is also: is there not a
| competitive advantage to a big enterprise that applies
| standards in a more intelligent way? You have a SaaS, I have a
| Fortune 500 company that could use your product but I cannot
| use it because my procurement process is as long and winding ad
| the Road to Hana. In the meantime my competitor has a smarter
| procurement process that takes into account the impact and risk
| involved in renting your software. Don't they get a competitive
| advantage over me by having a better process and as a result
| getting better vendors?
| mushufasa wrote:
| Unfortunately in most cases the buyers have way more
| liability/risk using a small vendor than opportunity. Often
| this is coming from regulators in certain industries.
|
| In scenarios where the company REALLY REALLY wants to buy the
| SaaS, they often will invest in the company, one of the
| reasons for which being to ensure they have the resources to
| go through all the red tape.
| bartman wrote:
| I've found CIS Controls v8.1 to be good and sane, with actual
| benefits to security. Level 1 is a solid base, and Level 2 is
| good for picking from depending on where risks exist in your
| business.
|
| CIS Benchmarks are worth a look too: They're best practices for
| securing typical cloud platforms, SaaS and OS.
| bradfox2 wrote:
| This is as designed to gatekeep these customers. Those in
| control of the checklists stand to benefit.
| jordigg wrote:
| SOC 2 is mostly about proving you do what your policies say,
| and there's more flexibility than people think.
|
| For small teams it doesn't have to be heavyweight. A risk
| register can be a simple doc with a few real risks and
| mitigations.
|
| That said, I agree there's a lot of theater. For smaller
| companies and budgets, it often turns into rubber stamping.
| Auditors rely on the evidence you provide, so the report can
| look much cleaner than day to day reality.
|
| Still, it has value. It forces you to formalize basic
| practices, and if you want those customers, you're signing up
| for that level of scrutiny.
| Bombthecat wrote:
| Going through this with a medical startup... We have like 2
| developer. But to get investment, put the app online etc. We
| need to fill out those paperwork... For things which just don't
| exist...
| sidewndr46 wrote:
| Isn't the point of the paperwork to get you to make those
| things exist?
| troupo wrote:
| > We need to fill out those paperwork... For things which
| just don't exist...
|
| Things like what? HIPAA?
| 1970-01-01 wrote:
| The risk register is ISO 27001. The "I" in ISO doesn't stand
| for Internet, it stands for international. You shouldn't be
| doing business with international customers if you don't have a
| risk register, which is why they're requesting it.
| SkinTaco wrote:
| Why is the line drawn at being international?
|
| What is it about customers in Ethiopia that necessitates
| this? What is it about American (non-international) customers
| that doesn't require a register?
| kingjimmy wrote:
| "is very european." ... aa yes consumer protections. very
| european.
| troupo wrote:
| Translation: all your rules and regulations are crap, and we
| don't want to comply with any of them.
|
| When in reality most rules and regulations are not crap, and
| you should care about them.
|
| _Especially_ when your startup advertises compliance with
| HIPAA (medical records), PCI-DSS (payments data) and a bunch of
| other data protection standards and regulations.
| cwal37 wrote:
| Delve seems clearly scummy, but dear god the author's company was
| also engaging in fraud with their own customers and just hoping
| to skate by.
|
| "The trouble starts when you look at the answers Delve's AI
| provided. Based on what your Delve policies claim, the
| questionnaire AI answers questions stating you have an MDM, had a
| 200 hour pen-test performed, and do regular backup restoration
| simulations. Tens of questions are answered like that. Great, you
| just lied to your vendor but at least you have a good shot at
| landing the deal. So what did we do? We kept our mouths shut."
|
| Pretty rotten stuff. I went from energy into the software startup
| world and as I've gotten further down that road and energy has
| become more and more of a hot field I've encountered a depressing
| increase in that "just do it to make a deal" ethos, but in
| critical infrastructure.
|
| Like, no, former Apple PM who learned about an interconnection
| queue from ChatGPT last week, you are not going to fix the grid,
| and even moreso you can't "just do X and ask forgiveness later",
| not in electricity.
| OsrsNeedsf2P wrote:
| At least they had the balls to post it
| cwal37 wrote:
| Per the piece, they only began to step away from Delve once
| they realized they couldn't close the deals they wanted and
| their hand was forced by outside asks.
|
| And then also it took a rather large data leak later on to
| provide extra ammunition to decide and go forward with
| publishing this.
|
| I'm glad they did, but there are a bunch of steps in between
| pure balls/altruism and what actually happened based on the
| blog.
| ibero wrote:
| uh isn't the data leaker the necessary accelerant and
| necessary component to validate against the rest of the
| ecosystem? isn't that what triggered the communication and
| coordination between multiple delve customers?
| chromatin wrote:
| > Delve was founded in 2023 by Karun Kaushik and Selin Kocalar,
| both Forbes 30 Under 30 members and MIT dropouts who met as
| freshmen.
|
| Forbes 30 under 30 remains undefeated
| dsr_ wrote:
| The methodology questions remain:
|
| does Forbes have a great method for identifying future felons?
|
| do future felons push harder to come to Forbes' attention?
|
| does being on the Forbes list unduly influence founders to
| commit felonies?
| zelphirkalt wrote:
| What is it with the dropouts and unethical businesses? It is
| almost as if dropping out makes them do things, and without
| credentials, those things are the things others will not do.
| love2read wrote:
| Interesting that the author (and "the others in his network")
| seem to only be concerned about the complete illegitimacy of
| their certs when they were already exposed and now they want to
| stand up and say they are the good guys for "exposing" Delve.
| ipython wrote:
| > the price quickly dropped to just $6,000 when they realized we
| were serious about going elsewhere, and they would throw in ISO
| 27001 and a 200 hour penetration test as well.
|
| I'm sorry, but... $6,000 / 200 == $30 / hour? Just assuming the
| value of the actual certifications is $zero?
|
| Wouldn't that raise some serious red flags?
| codegeek wrote:
| $6000 for both SOC 2 and ISO 27001 with Pen tests ? lol. I paid
| over $8k just for ISO 27001 for our small company and have been
| quoted a lot more for SOC 2.
| bob1029 wrote:
| Compliance isn't that hard once you stop looking for shortcuts
| and start spending time doing it correctly.
|
| AWS is probably the best _actual_ CaaS vendor out there. They
| have a product offering expressly designed to help their
| customers get through this jungle:
|
| https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-a...
|
| You are still responsible for everything on top of what AWS
| provides (software/configuration/policy), but their compliance
| package handles a massive portion of what you would otherwise
| have to do if you were on-prem. Physical security, hardware
| management, disaster recovery, et. al., you get essentially "for
| free".
| mrsmrtss wrote:
| I think that goes for any major cloud provider, not only AWS.
| But nothing is free, you pay a hefty premium to get this
| (compared to plain infra providers like Hetzner for example).
| codemog wrote:
| > Compliance isn't that hard once you stop looking for
| shortcuts and start spending time doing it correctly.
|
| Trying to understand how someone can have this perspective when
| it's usually someone's full time salaried job in a lot of
| companies.
| Bewelge wrote:
| Maybe they meant "Not hard != quickly done". I don't think
| many people think bureaucracy is especially difficult. It's
| just time consuming.
|
| But frankly if they meant that, the statement doesn't really
| say anything at all. Because what in this world is hard if
| you stop taking shortcuts and spend time doing it correctly?
| staticassertion wrote:
| I assume they mean "getting a SOC2 report", which is the part
| that Delve attempts to automate. The maintenance of controls,
| adoption of new policy as the company evolves, etc, is what
| someone will do in the full time role and that Delve et al
| would do nothing to assist with.
| Ucalegon wrote:
| A lot of that comes down to the costs associated with not
| being compliant and/or the requirements of existing
| contracts/insurance policies, where having dedicated FTEs to
| compliance is a requirement. Compliance might not be hard for
| the person/people managing the program, however it might seem
| difficult or complex to the FTEs that have to build to those
| standards if they do not have a security or governance
| background.
| pkilgore wrote:
| Slopliance?
| OsrsNeedsf2P wrote:
| Even if this is a hit piece made by a competitor, the evidence
| put forwards is very damning:
|
| > Conclusions present before customer signs or provides info
|
| If false, the defamation damages here would be in the tens of
| millions. Huge respect to whoever stuck their neck out to post
| this.
| tremarley wrote:
| Delve has released a response
|
| https://delve.co/blog/response-to-misleading-claims
| frankfrank13 wrote:
| > These are starting points only: customers are responsible for
| reviewing, modifying, and finalizing their own materials. Draft
| templates are not the same as "pre-filled evidence."
|
| Yeah, ok. BRB to start a bank where I template everyone a
| billion dollars, its up to you to be honest with how much money
| you have.
| sebmellen wrote:
| There's a deep lack of accountability here for their marketing
| statements. For example, "get SOC 2 compliant in days," which I
| would consider to be false advertising.
|
| That, plus their willingness to arrange an essentially
| fraudulent auditor network (try to find who the real CPA is
| behind Accorp, for example), and also massively upcharge the
| prices of the SOC reports that they offered as a bundled
| service within the platform. There was no separation here. Del
| is the transfer agent. Del was always the intermediary and the
| transfer agent. There is no independence in their default
| auditor relationships.
|
| At very best, this is a massive AICPA transgression.
|
| At worst, blatant fraud.
|
| I would wager that discovery would show the latter.
| CityOfThrowaway wrote:
| This basically boils down to, "Sure, we recommended you work
| with scammy low-quality auditors, but if you actually use them
| it's your own fault... we're just an automation tool!"
|
| In other words, I'm reading this as effectively a full
| admission that the claims are true but the company is saying
| not their responsibility.
|
| Very, very bad.
| jvwww wrote:
| Where does it say we recommend you work with scammy low-
| quality auditors? They say that they use third party audit
| firms that are used by other compliance companies.
| sebmellen wrote:
| This is clearly false from what I've seen. If you read the
| source Substack article and look through the list of
| auditors they have, it is impossible to trace down who the
| US-based CPA is that's issuing the report. These firms, for
| all intents and purposes, do not really exist. They use
| shell addresses in Wyoming and Texas that are registered
| agent offices, etc.
|
| But really all you have to do is look at the reports
| themselves. They are so shoddily written that it's hard to
| believe any legitimate firm would issue them. If you Ctrl F
| for Clueley in this thread, you will see my comment with a
| sample excerpt from the assertion of management for one of
| their reports.
| owebmaster wrote:
| We or they? Choose one
| joemi wrote:
| It can be inferred the use of "we" was as a quote. The
| bigger issue is that they did not clearly indicate that
| they were quoting.
| ibero wrote:
| if you go through the original Substack post it's clear the
| intention is to drive to those obfuscated auditors.
| svat wrote:
| > _"Non-denial denial" is a term of art in PR. Never read one?
| They're fun._
|
| -- patio11 about this response
| (https://x.com/patio11/status/2035115379169677717)
| Qasaur wrote:
| They've possibly dug an even deeper hole now.
|
| None of their ISO 27001 certificates, aside from the premium
| one-offs with the vCISO, are accredited by any reputable ISO
| accreditation body. I would even argue that IAS, who accredited
| Prescient Security (mentioned as a reputable body in the
| article), has a questionable reputation and certainly gives off
| a pay-to-play impression.
|
| You can look up the names of their partners below. The one body
| I found that is on the register (Accorp) is accredited by UAF,
| a known cert-mill accreditation body, and I'm not even sure
| it's the same Accorp that Delve has partnered with.
|
| For reference, you want a ISO certificate issued by a body
| accredited by UKAS (UK gov. adjacent non-profit), ANAB (ANSI),
| or equivalent, all government-recognised. This is normally the
| first thing I check whenever someone claims ISO 27001
| certification and it is a great heuristic to validate
| certification rigour.
|
| https://www.iafcertsearch.org/search/certification-bodies
|
| Shockingly low levels of DD by everyone involved here.
| llmslave wrote:
| People dont fully know it, but alot of capital in society gets
| accumulated by people with the right look, instead of with actual
| ability. In many cases, these startups start out as fraud, and
| hope to become real. VCs know this.
|
| But the tragedy is that there is a fixed pie of capital to be
| allocated, and so when they allocate to people like this, it
| steals opportunity from someone else
| frankfrank13 wrote:
| I can understand two 20 year olds committing fraud. I can't
| understand a team of engineers PRE-PUBLISHING A TRUST REPORT
| before a single field has been filled out. This is worse than
| fraud, its poor craftsmanship.
| aiisahik wrote:
| 80% of Compliance has always been a performative box checking
| exercise.
|
| They delivered the product that every company wanted - make the
| box checking faster.
| orochimaaru wrote:
| There is a legal liability that comes with the bow checking.
| Nobody cares about box checking. Everyone cares about legal
| liability.
| upmind wrote:
| What's the TLDR? Should one be worried if their business uses
| Delve?
| alanning wrote:
| For those looking for help with SOC2 compliance, I had a good
| experience with another YC company, Vanta. That was some years
| ago so not sure if anything has changed since then but I would
| recommend checking them out.
| sebmellen wrote:
| YC has funded both Vanta and OneLeet. It's a shame they also
| funded a hype machine like Delve.
|
| I would recommend both Vanta and OneLeet as good quality tools
| to work with, having used both. The founders of OneLeet are
| very accessible, and Vanta has all the integrations you would
| need as both a small startup and an enterprise-grade player.
|
| Secureframe and Drata are other tools in a similar class that
| are also legitimate.
| tptacek wrote:
| I like the Vanta people just fine and think it's a fine
| product, but I would not recommend it to startups looking to
| get SOC2.
|
| https://fly.io/blog/soc2-the-screenshots-will-continue-until...
|
| Most startups should be doing _way, way less_ than automation
| platforms like these tell them they need to do to get a SOC2
| attestation.
| dmix wrote:
| Not every sales team can convince a big paying customer that
| SOC2 isn't important. Fly.io might operate in a more
| technical customer base and can choose it's customers, but
| lots of B2B SaaS companies have to play the enterprise lawyer
| game to get big contracts. Our company hired an accounting
| firm which helped seal a deal and now we just advertise SOC2
| like everyone else.
___________________________________________________________________
(page generated 2026-03-20 23:00 UTC)