[HN Gopher] Delve - Fake Compliance as a Service
       ___________________________________________________________________
        
       Delve - Fake Compliance as a Service
        
       Author : freddykruger
       Score  : 479 points
       Date   : 2026-03-19 19:08 UTC (1 days ago)
        
 (HTM) web link (deepdelver.substack.com)
 (TXT) w3m dump (deepdelver.substack.com)
        
       | ersshh wrote:
       | Forbes 30u30 pipeline remains undefeated.
       | 
       | How did none of this come up during diligence? Feels like a prime
       | example of too good to be true.
        
         | sebmellen wrote:
         | Trust me, you can lie and get away with it if you go through YC
         | and dropped out of a top university. Garry Tan blocked me on X
         | for pointing this out. It's a big club, and you ain't in it!
         | 
         | Fortunately, some of the old-YC spirit seems to be alive here
         | on HN still.
        
           | jvwww wrote:
           | They likely barely had a product when they applied to YC.
           | It's more interesting as to why this wasn't discovered (if it
           | is even true) when they were raising their Series A.
        
         | allovertheworld wrote:
         | You mean from the beginning? They could've just done it
         | properly initially then moved to this scam process later
        
         | rithdmc wrote:
         | > How did none of this come up during diligence?
         | 
         | The article states that, "Even though we knew we'd technically
         | be lying about our security to anyone we sent these policies to
         | for review ... we decided to adopt these policies because we
         | simply didn't have the bandwidth to rewrite them all manually."
        
         | latchkey wrote:
         | This is the next one...
         | 
         | https://x.com/HotAisle/status/2035024494663016532
        
         | duped wrote:
         | Dishonesty is high signal for VC
         | 
         | Like no one characterizes it like that, but this is the same
         | business where you can tell a story about hiring a bunch of
         | college friends to pretend to be your employees so a client
         | comes to your "office" and thinks you're a legitimate business.
         | And instead of looking in horror at how casually you'll lie to
         | get business it's seen as scrappy and whimsical.
        
       | ManuelSuarez wrote:
       | https://www.reddit.com/r/soc2/comments/1q7u90o/real_or_fake_...
        
       | halamadrid wrote:
       | This was such as interesting read, but I found this link via
       | LinkedIn rather than hackernews.
       | 
       | I would have expected this to be somewhere at the top right now
       | given how deep the article digs and evidence seems legit.
        
         | sebmellen wrote:
         | I think it may be getting (intentionally?) suppressed from the
         | homepage. Given this is a YCombinator website, I wouldn't rule
         | that out.
         | 
         | Regardless, it's been an ongoing issue. I know a few involved
         | companies -- it takes basically 5 days to get a SOC 2 Type 2
         | report through Delve. And, of course, they market this way too:
         | "SOC 2 in days". Unbelievable.
        
           | instalabsai wrote:
           | Surprised/not surprised that this is getting buried from the
           | homepage
        
             | sebmellen wrote:
             | I just got blocked by another YC founder (and potential
             | investor in Delve?) for refuting his handwavey argument
             | that "all compliance companies do this" [0] -- this is
             | beyond just marketing, it is active and blatant/intentional
             | fraud. I don't see how it can be defended. But in that
             | sense it is a major crisis for anyone who invested in the
             | company.
             | 
             | [0]: https://x.com/kobyjconrad/status/2034843865396506864
        
             | dang wrote:
             | It got downweighted by HN's voting ring detector. Mods
             | didn't touch it, except to place the story on the frontpage
             | once we knew it existed.
        
           | browningstreet wrote:
           | It's a trending story on X. Was surprised there was no meaty
           | discussion here on HN.
        
           | andrewflnr wrote:
           | I see the submission time as an hour ago, so it actually
           | looks like it got a second-chanced, i.e. boosted by the site
           | admins.
        
             | dang wrote:
             | That's correct - you can see from
             | https://news.ycombinator.com/submitted?id=freddykruger that
             | this post was actually submitted 23 hours ago. The
             | timestamp at the top of the thread is relativized to fit
             | the second-chance pool (https://hn.algolia.com/?dateRange=a
             | ll&page=0&prefix=true&que...).
        
           | dang wrote:
           | In case anyone hasn't seen my other posts about this:
           | 
           | (1) I had no idea this story existed and woke up to claims
           | that I was obviously* suppressing it.
           | 
           | (2) I looked into it and found that no moderator had touched
           | either of the two submissions of the story, but that both
           | submissions had set off HN's voting ring detector. (Whether
           | there was a voting ring or not, I don't know - that software
           | isn't perfect. It has held up well over the years though.)
           | 
           | (3) We merged the two discussions and placed the merged
           | thread on the front page.
           | 
           | (4) Why? Because we moderate HN less, not more, when YC or a
           | YC startup is part of a story: https://hn.algolia.com/?dateRa
           | nge=all&page=0&prefix=false&qu.... This is literally the #1
           | principle of moderation in the sense that it was the very
           | first thing that pg drilled into me: https://hn.algolia.com/?
           | dateRange=all&page=0&prefix=true&que....
           | 
           | * https://quoteinvestigator.com/2018/11/18/know-trouble/
        
             | muglug wrote:
             | TIL that voting ring detection exists
        
               | dang wrote:
               | HN would be an entirely different place if people could
               | just arrange to get their stuff upvoted onto the front
               | page! We've spent hundreds of hours working on this over
               | the years. Still not perfect of course.
        
               | sebmellen wrote:
               | My theory is that a lot of people may have looked for a
               | story like this on the home page and then searched
               | 'Delve' to see if anything was submitted recently and
               | then upvoted one of those recently submitted posts.
        
               | x0x0 wrote:
               | in some slacks there are regular requests to upvote
               | stuff.
        
       | moomoo11 wrote:
       | I miss 2010s YC until like 2017 ish when crypto sort of just
       | caused a massive decline across the board.
       | 
       | I guess it is great if you're a grifter/scammer or looking to
       | just sell off to a FANG.
        
         | srikar_alter wrote:
         | agreed
        
       | gsibble wrote:
       | How does this not reach the front page?
        
         | slackfan wrote:
         | It does, but it's also a takedown of a YC-backed company.
         | 
         | Really great vetting there, guys.
        
           | stuckkeys wrote:
           | LOL -For a good minute the comments were not visible. Someone
           | is playing RR.
        
             | dang wrote:
             | We were in the process of merging the threads. Actually
             | tomhow had correctly merged them, but I misinterpreted
             | which submission had been first and undid that. Then
             | corrected my mistake.
             | 
             | Had you checked the other thread during that "good minute",
             | you'd have seen that all the comments were intact.
        
         | nedwin wrote:
         | It's on the front page for me?
        
         | dang wrote:
         | We just found out about this story and the submissions of it.
         | It looks like it didn't make the front page because it set off
         | HN's voting ring detector.
         | 
         | Mods didn't touch either thread except (1) we merged the
         | duplicate discussions and (2) we rolled back the voting ring
         | penalty so that the story would be on the frontpage.
         | 
         | This is in keeping with the principle that we moderate stories
         | less, not more, when YC or a YC startup is part of the story.
         | That's been the case since the beginning, and I've posted about
         | it dozens of times: https://hn.algolia.com/?dateRange=all&page=
         | 0&prefix=false&qu....
        
           | sebmellen wrote:
           | Respectfully, I think there may be an issue with your voting
           | ring detection, which is that if multiple people try to
           | submit the same article and are redirected to an existing
           | post and they upvote it, that might be setting off the voting
           | ring alert. Can you check that?
           | 
           | I would imagine that's what happened here.
        
             | dang wrote:
             | That's definitely not what happened here. The data would be
             | quite different in that case.
             | 
             | Edit: 10% of the votes came from resubmissions of the URL.
             | The other 90% came from other sources.
        
               | sebmellen wrote:
               | Curious to know! I submitted the duplicate article and
               | most definitely did not work with any voting ring.
        
       | ohyoutravel wrote:
       | All this evidence seems pretty legit. I found this on LinkedIn
       | and came here to post, but noticed it had already been posted.
       | Surprised I didn't see it on HN front page.
        
         | sebmellen wrote:
         | It is being suppressed by @dang, I believe they may have a
         | policy that allows suppression for bad YC-related news.
        
           | tomhow wrote:
           | Moderators didn't see it, and our policy is the precise
           | opposite of this - see https://hn.algolia.com/?dateRange=all&
           | page=0&prefix=false&qu... or, for more color, https://hn.algo
           | lia.com/?dateRange=all&page=0&prefix=true&que....
           | 
           | We've restored it to the front page now.
        
             | sebmellen wrote:
             | Yes, but your team claimed this set off "voting ring"
             | behavior [0] and it was suppressed for nearly a day because
             | of that. I am very curious how you determine what is, or is
             | not, "voting ring" behavior. I believe Dang is responding
             | in another thread about that.
             | 
             | [0]: https://news.ycombinator.com/item?id=47457689
        
               | dang wrote:
               | Obviously we don't publish how HN's voting ring detector
               | works. If we did, it would quickly stop working.
               | 
               | What matters in this case is (1) it's a software penalty
               | that has nothing to do with the content of a story, (2)
               | moderators didn't touch the submissions or even know they
               | existed, and (3) once we did know that they existed, we
               | merged the threads and placed the story on the frontpage
               | - that is, we went out of our way to give this story
               | _more_ attention, not less - in keeping with the
               | principle explained here: https://hn.algolia.com/?dateRan
               | ge=all&page=0&prefix=false&qu....
        
       | laidoffamazon wrote:
       | Major red flag with this should have been that their expensive
       | marketing predicated heavily on them being MIT dropouts instead
       | of any expertise in the space
        
       | AFF87 wrote:
       | I remember having sales calls with them and the vibe was that it
       | was "cheap and quick"... exactly what you want for your
       | compliance
        
       | LambdaComplex wrote:
       | > No custom tailoring, no AI guidance, no real automation. Just
       | pre-populated forms that required you to click "save".
       | 
       | I hate that I've become this cynical, but it's gotten to the
       | point where reading the "no x, no y, just z" construct makes me
       | assume that writing is AI generated (and then I immediately stop
       | caring about reading it)
        
       | fantasizr wrote:
       | there needs to be a fund with an ethos of "move slowly and do
       | things accurately"
        
         | sunir wrote:
         | The fund is called customers. The independent regulator is
         | called the AICPA. It really comes down to who is paying
         | attention
         | 
         | SOC2 is as useful as a privacy policy at protecting your data.
         | It's all humans following human incentives.
        
           | Spivak wrote:
           | The value of SOC2 is that it does take _some_ experience to
           | be able to plausibly fake the evidence which weeds out people
           | that truly have no idea what they 're doing. It also provides
           | a blueprint of the stuff you should be doing if you actually
           | care.
           | 
           | But beyond that it's not worth a whole lot.
        
             | fantasizr wrote:
             | yeah it's funny to see some defense of this practice as
             | "well the whole thing is pointless anyway so nothing is
             | lost by defrauding folks". Pretty hollow argument
        
         | DANmode wrote:
         | There are a few, roughly.
         | 
         | Like the best options in most categories, they don't spend a
         | bunch of money or time on brand presence, advertising.
         | 
         |  _You_ simply find _them_.
        
         | neutronicus wrote:
         | The United States military?
        
           | hrimfaxi wrote:
           | Slow is smooth and smooth is fast.
        
       | gmerc wrote:
       | Well now we know how Cluely and friends can claim to be SOC2
       | compliant.
        
       | rvz wrote:
       | Notice how none of Delve's affiliates on X are posting anything
       | after that Substack post. Probably their lawyers told them not to
       | say anything further.
       | 
       | What does that tell you about the scam that was unveiled?
       | 
       | Not good.
        
         | JimDabell wrote:
         | The only thing it tells us is that they have received competent
         | legal advice. Any counsel is going to tell you to shut up
         | regardless of whether you are in the right or wrong.
        
       | claudiug wrote:
       | wow, cannot imagine now companies that tool the compliance, and
       | get deals just to be fake. uff...
        
       | resiros wrote:
       | This seems like a hit job by a competitor. Really ruthless.
       | 
       | > Two months ago, an email went out to a few hundred Delve
       | clients informing them that Delve had leaked their audit reports,
       | alongside other confidential information, through a Google
       | spreadsheet that was publicly accessible.
       | 
       | Who leaked the audit reports? Who sent this email? Who is taking
       | the time to write this analysis and kill the company?
       | 
       | In my opinion, the majority of the points in the article are no
       | news. A compliance saas that offers templates for policies, all
       | of them do. The AI is a chatbot, well who thought.
       | 
       | I think the main point is the collusion between delve and the
       | auditors. Is the evidence for that clear?
        
         | sebmellen wrote:
         | Hit piece or not, the blatantly fraudulent behavior displayed
         | by Delve is reprehensible.
         | 
         | And they didn't even try. Read this management assertion for
         | one of the (known) affected companies:
         | 
         | > _We have prepared the accompanying description of Cluely,
         | Inc.,_ system titled  "Cluely is a desktop AI assistant to give
         | you answers in real-time, when you need it." _throughout the
         | period June 27, 2025 - September 27, 2025(description), based
         | on the criteria set forth in the Description Criteria DC
         | Section 200 2018 Description Criteria for a Description of a
         | Service Organization's System in a SOC 2 Report (description
         | criteria)._
         | 
         | > _The description is_ intended to provide users with
         | information about the  "Cluely is a desktop AI assistant to
         | give you answers in real-time, when you need it." that _may be
         | useful when assessing the risks arising from interactions with
         | Cluely, Inc. system, particularly information about the
         | suitability of design and operating effectiveness of Cluely,
         | Inc. controls to meet the criteria related to Security,
         | Availability, Processing Integrity, Confidentiality and Privacy
         | set forth in TSP Section 100, 2017 Trust Services Principles
         | and Criteria for Security, Availability, Processing Integrity,
         | Confidentiality and Privacy (applicable trust services
         | criteria)._
        
         | cyrusradfar wrote:
         | There's no need for some conspiracy.
         | 
         | It's a juicy story to talk about that hits a lot of checkboxes
         | that make it viral --                 1. the hustle culture
         | they promoted online was gross       2. they followed the 30u30
         | Forbes pattern like Liz Holmes, FTX, etc.        3. they're a
         | YC co, so their's plenty of popular voices supporting them
         | 
         | The 3rd isn't to slight the program but folks definitely slam
         | any companies that seem to be in the moral gray area as a proof
         | the program is nihilistic and a net negative. People like to
         | shove mistakes in the face of "successful" folks like
         | investors/VCs.
         | 
         | Finally, the security and compliance community is litigious by
         | their nature and this startup, in general, was a net negative
         | for a lot of people who do fractional / consulting work in
         | security.
        
           | sebmellen wrote:
           | What's more surprising to me, as a layperson, is that I found
           | this out and investigated their shady auditor network in late
           | December. It didn't take much work.
           | 
           | Insight Partners invested in a 32 MILLION DOLLAR ROUND
           | without any apparent shred of due diligence. What does that
           | say about the VC market writ large?
        
         | emilycg wrote:
         | The key problem is the audits and the auditors. I have
         | independently verified for our vendors that they have the same
         | templated SOC2 as all of the leaked reports, which is
         | concerning because that shows the auditors did not actually
         | validate the controls.
         | 
         | SOC2 is supposed to give you an INDEPENDENT evaluation of the
         | compliance of a company "are they doing what they say they are"
         | 
         | If the SOC2 report is just a pre-populated template, it is
         | meaningless.
         | 
         | It doesn't really matter the motivation of the "DeepDelver" -
         | this has implications across all companies that rely on these
         | vendors that have been "assessed" by Delve.
        
           | OsrsNeedsf2P wrote:
           | Really curious what you're going to do, going forward. Will
           | you be rejecting compliance certified with Delve? Will you be
           | forcing your vendors to redo compliance?
        
       | sebmellen wrote:
       | Delve did not even try to fake the reports well. They could have
       | used AI tooling to write somewhat plausible Assertions of
       | Management, but they just dropped in clear form submissions to
       | the reports they provided. Here is an example from Cluely:
       | 
       | > _We have prepared the accompanying description of Cluely, Inc.,
       | system titled "Cluely is a desktop AI assistant to give you
       | answers in real-time, when you need it." throughout the period
       | June 27, 2025 - September 27, 2025(description), based on the
       | criteria set forth in the Description Criteria DC Section 200
       | 2018 Description Criteria for a Description of a Service
       | Organization's System in a SOC 2 Report (description criteria)._
       | 
       | > _The description is intended to provide users with information
       | about the "Cluely is a desktop AI assistant to give you answers
       | in real-time, when you need it." that may be useful when
       | assessing the risks arising from interactions with Cluely, Inc.
       | system, particularly information about the suitability of design
       | and operating effectiveness of Cluely, Inc. controls to meet the
       | criteria related to Security, Availability, Processing Integrity,
       | Confidentiality and Privacy set forth in TSP Section 100, 2017
       | Trust Services Principles and Criteria for Security,
       | Availability, Processing Integrity, Confidentiality and Privacy
       | (applicable trust services criteria)._
       | 
       | I mean, just re-read this sentence:
       | 
       | > _The description is intended to provide users with information
       | about the "Cluely is a desktop AI assistant to give you answers
       | in real-time, when you need it." that may be useful_
       | 
       | It makes no sense at all.
       | 
       | Someone implemented the code to automate this report mill, and
       | didn't think to even smooth it out with an LLM! There was clear
       | intent here.
       | 
       | To imagine that an auditor reviewed and stamped this as a
       | coherent body of work beggars belief.
        
       | biggletiddies wrote:
       | Cluely and HockeyStack are scam companies too.
       | 
       | Cluely did the ChatGPT wrapper to cheat on interviews then sold
       | the customer data to recruiters. The whole company promise is a
       | scam, and useless since we have LLMs.
       | 
       | HockeyStack held contests for people to win cars etc and never
       | delivered. They also lied about having revenues and a product
       | when they had nothing built. Along with Greptile they were doing
       | 7day weeks of unpaid labor from "trial periods".
       | 
       | Scams all around.
        
         | porridgeraisin wrote:
         | Wait what's the greptile story?
        
           | buttsack wrote:
           | It says right there, 7-day work weeks (no days off).
           | 
           | Also they were part of the cohort forcing workers to stay
           | minimum until 9PM.
           | 
           | Like every AI company, their "product" is a Next.js website,
           | OPENAI_API_KEY, and a Stripe checkout page.
        
             | porridgeraisin wrote:
             | Ah ok. What's with the "unpaid labour" part?
        
               | buttsack wrote:
               | It's also in the original post. Greptile, HockeyStack,
               | and others from that cohort of 20-year old founders out
               | of YC were having software engineer candidates come in
               | day-in and day-out, staying until 9PM under the threat of
               | being rejected if they left earlier.
               | 
               | They were not paid at all, they were working long-term on
               | a "trial period". And yes it's very illegal. I was there
               | and saw it first-hand.
               | 
               | The guys they had on trial periods - though I'm sure they
               | were very intelligent - were not really firing on all
               | cylinders if you know what I mean.
        
         | calderwoodra wrote:
         | Greptile is an awesome product, not sure where the scam is
         | there
        
       | frenchie4111 wrote:
       | wow you guys really delved into this
        
       | suriya-ganesh wrote:
       | I've gone through this process and is this not a failure from the
       | institute that are giving away these certifications for a fee
       | without any due diligence?
       | 
       | intermediaries like delve have only amplified this failure.
       | 
       | it was obvious to anyone who was involved in this industry that,
       | all of this is just security theatre with nothing really to back
       | it up.
        
       | stringtoint wrote:
       | Love the depth of this post.
       | 
       | We were actually looking at it as well recently (we're using
       | Drata). I was thinking "Cool, this looks like the next cool step
       | forward". The claims didn't sound out of the world in my ears.
       | 
       | Every time an issue like this appears I wonder how many more
       | undiscovered frauds are out there.
        
       | egorfine wrote:
       | Compliance is something that no one ever wants and everybody
       | hates. Not a single founder wakes up in the morning thinking to
       | themselves: "oh I wish I could make my company XYZ-123
       | compliant!"
       | 
       | Thus providing compliance is really just paying someone to shift
       | responsibility.
       | 
       | The regulator can ask whether you are compliant. You can present
       | certificate from Delve or someone else and that's the end of it.
        
         | Duhck wrote:
         | When I worked in cybersecurity I had a similar realization. No
         | one cared about security posture. They cared about insurance
         | policies. People hired us to shift blame instead of improve
         | security posture. this is not terribly different
        
           | bjackman wrote:
           | One of my FAANG security projects incidentally helped with
           | some compliance efforts (I made very sure it was incidental,
           | constantly said things like "I am thrilled that I can help
           | you guys achieve your goals but I wanna be clear that I don't
           | give a shit about compliance and I won't be allowing it to
           | influence the direction of my product" in meetings, it must
           | have been extremely annoying to work with me).
           | 
           | At some point I was asked to look over the documents for the
           | compliance definition and it was really hilarious. I had to
           | give my engineering perspective on which aspects of the
           | requirements we were and weren't meeting.
           | 
           | But they were stuff like "you must have logs". "You must
           | authenticate users". "You must log failed authentication
           | attempts".
           | 
           | Did we fulfill these requirements? It's a meaningless
           | question. Unless you were literally running an open door
           | telnet service or something you could interpret the questions
           | so as to support any answer you wanted to give.
           | 
           | So I just had to be like "do you want me to say yes?" and
           | they did, so I said yes. Nothing productive was ever achieved
           | during that engagement.
        
           | leeter wrote:
           | This is why I've said for years: If you want to drive best
           | practices and policy with companies you can only do it with
           | liability. Particularly non-insurable and non-tax deductible
           | liability. If a company can't offload civil or criminal
           | penalties to their insurance company and take the tax write
           | down, they suddenly start caring about it.
           | 
           | That said, this should be used sparingly; as it embeds a
           | behavior deep. If that behavior later no longer makes sense
           | it can be extremely costly to change it later.
        
             | robocat wrote:
             | > Particularly non-insurable and non-tax deductible
             | liability
             | 
             | Too often liabilities exceed assets, or the liabilities are
             | externalised.
             | 
             | Liability doesn't work as an incentive for many risks. For
             | uncommon but extreme risks, it can be better to roll the
             | dice on company failure than regularly pay low amounts for
             | mitigation.
             | 
             | It is especially effective to ignore liabilities when a
             | company has poor profitability anyways.
             | 
             | And then you see major companies sidestep the costs of
             | their liabilities (plenty of examples after security
             | failures, but also companies like Johnson&Johnson).
        
           | wccrawford wrote:
           | I think it's subtly different than that.
           | 
           | Companies _do_ want to be secure. They try, and they often
           | fail because it 's _hard_.
           | 
           | They hire auditors to find problems _and_ to shift blame. But
           | since they only have 30 days to fix the problems that are
           | found, it 's going to see a _lot_ like they only care about
           | shifting the blame. Because at that point, they only care
           | about passing that audit.
           | 
           | Right after that, though, they start caring about security
           | again.
           | 
           | How do I know? 19 years experience going through those audits
           | on the company side. For 11 months of the year, it was clear
           | the boss cared about security. For that 1 month during the
           | 'free retest' period, they only cared about passing that
           | audit.
        
         | Muromec wrote:
         | Not a single person wakes up in the morning thinking they wish
         | to pay taxes and rent and do the laundry the other stuff that
         | has to be done. I would be nice to smoke weed and play video
         | games all day and order the deliveries.
         | 
         | Some things just have to be done.
        
           | egorfine wrote:
           | > thinking they wish to pay taxes
           | 
           | Wellll this is not always the case. I have moved from a
           | shithole country to a nice one and oh boy I am crying in
           | gratitude every month that I pay taxes. Because it is every
           | day that I can see my money working for me in the
           | environment.
           | 
           | But your point stands.
        
             | Muromec wrote:
             | As a person who moved to a high-tax country I understand
             | the sentiment. It's usually lost on the people who were
             | always there paying those taxes. Somehow it often doesn't
             | click that they get something in return.
             | 
             | The same applies to all the audit and bureaucracy stuff.
             | Does it do something? If you don't feel it does, does it
             | mean it's not? I don't know really, but I hope somebody is
             | rotating their key material as they provided in their
             | security posture.
        
             | kakacik wrote:
             | There are well-used tax money, then there are stupidly
             | burned tax money on ie buying favors of some part of
             | population before elections, financing blindly without any
             | checks social security programs that get abused to no end,
             | or simply plain old corruption.
             | 
             | I love bringing Switzerland up to annoy most of
             | western/northern Europeans since their success is so
             | obvious and undeniable while going in very different
             | direction than most of Europe. Low to low-medium taxes, yet
             | state budgets are frequently in positive numbers, there is
             | no end to money spend on infra projects, train infra, but
             | also rather strong social programs (just not ridiculously
             | bad as mentioned above), top notch free healthcare and
             | education. VAT taxes are 2-8% instead of 20-23% in all
             | countries around. Country simply works(TM) because
             | population is not hard comfort-zone-addicted and entitled
             | bunch of spoiled whiny kids, they work relatively hard and
             | it brings results, consistently and long term. They don't
             | work more than americans nor asians, but thats enough for
             | their prosperity.
             | 
             | Do you think lets say a heavy tax burden in say Italy, or
             | even France (not even going more into southern or eastern
             | EU since that would be a small book) is really used well
             | and efficiently? I visit those places frequently and it
             | certainly doesn't seem that way. Random examples - Italy
             | has garbage everywhere, people drive to highway stops to
             | drop it there (so the wind blows it all around).
             | Infrastructure seems like from 80s, with added age. From
             | people dealing with bureaucracy there - its stuck in 19th
             | century, direct approach will get you often nowhere. France
             | - most communist state in western Europe, heck in _all_
             | Europe, sans Belarus maybe. Yet if you talk to people, they
             | are constantly pissed off at government, never happy with
             | society or state they live in. I don 't blame them,
             | listening to French colleagues complain is often rather sad
             | experience. Not something you read in travel guides, do
             | you.
        
               | KPGv2 wrote:
               | It doesn't hurt that Swiss immigration is very difficult
               | to get through, and they have all that Holocaust money no
               | Nazi or dead Jewish victim is ever going to come claim.
        
               | hermanzegerman wrote:
               | Well let's see how good that Swiss Model would work as a
               | big normal state, and not as a small tax haven, smaller
               | than the State of Baden-Wurttemberg living off those
               | surrounding states (siphoning up wealthy people, who got
               | rich in those countries, and also their academics, that
               | they didn't have to pay the education for)
        
               | Muromec wrote:
               | >Low to low-medium taxes, yet state budgets are
               | frequently in positive numbers
               | 
               | >because population is not hard comfort-zone-addicted and
               | entitled bunch of spoiled whiny kids
               | 
               | I'm not sure why would I need lower taxes in exchange for
               | more work. This somehow feels like a scam.
        
         | tfrancisl wrote:
         | Maybe no one wakes up wanting to deal with compliance, but it
         | you found a company that has legal or moral obligations to be
         | compliant with these standards, you sure have signed yourself
         | up for it. Passing the responsibility off to some other company
         | is, quite simply, irresponsible.
        
           | egorfine wrote:
           | Problem is, compliance is often detrimental to the cause. You
           | want to encrypt users' data at rest? Illegal. You must store
           | users data in a way prescribed by the law and it is extremely
           | cumbersome, outdated and insecure.
        
           | egorfine wrote:
           | > Passing the responsibility off to some other company is,
           | quite simply, irresponsible.
           | 
           | Then do not pass the responsibility. But here's the trick:
           | the regulator would like to see an audit done by a firm and
           | purchasing audit services is exactly that: passing
           | responsibility. So legally you can't be compliant unless you
           | passed responsibility.
        
             | tfrancisl wrote:
             | These compliance companies are not primarily tasked with
             | auditing, as this article makes very clear. Delve is in
             | control of the auditing process in a way that is
             | inappropriate and unusual for this industry. The work that
             | the company with these obligations should be doing
             | themselves is generating the Section 3 description and the
             | controls. The auditor then independently verifies their
             | compliance with the controls. Thats a clear delineation of
             | responsibilty, IMO
        
         | bedatadriven wrote:
         | I don't want to work wherever you do your thing. Software as a
         | service means you provide a service, and you should take your
         | responsibility to protect your customer's data super seriously.
         | Compliance frameworks are one useful tool among many to support
         | this effort. It helps us identify gaps, identify risks, make
         | improvements. It also give us a way to communicate what we do
         | to our partners. The behavior described in the medium post is
         | fraud, pure and simple.
         | 
         | I am a founder, and my ambition includes meeting the highest
         | possible standards for my customers.
        
           | xtracto wrote:
           | I've done a mix of SOC2, ISO27001 and PCI L1 for 3 different
           | startups. 2 of them b2b. All certified 100% and fully
           | compliant.
           | 
           | The problem with the current frameworks is that the
           | "controls" are so asinine and auditors so hard headed, that
           | getting certified becomes a matter of "checking the box" .
           | 
           | Particularly most of those frameworks REQUIRE maintaining so
           | much paper red tape that make a 10 person startup want to
           | kill themselves. And in addition the costs are stupid high
           | for startups that are just "starting up".
           | 
           | On the flip side, how many large companies have we seen that
           | have all the SOCs, ISOS and whatnot certifications, and they
           | get pwn3d and their data stolen or exposed.
           | 
           | It tells you that a place being certified doesn't guarantee
           | shit.
           | 
           | The reality is that large companies ask for certs as a CYA
           | mechanism: the "security" department of LargeCo, asks for the
           | compliance cert so that when shit hits the fan, they can say
           | "not my fault, they told me they were compliant"
           | 
           | The good thing is that with the new Bullshit generators (llm)
           | this certifification/compliance process will collapse.
        
         | solatic wrote:
         | > Not a single founder wakes up in the morning thinking to
         | themselves: "oh I wish I could make my company XYZ-123
         | compliant!"
         | 
         | Somehow I doubt that you are in the B2B/Enterprise space. When
         | you're pitching demos and you hear from people "we really wish
         | we could buy your product but we can't because Finance won't
         | approve the expenditure unless you get XYZ-123", and you hear
         | that over and over again because that is the real-world
         | industry that you live in, then you better believe that there
         | are founders who wake up in the morning wishing that.
         | 
         | You clearly have no understanding of what compliance does.
         | Compliance does not "shift responsibility". Compliance is you
         | demonstrating to your customers that you give enough of a shit
         | that you're willing to pay the table stakes to sit at the
         | table. You can complain that the game has table stakes, but all
         | worthwhile games have them.
        
           | kobieps wrote:
           | This
        
       | throwaway2016a wrote:
       | There is a lot of serious allegations in here. But some of these
       | complaints apply to most SOC 2 compliance services. For example:
       | it points out that Delve provides pre-filled documents and
       | encourages you to accept them as is. In my experience that is
       | typical. I have seen companies just rubber stamp pre-created
       | documents that describe IT processes that do not accurately
       | reflect actual policy because the MBA[1] running the project
       | didn't want to pull in IT and had no idea what any of it meant.
       | 
       | [1] No offense to MBA, just using it as a placeholder for:
       | business stakeholder with no IT background.
        
         | hrimfaxi wrote:
         | Giving you template device management policies is one thing,
         | it's a whole other thing to say you don't have to have board
         | meetings and generating fake minutes.
        
           | throwaway2016a wrote:
           | 100%, accepting pre-generated board meeting notes is
           | egregious. This whole thing is awful and I am in no way
           | defending it. The opposite, I think other compliance as a
           | service companies also need to be scrutinized as well.
        
           | x0x0 wrote:
           | If you aren't either having the minimal meetings or written
           | consents per the requirements for the delaware C, something
           | outside Delve's hands has gone off the rails...
        
         | whatinthenote wrote:
         | Doesn't seem like a problem with SOC 2 compliance, seems like a
         | problem where a company appointed someone who is not suited to
         | handle a SOC 2 project.
         | 
         | As for the pre-filled stuff, that's what other SOC 2 companies
         | mean when they try to sell you "compliance in a box." Not that
         | bad if the company is starting from scratch (<1 year), but not
         | realistic for a company that has an existing IT footprint.
         | 
         | However, the allegations here is that it is fraud. An "AI"
         | company acting as a front for certification mills.
        
       | latchkey wrote:
       | I've been talking about this for a while now. For those of you
       | thinking... Oh, I use a "good" company... think otherwise.
       | 
       | https://x.com/HotAisle/status/1946302651383329081
       | 
       | The whole thing is a racket.
        
       | stuckkeys wrote:
       | Great write up. What makes this interesting...I thought it was
       | cool what they were doing...but also seemed too good to be true.
       | I went ahead a booked a demo call with them. Great personas. Very
       | friendly. Can't say they had all the answers, but they did bring
       | a CISO on the last meeting, which seemed a bit scripted. They
       | also never disclosed any breaches, even after I asked them.
       | Yikes. Good luck to the orgs that went through all that process.
        
       | Muromec wrote:
       | The only job of a test is to fail, so if you never see the page
       | red it's not doing anything. It's refreshing to see this being
       | called out instead of going with the flow because "everyone is
       | doing so".
        
       | hintymad wrote:
       | Question: how likely is it that a number of 20-year olds have the
       | passion of solving the problem of compliance auditing? I can
       | hardly imagine that I'd even be interested in taking a look at
       | the domain. It's just... so mundane. Or maybe the alpha-type
       | overachievers don't care about the domain but the opportunity?
        
         | wmf wrote:
         | Solving boring problems has been conventional startup wisdom
         | for a long time. And a "mundane" startup might be more
         | interesting than traditional high-paying jobs like
         | finance/law/consulting.
         | https://www.joelonsoftware.com/2007/12/06/where-theres-muck-...
        
         | busseio wrote:
         | I work for a firm that develops custom software in regulated
         | industries, and we have brilliant software & data engineers in
         | their 20's working on compliance auditing, and more
         | specifically "Compliance Management System health monitoring."
         | 
         | We've be able to use a lot of AI-assisted engineering and AI in
         | the software to solve longstanding business challenges in this
         | space.
         | 
         | I won't make assumptions about where you're located, but on the
         | East Coast US it is big business among banks, utilities,
         | healthcare, etc.
        
         | hardwaregeek wrote:
         | I wonder if it's almost like a new version of management
         | consulting. You hire/invest in a bunch of smart 20-somethings
         | who seem generally intelligent with the idea that they'll
         | "disrupt" an industry with their from-first principles
         | approach. Do the 23 year old McKinsey consultants particularly
         | care about their work? No, but the McKinsey name is a fast way
         | to gain clout and access to executives. Ditto the YC name
        
         | ohmahjong wrote:
         | I'm in the industry (albeit not a 20-year old), and agree that
         | the domain itself is incredibly dry.
         | 
         | The tech is quite interesting, thankfully.
         | 
         | From a customer perspective it's interesting - compliance sucks
         | so much that even a slight improvement/automation goes a long
         | way
        
         | laidoffamazon wrote:
         | The problem may not be "intellectually interesting" to them at
         | all, but building B2B SaaS does appeal to them from a
         | lifestyle/prestige/pedigree perspective and will probably get
         | them an exit to become a Venture investor even if they fail.
        
         | jazzyjackson wrote:
         | I think there are lots of 20 year olds with a passion for
         | making money
        
         | poupdich wrote:
         | Perhaps more relevant is how much can a 20-year old possibly
         | know about your business, or any business
        
         | victorbjorklund wrote:
         | I'm currently working on a KYC compliance startup. Loads of fun
         | both technically and also KYC in it self. Most things can be
         | fun and interesting to someone.
        
       | imaurer wrote:
       | vibe compliance
        
       | fareesh wrote:
       | A lot of startups move fast with a small team.
       | 
       | You build something great and big corporation X wants to buy a
       | subscription but you need to be certified.
       | 
       | Much of this is a good checklist but some of it is very european.
       | 
       | "Where is the risk register to track controls in your 7 person
       | company?"
       | 
       | Now instead of doing what your team does best, you are doing
       | paperwork theater for frameworks designed for a 100,000 employee
       | enterprise.
       | 
       | You are documenting things nobody will read, making up processes
       | that don't exist and translating the operations of a lean company
       | into bureaucratic language.
       | 
       | What's needed is a variant of these standards for small teams,
       | which is proportionate and pragmatic.
        
         | ljm wrote:
         | Maybe you suouldn't be hacking due diligence if your team isn't
         | ready for it
        
           | ceejayoz wrote:
           | Isn't ready for, or doesn't need?
           | 
           | I had to have meetings with... myself, at times, for
           | compliance reasons.
        
         | phyzix5761 wrote:
         | What is the purpose of a business though? To make profits for
         | its owners. If the profit lies in doing all this corporate
         | theater then that's the business. A company that focuses only
         | on providing a service and product but ignores how their
         | customer needs to use said service and product is going to go
         | out of business.
        
           | eikenberry wrote:
           | That is "a" purpose of a business, but not the primary
           | purpose. The primary purpose of business is to provide a
           | service or product people want. You can want profits all day
           | long but if you don't have something people want you don't
           | have a business.
        
           | throttlebody wrote:
           | I would argue that profits are a result of what you do and
           | not the purpose... Obviously intertwined but that's why its
           | important to pick something you like
        
         | IgorPartola wrote:
         | Exactly this. But my question here is also: is there not a
         | competitive advantage to a big enterprise that applies
         | standards in a more intelligent way? You have a SaaS, I have a
         | Fortune 500 company that could use your product but I cannot
         | use it because my procurement process is as long and winding ad
         | the Road to Hana. In the meantime my competitor has a smarter
         | procurement process that takes into account the impact and risk
         | involved in renting your software. Don't they get a competitive
         | advantage over me by having a better process and as a result
         | getting better vendors?
        
           | mushufasa wrote:
           | Unfortunately in most cases the buyers have way more
           | liability/risk using a small vendor than opportunity. Often
           | this is coming from regulators in certain industries.
           | 
           | In scenarios where the company REALLY REALLY wants to buy the
           | SaaS, they often will invest in the company, one of the
           | reasons for which being to ensure they have the resources to
           | go through all the red tape.
        
         | bartman wrote:
         | I've found CIS Controls v8.1 to be good and sane, with actual
         | benefits to security. Level 1 is a solid base, and Level 2 is
         | good for picking from depending on where risks exist in your
         | business.
         | 
         | CIS Benchmarks are worth a look too: They're best practices for
         | securing typical cloud platforms, SaaS and OS.
        
         | bradfox2 wrote:
         | This is as designed to gatekeep these customers. Those in
         | control of the checklists stand to benefit.
        
         | jordigg wrote:
         | SOC 2 is mostly about proving you do what your policies say,
         | and there's more flexibility than people think.
         | 
         | For small teams it doesn't have to be heavyweight. A risk
         | register can be a simple doc with a few real risks and
         | mitigations.
         | 
         | That said, I agree there's a lot of theater. For smaller
         | companies and budgets, it often turns into rubber stamping.
         | Auditors rely on the evidence you provide, so the report can
         | look much cleaner than day to day reality.
         | 
         | Still, it has value. It forces you to formalize basic
         | practices, and if you want those customers, you're signing up
         | for that level of scrutiny.
        
         | Bombthecat wrote:
         | Going through this with a medical startup... We have like 2
         | developer. But to get investment, put the app online etc. We
         | need to fill out those paperwork... For things which just don't
         | exist...
        
           | sidewndr46 wrote:
           | Isn't the point of the paperwork to get you to make those
           | things exist?
        
           | troupo wrote:
           | > We need to fill out those paperwork... For things which
           | just don't exist...
           | 
           | Things like what? HIPAA?
        
         | 1970-01-01 wrote:
         | The risk register is ISO 27001. The "I" in ISO doesn't stand
         | for Internet, it stands for international. You shouldn't be
         | doing business with international customers if you don't have a
         | risk register, which is why they're requesting it.
        
           | SkinTaco wrote:
           | Why is the line drawn at being international?
           | 
           | What is it about customers in Ethiopia that necessitates
           | this? What is it about American (non-international) customers
           | that doesn't require a register?
        
         | kingjimmy wrote:
         | "is very european." ... aa yes consumer protections. very
         | european.
        
         | troupo wrote:
         | Translation: all your rules and regulations are crap, and we
         | don't want to comply with any of them.
         | 
         | When in reality most rules and regulations are not crap, and
         | you should care about them.
         | 
         |  _Especially_ when your startup advertises compliance with
         | HIPAA (medical records), PCI-DSS (payments data) and a bunch of
         | other data protection standards and regulations.
        
       | cwal37 wrote:
       | Delve seems clearly scummy, but dear god the author's company was
       | also engaging in fraud with their own customers and just hoping
       | to skate by.
       | 
       | "The trouble starts when you look at the answers Delve's AI
       | provided. Based on what your Delve policies claim, the
       | questionnaire AI answers questions stating you have an MDM, had a
       | 200 hour pen-test performed, and do regular backup restoration
       | simulations. Tens of questions are answered like that. Great, you
       | just lied to your vendor but at least you have a good shot at
       | landing the deal. So what did we do? We kept our mouths shut."
       | 
       | Pretty rotten stuff. I went from energy into the software startup
       | world and as I've gotten further down that road and energy has
       | become more and more of a hot field I've encountered a depressing
       | increase in that "just do it to make a deal" ethos, but in
       | critical infrastructure.
       | 
       | Like, no, former Apple PM who learned about an interconnection
       | queue from ChatGPT last week, you are not going to fix the grid,
       | and even moreso you can't "just do X and ask forgiveness later",
       | not in electricity.
        
         | OsrsNeedsf2P wrote:
         | At least they had the balls to post it
        
           | cwal37 wrote:
           | Per the piece, they only began to step away from Delve once
           | they realized they couldn't close the deals they wanted and
           | their hand was forced by outside asks.
           | 
           | And then also it took a rather large data leak later on to
           | provide extra ammunition to decide and go forward with
           | publishing this.
           | 
           | I'm glad they did, but there are a bunch of steps in between
           | pure balls/altruism and what actually happened based on the
           | blog.
        
             | ibero wrote:
             | uh isn't the data leaker the necessary accelerant and
             | necessary component to validate against the rest of the
             | ecosystem? isn't that what triggered the communication and
             | coordination between multiple delve customers?
        
       | chromatin wrote:
       | > Delve was founded in 2023 by Karun Kaushik and Selin Kocalar,
       | both Forbes 30 Under 30 members and MIT dropouts who met as
       | freshmen.
       | 
       | Forbes 30 under 30 remains undefeated
        
         | dsr_ wrote:
         | The methodology questions remain:
         | 
         | does Forbes have a great method for identifying future felons?
         | 
         | do future felons push harder to come to Forbes' attention?
         | 
         | does being on the Forbes list unduly influence founders to
         | commit felonies?
        
         | zelphirkalt wrote:
         | What is it with the dropouts and unethical businesses? It is
         | almost as if dropping out makes them do things, and without
         | credentials, those things are the things others will not do.
        
       | love2read wrote:
       | Interesting that the author (and "the others in his network")
       | seem to only be concerned about the complete illegitimacy of
       | their certs when they were already exposed and now they want to
       | stand up and say they are the good guys for "exposing" Delve.
        
       | ipython wrote:
       | > the price quickly dropped to just $6,000 when they realized we
       | were serious about going elsewhere, and they would throw in ISO
       | 27001 and a 200 hour penetration test as well.
       | 
       | I'm sorry, but... $6,000 / 200 == $30 / hour? Just assuming the
       | value of the actual certifications is $zero?
       | 
       | Wouldn't that raise some serious red flags?
        
         | codegeek wrote:
         | $6000 for both SOC 2 and ISO 27001 with Pen tests ? lol. I paid
         | over $8k just for ISO 27001 for our small company and have been
         | quoted a lot more for SOC 2.
        
       | bob1029 wrote:
       | Compliance isn't that hard once you stop looking for shortcuts
       | and start spending time doing it correctly.
       | 
       | AWS is probably the best _actual_ CaaS vendor out there. They
       | have a product offering expressly designed to help their
       | customers get through this jungle:
       | 
       | https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-a...
       | 
       | You are still responsible for everything on top of what AWS
       | provides (software/configuration/policy), but their compliance
       | package handles a massive portion of what you would otherwise
       | have to do if you were on-prem. Physical security, hardware
       | management, disaster recovery, et. al., you get essentially "for
       | free".
        
         | mrsmrtss wrote:
         | I think that goes for any major cloud provider, not only AWS.
         | But nothing is free, you pay a hefty premium to get this
         | (compared to plain infra providers like Hetzner for example).
        
         | codemog wrote:
         | > Compliance isn't that hard once you stop looking for
         | shortcuts and start spending time doing it correctly.
         | 
         | Trying to understand how someone can have this perspective when
         | it's usually someone's full time salaried job in a lot of
         | companies.
        
           | Bewelge wrote:
           | Maybe they meant "Not hard != quickly done". I don't think
           | many people think bureaucracy is especially difficult. It's
           | just time consuming.
           | 
           | But frankly if they meant that, the statement doesn't really
           | say anything at all. Because what in this world is hard if
           | you stop taking shortcuts and spend time doing it correctly?
        
           | staticassertion wrote:
           | I assume they mean "getting a SOC2 report", which is the part
           | that Delve attempts to automate. The maintenance of controls,
           | adoption of new policy as the company evolves, etc, is what
           | someone will do in the full time role and that Delve et al
           | would do nothing to assist with.
        
           | Ucalegon wrote:
           | A lot of that comes down to the costs associated with not
           | being compliant and/or the requirements of existing
           | contracts/insurance policies, where having dedicated FTEs to
           | compliance is a requirement. Compliance might not be hard for
           | the person/people managing the program, however it might seem
           | difficult or complex to the FTEs that have to build to those
           | standards if they do not have a security or governance
           | background.
        
       | pkilgore wrote:
       | Slopliance?
        
       | OsrsNeedsf2P wrote:
       | Even if this is a hit piece made by a competitor, the evidence
       | put forwards is very damning:
       | 
       | > Conclusions present before customer signs or provides info
       | 
       | If false, the defamation damages here would be in the tens of
       | millions. Huge respect to whoever stuck their neck out to post
       | this.
        
       | tremarley wrote:
       | Delve has released a response
       | 
       | https://delve.co/blog/response-to-misleading-claims
        
         | frankfrank13 wrote:
         | > These are starting points only: customers are responsible for
         | reviewing, modifying, and finalizing their own materials. Draft
         | templates are not the same as "pre-filled evidence."
         | 
         | Yeah, ok. BRB to start a bank where I template everyone a
         | billion dollars, its up to you to be honest with how much money
         | you have.
        
         | sebmellen wrote:
         | There's a deep lack of accountability here for their marketing
         | statements. For example, "get SOC 2 compliant in days," which I
         | would consider to be false advertising.
         | 
         | That, plus their willingness to arrange an essentially
         | fraudulent auditor network (try to find who the real CPA is
         | behind Accorp, for example), and also massively upcharge the
         | prices of the SOC reports that they offered as a bundled
         | service within the platform. There was no separation here. Del
         | is the transfer agent. Del was always the intermediary and the
         | transfer agent. There is no independence in their default
         | auditor relationships.
         | 
         | At very best, this is a massive AICPA transgression.
         | 
         | At worst, blatant fraud.
         | 
         | I would wager that discovery would show the latter.
        
         | CityOfThrowaway wrote:
         | This basically boils down to, "Sure, we recommended you work
         | with scammy low-quality auditors, but if you actually use them
         | it's your own fault... we're just an automation tool!"
         | 
         | In other words, I'm reading this as effectively a full
         | admission that the claims are true but the company is saying
         | not their responsibility.
         | 
         | Very, very bad.
        
           | jvwww wrote:
           | Where does it say we recommend you work with scammy low-
           | quality auditors? They say that they use third party audit
           | firms that are used by other compliance companies.
        
             | sebmellen wrote:
             | This is clearly false from what I've seen. If you read the
             | source Substack article and look through the list of
             | auditors they have, it is impossible to trace down who the
             | US-based CPA is that's issuing the report. These firms, for
             | all intents and purposes, do not really exist. They use
             | shell addresses in Wyoming and Texas that are registered
             | agent offices, etc.
             | 
             | But really all you have to do is look at the reports
             | themselves. They are so shoddily written that it's hard to
             | believe any legitimate firm would issue them. If you Ctrl F
             | for Clueley in this thread, you will see my comment with a
             | sample excerpt from the assertion of management for one of
             | their reports.
        
             | owebmaster wrote:
             | We or they? Choose one
        
               | joemi wrote:
               | It can be inferred the use of "we" was as a quote. The
               | bigger issue is that they did not clearly indicate that
               | they were quoting.
        
             | ibero wrote:
             | if you go through the original Substack post it's clear the
             | intention is to drive to those obfuscated auditors.
        
         | svat wrote:
         | > _"Non-denial denial" is a term of art in PR. Never read one?
         | They're fun._
         | 
         | -- patio11 about this response
         | (https://x.com/patio11/status/2035115379169677717)
        
         | Qasaur wrote:
         | They've possibly dug an even deeper hole now.
         | 
         | None of their ISO 27001 certificates, aside from the premium
         | one-offs with the vCISO, are accredited by any reputable ISO
         | accreditation body. I would even argue that IAS, who accredited
         | Prescient Security (mentioned as a reputable body in the
         | article), has a questionable reputation and certainly gives off
         | a pay-to-play impression.
         | 
         | You can look up the names of their partners below. The one body
         | I found that is on the register (Accorp) is accredited by UAF,
         | a known cert-mill accreditation body, and I'm not even sure
         | it's the same Accorp that Delve has partnered with.
         | 
         | For reference, you want a ISO certificate issued by a body
         | accredited by UKAS (UK gov. adjacent non-profit), ANAB (ANSI),
         | or equivalent, all government-recognised. This is normally the
         | first thing I check whenever someone claims ISO 27001
         | certification and it is a great heuristic to validate
         | certification rigour.
         | 
         | https://www.iafcertsearch.org/search/certification-bodies
         | 
         | Shockingly low levels of DD by everyone involved here.
        
       | llmslave wrote:
       | People dont fully know it, but alot of capital in society gets
       | accumulated by people with the right look, instead of with actual
       | ability. In many cases, these startups start out as fraud, and
       | hope to become real. VCs know this.
       | 
       | But the tragedy is that there is a fixed pie of capital to be
       | allocated, and so when they allocate to people like this, it
       | steals opportunity from someone else
        
       | frankfrank13 wrote:
       | I can understand two 20 year olds committing fraud. I can't
       | understand a team of engineers PRE-PUBLISHING A TRUST REPORT
       | before a single field has been filled out. This is worse than
       | fraud, its poor craftsmanship.
        
       | aiisahik wrote:
       | 80% of Compliance has always been a performative box checking
       | exercise.
       | 
       | They delivered the product that every company wanted - make the
       | box checking faster.
        
         | orochimaaru wrote:
         | There is a legal liability that comes with the bow checking.
         | Nobody cares about box checking. Everyone cares about legal
         | liability.
        
       | upmind wrote:
       | What's the TLDR? Should one be worried if their business uses
       | Delve?
        
       | alanning wrote:
       | For those looking for help with SOC2 compliance, I had a good
       | experience with another YC company, Vanta. That was some years
       | ago so not sure if anything has changed since then but I would
       | recommend checking them out.
        
         | sebmellen wrote:
         | YC has funded both Vanta and OneLeet. It's a shame they also
         | funded a hype machine like Delve.
         | 
         | I would recommend both Vanta and OneLeet as good quality tools
         | to work with, having used both. The founders of OneLeet are
         | very accessible, and Vanta has all the integrations you would
         | need as both a small startup and an enterprise-grade player.
         | 
         | Secureframe and Drata are other tools in a similar class that
         | are also legitimate.
        
         | tptacek wrote:
         | I like the Vanta people just fine and think it's a fine
         | product, but I would not recommend it to startups looking to
         | get SOC2.
         | 
         | https://fly.io/blog/soc2-the-screenshots-will-continue-until...
         | 
         | Most startups should be doing _way, way less_ than automation
         | platforms like these tell them they need to do to get a SOC2
         | attestation.
        
           | dmix wrote:
           | Not every sales team can convince a big paying customer that
           | SOC2 isn't important. Fly.io might operate in a more
           | technical customer base and can choose it's customers, but
           | lots of B2B SaaS companies have to play the enterprise lawyer
           | game to get big contracts. Our company hired an accounting
           | firm which helped seal a deal and now we just advertise SOC2
           | like everyone else.
        
       ___________________________________________________________________
       (page generated 2026-03-20 23:00 UTC)