Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

81–90 of 327 posts

Re: Delve – Fake Compliance as a Service

#81

Earlier quoted context omitted.

Maybe no one wakes up wanting to deal with compliance, but it you found a company that has legal or moral obligations to be compliant with these standards, you sure have signed yourself up for it. Passing the responsibility off to some other company is, quite simply, irresponsible.

> Passing the responsibility off to some other company is, quite simply, irresponsible. Then do not pass the responsibility. But here's the trick: the regulator would like to see an audit done by a firm and purchasing audit services is exactly that: passing responsibility. So legally you can't be compliant unless you passed responsibility.

These compliance companies are not primarily tasked with auditing, as this article makes very clear. Delve is in control of the auditing process in a way that is inappropriate and unusual for this industry. The work that the company with these obligations should be doing themselves is generating the Section 3 description and the controls. The auditor then independently verifies their compliance with the controls. Thats a clear delineation of responsibilty, IMO

Re: Delve – Fake Compliance as a Service

#82
post #61
post #33

Earlier quoted context omitted.

The fund is called customers. The independent regulator is called the AICPA. It really comes down to who is paying attention SOC2 is as useful as a privacy policy at protecting your data. It’s all humans following human incentives.

The value of SOC2 is that it does take some experience to be able to plausibly fake the evidence which weeds out people that truly have no idea what they're doing. It also provides a blueprint of the stuff you should be doing if you actually care. But beyond that it's not worth a whole lot.

yeah it's funny to see some defense of this practice as "well the whole thing is pointless anyway so nothing is lost by defrauding folks". Pretty hollow argument

Re: Delve – Fake Compliance as a Service

#83

Cluely and HockeyStack are scam companies too. Cluely did the ChatGPT wrapper to cheat on interviews then sold the customer data to recruiters. The whole company promise is a scam, and useless since we have LLMs. HockeyStack held contests for people to win cars etc and never delivered. They also lied about having revenues and a product when they had nothing built. Along with Greptile they were doing 7day weeks of unp…

Wait what's the greptile story?

It says right there, 7-day work weeks (no days off).

Also they were part of the cohort forcing workers to stay minimum until 9PM.

Like every AI company, their "product" is a Next.js website, OPENAI_API_KEY, and a Stripe checkout page.

Re: Delve – Fake Compliance as a Service

#84

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

I don't want to work wherever you do your thing. Software as a service means you provide a service, and you should take your responsibility to protect your customer's data super seriously. Compliance frameworks are one useful tool among many to support this effort. It helps us identify gaps, identify risks, make improvements. It also give us a way to communicate what we do to our partners. The behavior described in the medium post is fraud, pure and simple.

I am a founder, and my ambition includes meeting the highest possible standards for my customers.

Re: Delve – Fake Compliance as a Service

#85
post #65

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

When I worked in cybersecurity I had a similar realization. No one cared about security posture. They cared about insurance policies. People hired us to shift blame instead of improve security posture. this is not terribly different

I think it's subtly different than that.

Companies do want to be secure. They try, and they often fail because it's hard.

They hire auditors to find problems and to shift blame. But since they only have 30 days to fix the problems that are found, it's going to see a lot like they only care about shifting the blame. Because at that point, they only care about passing that audit.

Right after that, though, they start caring about security again.

How do I know? 19 years experience going through those audits on the company side. For 11 months of the year, it was clear the boss cared about security. For that 1 month during the 'free retest' period, they only cared about passing that audit.

Re: Delve – Fake Compliance as a Service

#86
post #3

Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.

Dishonesty is high signal for VC

Like no one characterizes it like that, but this is the same business where you can tell a story about hiring a bunch of college friends to pretend to be your employees so a client comes to your "office" and thinks you're a legitimate business. And instead of looking in horror at how casually you'll lie to get business it's seen as scrappy and whimsical.

Re: Delve – Fake Compliance as a Service

#87

Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing? I can hardly imagine that I'd even be interested in taking a look at the domain. It's just... so mundane. Or maybe the alpha-type overachievers don't care about the domain but the opportunity?

Solving boring problems has been conventional startup wisdom for a long time. And a "mundane" startup might be more interesting than traditional high-paying jobs like finance/law/consulting. https://www.joelonsoftware.com/2007/12/06/where-theres-muck-...

Re: Delve – Fake Compliance as a Service

#89

Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing? I can hardly imagine that I'd even be interested in taking a look at the domain. It's just... so mundane. Or maybe the alpha-type overachievers don't care about the domain but the opportunity?

I work for a firm that develops custom software in regulated industries, and we have brilliant software & data engineers in their 20's working on compliance auditing, and more specifically "Compliance Management System health monitoring."

We've be able to use a lot of AI-assisted engineering and AI in the software to solve longstanding business challenges in this space.

I won't make assumptions about where you're located, but on the East Coast US it is big business among banks, utilities, healthcare, etc.

Re: Delve – Fake Compliance as a Service

#90

Cluely and HockeyStack are scam companies too. Cluely did the ChatGPT wrapper to cheat on interviews then sold the customer data to recruiters. The whole company promise is a scam, and useless since we have LLMs. HockeyStack held contests for people to win cars etc and never delivered. They also lied about having revenues and a product when they had nothing built. Along with Greptile they were doing 7day weeks of unp…

Greptile is an awesome product, not sure where the scam is there
Post reply on HN