Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

111–120 of 327 posts

Re: Delve – Fake Compliance as a Service

#111
post #53

Earlier quoted context omitted.

I think it may be getting (intentionally?) suppressed from the homepage. Given this is a YCombinator website, I wouldn't rule that out. Regardless, it's been an ongoing issue. I know a few involved companies — it takes basically 5 days to get a SOC 2 Type 2 report through Delve. And, of course, they market this way too: "SOC 2 in days". Unbelievable.

In case anyone hasn't seen my other posts about this: (1) I had no idea this story existed and woke up to claims that I was obviously* suppressing it. (2) I looked into it and found that no moderator had touched either of the two submissions of the story, but that both submissions had set off HN's voting ring detector. (Whether there was a voting ring or not, I don't know - that software isn't perfect. It has held up…

TIL that voting ring detection exists

Re: Delve – Fake Compliance as a Service

#112
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

This is as designed to gatekeep these customers. Those in control of the checklists stand to benefit.

Re: Delve – Fake Compliance as a Service

#114

> Delve was founded in 2023 by Karun Kaushik and Selin Kocalar, both Forbes 30 Under 30 members and MIT dropouts who met as freshmen. Forbes 30 under 30 remains undefeated

The methodology questions remain:

does Forbes have a great method for identifying future felons?

do future felons push harder to come to Forbes' attention?

does being on the Forbes list unduly influence founders to commit felonies?

Re: Delve – Fake Compliance as a Service

#115

> Delve was founded in 2023 by Karun Kaushik and Selin Kocalar, both Forbes 30 Under 30 members and MIT dropouts who met as freshmen. Forbes 30 under 30 remains undefeated

What is it with the dropouts and unethical businesses? It is almost as if dropping out makes them do things, and without credentials, those things are the things others will not do.

Re: Delve – Fake Compliance as a Service

#116

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

I don't want to work wherever you do your thing. Software as a service means you provide a service, and you should take your responsibility to protect your customer's data super seriously. Compliance frameworks are one useful tool among many to support this effort. It helps us identify gaps, identify risks, make improvements. It also give us a way to communicate what we do to our partners. The behavior described in t…

I've done a mix of SOC2, ISO27001 and PCI L1 for 3 different startups. 2 of them b2b. All certified 100% and fully compliant.

The problem with the current frameworks is that the "controls" are so asinine and auditors so hard headed, that getting certified becomes a matter of "checking the box" .

Particularly most of those frameworks REQUIRE maintaining so much paper red tape that make a 10 person startup want to kill themselves. And in addition the costs are stupid high for startups that are just "starting up".

On the flip side, how many large companies have we seen that have all the SOCs, ISOS and whatnot certifications, and they get pwn3d and their data stolen or exposed.

It tells you that a place being certified doesn't guarantee shit.

The reality is that large companies ask for certs as a CYA mechanism: the "security" department of LargeCo, asks for the compliance cert so that when shit hits the fan, they can say "not my fault, they told me they were compliant"

The good thing is that with the new Bullshit generators (llm) this certifification/compliance process will collapse.

Re: Delve – Fake Compliance as a Service

#118

Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing? I can hardly imagine that I'd even be interested in taking a look at the domain. It's just... so mundane. Or maybe the alpha-type overachievers don't care about the domain but the opportunity?

I'm in the industry (albeit not a 20-year old), and agree that the domain itself is incredibly dry.

The tech is quite interesting, thankfully.

From a customer perspective it's interesting - compliance sucks so much that even a slight improvement/automation goes a long way

Re: Delve – Fake Compliance as a Service

#119
Even if this is a hit piece made by a competitor, the evidence put forwards is very damning:

> Conclusions present before customer signs or provides info

If false, the defamation damages here would be in the tens of millions. Huge respect to whoever stuck their neck out to post this.

Re: Delve – Fake Compliance as a Service

#120

There is a lot of serious allegations in here. But some of these complaints apply to most SOC 2 compliance services. For example: it points out that Delve provides pre-filled documents and encourages you to accept them as is. In my experience that is typical. I have seen companies just rubber stamp pre-created documents that describe IT processes that do not accurately reflect actual policy because the MBA[1] running…

Doesn't seem like a problem with SOC 2 compliance, seems like a problem where a company appointed someone who is not suited to handle a SOC 2 project.

As for the pre-filled stuff, that's what other SOC 2 companies mean when they try to sell you "compliance in a box." Not that bad if the company is starting from scratch (However, the allegations here is that it is fraud. An "AI" company acting as a front for certification mills.

Post reply on HN