Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

121–130 of 327 posts

Re: Delve – Fake Compliance as a Service

#121

Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing? I can hardly imagine that I'd even be interested in taking a look at the domain. It's just... so mundane. Or maybe the alpha-type overachievers don't care about the domain but the opportunity?

The problem may not be "intellectually interesting" to them at all, but building B2B SaaS does appeal to them from a lifestyle/prestige/pedigree perspective and will probably get them an exit to become a Venture investor even if they fail.

Re: Delve – Fake Compliance as a Service

#122

Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. AWS is probably the best actual CaaS vendor out there. They have a product offering expressly designed to help their customers get through this jungle: https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-a... You are still responsible for everything on top of what AWS provides (software/configuration/poli…

I think that goes for any major cloud provider, not only AWS. But nothing is free, you pay a hefty premium to get this (compared to plain infra providers like Hetzner for example).

Re: Delve – Fake Compliance as a Service

#123
post #98

Delve seems clearly scummy, but dear god the author's company was also engaging in fraud with their own customers and just hoping to skate by. "The trouble starts when you look at the answers Delve’s AI provided. Based on what your Delve policies claim, the questionnaire AI answers questions stating you have an MDM, had a 200 hour pen-test performed, and do regular backup restoration simulations. Tens of questions ar…

At least they had the balls to post it

Re: Delve – Fake Compliance as a Service

#124
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

What is the purpose of a business though? To make profits for its owners. If the profit lies in doing all this corporate theater then that's the business. A company that focuses only on providing a service and product but ignores how their customer needs to use said service and product is going to go out of business.

That is "a" purpose of a business, but not the primary purpose. The primary purpose of business is to provide a service or product people want. You can want profits all day long but if you don't have something people want you don't have a business.

Re: Delve – Fake Compliance as a Service

#125

Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing? I can hardly imagine that I'd even be interested in taking a look at the domain. It's just... so mundane. Or maybe the alpha-type overachievers don't care about the domain but the opportunity?

I think there are lots of 20 year olds with a passion for making money

Re: Delve – Fake Compliance as a Service

#126
post #55
post #37

This seems like a hit job by a competitor. Really ruthless. > Two months ago, an email went out to a few hundred Delve clients informing them that Delve had leaked their audit reports, alongside other confidential information, through a Google spreadsheet that was publicly accessible. Who leaked the audit reports? Who sent this email? Who is taking the time to write this analysis and kill the company? In my opinion,…

The key problem is the audits and the auditors. I have independently verified for our vendors that they have the same templated SOC2 as all of the leaked reports, which is concerning because that shows the auditors did not actually validate the controls. SOC2 is supposed to give you an INDEPENDENT evaluation of the compliance of a company "are they doing what they say they are" If the SOC2 report is just a pre-popula…

Really curious what you're going to do, going forward. Will you be rejecting compliance certified with Delve? Will you be forcing your vendors to redo compliance?

Re: Delve – Fake Compliance as a Service

#127
post #102
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

Maybe you suouldn't be hacking due diligence if your team isn't ready for it

Isn't ready for, or doesn't need?

I had to have meetings with… myself, at times, for compliance reasons.

Re: Delve – Fake Compliance as a Service

#128
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

SOC 2 is mostly about proving you do what your policies say, and there’s more flexibility than people think.

For small teams it doesn’t have to be heavyweight. A risk register can be a simple doc with a few real risks and mitigations.

That said, I agree there’s a lot of theater. For smaller companies and budgets, it often turns into rubber stamping. Auditors rely on the evidence you provide, so the report can look much cleaner than day to day reality.

Still, it has value. It forces you to formalize basic practices, and if you want those customers, you’re signing up for that level of scrutiny.

Re: Delve – Fake Compliance as a Service

#129
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

What is the purpose of a business though? To make profits for its owners. If the profit lies in doing all this corporate theater then that's the business. A company that focuses only on providing a service and product but ignores how their customer needs to use said service and product is going to go out of business.

I would argue that profits are a result of what you do and not the purpose... Obviously intertwined but that's why its important to pick something you like

Re: Delve – Fake Compliance as a Service

#130
post #111
post #53

Earlier quoted context omitted.

In case anyone hasn't seen my other posts about this: (1) I had no idea this story existed and woke up to claims that I was obviously* suppressing it. (2) I looked into it and found that no moderator had touched either of the two submissions of the story, but that both submissions had set off HN's voting ring detector. (Whether there was a voting ring or not, I don't know - that software isn't perfect. It has held up…

TIL that voting ring detection exists

HN would be an entirely different place if people could just arrange to get their stuff upvoted onto the front page! We've spent hundreds of hours working on this over the years. Still not perfect of course.
Post reply on HN