Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

151–160 of 327 posts

Re: Delve – Fake Compliance as a Service

#151

Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. AWS is probably the best actual CaaS vendor out there. They have a product offering expressly designed to help their customers get through this jungle: https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-a... You are still responsible for everything on top of what AWS provides (software/configuration/poli…

> Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. Trying to understand how someone can have this perspective when it’s usually someone’s full time salaried job in a lot of companies.

A lot of that comes down to the costs associated with not being compliant and/or the requirements of existing contracts/insurance policies, where having dedicated FTEs to compliance is a requirement. Compliance might not be hard for the person/people managing the program, however it might seem difficult or complex to the FTEs that have to build to those standards if they do not have a security or governance background.

Re: Delve – Fake Compliance as a Service

#152

Delve has released a response https://delve.co/blog/response-to-misleading-claims

This basically boils down to, "Sure, we recommended you work with scammy low-quality auditors, but if you actually use them it's your own fault... we're just an automation tool!"

In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility.

Very, very bad.

Re: Delve – Fake Compliance as a Service

#156
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

The risk register is ISO 27001. The "I" in ISO doesn't stand for Internet, it stands for international. You shouldn't be doing business with international customers if you don't have a risk register, which is why they're requesting it.

Why is the line drawn at being international?

What is it about customers in Ethiopia that necessitates this? What is it about American (non-international) customers that doesn't require a register?

Re: Delve – Fake Compliance as a Service

#157

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

Re: Delve – Fake Compliance as a Service

#159

Delve has released a response https://delve.co/blog/response-to-misleading-claims

This basically boils down to, "Sure, we recommended you work with scammy low-quality auditors, but if you actually use them it's your own fault... we're just an automation tool!" In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility. Very, very bad.

Where does it say we recommend you work with scammy low-quality auditors? They say that they use third party audit firms that are used by other compliance companies.

Re: Delve – Fake Compliance as a Service

#160

Earlier quoted context omitted.

It says right there, 7-day work weeks (no days off). Also they were part of the cohort forcing workers to stay minimum until 9PM. Like every AI company, their "product" is a Next.js website, OPENAI_API_KEY, and a Stripe checkout page.

Ah ok. What's with the "unpaid labour" part?

It's also in the original post. Greptile, HockeyStack, and others from that cohort of 20-year old founders out of YC were having software engineer candidates come in day-in and day-out, staying until 9PM under the threat of being rejected if they left earlier.

They were not paid at all, they were working long-term on a "trial period". And yes it's very illegal. I was there and saw it first-hand.

The guys they had on trial periods - though I'm sure they were very intelligent - were not really firing on all cylinders if you know what I mean.

Post reply on HN