Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. AWS is probably the best actual CaaS vendor out there. They have a product offering expressly designed to help their customers get through this jungle: https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-a... You are still responsible for everything on top of what AWS provides (software/configuration/poli…
> Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. Trying to understand how someone can have this perspective when it’s usually someone’s full time salaried job in a lot of companies.
Delve – Fake Compliance as a Service
151–160 of 327 posts
Re: Delve – Fake Compliance as a Service
#152Delve has released a response https://delve.co/blog/response-to-misleading-claims
In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility.
Very, very bad.
Re: Delve – Fake Compliance as a Service
#153Re: Delve – Fake Compliance as a Service
#154Re: Delve – Fake Compliance as a Service
#155They delivered the product that every company wanted - make the box checking faster.
Re: Delve – Fake Compliance as a Service
#156A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…
The risk register is ISO 27001. The "I" in ISO doesn't stand for Internet, it stands for international. You shouldn't be doing business with international customers if you don't have a risk register, which is why they're requesting it.
What is it about customers in Ethiopia that necessitates this? What is it about American (non-international) customers that doesn't require a register?
Re: Delve – Fake Compliance as a Service
#15780% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
Re: Delve – Fake Compliance as a Service
#158Re: Delve – Fake Compliance as a Service
#159Delve has released a response https://delve.co/blog/response-to-misleading-claims
This basically boils down to, "Sure, we recommended you work with scammy low-quality auditors, but if you actually use them it's your own fault... we're just an automation tool!" In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility. Very, very bad.
Re: Delve – Fake Compliance as a Service
#160Earlier quoted context omitted.
It says right there, 7-day work weeks (no days off). Also they were part of the cohort forcing workers to stay minimum until 9PM. Like every AI company, their "product" is a Next.js website, OPENAI_API_KEY, and a Stripe checkout page.
Ah ok. What's with the "unpaid labour" part?
They were not paid at all, they were working long-term on a "trial period". And yes it's very illegal. I was there and saw it first-hand.
The guys they had on trial periods - though I'm sure they were very intelligent - were not really firing on all cylinders if you know what I mean.