Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

161–170 of 327 posts

Re: Delve – Fake Compliance as a Service

#161

Cluely and HockeyStack are scam companies too. Cluely did the ChatGPT wrapper to cheat on interviews then sold the customer data to recruiters. The whole company promise is a scam, and useless since we have LLMs. HockeyStack held contests for people to win cars etc and never delivered. They also lied about having revenues and a product when they had nothing built. Along with Greptile they were doing 7day weeks of unp…

Greptile is an awesome product, not sure where the scam is there

[dead]

Re: Delve – Fake Compliance as a Service

#163
post #159

Earlier quoted context omitted.

This basically boils down to, "Sure, we recommended you work with scammy low-quality auditors, but if you actually use them it's your own fault... we're just an automation tool!" In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility. Very, very bad.

Where does it say we recommend you work with scammy low-quality auditors? They say that they use third party audit firms that are used by other compliance companies.

This is clearly false from what I've seen. If you read the source Substack article and look through the list of auditors they have, it is impossible to trace down who the US-based CPA is that's issuing the report. These firms, for all intents and purposes, do not really exist. They use shell addresses in Wyoming and Texas that are registered agent offices, etc.

But really all you have to do is look at the reports themselves. They are so shoddily written that it's hard to believe any legitimate firm would issue them. If you Ctrl F for Clueley in this thread, you will see my comment with a sample excerpt from the assertion of management for one of their reports.

Re: Delve – Fake Compliance as a Service

#164

For those looking for help with SOC2 compliance, I had a good experience with another YC company, Vanta. That was some years ago so not sure if anything has changed since then but I would recommend checking them out.

YC has funded both Vanta and OneLeet. It's a shame they also funded a hype machine like Delve.

I would recommend both Vanta and OneLeet as good quality tools to work with, having used both. The founders of OneLeet are very accessible, and Vanta has all the integrations you would need as both a small startup and an enterprise-grade player.

Secureframe and Drata are other tools in a similar class that are also legitimate.

Re: Delve – Fake Compliance as a Service

#165
post #111
post #53

Earlier quoted context omitted.

In case anyone hasn't seen my other posts about this: (1) I had no idea this story existed and woke up to claims that I was obviously* suppressing it. (2) I looked into it and found that no moderator had touched either of the two submissions of the story, but that both submissions had set off HN's voting ring detector. (Whether there was a voting ring or not, I don't know - that software isn't perfect. It has held up…

TIL that voting ring detection exists

in some slacks there are regular requests to upvote stuff.

Re: Delve – Fake Compliance as a Service

#166

For those looking for help with SOC2 compliance, I had a good experience with another YC company, Vanta. That was some years ago so not sure if anything has changed since then but I would recommend checking them out.

I like the Vanta people just fine and think it's a fine product, but I would not recommend it to startups looking to get SOC2.

https://fly.io/blog/soc2-the-screenshots-will-continue-until...

Most startups should be doing way, way less than automation platforms like these tell them they need to do to get a SOC2 attestation.

Re: Delve – Fake Compliance as a Service

#168
post #159

Earlier quoted context omitted.

This basically boils down to, "Sure, we recommended you work with scammy low-quality auditors, but if you actually use them it's your own fault... we're just an automation tool!" In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility. Very, very bad.

Where does it say we recommend you work with scammy low-quality auditors? They say that they use third party audit firms that are used by other compliance companies.

We or they? Choose one

Re: Delve – Fake Compliance as a Service

#169

Delve has released a response https://delve.co/blog/response-to-misleading-claims

They’ve possibly dug an even deeper hole now.

None of their ISO 27001 certificates, aside from the premium one-offs with the vCISO, are accredited by any reputable ISO accreditation body. I would even argue that IAS, who accredited Prescient Security (mentioned as a reputable body in the article), has a questionable reputation and certainly gives off a pay-to-play impression.

You can look up the names of their partners below. The one body I found that is on the register (Accorp) is accredited by UAF, a known cert-mill accreditation body, and I’m not even sure it’s the same Accorp that Delve has partnered with.

For reference, you want a ISO certificate issued by a body accredited by UKAS (UK gov. adjacent non-profit), ANAB (ANSI), or equivalent, all government-recognised. This is normally the first thing I check whenever someone claims ISO 27001 certification and it is a great heuristic to validate certification rigour.

https://www.iafcertsearch.org/search/certification-bodies

Shockingly low levels of DD by everyone involved here.

Re: Delve – Fake Compliance as a Service

#170
post #159

Earlier quoted context omitted.

This basically boils down to, "Sure, we recommended you work with scammy low-quality auditors, but if you actually use them it's your own fault... we're just an automation tool!" In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility. Very, very bad.

Where does it say we recommend you work with scammy low-quality auditors? They say that they use third party audit firms that are used by other compliance companies.

if you go through the original Substack post it’s clear the intention is to drive to those obfuscated auditors.
Post reply on HN