Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

211–220 of 327 posts

Re: Delve – Fake Compliance as a Service

#212

Earlier quoted context omitted.

> I’m gonna name some names. *Doesn’t name any names.* Not that I want you to, I feel it would open you up to libel exposure. But can we both acknowledge that you didn’t name the entity that coasted through their audit?

I did, and then I thought twice. Let’s say it’s a synonym for a piece of non-reflective geology.

I always think of obsidian when I see their name and that's reflective

Re: Delve – Fake Compliance as a Service

#213
post #86
post #3

Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.

Dishonesty is high signal for VC Like no one characterizes it like that, but this is the same business where you can tell a story about hiring a bunch of college friends to pretend to be your employees so a client comes to your "office" and thinks you're a legitimate business. And instead of looking in horror at how casually you'll lie to get business it's seen as scrappy and whimsical.

I think they're fairly open about looking for this signal, "be naughty" is one of their core tenants, no?

Re: Delve – Fake Compliance as a Service

#214
post #179

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?

Pay to play and keep selling. Understand the liabilities and cover your ass, address the biggest risks.

The point of SOC2 is really demonstrate that you have controls. The other fake compliance areas are scarier for sure. You used to see really blatant issues — I recall early SaaS companies pitching to my enterprise with sales engineers showing me customer data.

Microsoft refused to provide diagrams to the Feds detailing how Azure works. They got the FedRAMP High stamp anyway, because they already sold it to half the Fed. That’s more real… as a situation where a Chinese hacker could compromise data in a dedicated “government cloud” by compromising a certificate in an onprem dev environment should be impossible… yet it happened.

Re: Delve – Fake Compliance as a Service

#217
post #179

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?

Big four have been caught approving fraudulent accounts too, so why not SOC? :)

Re: Delve – Fake Compliance as a Service

#218

Earlier quoted context omitted.

This is clearly false from what I've seen. If you read the source Substack article and look through the list of auditors they have, it is impossible to trace down who the US-based CPA is that's issuing the report. These firms, for all intents and purposes, do not really exist. They use shell addresses in Wyoming and Texas that are registered agent offices, etc. But really all you have to do is look at the reports the…

Present assurance definitely exists in the US. Outside of delve, I have seen their reports for vanta and it’s the same. it was 95% policy inspections and 5% loooked at a GRC tool.

I've used Prescient in the past and found them on par with others. Policy evidence is at most about 30%. Everything else is show-don't-tell. Either live screen shares, screenshots, non-policy documentation, or evidence from a shared vendor that's integrated into the environments and security tools (like Drata).

Re: Delve – Fake Compliance as a Service

#219
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

> Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee enterprise. Have you considered that the kind of companies that demand SOC2 compliance would be happy to pay extra for SOC2 compliance, if you offered it as an optional add-on costing $200k per year?

$200k is more for FedRAMP or PROTECTED+, but I think you’d be able to create a “compliance” addon for $20k quite successfully.

Re: Delve – Fake Compliance as a Service

#220
Lots of companies affected this, what blows my mind is when VC's were funding this how come no due-diligence was done on something as important as compliance. who even tries to scam on compliance like it's a known way to get caught.
Post reply on HN