Delve – Fake Compliance as a Service
211–220 of 327 posts
Re: Delve – Fake Compliance as a Service
#212Earlier quoted context omitted.
> I’m gonna name some names. *Doesn’t name any names.* Not that I want you to, I feel it would open you up to libel exposure. But can we both acknowledge that you didn’t name the entity that coasted through their audit?
I did, and then I thought twice. Let’s say it’s a synonym for a piece of non-reflective geology.
Re: Delve – Fake Compliance as a Service
#213Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.
Dishonesty is high signal for VC Like no one characterizes it like that, but this is the same business where you can tell a story about hiring a bunch of college friends to pretend to be your employees so a client comes to your "office" and thinks you're a legitimate business. And instead of looking in horror at how casually you'll lie to get business it's seen as scrappy and whimsical.
Re: Delve – Fake Compliance as a Service
#21480% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?
The point of SOC2 is really demonstrate that you have controls. The other fake compliance areas are scarier for sure. You used to see really blatant issues — I recall early SaaS companies pitching to my enterprise with sales engineers showing me customer data.
Microsoft refused to provide diagrams to the Feds detailing how Azure works. They got the FedRAMP High stamp anyway, because they already sold it to half the Fed. That’s more real… as a situation where a Chinese hacker could compromise data in a dedicated “government cloud” by compromising a certificate in an onprem dev environment should be impossible… yet it happened.
Re: Delve – Fake Compliance as a Service
#215wow you guys really delved into this
Re: Delve – Fake Compliance as a Service
#216Re: Delve – Fake Compliance as a Service
#21780% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?
Re: Delve – Fake Compliance as a Service
#218Earlier quoted context omitted.
This is clearly false from what I've seen. If you read the source Substack article and look through the list of auditors they have, it is impossible to trace down who the US-based CPA is that's issuing the report. These firms, for all intents and purposes, do not really exist. They use shell addresses in Wyoming and Texas that are registered agent offices, etc. But really all you have to do is look at the reports the…
Present assurance definitely exists in the US. Outside of delve, I have seen their reports for vanta and it’s the same. it was 95% policy inspections and 5% loooked at a GRC tool.
Re: Delve – Fake Compliance as a Service
#219A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…
> Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee enterprise. Have you considered that the kind of companies that demand SOC2 compliance would be happy to pay extra for SOC2 compliance, if you offered it as an optional add-on costing $200k per year?