Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

221–230 of 327 posts

Re: Delve – Fake Compliance as a Service

#221

Lots of companies affected this, what blows my mind is when VC's were funding this how come no due-diligence was done on something as important as compliance. who even tries to scam on compliance like it's a known way to get caught.

I genuinely think this is because the elites like the MIT dropouts that started this company think the rest of us observers are stupid.

They have a billboard with the copy "Compliance before you tell your parents you dropped out of MIT"

Re: Delve – Fake Compliance as a Service

#222

Lots of companies affected this, what blows my mind is when VC's were funding this how come no due-diligence was done on something as important as compliance. who even tries to scam on compliance like it's a known way to get caught.

They're "AI Native". This maps with how the entire "AI revolution" has felt to me - like no due diligence has been done to validate the output of anything, and instead just the "AI" stamp is enough to satisfy investors.

Re: Delve – Fake Compliance as a Service

#223

Earlier quoted context omitted.

Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…

> I’m gonna name some names. *Doesn’t name any names.* Not that I want you to, I feel it would open you up to libel exposure. But can we both acknowledge that you didn’t name the entity that coasted through their audit?

He didn't say when he was gonna name some names.

Re: Delve – Fake Compliance as a Service

#225

Earlier quoted context omitted.

I did, and then I thought twice. Let’s say it’s a synonym for a piece of non-reflective geology.

I always think of obsidian when I see their name and that's reflective

pretty sure he means blackstone or blackrock

Re: Delve – Fake Compliance as a Service

#226
post #171
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

Translation: all your rules and regulations are crap, and we don't want to comply with any of them. When in reality most rules and regulations are not crap, and you should care about them. Especially when your startup advertises compliance with HIPAA (medical records), PCI-DSS (payments data) and a bunch of other data protection standards and regulations.

Most rules and regulations are not crap.

But whole compliance industry is crap.

One way they inflate expectations to extract money the other way they cut corners to rubber stamp BS to make it as cheap as possible for themselves.

Re: Delve – Fake Compliance as a Service

#227
post #167

Delve has released a response https://delve.co/blog/response-to-misleading-claims

> “Non-denial denial” is a term of art in PR. Never read one? They’re fun. — patio11 about this response ( https://x.com/patio11/status/2035115379169677717 )

To me this is the money shot (but it takes a couple of passes to understand):

> No small amount of criticism of LLMs is downstream of past decisions to reify form over function, resulting in the substance having been optimized out. Now the LLM threatens to make the form available in seconds

Re: Delve – Fake Compliance as a Service

#228

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

These days, nobody cares about legal liability, which is the likelihood of losing a lawsuit if there's a lawsuit, either. They only care about actual lawsuits against their company. They have noticed they're pretty rare and if the company's going to go under it's going to go under anyway, so might as well take the extra profits from not worrying about it

Re: Delve – Fake Compliance as a Service

#229
post #138

Earlier quoted context omitted.

Trust me, you can lie and get away with it if you go through YC and dropped out of a top university. Garry Tan blocked me on X for pointing this out. It's a big club, and you ain't in it! Fortunately, some of the old-YC spirit seems to be alive here on HN still.

They likely barely had a product when they applied to YC. It's more interesting as to why this wasn't discovered (if it is even true) when they were raising their Series A.

Why would anyone actually care about this, as long as money is made?

Re: Delve – Fake Compliance as a Service

#230

Earlier quoted context omitted.

Ah ok. What's with the "unpaid labour" part?

It's also in the original post. Greptile, HockeyStack, and others from that cohort of 20-year old founders out of YC were having software engineer candidates come in day-in and day-out, staying until 9PM under the threat of being rejected if they left earlier. They were not paid at all, they were working long-term on a "trial period". And yes it's very illegal. I was there and saw it first-hand. The guys they had on…

Yikes
Post reply on HN