Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

231–240 of 327 posts

Re: Delve – Fake Compliance as a Service

#232

Earlier quoted context omitted.

I don't want to work wherever you do your thing. Software as a service means you provide a service, and you should take your responsibility to protect your customer's data super seriously. Compliance frameworks are one useful tool among many to support this effort. It helps us identify gaps, identify risks, make improvements. It also give us a way to communicate what we do to our partners. The behavior described in t…

I've done a mix of SOC2, ISO27001 and PCI L1 for 3 different startups. 2 of them b2b. All certified 100% and fully compliant. The problem with the current frameworks is that the "controls" are so asinine and auditors so hard headed, that getting certified becomes a matter of "checking the box" . Particularly most of those frameworks REQUIRE maintaining so much paper red tape that make a 10 person startup want to kill…

Well, yes, but that's the point of many contracts, they are often designed to shift risk to parties that are better equipped to handle those risks. We run our app on GCP because as a 20 person company I don't want to be responsible for physical security and a million other risks.

With ISO27001 or SOC 2, I have more information about the other party's ability to manage those risks than just taking their word for it. I'm trusting a third party auditor to vouch for them.

Fraud undermines all kinds of relationships and yes LLMs make it worse. The last job we opened I got hundreds of perfect cover letters asserting the candidates met all of the criteria. Bah.

My perhaps naive hope is that a few of these companies involved will face criminal fraud charges and we will start to develop new reflexes as a society that just bc LLMs making lying very very easy, there are still consequences.

Re: Delve – Fake Compliance as a Service

#233
post #167

Earlier quoted context omitted.

> “Non-denial denial” is a term of art in PR. Never read one? They’re fun. — patio11 about this response ( https://x.com/patio11/status/2035115379169677717 )

To me this is the money shot (but it takes a couple of passes to understand): > No small amount of criticism of LLMs is downstream of past decisions to reify form over function, resulting in the substance having been optimized out. Now the LLM threatens to make the form available in seconds

Had to do a double take, but true

Re: Delve – Fake Compliance as a Service

#234

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

> 80% of Compliance has always been a performative box checking exercise.

You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did.

If you didn't check that box you could always claim you didn't know you weren't supposed to do what you did. As soon as you've checked “yes, I'm doing things in the approved way”, this excuse disappears.

Re: Delve – Fake Compliance as a Service

#235
post #228

Earlier quoted context omitted.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

These days, nobody cares about legal liability, which is the likelihood of losing a lawsuit if there's a lawsuit, either. They only care about actual lawsuits against their company. They have noticed they're pretty rare and if the company's going to go under it's going to go under anyway, so might as well take the extra profits from not worrying about it

If someone checked one box, and the company goes under because of a lawsuit linked to not doing what this box said, then the individual who checked that box becomes personally liable of the damages done to the shareholders asset (the value of the company).

You don't want to be in this position, really. And that's the whole point of compliance.

Re: Delve – Fake Compliance as a Service

#236
post #18

I remember having sales calls with them and the vibe was that it was "cheap and quick"... exactly what you want for your compliance

Most people only care about compliance if it stops them from closing a deal. I was at a startup where some enterprise said we needed a SOC 2. The founder talked them out of it by giving them a discount if they'd waive the requirement.

My company is tiny (just me) and at one point a client sent over a questionnaire that I needed to fill out. Half the things I already did, about 1/4th I did right then so I could check the box (added features/reports/etc), and the last 1/4th I looked into (including SOC2) and decided I’d rather lose the deal than try to do those things. I was completely truthful in the questionnaire and for those sections I just put “We can provide this but it costs extra”.

I ended up getting the contract and they never asked for those extra things. I guess that’s kind of the same thing your founder did but in reverse. Discount to skip it vs it will cost more to add it.

To be clear, I think most of the questionnaire was just “we want these answers on file”, I’m not in an industry where most of what they asked for is reasonable/needed. Though it scared the hell out of me when I got it because SOC2 (and some other things they asked about) is not cheap. Literally 1-2x the cost of the service I was selling. All for something I consider a _very_ small step about snake oil.

Re: Delve – Fake Compliance as a Service

#237

Earlier quoted context omitted.

Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…

> I’m gonna name some names. *Doesn’t name any names.* Not that I want you to, I feel it would open you up to libel exposure. But can we both acknowledge that you didn’t name the entity that coasted through their audit?

He technically did name many names: > Apple, Boeing, BAE systems, Philips, Siemens

Re: Delve – Fake Compliance as a Service

#239

Considering how YC companies are customers of other YC companies (presumably to lift ARR), how many YC companies have Delve compliance? Should we worry about AI startup customer data…

You can safely assume that all AI startups are stealing their customer data, don’t worry about that
Post reply on HN