Guys guys, if only it had some of that real AI it would be all good!!
Delve – Fake Compliance as a Service
231–240 of 327 posts
Re: Delve – Fake Compliance as a Service
#232Earlier quoted context omitted.
I don't want to work wherever you do your thing. Software as a service means you provide a service, and you should take your responsibility to protect your customer's data super seriously. Compliance frameworks are one useful tool among many to support this effort. It helps us identify gaps, identify risks, make improvements. It also give us a way to communicate what we do to our partners. The behavior described in t…
I've done a mix of SOC2, ISO27001 and PCI L1 for 3 different startups. 2 of them b2b. All certified 100% and fully compliant. The problem with the current frameworks is that the "controls" are so asinine and auditors so hard headed, that getting certified becomes a matter of "checking the box" . Particularly most of those frameworks REQUIRE maintaining so much paper red tape that make a 10 person startup want to kill…
With ISO27001 or SOC 2, I have more information about the other party's ability to manage those risks than just taking their word for it. I'm trusting a third party auditor to vouch for them.
Fraud undermines all kinds of relationships and yes LLMs make it worse. The last job we opened I got hundreds of perfect cover letters asserting the candidates met all of the criteria. Bah.
My perhaps naive hope is that a few of these companies involved will face criminal fraud charges and we will start to develop new reflexes as a society that just bc LLMs making lying very very easy, there are still consequences.
Re: Delve – Fake Compliance as a Service
#233Earlier quoted context omitted.
> “Non-denial denial” is a term of art in PR. Never read one? They’re fun. — patio11 about this response ( https://x.com/patio11/status/2035115379169677717 )
To me this is the money shot (but it takes a couple of passes to understand): > No small amount of criticism of LLMs is downstream of past decisions to reify form over function, resulting in the substance having been optimized out. Now the LLM threatens to make the form available in seconds
Re: Delve – Fake Compliance as a Service
#23480% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did.
If you didn't check that box you could always claim you didn't know you weren't supposed to do what you did. As soon as you've checked “yes, I'm doing things in the approved way”, this excuse disappears.
Re: Delve – Fake Compliance as a Service
#235Earlier quoted context omitted.
There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.
These days, nobody cares about legal liability, which is the likelihood of losing a lawsuit if there's a lawsuit, either. They only care about actual lawsuits against their company. They have noticed they're pretty rare and if the company's going to go under it's going to go under anyway, so might as well take the extra profits from not worrying about it
You don't want to be in this position, really. And that's the whole point of compliance.
Re: Delve – Fake Compliance as a Service
#236I remember having sales calls with them and the vibe was that it was "cheap and quick"... exactly what you want for your compliance
Most people only care about compliance if it stops them from closing a deal. I was at a startup where some enterprise said we needed a SOC 2. The founder talked them out of it by giving them a discount if they'd waive the requirement.
I ended up getting the contract and they never asked for those extra things. I guess that’s kind of the same thing your founder did but in reverse. Discount to skip it vs it will cost more to add it.
To be clear, I think most of the questionnaire was just “we want these answers on file”, I’m not in an industry where most of what they asked for is reasonable/needed. Though it scared the hell out of me when I got it because SOC2 (and some other things they asked about) is not cheap. Literally 1-2x the cost of the service I was selling. All for something I consider a _very_ small step about snake oil.
Re: Delve – Fake Compliance as a Service
#237Earlier quoted context omitted.
Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…
> I’m gonna name some names. *Doesn’t name any names.* Not that I want you to, I feel it would open you up to libel exposure. But can we both acknowledge that you didn’t name the entity that coasted through their audit?
Re: Delve – Fake Compliance as a Service
#238Re: Delve – Fake Compliance as a Service
#239Considering how YC companies are customers of other YC companies (presumably to lift ARR), how many YC companies have Delve compliance? Should we worry about AI startup customer data…
Re: Delve – Fake Compliance as a Service
#24080% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.