Live data from Hacker News

We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

trustcompliance.xyz

71–80 of 83 posts

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#72
post #44

Earlier quoted context omitted.

Since you know a lot about SOC: is SOC2 Type I (point in time) enough to close enterprise sales? Is it worth getting for a new startup (seems super simple)?

Yes, it is, and no, you should not get it, not until you know you need it. If you have to ask, defer.

Thanks!

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#73

Looking at our SOC 2 report (we don't use Delve, our auditor isn't on their list) I don't think this is quite the smoking gun it might look like if you're not reading SOC 2 reports for a living. There's a fair amount of boiler plate language in these reports, and a bunch of re-stating the SOC 2 controls. I'd expect two reports (same auditors, same platforms) to be nearly identical. If they're both using AWS, Github,…

The main issue isn't about the reports being copy-pasted - it's about they are created with no audit ever being done.

You literally paid to get your cert without ever getting audited.

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#74
post #22

Earlier quoted context omitted.

It's security theater. Friendly plug for Oneleet, who actually talked us out of getting it. We were considering getting certified, but it only really makes sense if your customers require you to have it.

Tangential to this but do ISO certifications make sense or are they security theater as well? And another question but as a consumer, is there any certification which can meaningfully try to show if people/business take their security carefully or are all things security theater in that aspect and at some point, we just have to trust the enterprise and look for other signals of security (like for example blog posts w…

Not really. As long as current system where auditors are also clients of company being audited, the conflict of interest is too high.

Also, not to mention in many countries, the cost of getting breached is nothing so many companies are willing to just hope for the best and payout in case of the worst.

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#75

Looking at our SOC 2 report (we don't use Delve, our auditor isn't on their list) I don't think this is quite the smoking gun it might look like if you're not reading SOC 2 reports for a living. There's a fair amount of boiler plate language in these reports, and a bunch of re-stating the SOC 2 controls. I'd expect two reports (same auditors, same platforms) to be nearly identical. If they're both using AWS, Github,…

yes. I think some overlap is normal, but this is not that, eg. seen:

• same pagination across hundreds of reports → 100% template output • same auditor license everywhere → either extreme concentration or just rubber stamping • zero exceptions across all clients → unrealistic, real audits always find something.. right? • system descriptions pulled from marketing sites → .. copy paste

at one point you’re really looking at reports that were never really produced per each company

and that’s the problem

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#76

Earlier quoted context omitted.

I don't think that is an important point.

it does highlight the efficiency value of boilerplate. you only have to proof it once, really well of course. all downstream instances get the benefit of that one very good review.

boilerplate overlap is expected, no one rewrites these from scratch

though when everything lines up the same way across hundreds of reports, it gets weird...

I mean look at those reports; same pagination, same auditor showing up almost everywhere, no exceptions across all clients.. not even efficient templates should be like that

you still expect variation in scope, findings, structure, even if the base language is reused

big signal

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#77
post #68

" let r = ["Acme Corp", "CloudVault", "DataSync Pro", "NexGen AI", "SecureStack", "TrustLayer", "Vanta", "ComplianceIQ", "InfraSec", "ByteShield", "PipelineOps", "CyberNova", "TokenGuard", "ZeroTrust Labs", "Aether Security", "PrismData", "CloudArmor", "RiskLens", "AuditTrail", "ShieldIO"] , n = ["just checked", "searched for", "ran a scan on", "verified"] , a = ["San Francisco, CA", "New York, NY", "Austin, TX", "Lo…

fair call on the popups, they’re not real-time. I added them quickly to make the page feel less empty while testing engagement, probably not the best call in hindsight and I’ll remove or replace them with something real. on the "vibecoded" part, yeah I moved fast. this was built in under a day to get something out and see if people even care about this angle. that doesn’t mean the underlying data or direction is fake…

Cybersecurity compliance, but .xyz site built under a day to get something out fast to drum up engagement and "test the vibes on the idea". Makes one wonder what became of this industry.

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#78
post #64

Earlier quoted context omitted.

What about enterprise customers / sales?

For enterprise sales you can get a SOC 2 Type I faster than any enterprise sale goes through. Typically, most enterprises are okay if you show them proof that you are "in the process" of getting the certification by showing them that you have signed up with one of those platforms (Delve, Vanta, etc.), so you would be okay to start only when you are about to close one of those enterprise deals.

Great info, thanks!

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#79
post #64

Earlier quoted context omitted.

For enterprise sales you can get a SOC 2 Type I faster than any enterprise sale goes through. Typically, most enterprises are okay if you show them proof that you are "in the process" of getting the certification by showing them that you have signed up with one of those platforms (Delve, Vanta, etc.), so you would be okay to start only when you are about to close one of those enterprise deals.

Yeah, we got a signed letter of engagement from our auditor, which was enough to unlock a customer without having to go through any sidestepping process.

Thanks!

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#80
post #67
post #11

> "We may receive compensation from vendors listed below. All recommendations are based on independent research." this + new HN account? couldn't be more obviously a competitor. not to defend delve, but can’t be pushing this like some noble effort with the goal of transparency also lol @ the fake realtime "just searched for" toasts on a setInterval in the bottom left.

hello, this isn’t a competitor. I run a consulting company in the cybersecurity space and saw a chance to make this whole process more transparent. I agree it came off a bit clickbaity, I'm sorry, Claude probably pushed it too far. but I don’t have an audience anywhere, no following on social, so I needed to ship something fast and make it engaging. the intent wasn’t just this Delve thing, the goal is to move away fr…

> I agree it came off a bit clickbaity

Not clickbaity, but downright misleading and, for all we know about the XHR traffic, potentially malicious.

> But i need a way to marketing this intially.

Posting a site which blatantly fakes statistics, such as the ones mentioned two posts up from here, is not doing any favors.

Sending XHR requests with opaque binary data every few seconds is not doing you any favors. No information-only site has _any_ business XHR-posting opaque state every several seconds.

"Post it quickly at all costs, accuracy be damned," is not a viable strategy for a legitimate and believable site.

Post reply on HN