Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

141–150 of 327 posts

Re: Delve – Fake Compliance as a Service

#141

Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. AWS is probably the best actual CaaS vendor out there. They have a product offering expressly designed to help their customers get through this jungle: https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-a... You are still responsible for everything on top of what AWS provides (software/configuration/poli…

> Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. Trying to understand how someone can have this perspective when it’s usually someone’s full time salaried job in a lot of companies.

Maybe they meant "Not hard != quickly done". I don't think many people think bureaucracy is especially difficult. It's just time consuming.

But frankly if they meant that, the statement doesn't really say anything at all. Because what in this world is hard if you stop taking shortcuts and spend time doing it correctly?

Re: Delve – Fake Compliance as a Service

#142
People dont fully know it, but alot of capital in society gets accumulated by people with the right look, instead of with actual ability. In many cases, these startups start out as fraud, and hope to become real. VCs know this.

But the tragedy is that there is a fixed pie of capital to be allocated, and so when they allocate to people like this, it steals opportunity from someone else

Re: Delve – Fake Compliance as a Service

#144
post #98

Delve seems clearly scummy, but dear god the author's company was also engaging in fraud with their own customers and just hoping to skate by. "The trouble starts when you look at the answers Delve’s AI provided. Based on what your Delve policies claim, the questionnaire AI answers questions stating you have an MDM, had a 200 hour pen-test performed, and do regular backup restoration simulations. Tens of questions ar…

At least they had the balls to post it

Per the piece, they only began to step away from Delve once they realized they couldn't close the deals they wanted and their hand was forced by outside asks.

And then also it took a rather large data leak later on to provide extra ammunition to decide and go forward with publishing this.

I'm glad they did, but there are a bunch of steps in between pure balls/altruism and what actually happened based on the blog.

Re: Delve – Fake Compliance as a Service

#145
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

Going through this with a medical startup... We have like 2 developer. But to get investment, put the app online etc. We need to fill out those paperwork... For things which just don't exist...

Isn't the point of the paperwork to get you to make those things exist?

Re: Delve – Fake Compliance as a Service

#146
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

"is very european." ... aa yes consumer protections. very european.

Re: Delve – Fake Compliance as a Service

#147

Delve has released a response https://delve.co/blog/response-to-misleading-claims

> These are starting points only: customers are responsible for reviewing, modifying, and finalizing their own materials. Draft templates are not the same as “pre-filled evidence.”

Yeah, ok. BRB to start a bank where I template everyone a billion dollars, its up to you to be honest with how much money you have.

Re: Delve – Fake Compliance as a Service

#148
post #130
post #111

Earlier quoted context omitted.

TIL that voting ring detection exists

HN would be an entirely different place if people could just arrange to get their stuff upvoted onto the front page! We've spent hundreds of hours working on this over the years. Still not perfect of course.

My theory is that a lot of people may have looked for a story like this on the home page and then searched ‘Delve’ to see if anything was submitted recently and then upvoted one of those recently submitted posts.

Re: Delve – Fake Compliance as a Service

#149

Delve has released a response https://delve.co/blog/response-to-misleading-claims

There's a deep lack of accountability here for their marketing statements. For example, "get SOC 2 compliant in days," which I would consider to be false advertising.

That, plus their willingness to arrange an essentially fraudulent auditor network (try to find who the real CPA is behind Accorp, for example), and also massively upcharge the prices of the SOC reports that they offered as a bundled service within the platform. There was no separation here. Del is the transfer agent. Del was always the intermediary and the transfer agent. There is no independence in their default auditor relationships.

At very best, this is a massive AICPA transgression.

At worst, blatant fraud.

I would wager that discovery would show the latter.

Re: Delve – Fake Compliance as a Service

#150

Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. AWS is probably the best actual CaaS vendor out there. They have a product offering expressly designed to help their customers get through this jungle: https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-a... You are still responsible for everything on top of what AWS provides (software/configuration/poli…

> Compliance isn't that hard once you stop looking for shortcuts and start spending time doing it correctly. Trying to understand how someone can have this perspective when it’s usually someone’s full time salaried job in a lot of companies.

I assume they mean "getting a SOC2 report", which is the part that Delve attempts to automate. The maintenance of controls, adoption of new policy as the company evolves, etc, is what someone will do in the full time role and that Delve et al would do nothing to assist with.
Post reply on HN