Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

171–180 of 327 posts

Re: Delve – Fake Compliance as a Service

#171
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

Translation: all your rules and regulations are crap, and we don't want to comply with any of them.

When in reality most rules and regulations are not crap, and you should care about them.

Especially when your startup advertises compliance with HIPAA (medical records), PCI-DSS (payments data) and a bunch of other data protection standards and regulations.

Re: Delve – Fake Compliance as a Service

#172
post #159

Earlier quoted context omitted.

Where does it say we recommend you work with scammy low-quality auditors? They say that they use third party audit firms that are used by other compliance companies.

We or they? Choose one

It can be inferred the use of "we" was as a quote. The bigger issue is that they did not clearly indicate that they were quoting.

Re: Delve – Fake Compliance as a Service

#173
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

Going through this with a medical startup... We have like 2 developer. But to get investment, put the app online etc. We need to fill out those paperwork... For things which just don't exist...

> We need to fill out those paperwork... For things which just don't exist...

Things like what? HIPAA?

Re: Delve – Fake Compliance as a Service

#174

For those looking for help with SOC2 compliance, I had a good experience with another YC company, Vanta. That was some years ago so not sure if anything has changed since then but I would recommend checking them out.

I like the Vanta people just fine and think it's a fine product, but I would not recommend it to startups looking to get SOC2. https://fly.io/blog/soc2-the-screenshots-will-continue-until... Most startups should be doing way, way less than automation platforms like these tell them they need to do to get a SOC2 attestation.

Not every sales team can convince a big paying customer that SOC2 isn't important. Lots of B2B SaaS companies have to play the enterprise lawyer game to get big contracts.

Re: Delve – Fake Compliance as a Service

#175
post #144

Earlier quoted context omitted.

At least they had the balls to post it

Per the piece, they only began to step away from Delve once they realized they couldn't close the deals they wanted and their hand was forced by outside asks. And then also it took a rather large data leak later on to provide extra ammunition to decide and go forward with publishing this. I'm glad they did, but there are a bunch of steps in between pure balls/altruism and what actually happened based on the blog.

uh isn’t the data leaker the necessary accelerant and necessary component to validate against the rest of the ecosystem? isn’t that what triggered the communication and coordination between multiple delve customers?

Re: Delve – Fake Compliance as a Service

#176
post #18

I remember having sales calls with them and the vibe was that it was "cheap and quick"... exactly what you want for your compliance

Most people only care about compliance if it stops them from closing a deal. I was at a startup where some enterprise said we needed a SOC 2. The founder talked them out of it by giving them a discount if they'd waive the requirement.

Re: Delve – Fake Compliance as a Service

#179

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?

Re: Delve – Fake Compliance as a Service

#180
post #174

Earlier quoted context omitted.

I like the Vanta people just fine and think it's a fine product, but I would not recommend it to startups looking to get SOC2. https://fly.io/blog/soc2-the-screenshots-will-continue-until... Most startups should be doing way, way less than automation platforms like these tell them they need to do to get a SOC2 attestation.

Not every sales team can convince a big paying customer that SOC2 isn't important. Lots of B2B SaaS companies have to play the enterprise lawyer game to get big contracts.

Fly is not saying "just ignore SOC2 compliance". Fly is saying "yes, get SOC2, we had to become SOC2 compliant, and also, you can work with your auditor to achieve SOC2 compliance in a more sane way than if you just do whatever is recommended upfront."

Basically, they are saying that you should tailor your SOC2 implementation so that it's actually useful without being a horrible overbearing process, that you have that option and should take it.

Post reply on HN