Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

181–190 of 327 posts

Re: Delve – Fake Compliance as a Service

#181
post #167

Delve has released a response https://delve.co/blog/response-to-misleading-claims

> “Non-denial denial” is a term of art in PR. Never read one? They’re fun. — patio11 about this response ( https://x.com/patio11/status/2035115379169677717 )

*Actual fun may vary.

Re: Delve – Fake Compliance as a Service

#182

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

Here's me founding a company and thinking "Shit I really need to be on ITIL 4 and ISO9000 before I even consider taking this to market", but I guess we move in different circles.

Re: Delve – Fake Compliance as a Service

#183

Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing? I can hardly imagine that I'd even be interested in taking a look at the domain. It's just... so mundane. Or maybe the alpha-type overachievers don't care about the domain but the opportunity?

> Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing?

It mentions that they had a medical scribe product and ran into HIPAA compliance issues with it, so it's not a leap to think someone might go "hey this stuff is what sunk us last time, I bet we're not the only people with that problem".

Re: Delve – Fake Compliance as a Service

#184
post #174

Earlier quoted context omitted.

I like the Vanta people just fine and think it's a fine product, but I would not recommend it to startups looking to get SOC2. https://fly.io/blog/soc2-the-screenshots-will-continue-until... Most startups should be doing way, way less than automation platforms like these tell them they need to do to get a SOC2 attestation.

Not every sales team can convince a big paying customer that SOC2 isn't important. Lots of B2B SaaS companies have to play the enterprise lawyer game to get big contracts.

This feels like a weird response to a comment recommending how to approach getting a SOC2, that links to a blog post about Fly.io's SOC2.

The pitch isn't "don't get a SOC2", or "convince big paying customers that SOC2 isn't important". It's "don't worry about SOC2 until a big paying customer says they'll make big payments if you get it, and when you do worry about it, don't let SOC2 compliance trick you into doing bonkers infrastructure things"

Re: Delve – Fake Compliance as a Service

#185

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

Nah. I’m gonna name some names.

I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material.

Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes.

Anyway, a massive PE entity bought them in a hostile takeover, fired everybody, binned the ISMS, moved to some “compliance” goons.

I saw the box ticking chicanery as it happened - as after firing everyone they of course didn’t follow the off boarding process, so I retained full access to their JIRA. I only lost access a year later when atlassian terminated the account for non-payment.

Nobody actually gives a shit, about anything.

Re: Delve – Fake Compliance as a Service

#186

Delve has released a response https://delve.co/blog/response-to-misleading-claims

This response is just... simply... terrible.

"Below are just some of the many inaccuracies in the story and then the truth."

"[G]iven how competitive this industry is, attacks like this sadly come with the territory."

"We are actively investigating any leaks and are still reviewing the Substack. If there are more attacks to respond to we will do so."

When you have a PR problem, you don't hire your marketing intern to write the response. You hire a PR consultant. Their funders' Rolodexes are probably full of them. If the Board approved the response, I'd be frankly shocked.

Re: Delve – Fake Compliance as a Service

#187
It feels like I'm screaming into the void, but compliance work is bad is because people make it so.

Willfully paying for a service that offers SOC 2 reports at 1/5th the usual rate and delivers them in days instead of months and deluding themselves (and others) that it's a proper audit.

Taking cookie cutter policies/controls jamming it into your org without any awareness whatsoever. Acting surprised when employees complain about draconian rules and the audit process is a pain because you wanted to take the shortcut.

Why can't people just do it the proper way the first time? Pay for a reputable auditing firm, write your own policies and implement controls that map to the actual organization, do a gap assessment with the auditing firm so that both parties is aligned on expectations, and spend the necessary time to undergo the audit. Getting it should be a milestone if you actually take it seriously and have a modicum of professionalism.

In my eyes, audits should be a trust exercise. You trust that your organization is organized in a way that meets standards (by doing the work) and the auditors trust that you aren't faking your evidence. As someone who has to regularly vet countless new software purchases, SOC 2 actually serves a role. Does anyone have a better idea of getting third party validation of how another company operates? Like sending them tons of questionnaires is the solution?

All this just breaks that trust by facilitating certification mills. Another example of fraud stemming from a country that churns out fake degrees, fake papers, fake conferences, and fake references.

Re: Delve – Fake Compliance as a Service

#188

Earlier quoted context omitted.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…

Until someone rich and powerful gets ripped off -- then, suddenly, lots of people care a lot.

Re: Delve – Fake Compliance as a Service

#189

Even if this is a hit piece made by a competitor, the evidence put forwards is very damning: > Conclusions present before customer signs or provides info If false, the defamation damages here would be in the tens of millions. Huge respect to whoever stuck their neck out to post this.

In theory, yes, but you can't squeeze blood from a stone.
Post reply on HN