Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

191–200 of 327 posts

Re: Delve – Fake Compliance as a Service

#191
post #159

Earlier quoted context omitted.

Where does it say we recommend you work with scammy low-quality auditors? They say that they use third party audit firms that are used by other compliance companies.

This is clearly false from what I've seen. If you read the source Substack article and look through the list of auditors they have, it is impossible to trace down who the US-based CPA is that's issuing the report. These firms, for all intents and purposes, do not really exist. They use shell addresses in Wyoming and Texas that are registered agent offices, etc. But really all you have to do is look at the reports the…

Present assurance definitely exists in the US. Outside of delve, I have seen their reports for vanta and it’s the same. it was 95% policy inspections and 5% loooked at a GRC tool.

Re: Delve – Fake Compliance as a Service

#192

There is a lot of serious allegations in here. But some of these complaints apply to most SOC 2 compliance services. For example: it points out that Delve provides pre-filled documents and encourages you to accept them as is. In my experience that is typical. I have seen companies just rubber stamp pre-created documents that describe IT processes that do not accurately reflect actual policy because the MBA[1] running…

Giving you template device management policies is one thing, it's a whole other thing to say you don't have to have board meetings and generating fake minutes.

Many small companies operate without any formal board meetings.

Not every company is a Delaware C corp.

Re: Delve – Fake Compliance as a Service

#194
post #53

Earlier quoted context omitted.

I think it may be getting (intentionally?) suppressed from the homepage. Given this is a YCombinator website, I wouldn't rule that out. Regardless, it's been an ongoing issue. I know a few involved companies — it takes basically 5 days to get a SOC 2 Type 2 report through Delve. And, of course, they market this way too: "SOC 2 in days". Unbelievable.

In case anyone hasn't seen my other posts about this: (1) I had no idea this story existed and woke up to claims that I was obviously* suppressing it. (2) I looked into it and found that no moderator had touched either of the two submissions of the story, but that both submissions had set off HN's voting ring detector. (Whether there was a voting ring or not, I don't know - that software isn't perfect. It has held up…

>I had no idea this story existed and woke up to claims that I was obviously* suppressing it.

To be fair, it seems you’re saying the submission was being suppressed, just not intentionally. Lots of props of course for transparency and reboosting the story

Re: Delve – Fake Compliance as a Service

#195
post #97

A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…

The risk register is ISO 27001. The "I" in ISO doesn't stand for Internet, it stands for international. You shouldn't be doing business with international customers if you don't have a risk register, which is why they're requesting it.

Shouldn’t according to who? Who appointed ISO to say what should and shouldn’t be done?

Re: Delve – Fake Compliance as a Service

#196

For those looking for help with SOC2 compliance, I had a good experience with another YC company, Vanta. That was some years ago so not sure if anything has changed since then but I would recommend checking them out.

I had a pretty poor experience as a startup on Vanta. Maybe this is my own ignorance, but I told them when our contract was to renew that we do NOT want to renew. We were an early-stage startup soon to shut down and didn't need it. We never touched Vanta for 10 months before this, we never got SOC-2 (it was deprioritized). Not a single login in 10 months.

Nevertheless, they said it was: too late to opt out, that it can't be canceled or postponed, and then kept emailing us endlessly and sending to collections to pay them another $10K platform fee for the next year (more than we had in the company bank account).

I understand this with large corporations, but I don't think they're a good fit for startups.

Re: Delve – Fake Compliance as a Service

#197

Earlier quoted context omitted.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…

Yeah - probably. Didn’t Microsoft have Chinese engineers work classified government stuff?

I guess if you have the muscle to brush off legal action from the govt you’re ok. If you’re an unsuspecting startup - that could be a problem.

Re: Delve – Fake Compliance as a Service

#198
post #179

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?

If you want to do it right, hire a CPA who takes it seriously and spend the time to complete it in-house and fully understand it. Then engage one of the big 4 to sign off on it. The big 4 don’t offer much for SOC2 above what Delve does, it’s all smoke and mirrors unless you personally take it seriously.

Re: Delve – Fake Compliance as a Service

#199

Earlier quoted context omitted.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…

> I’m gonna name some names.

*Doesn’t name any names.*

Not that I want you to, I feel it would open you up to libel exposure. But can we both acknowledge that you didn’t name the entity that coasted through their audit?

Post reply on HN