Earlier quoted context omitted.
Where does it say we recommend you work with scammy low-quality auditors? They say that they use third party audit firms that are used by other compliance companies.
This is clearly false from what I've seen. If you read the source Substack article and look through the list of auditors they have, it is impossible to trace down who the US-based CPA is that's issuing the report. These firms, for all intents and purposes, do not really exist. They use shell addresses in Wyoming and Texas that are registered agent offices, etc. But really all you have to do is look at the reports the…
Delve – Fake Compliance as a Service
191–200 of 327 posts
Re: Delve – Fake Compliance as a Service
#192There is a lot of serious allegations in here. But some of these complaints apply to most SOC 2 compliance services. For example: it points out that Delve provides pre-filled documents and encourages you to accept them as is. In my experience that is typical. I have seen companies just rubber stamp pre-created documents that describe IT processes that do not accurately reflect actual policy because the MBA[1] running…
Giving you template device management policies is one thing, it's a whole other thing to say you don't have to have board meetings and generating fake minutes.
Not every company is a Delaware C corp.
Re: Delve – Fake Compliance as a Service
#193Should we worry about AI startup customer data…
Re: Delve – Fake Compliance as a Service
#194Earlier quoted context omitted.
I think it may be getting (intentionally?) suppressed from the homepage. Given this is a YCombinator website, I wouldn't rule that out. Regardless, it's been an ongoing issue. I know a few involved companies — it takes basically 5 days to get a SOC 2 Type 2 report through Delve. And, of course, they market this way too: "SOC 2 in days". Unbelievable.
In case anyone hasn't seen my other posts about this: (1) I had no idea this story existed and woke up to claims that I was obviously* suppressing it. (2) I looked into it and found that no moderator had touched either of the two submissions of the story, but that both submissions had set off HN's voting ring detector. (Whether there was a voting ring or not, I don't know - that software isn't perfect. It has held up…
To be fair, it seems you’re saying the submission was being suppressed, just not intentionally. Lots of props of course for transparency and reboosting the story
Re: Delve – Fake Compliance as a Service
#195A lot of startups move fast with a small team. You build something great and big corporation X wants to buy a subscription but you need to be certified. Much of this is a good checklist but some of it is very european. "Where is the risk register to track controls in your 7 person company?" Now instead of doing what your team does best, you are doing paperwork theater for frameworks designed for a 100,000 employee en…
The risk register is ISO 27001. The "I" in ISO doesn't stand for Internet, it stands for international. You shouldn't be doing business with international customers if you don't have a risk register, which is why they're requesting it.
Re: Delve – Fake Compliance as a Service
#196For those looking for help with SOC2 compliance, I had a good experience with another YC company, Vanta. That was some years ago so not sure if anything has changed since then but I would recommend checking them out.
Nevertheless, they said it was: too late to opt out, that it can't be canceled or postponed, and then kept emailing us endlessly and sending to collections to pay them another $10K platform fee for the next year (more than we had in the company bank account).
I understand this with large corporations, but I don't think they're a good fit for startups.
Re: Delve – Fake Compliance as a Service
#197Earlier quoted context omitted.
There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.
Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…
I guess if you have the muscle to brush off legal action from the govt you’re ok. If you’re an unsuspecting startup - that could be a problem.
Re: Delve – Fake Compliance as a Service
#19880% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?
Re: Delve – Fake Compliance as a Service
#199Earlier quoted context omitted.
There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.
Nah. I’m gonna name some names. I had a client in the compliance space - they handle detailed product information for Apple, Boeing, BAE systems, Philips, Siemens - you know, nothing important, just literally classified material and incredibly sensitive corporate material. Anyway. We did ISO27001. We did it well, audited by Lloyds register, reputable stuff all the way down. Built actual meaningful processes. Anyway,…
*Doesn’t name any names.*
Not that I want you to, I feel it would open you up to libel exposure. But can we both acknowledge that you didn’t name the entity that coasted through their audit?
Re: Delve – Fake Compliance as a Service
#200The rookie mistake they made is they forgot to bribe the regulators with promises of future job offers.