Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

241–250 of 327 posts

Re: Delve – Fake Compliance as a Service

#243

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…

> the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did.

Maybe so, but how often are small companies actually sued for compliance survey misrepresentations? My most positive look at such surveys, after filtering out all the nonsense, is sometimes they flag something we've missed in our self-directed efforts.

Re: Delve – Fake Compliance as a Service

#244

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

In practice the only liability you might wind up with is whether you technically met the conditions for checking the box (instead of just checking falsely). But the liability for the overall consequences of not doing the actual job the checklist sets out to do tends to stay where it is.

Re: Delve – Fake Compliance as a Service

#245
post #228

Earlier quoted context omitted.

These days, nobody cares about legal liability, which is the likelihood of losing a lawsuit if there's a lawsuit, either. They only care about actual lawsuits against their company. They have noticed they're pretty rare and if the company's going to go under it's going to go under anyway, so might as well take the extra profits from not worrying about it

If someone checked one box, and the company goes under because of a lawsuit linked to not doing what this box said, then the individual who checked that box becomes personally liable of the damages done to the shareholders asset (the value of the company). You don't want to be in this position, really. And that's the whole point of compliance.

Maybe. If their boss told them to do it and their boss is the CEO, probably not. It's on the prosecutor to prove the individual employee committed a crime worthy of piercing the corporate veil.

Re: Delve – Fake Compliance as a Service

#246

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

I don't want to work wherever you do your thing. Software as a service means you provide a service, and you should take your responsibility to protect your customer's data super seriously. Compliance frameworks are one useful tool among many to support this effort. It helps us identify gaps, identify risks, make improvements. It also give us a way to communicate what we do to our partners. The behavior described in t…

I think the thing we are confusing here is "compliance" vs the "highest possible standards".

In theory these two terms mean the same thing.

In practice compliance can be detrimental to the cause and values that you and I both share seemingly.

> I am a founder, and my ambition includes meeting the highest possible standards for my customers.

Same here. This is why I don't care about "compliance" - because I take the privacy of my customers sacred. For example, that means no KYC on my customers. And compliance requires KYC.

Re: Delve – Fake Compliance as a Service

#247
post #99
post #91

Earlier quoted context omitted.

There are well-used tax money, then there are stupidly burned tax money on ie buying favors of some part of population before elections, financing blindly without any checks social security programs that get abused to no end, or simply plain old corruption. I love bringing Switzerland up to annoy most of western/northern Europeans since their success is so obvious and undeniable while going in very different directio…

It doesn't hurt that Swiss immigration is very difficult to get through, and they have all that Holocaust money no Nazi or dead Jewish victim is ever going to come claim.

Lol was expecting such brilliant comment, didn't disappoint. A true sign of an educated peer, who knows Swiss history and current economics and understands well how much that money that was put into private banks contributed in last decades (cue - zero). But maga-level of discussions never fail to mention this, with zero facts to back that up.

Immigration is tough, but managed way better than any EU country. Half of the world wants to come here, its a tiny place so it only makes sense they take only those who can find job in the country. Even though EU tried many times to strong arm them.

I don't think people understand the concept of neutrality, its fine only if it suits them. They accepted both jewish and other refugees, and also germans. Even when completely surrounded by axis. Nazi leadership repeatedly claimed in their writing how Swiss confederacy is the biggest principal enemy of nazi 3rd reich and must be eliminated at all costs. (Some) Swiss understood the danger much better than rest of European countries who tried to appease hitler. Also Swiss helped allies way more than they tolerated nazis and gave them ie access to Campione d'Italia to organize fight against axis. For further reading please check this starting point [1] if you actually care to understand history

[1] https://en.wikipedia.org/wiki/Henri_Guisan

Re: Delve – Fake Compliance as a Service

#248

Earlier quoted context omitted.

I've done a mix of SOC2, ISO27001 and PCI L1 for 3 different startups. 2 of them b2b. All certified 100% and fully compliant. The problem with the current frameworks is that the "controls" are so asinine and auditors so hard headed, that getting certified becomes a matter of "checking the box" . Particularly most of those frameworks REQUIRE maintaining so much paper red tape that make a 10 person startup want to kill…

Well, yes, but that's the point of many contracts, they are often designed to shift risk to parties that are better equipped to handle those risks. We run our app on GCP because as a 20 person company I don't want to be responsible for physical security and a million other risks. With ISO27001 or SOC 2, I have more information about the other party's ability to manage those risks than just taking their word for it. I…

> With ISO27001 or SOC 2, I have more information about the other party's ability to

... spend time and money to emulate the asinine requirements of outdated standards instead of actually making the product better and more secure.

> I'm trusting a third party auditor to vouch for them.

Like Delve?

Re: Delve – Fake Compliance as a Service

#249
post #79

Earlier quoted context omitted.

> thinking they wish to pay taxes Wellll this is not always the case. I have moved from a shithole country to a nice one and oh boy I am crying in gratitude every month that I pay taxes. Because it is every day that I can see my money working for me in the environment. But your point stands.

As a person who moved to a high-tax country I understand the sentiment. It's usually lost on the people who were always there paying those taxes. Somehow it often doesn't click that they get something in return. The same applies to all the audit and bureaucracy stuff. Does it do something? If you don't feel it does, does it mean it's not? I don't know really, but I hope somebody is rotating their key material as they…

> somebody is rotating their key material as they provided in their security posture

no. Because actually rotating keys and passing audit for rotating keys are two different things and oftentimes those two are unrelated.

Re: Delve – Fake Compliance as a Service

#250
post #91

Earlier quoted context omitted.

There are well-used tax money, then there are stupidly burned tax money on ie buying favors of some part of population before elections, financing blindly without any checks social security programs that get abused to no end, or simply plain old corruption. I love bringing Switzerland up to annoy most of western/northern Europeans since their success is so obvious and undeniable while going in very different directio…

Well let's see how good that Swiss Model would work as a big normal state, and not as a small tax haven, smaller than the State of Baden-Württemberg living off those surrounding states (siphoning up wealthy people, who got rich in those countries, and also their academics, that they didn't have to pay the education for)

Free Schengen movement that you germans fought so hard for. Its nice only if you siphon talent from the eastern part of EU and poorer parts of the world (where same brain drain logic and morality applies), but when people go to better places suddenly its an issue?
Post reply on HN