Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

281–290 of 327 posts

Re: Delve – Fake Compliance as a Service

#281

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

That’s a separate excercise in most cases. Obtaining the cert is it’s in excercise and not sticky a security excercise

Re: Delve – Fake Compliance as a Service

#282

Earlier quoted context omitted.

It has to work in with a bunch of organisations who are doing (or attempting to do) ITIL 4 and are fairly insistent on things like consistency across ITSM platforms. The things is, you know and I know, ITIL is like sex in high school. Everyone says they're doing it loads, everyone says they know all about it, everyone says they're really good at it, but no-one is any good at it, no-one knows anything about it, and no…

This is hilarious. I had to steal this for my Twitter post.

Xitter with the X pronounced like in Mandarin.

Re: Delve – Fake Compliance as a Service

#283
post #138

Earlier quoted context omitted.

Trust me, you can lie and get away with it if you go through YC and dropped out of a top university. Garry Tan blocked me on X for pointing this out. It's a big club, and you ain't in it! Fortunately, some of the old-YC spirit seems to be alive here on HN still.

They likely barely had a product when they applied to YC. It's more interesting as to why this wasn't discovered (if it is even true) when they were raising their Series A.

Well that's what I'm saying. The problem is if you went through YCombinator there's very little diligence when raising your Series A. I've seen it happen for a couple of startups that I was tangentially involved in.

Re: Delve – Fake Compliance as a Service

#284
post #205

Earlier quoted context omitted.

>I had no idea this story existed and woke up to claims that I was obviously* suppressing it. To be fair, it seems you’re saying the submission was being suppressed, just not intentionally. Lots of props of course for transparency and reboosting the story

When people use the word "suppressed" they usually mean that we were personally intervening to do something suppressive. This being the internet, they say that with supreme confidence whether it's true or not. For example, the comment I was referring to, which was the first one I saw, said "It is being suppressed by @dang" ( https://news.ycombinator.com/item?id=47457010 ). You can't get more personal, definitive, or…

Okay but my comment here said that it was being suppressed (intentionally?).

In my other comment, I actually did not mean to write “it is being suppressed by dang” but rather “it is being suppressed @dang”… Because my impression is that that alerts you somehow? I may be wrong about this.

Please give your long-time readers the benefit of the doubt. I was correct that it was being suppressed. I'm also very thankful for your moderation of the site. I know you do a lot of hard work on that front.

Re: Delve – Fake Compliance as a Service

#285

Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing? I can hardly imagine that I'd even be interested in taking a look at the domain. It's just... so mundane. Or maybe the alpha-type overachievers don't care about the domain but the opportunity?

I also think this has to do a lot with storytelling and message in the company. Do you have someone that can motivate and etc. Many things are boring under the hood to someone and interesting to someone else, but a good story about why and how is what makes a difference.

Re: Delve – Fake Compliance as a Service

#287
post #95

Earlier quoted context omitted.

> Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Somehow I doubt that you are in the B2B/Enterprise space. When you're pitching demos and you hear from people "we really wish we could buy your product but we can't because Finance won't approve the expenditure unless you get XYZ-123", and you hear that over and over again because that is the…

I think we are confusing something here. > we really wish we could buy your product but we can't because Finance won't approve the expenditure unless you get XYZ-123 So you are not dreaming about XYZ-123 compliance, you are dreaming about being able to make sales to corporate entities. This is a subtle semantic difference. > there are founders who wake up in the morning wishing Wishing juicy corporate customers. Not…

I think you're the one confusing something here. Wishing for "juicy corporate customers" - why? You might as well say that you wake up in the morning wishing for an ocean of money to flood your accounts and become Scrooge McDuck. I'm not sure what site you think you're on, but this is Hacker News, you know, the site of YC where PG wrote his famous essay telling people, "make something people want"? https://paulgraham.com/good.html

Well guess what people told you they wanted? They wanted XYZ-123. And you're not going to find success until you learn to get obsessed about making something people want.

Re: Delve – Fake Compliance as a Service

#288

80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.

There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.

Small businesses very much like to gamble with the box checking.

Re: Delve – Fake Compliance as a Service

#289
post #179

Earlier quoted context omitted.

Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?

Last time I went through SOC 2 we talked to our auditor about this. His view was that there are and basically always have been auditors/companies that will sign off on anything without verifying it if you're paying them. The rest of the industry knows who they are though. If you are taking things seriously and hire an auditor who does, that's one of the things that they look at when you're reviewing the reports from…

From the article, OP dealt with this.

> But what do you do when the enterprise you are selling to asks you to show that pen-test report (which you never did despite paying for it, because Delve told you a pentest-tools.com vulnerability scan sufficed)? When they ask for your most recent risk assessment, do you just screenshot Delve’s pre-fabricated assessment and pray nobody will pay attention?

> It was that point where the realization sank in. We knew we messed up. We were unable to answer most questions honestly without jeopardizing the deals we were trying to land. We scrambled to get things done the proper way outside of Delve, in an effort to pretend to know what we were doing, but it ended up simply being too much work to get done quickly enough to save things.

Re: Delve – Fake Compliance as a Service

#290
SOC2 is quite a racket on its own so I'm not surprised to read this industry creates players like this.

I hope that with LLMs, answering security questionnaires will be much less time consuming for companies and less would opt out to get a full blown SOC2 cert. But it will probably play the other way.

Post reply on HN