Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

31–40 of 327 posts

Re: Delve – Fake Compliance as a Service

#31
post #12

How does this not reach the front page?

We just found out about this story and the submissions of it. It looks like it didn't make the front page because it set off HN's voting ring detector.

Mods didn't touch either thread except (1) we merged the duplicate discussions and (2) we rolled back the voting ring penalty so that the story would be on the frontpage.

This is in keeping with the principle that we moderate stories less, not more, when YC or a YC startup is part of the story. That's been the case since the beginning, and I've posted about it dozens of times: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu....

Re: Delve – Fake Compliance as a Service

#32
post #29

Notice how none of Delve's affiliates on X are posting anything after that Substack post. Probably their lawyers told them not to say anything further. What does that tell you about the scam that was unveiled? Not good.

The only thing it tells us is that they have received competent legal advice. Any counsel is going to tell you to shut up regardless of whether you are in the right or wrong.

Re: Delve – Fake Compliance as a Service

#33

there needs to be a fund with an ethos of "move slowly and do things accurately"

The fund is called customers. The independent regulator is called the AICPA. It really comes down to who is paying attention

SOC2 is as useful as a privacy policy at protecting your data. It’s all humans following human incentives.

Re: Delve – Fake Compliance as a Service

#35
post #31
post #12

How does this not reach the front page?

We just found out about this story and the submissions of it. It looks like it didn't make the front page because it set off HN's voting ring detector. Mods didn't touch either thread except (1) we merged the duplicate discussions and (2) we rolled back the voting ring penalty so that the story would be on the frontpage. This is in keeping with the principle that we moderate stories less, not more, when YC or a YC st…

[flagged]

Re: Delve – Fake Compliance as a Service

#37
This seems like a hit job by a competitor. Really ruthless.

> Two months ago, an email went out to a few hundred Delve clients informing them that Delve had leaked their audit reports, alongside other confidential information, through a Google spreadsheet that was publicly accessible.

Who leaked the audit reports? Who sent this email? Who is taking the time to write this analysis and kill the company?

In my opinion, the majority of the points in the article are no news. A compliance saas that offers templates for policies, all of them do. The AI is a chatbot, well who thought.

I think the main point is the collusion between delve and the auditors. Is the evidence for that clear?

Re: Delve – Fake Compliance as a Service

#38
post #31
post #12

How does this not reach the front page?

We just found out about this story and the submissions of it. It looks like it didn't make the front page because it set off HN's voting ring detector. Mods didn't touch either thread except (1) we merged the duplicate discussions and (2) we rolled back the voting ring penalty so that the story would be on the frontpage. This is in keeping with the principle that we moderate stories less, not more, when YC or a YC st…

Respectfully, I think there may be an issue with your voting ring detection, which is that if multiple people try to submit the same article and are redirected to an existing post and they upvote it, that might be setting off the voting ring alert. Can you check that?

I would imagine that's what happened here.

Re: Delve – Fake Compliance as a Service

#39
post #31

Earlier quoted context omitted.

We just found out about this story and the submissions of it. It looks like it didn't make the front page because it set off HN's voting ring detector. Mods didn't touch either thread except (1) we merged the duplicate discussions and (2) we rolled back the voting ring penalty so that the story would be on the frontpage. This is in keeping with the principle that we moderate stories less, not more, when YC or a YC st…

Respectfully, I think there may be an issue with your voting ring detection, which is that if multiple people try to submit the same article and are redirected to an existing post and they upvote it, that might be setting off the voting ring alert. Can you check that? I would imagine that's what happened here.

That's definitely not what happened here. The data would be quite different in that case.

Edit: 10% of the votes came from resubmissions of the URL. The other 90% came from other sources.

Re: Delve – Fake Compliance as a Service

#40
post #37

This seems like a hit job by a competitor. Really ruthless. > Two months ago, an email went out to a few hundred Delve clients informing them that Delve had leaked their audit reports, alongside other confidential information, through a Google spreadsheet that was publicly accessible. Who leaked the audit reports? Who sent this email? Who is taking the time to write this analysis and kill the company? In my opinion,…

Hit piece or not, the blatantly fraudulent behavior displayed by Delve is reprehensible.

And they didn't even try. Read this management assertion for one of the (known) affected companies:

> We have prepared the accompanying description of Cluely, Inc., system titled "Cluely is a desktop AI assistant to give you answers in real-time, when you need it." throughout the period June 27, 2025 - September 27, 2025(description), based on the criteria set forth in the Description Criteria DC Section 200 2018 Description Criteria for a Description of a Service Organization’s System in a SOC 2 Report (description criteria).

> The description is intended to provide users with information about the "Cluely is a desktop AI assistant to give you answers in real-time, when you need it." that may be useful when assessing the risks arising from interactions with Cluely, Inc. system, particularly information about the suitability of design and operating effectiveness of Cluely, Inc. controls to meet the criteria related to Security, Availability, Processing Integrity, Confidentiality and Privacy set forth in TSP Section 100, 2017 Trust Services Principles and Criteria for Security, Availability, Processing Integrity, Confidentiality and Privacy (applicable trust services criteria).

Post reply on HN