Lots of companies affected this, what blows my mind is when VC's were funding this how come no due-diligence was done on something as important as compliance. who even tries to scam on compliance like it's a known way to get caught.
They're "AI Native". This maps with how the entire "AI revolution" has felt to me - like no due diligence has been done to validate the output of anything, and instead just the "AI" stamp is enough to satisfy investors.
Delve – Fake Compliance as a Service
301–310 of 327 posts
Re: Delve – Fake Compliance as a Service
#302Lots of companies affected this, what blows my mind is when VC's were funding this how come no due-diligence was done on something as important as compliance. who even tries to scam on compliance like it's a known way to get caught.
I genuinely think this is because the elites like the MIT dropouts that started this company think the rest of us observers are stupid. They have a billboard with the copy "Compliance before you tell your parents you dropped out of MIT"
Re: Delve – Fake Compliance as a Service
#303Re: Delve – Fake Compliance as a Service
#304Re: Delve – Fake Compliance as a Service
#305For those looking for help with SOC2 compliance, I had a good experience with another YC company, Vanta. That was some years ago so not sure if anything has changed since then but I would recommend checking them out.
The integrations are what makes it really useful, but elements are not correctly connected between them, or are too limited to be useful : for instance access review information tells you who is an "admin", but ignores the various permissions levels (e.g: on GitHub, you can be an admin of a repository) which exists on each platforms. So let's say you are using rbac access policies, then all vanta integrations are meaningless because you cannot check roles, and you have to build /buy another tool...
Their policy builder is a bad joke, slow, incomplete, and you lose all automations when you need to change even one word. The default policies are quite bad anyway, very long and complex, pushing you to use forms which are not integrated into the platform, so again you have to maintain a duplicate system elsewhere.
Generally speaking, there's no help to keep in sync policies with processes and proofs, and let me tell you it goes out of sync very fast!
Re: Delve – Fake Compliance as a Service
#306Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.
FWIW I think the 30u30 to fraud pipeline is overstated. There are 600 people on the American Forbes 30u30 list every year (it's "30 under 30 each year in each of 20 categories"), with 20ish notable instances of fraud, so maybe a quarter percent of the people on the 30u30 list will later become famous for fraud.
Re: Delve – Fake Compliance as a Service
#307Re: Delve – Fake Compliance as a Service
#308Delve seems clearly scummy, but dear god the author's company was also engaging in fraud with their own customers and just hoping to skate by. "The trouble starts when you look at the answers Delve’s AI provided. Based on what your Delve policies claim, the questionnaire AI answers questions stating you have an MDM, had a 200 hour pen-test performed, and do regular backup restoration simulations. Tens of questions ar…
Just bribe the WECC auditors!
Re: Delve – Fake Compliance as a Service
#309Re: Delve – Fake Compliance as a Service
#310Earlier quoted context omitted.
> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…
Not really, and I kinda envy you that you haven't really worked up close with compliance-related people. A lot of compliance is basically corruption - while in country A, you might fall out of a window if you don't buy from the right people at 10x prices, but in 'civilized' country B, you have to buy from vendor X (who has the necessary paperwork), at 10x prices, or you wont be able to sell the product - and there ar…