Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

301–310 of 327 posts

Re: Delve – Fake Compliance as a Service

#301

Lots of companies affected this, what blows my mind is when VC's were funding this how come no due-diligence was done on something as important as compliance. who even tries to scam on compliance like it's a known way to get caught.

They're "AI Native". This maps with how the entire "AI revolution" has felt to me - like no due diligence has been done to validate the output of anything, and instead just the "AI" stamp is enough to satisfy investors.

I get where you are coming from, but still claiming "AI native" shouldn't change anything when it comes to due diligence. I agree tho the 'AI stamp" is letting a lot of things through.

Re: Delve – Fake Compliance as a Service

#302

Lots of companies affected this, what blows my mind is when VC's were funding this how come no due-diligence was done on something as important as compliance. who even tries to scam on compliance like it's a known way to get caught.

I genuinely think this is because the elites like the MIT dropouts that started this company think the rest of us observers are stupid. They have a billboard with the copy "Compliance before you tell your parents you dropped out of MIT"

Yeah that's a wild billboard lmao. btw 99% of MIT people are no different then the rest they just worked hard or paid hefty amounts, I have lots of friends that went there. Nonetheless the 1% are geniuses. Also saying MIT dropouts instantly makes your story credible, it's a funny concept. I'm starting to feel like an MIT dropout these days.

Re: Delve – Fake Compliance as a Service

#305

For those looking for help with SOC2 compliance, I had a good experience with another YC company, Vanta. That was some years ago so not sure if anything has changed since then but I would recommend checking them out.

Vanta misses a lot of things to cover iso27001, and clearly misunderstand this norm at times.

The integrations are what makes it really useful, but elements are not correctly connected between them, or are too limited to be useful : for instance access review information tells you who is an "admin", but ignores the various permissions levels (e.g: on GitHub, you can be an admin of a repository) which exists on each platforms. So let's say you are using rbac access policies, then all vanta integrations are meaningless because you cannot check roles, and you have to build /buy another tool...

Their policy builder is a bad joke, slow, incomplete, and you lose all automations when you need to change even one word. The default policies are quite bad anyway, very long and complex, pushing you to use forms which are not integrated into the platform, so again you have to maintain a duplicate system elsewhere.

Generally speaking, there's no help to keep in sync policies with processes and proofs, and let me tell you it goes out of sync very fast!

Re: Delve – Fake Compliance as a Service

#306
post #3

Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.

FWIW I think the 30u30 to fraud pipeline is overstated. There are 600 people on the American Forbes 30u30 list every year (it's "30 under 30 each year in each of 20 categories"), with 20ish notable instances of fraud, so maybe a quarter percent of the people on the 30u30 list will later become famous for fraud.

I think the pipeline is not really about the 30u30 list as a whole, but about the cover of the magazine, which I feel has had a very high rate of fraud.

Re: Delve – Fake Compliance as a Service

#308
post #98

Delve seems clearly scummy, but dear god the author's company was also engaging in fraud with their own customers and just hoping to skate by. "The trouble starts when you look at the answers Delve’s AI provided. Based on what your Delve policies claim, the questionnaire AI answers questions stating you have an MDM, had a 200 hour pen-test performed, and do regular backup restoration simulations. Tens of questions ar…

> Like, no, former Apple PM who learned about an interconnection queue from ChatGPT last week, you are not going to fix the grid, and even moreso you can't "just do X and ask forgiveness later", not in electricity.

Just bribe the WECC auditors!

Re: Delve – Fake Compliance as a Service

#310

Earlier quoted context omitted.

> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…

Not really, and I kinda envy you that you haven't really worked up close with compliance-related people. A lot of compliance is basically corruption - while in country A, you might fall out of a window if you don't buy from the right people at 10x prices, but in 'civilized' country B, you have to buy from vendor X (who has the necessary paperwork), at 10x prices, or you wont be able to sell the product - and there ar…

Sonarqube did not flag public fields as a security issue by default the last time I used it — however it has found several real vulnerabilities for me before.
Post reply on HN