Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

61–70 of 327 posts

Re: Delve – Fake Compliance as a Service

#61
post #33

there needs to be a fund with an ethos of "move slowly and do things accurately"

The fund is called customers. The independent regulator is called the AICPA. It really comes down to who is paying attention SOC2 is as useful as a privacy policy at protecting your data. It’s all humans following human incentives.

The value of SOC2 is that it does take some experience to be able to plausibly fake the evidence which weeds out people that truly have no idea what they're doing. It also provides a blueprint of the stuff you should be doing if you actually care.

But beyond that it's not worth a whole lot.

Re: Delve – Fake Compliance as a Service

#62
post #21

Earlier quoted context omitted.

Moderators didn't see it, and our policy is the precise opposite of this – see https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu... or, for more color, https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... . We've restored it to the front page now.

Yes, but your team claimed this set off "voting ring" behavior [0] and it was suppressed for nearly a day because of that. I am very curious how you determine what is, or is not, "voting ring" behavior. I believe Dang is responding in another thread about that. [0]: https://news.ycombinator.com/item?id=47457689

Obviously we don't publish how HN's voting ring detector works. If we did, it would quickly stop working.

What matters in this case is (1) it's a software penalty that has nothing to do with the content of a story, (2) moderators didn't touch the submissions or even know they existed, and (3) once we did know that they existed, we merged the threads and placed the story on the frontpage - that is, we went out of our way to give this story more attention, not less - in keeping with the principle explained here: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu....

Re: Delve – Fake Compliance as a Service

#63
There is a lot of serious allegations in here. But some of these complaints apply to most SOC 2 compliance services. For example: it points out that Delve provides pre-filled documents and encourages you to accept them as is. In my experience that is typical. I have seen companies just rubber stamp pre-created documents that describe IT processes that do not accurately reflect actual policy because the MBA[1] running the project didn't want to pull in IT and had no idea what any of it meant.

[1] No offense to MBA, just using it as a placeholder for: business stakeholder with no IT background.

Re: Delve – Fake Compliance as a Service

#65

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

When I worked in cybersecurity I had a similar realization. No one cared about security posture. They cared about insurance policies. People hired us to shift blame instead of improve security posture. this is not terribly different

Re: Delve – Fake Compliance as a Service

#67

There is a lot of serious allegations in here. But some of these complaints apply to most SOC 2 compliance services. For example: it points out that Delve provides pre-filled documents and encourages you to accept them as is. In my experience that is typical. I have seen companies just rubber stamp pre-created documents that describe IT processes that do not accurately reflect actual policy because the MBA[1] running…

Giving you template device management policies is one thing, it's a whole other thing to say you don't have to have board meetings and generating fake minutes.

Re: Delve – Fake Compliance as a Service

#68

There is a lot of serious allegations in here. But some of these complaints apply to most SOC 2 compliance services. For example: it points out that Delve provides pre-filled documents and encourages you to accept them as is. In my experience that is typical. I have seen companies just rubber stamp pre-created documents that describe IT processes that do not accurately reflect actual policy because the MBA[1] running…

Giving you template device management policies is one thing, it's a whole other thing to say you don't have to have board meetings and generating fake minutes.

100%, accepting pre-generated board meeting notes is egregious. This whole thing is awful and I am in no way defending it. The opposite, I think other compliance as a service companies also need to be scrutinized as well.

Re: Delve – Fake Compliance as a Service

#70

Compliance is something that no one ever wants and everybody hates. Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Thus providing compliance is really just paying someone to shift responsibility. The regulator can ask whether you are compliant. You can present certificate from Delve or someone else and that's the end of it.

Not a single person wakes up in the morning thinking they wish to pay taxes and rent and do the laundry the other stuff that has to be done. I would be nice to smoke weed and play video games all day and order the deliveries.

Some things just have to be done.

Post reply on HN