The damage this will do to the reputation of the SOC2 Security Attestation is incalculable.
Does SOC2 in general have a particularly high reputation? The only security compliance frameworks that have any particular reputation with me are the ones associated with the department of defense where the consequences range between a slap on the wrist warning or a small 5 figure fine to execution for espionage (which only ever happened for Julius and Ethel Rosenberg, though one could imagine there may have been mor…
We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
61–70 of 83 posts
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#62I've worked with SOC2-certified companies where employees would email each other plaintext credentials, publish them in Notion pages, etc. You cannot cure stupidity by "complying".
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#63> "We may receive compensation from vendors listed below. All recommendations are based on independent research." this + new HN account? couldn't be more obviously a competitor. not to defend delve, but can’t be pushing this like some noble effort with the goal of transparency also lol @ the fake realtime "just searched for" toasts on a setInterval in the bottom left.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#64Earlier quoted context omitted.
It's security theater. Friendly plug for Oneleet, who actually talked us out of getting it. We were considering getting certified, but it only really makes sense if your customers require you to have it.
What about enterprise customers / sales?
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#65Earlier quoted context omitted.
Does SOC2 in general have a particularly high reputation? The only security compliance frameworks that have any particular reputation with me are the ones associated with the department of defense where the consequences range between a slap on the wrist warning or a small 5 figure fine to execution for espionage (which only ever happened for Julius and Ethel Rosenberg, though one could imagine there may have been mor…
It's the universal de facto standard at least in North America, and nobody takes it especially seriously. About the best thing you could say for it is that it verifies that you're an actual company and not 3 raccoons in a trench coat. But if you're savvy about how you manage your auditors, you can get an attestation for 3 raccoons as well.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#66Earlier quoted context omitted.
What about enterprise customers / sales?
For enterprise sales you can get a SOC 2 Type I faster than any enterprise sale goes through. Typically, most enterprises are okay if you show them proof that you are "in the process" of getting the certification by showing them that you have signed up with one of those platforms (Delve, Vanta, etc.), so you would be okay to start only when you are about to close one of those enterprise deals.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#67> "We may receive compensation from vendors listed below. All recommendations are based on independent research." this + new HN account? couldn't be more obviously a competitor. not to defend delve, but can’t be pushing this like some noble effort with the goal of transparency also lol @ the fake realtime "just searched for" toasts on a setInterval in the bottom left.
I agree it came off a bit clickbaity, I'm sorry, Claude probably pushed it too far. but I don’t have an audience anywhere, no following on social, so I needed to ship something fast and make it engaging. the intent wasn’t just this Delve thing, the goal is to move away from it and turn it into a proper hub for compliance transparency over time. But i need a way to marketing this intially.
it’s been less than 24h, I built and pushed everything pretty quickly, so yeah there are rough edges. I’m already working through them and fixing things.
on the account being new, I get how that looks. I mostly use X and reddit, this is actually my first time posting on HN so I had to create an account.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#68" let r = ["Acme Corp", "CloudVault", "DataSync Pro", "NexGen AI", "SecureStack", "TrustLayer", "Vanta", "ComplianceIQ", "InfraSec", "ByteShield", "PipelineOps", "CyberNova", "TokenGuard", "ZeroTrust Labs", "Aether Security", "PrismData", "CloudArmor", "RiskLens", "AuditTrail", "ShieldIO"] , n = ["just checked", "searched for", "ran a scan on", "verified"] , a = ["San Francisco, CA", "New York, NY", "Austin, TX", "Lo…
on the "vibecoded" part, yeah I moved fast. this was built in under a day to get something out and see if people even care about this angle. that doesn’t mean the underlying data or direction is fake though.
the domain choice is just speed and availability, not some SEO master plan. if this turns into something real I’ll move it to a proper brand/domain.
and yeah I get why it looks like a growth/SEO play, but the actual goal is to push more transparency around these audits. if I just wanted traffic there are easier angles than going after something this niche and messy.
either way, appreciate you calling it out, some of it is fair and already being fixed.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#69We analyzed the leaked Delve audit reports and found some wild patterns: - The same auditor license number (PAC-FIRM-LIC-47383) appears in 487 out of 494 reports - Every Type II report has identical page numbers: Section 4 at page 30, tests at page 59, Section 5 at page 82 - 220+ "No exceptions noted" per report, across every single client - The system descriptions were copy-pasted from each company's marketing websi…
Genuinely curious: if you just need an independent audit report to check a box, do you really care how good a job the auditor did?
As a user/customer/potential victim? Yeah, you do.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#70Just know that alot of startups with all star founders are closer to delve than not. Its mostly marketing, "look at this MIT genius that noticed something about legacy xyz industry that no one else did" Truth is venture funds are allocating a limited pie of what is really societies capital to people that dont deserve it
> Truth is venture funds are allocating a limited pie This pie does not seem that limited recently.