Imagine paying for cybersecurity compliance — and then finding out it was fake
This story is honestly wild. There's a Y Combinator-backed startup called Delve that raised $32 million at a $300 million valuation. Their product: helping companies comply with privacy and security regulations like HIPAA (US healthcare data law) and GDPR (Europe's privacy regulation). Companies pay Delve to get compliant. Except — according to a detailed anonymous accusation — Delve was giving them fake compliance all along.
If true, this is not just embarrassing. Companies that relied on Delve's compliance reports could face criminal liability under HIPAA and six-figure fines under GDPR. That's genuinely serious.
What is Delve and why does this matter?
Delve is what's called a compliance automation startup. The idea is simple and genuinely useful: compliance with regulations like SOC 2, HIPAA, ISO 27001, and GDPR is expensive, time-consuming, and requires a lot of documentation. Startups and mid-sized companies hate doing it manually. So tools like Delve promise to automate most of it — generating reports, tracking controls, collecting evidence — and make the process faster and cheaper.
Delve specifically positioned itself as the fastest compliance platform available. Y Combinator backing and a $300 million valuation from Insight Partners-led Series A suggests investors believed the pitch. Hundreds of companies signed up.
The accusation — in detail
An anonymous Substack post appeared this week, credited to someone calling themselves "DeepDelver" who described themselves as a former Delve customer. They said they chose to remain anonymous "out of fear for retaliation by Delve."
The accusations are specific and alarming. DeepDelver claims Delve:
Fabricated evidence of board meetings, tests, and processes that never happened. Compliance certifications require evidence that your company actually did certain things — held security reviews, ran penetration tests, documented processes. DeepDelver alleges Delve generated fake evidence for these.
Generated auditor conclusions on behalf of "certification mills" that rubber-stamped reports. The auditors who sign off on compliance reports are supposed to be independent. DeepDelver alleges Delve worked with auditors who would rubber-stamp whatever Delve submitted without proper verification.
Skipped major framework requirements while telling clients they were 100% compliant. Imagine going to a doctor for a full health checkup, but they only checked your blood pressure and told you everything is fine. Same idea — Delve allegedly skipped significant parts of the compliance frameworks while marking clients as fully compliant.
Customers were then forced to either adopt the fake evidence or do the real work manually — which was "mostly manual work with little real automation or AI" despite Delve's AI-powered promises.
How the accusation started — a spreadsheet leak
The story has a specific trigger. In December, Delve apparently sent out an email to customers saying that a spreadsheet with confidential client reports had been leaked. Delve CEO Karun Kaushik followed up assuring customers they were still in compliance and no external party had accessed sensitive data.
But several customers — already unsatisfied with Delve's service — became suspicious. DeepDelver writes: "Having the shared experience of being underwhelmed with the Delve experience, and having the overall sense that something fishy was going on, we decided to pool resources and investigate together."
What they found — according to their account — was the fake compliance operation described above.
Delve's response
Delve published a blog post calling the Substack post "misleading" and saying it "contains a number of inaccurate claims." A denial, but not a detailed point-by-point rebuttal of the specific allegations.
The startup has not publicly addressed the specific claims about fabricated board meeting evidence or rubber-stamp auditors. That's notable — when accusations are this specific, a vague "this is misleading" response doesn't really address them.
Why Indian companies and startups should care
Here's the India angle that matters. Indian startups increasingly handle data that falls under international compliance requirements. If you're a Bangalore SaaS startup with US healthcare clients, you need HIPAA compliance. If you have European customers, GDPR applies. Indian IT services companies working with global clients face these requirements constantly.
The compliance automation market — where Delve competes — has Indian-facing alternatives too. Companies like Scrut Automation, Sprinto, and Securiti.ai are Indian-founded compliance startups that have been growing in this space. The Delve scandal, if the allegations hold up, is actually an opportunity for these Indian alternatives to gain trust.
For Indian startup founders specifically: if you're using any compliance automation tool — not just Delve, but any of them — this story is a reminder to independently verify your compliance status. Don't assume that because a tool told you that you're compliant, you actually are. Ask your auditors to verify independently. The risk of a GDPR fine alone (up to 4% of annual global revenue) makes this worth the extra effort.
For Indian IT professionals at MNCs: if your company uses Delve for any compliance certifications, your legal and compliance team should be reviewing this story immediately and potentially seeking independent verification of your compliance status.
The broader problem — compliance theater
What DeepDelver describes has a name in the industry: compliance theater. It's when a company goes through the motions of compliance — collecting the right-sounding documents, getting a certificate — without actually implementing the security controls and processes that make compliance meaningful.
The problem is that for many companies, especially startups, compliance is a box-checking exercise driven by sales requirements rather than genuine security concern. A customer says "we need you to be SOC 2 compliant," and the startup needs the certificate to close the deal — fast. Tools that promise compliance in weeks rather than months are incredibly attractive in this environment. And that creates incentives to cut corners.
Delve's alleged behavior — if true — is an extreme version of this. But the pressure to make compliance faster and cheaper is real across the industry.
My honest take
The accusations against Delve are very specific. Fabricated board meeting records, rubber-stamp auditors, skipping framework requirements — these aren't vague claims, they're operational details that someone with insider knowledge would know. The anonymous sourcing is a legitimate concern, but the level of detail in the Substack post suggests this is more than just a disgruntled customer venting.
Delve's response — calling the post "misleading" without addressing the specific allegations — is not reassuring. When you've raised $32 million from reputable investors and serve hundreds of customers, you have the resources to respond more specifically if the allegations are genuinely false.
The investors (Y Combinator and Insight Partners) will be watching this closely. At a $300 million valuation, this company has serious downside risk if even a portion of the allegations prove true. Regulators — particularly in healthcare and data privacy — don't look kindly on compliance fraud.
For anyone using compliance automation tools: verify independently. The certificate alone means nothing if the controls behind it are fabricated.




Comments (0)
Be the first to comment!