‹ Back to Home

A $300 Million Compliance Startup Is Accused of Faking the Compliance Reports It Sold to Hundreds of Companies

Delve — a Y Combinator-backed startup valued at $300 million — is accused of selling 'fake compliance' to hundreds of customers. The allegation: fabricated board meeting records, made-up audit evidence, and rubber-stamped certifications that left customers exposed to HIPAA and GDPR violations. Here's the full story.

Keerthika 6 min read 622
Follow on Google
Updated 5 months ago
Startups A $300 Million Compliance Startup Is Accused of Faking the Compliance Reports It Sold to Hundreds of Companies 6 min left Follow on Google
A $300 Million Compliance Startup Is Accused of Faking the Compliance Reports It Sold to Hundreds of Companies

TamilTech AI summary

Delve is a Y Combinator-backed compliance automation startup valued around $300 million that helps companies meet rules like HIPAA, GDPR, and SOC 2, but an anonymous former customer claims it sold fake compliance instead of the real thing. The accusation says Delve fabricated evidence such as board meetings and tests, worked with rubber-stamp auditors, and skipped major framework requirements while still telling clients they were fully compliant. That matters because companies that trusted those reports could face serious fines or even criminal liability if regulators dig in, and the startup’s public reply mostly called the post misleading without fully tackling the specific claims. A leaked spreadsheet of client reports apparently sparked customers to dig deeper and share what they found. If you use any compliance automation tool, independently verify your status with real auditors rather than trusting a certificate alone, because “compliance theater” can leave you exposed even when the paperwork looks fine.

  • Delve raised $32M at $300M valuation — accused of fabricating compliance evidence for hundreds of clients
  • Fake board meeting records, rubber-stamp auditors, skipped HIPAA/GDPR requirements alleged
  • Indian startups with US/EU clients should independently verify compliance — don't trust certificates alone

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

Imagine paying for cybersecurity compliance — and then finding out it was fake

This story is honestly wild. There's a Y Combinator-backed startup called Delve that raised $32 million at a $300 million valuation. Their product: helping companies comply with privacy and security regulations like HIPAA (US healthcare data law) and GDPR (Europe's privacy regulation). Companies pay Delve to get compliant. Except — according to a detailed anonymous accusation — Delve was giving them fake compliance all along.

If true, this is not just embarrassing. Companies that relied on Delve's compliance reports could face criminal liability under HIPAA and six-figure fines under GDPR. That's genuinely serious.

What is Delve and why does this matter?

Delve is what's called a compliance automation startup. The idea is simple and genuinely useful: compliance with regulations like SOC 2, HIPAA, ISO 27001, and GDPR is expensive, time-consuming, and requires a lot of documentation. Startups and mid-sized companies hate doing it manually. So tools like Delve promise to automate most of it — generating reports, tracking controls, collecting evidence — and make the process faster and cheaper.

Delve specifically positioned itself as the fastest compliance platform available. Y Combinator backing and a $300 million valuation from Insight Partners-led Series A suggests investors believed the pitch. Hundreds of companies signed up.

The accusation — in detail

An anonymous Substack post appeared this week, credited to someone calling themselves "DeepDelver" who described themselves as a former Delve customer. They said they chose to remain anonymous "out of fear for retaliation by Delve."

The accusations are specific and alarming. DeepDelver claims Delve:

Fabricated evidence of board meetings, tests, and processes that never happened. Compliance certifications require evidence that your company actually did certain things — held security reviews, ran penetration tests, documented processes. DeepDelver alleges Delve generated fake evidence for these.

Generated auditor conclusions on behalf of "certification mills" that rubber-stamped reports. The auditors who sign off on compliance reports are supposed to be independent. DeepDelver alleges Delve worked with auditors who would rubber-stamp whatever Delve submitted without proper verification.

Skipped major framework requirements while telling clients they were 100% compliant. Imagine going to a doctor for a full health checkup, but they only checked your blood pressure and told you everything is fine. Same idea — Delve allegedly skipped significant parts of the compliance frameworks while marking clients as fully compliant.

Customers were then forced to either adopt the fake evidence or do the real work manually — which was "mostly manual work with little real automation or AI" despite Delve's AI-powered promises.

How the accusation started — a spreadsheet leak

The story has a specific trigger. In December, Delve apparently sent out an email to customers saying that a spreadsheet with confidential client reports had been leaked. Delve CEO Karun Kaushik followed up assuring customers they were still in compliance and no external party had accessed sensitive data.

But several customers — already unsatisfied with Delve's service — became suspicious. DeepDelver writes: "Having the shared experience of being underwhelmed with the Delve experience, and having the overall sense that something fishy was going on, we decided to pool resources and investigate together."

What they found — according to their account — was the fake compliance operation described above.

Delve's response

Delve published a blog post calling the Substack post "misleading" and saying it "contains a number of inaccurate claims." A denial, but not a detailed point-by-point rebuttal of the specific allegations.

The startup has not publicly addressed the specific claims about fabricated board meeting evidence or rubber-stamp auditors. That's notable — when accusations are this specific, a vague "this is misleading" response doesn't really address them.

Why Indian companies and startups should care

Here's the India angle that matters. Indian startups increasingly handle data that falls under international compliance requirements. If you're a Bangalore SaaS startup with US healthcare clients, you need HIPAA compliance. If you have European customers, GDPR applies. Indian IT services companies working with global clients face these requirements constantly.

The compliance automation market — where Delve competes — has Indian-facing alternatives too. Companies like Scrut Automation, Sprinto, and Securiti.ai are Indian-founded compliance startups that have been growing in this space. The Delve scandal, if the allegations hold up, is actually an opportunity for these Indian alternatives to gain trust.

For Indian startup founders specifically: if you're using any compliance automation tool — not just Delve, but any of them — this story is a reminder to independently verify your compliance status. Don't assume that because a tool told you that you're compliant, you actually are. Ask your auditors to verify independently. The risk of a GDPR fine alone (up to 4% of annual global revenue) makes this worth the extra effort.

For Indian IT professionals at MNCs: if your company uses Delve for any compliance certifications, your legal and compliance team should be reviewing this story immediately and potentially seeking independent verification of your compliance status.

The broader problem — compliance theater

What DeepDelver describes has a name in the industry: compliance theater. It's when a company goes through the motions of compliance — collecting the right-sounding documents, getting a certificate — without actually implementing the security controls and processes that make compliance meaningful.

The problem is that for many companies, especially startups, compliance is a box-checking exercise driven by sales requirements rather than genuine security concern. A customer says "we need you to be SOC 2 compliant," and the startup needs the certificate to close the deal — fast. Tools that promise compliance in weeks rather than months are incredibly attractive in this environment. And that creates incentives to cut corners.

Delve's alleged behavior — if true — is an extreme version of this. But the pressure to make compliance faster and cheaper is real across the industry.

My honest take

The accusations against Delve are very specific. Fabricated board meeting records, rubber-stamp auditors, skipping framework requirements — these aren't vague claims, they're operational details that someone with insider knowledge would know. The anonymous sourcing is a legitimate concern, but the level of detail in the Substack post suggests this is more than just a disgruntled customer venting.

Delve's response — calling the post "misleading" without addressing the specific allegations — is not reassuring. When you've raised $32 million from reputable investors and serve hundreds of customers, you have the resources to respond more specifically if the allegations are genuinely false.

The investors (Y Combinator and Insight Partners) will be watching this closely. At a $300 million valuation, this company has serious downside risk if even a portion of the allegations prove true. Regulators — particularly in healthcare and data privacy — don't look kindly on compliance fraud.

For anyone using compliance automation tools: verify independently. The certificate alone means nothing if the controls behind it are fabricated.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,346 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story RentoMojo Hits Dalal Street With 19% Listing Pop: What It Means for Indian Renters
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications