Delve accused of deceiving customers with 'fake compliance' scheme

A recent anonymous Substack post accuses compliance startup Delve of misleading hundreds of customers into believing they were compliant with privacy and security regulations, potentially exposing them to criminal liability under HIPAA and substantial GDPR fines.
Delve, a Y Combinator-backed startup, announced a $32 million Series A last year at a $300 million valuation (the round was led by Insight Partners). On Friday, the startup attempted to refute the accusations on its blog, calling the Substack post "misleading" and claiming it contains a number of inaccurate statements.
The Substack post is attributed to "DeepDelver," who described themselves as a former employee of a Delve client.
DeepDelver described receiving an email in December stating that the startup had leaked a spreadsheet containing confidential client reports. Although Delve CEO Karun Kaushik reportedly assured customers in a follow-up email that they remained compliant and that no external party accessed sensitive data, DeepDelver said they and other clients grew suspicious.
"Having all been underwhelmed by the Delve experience and sensing something questionable, we decided to combine our resources and investigate together," they wrote.
Their conclusion? That Delve achieves its claimed status as the fastest platform by producing fake evidence, generating auditor conclusions for certification mills that rubber-stamp reports, and skipping major framework requirements while telling clients they have achieved full compliance.
DeepDelver elaborated on these claims, accusing the startup of supplying customers with fabricated evidence of board meetings, tests, and processes that never occurred, then forcing them to choose between adopting that fake evidence or performing largely manual work with minimal real automation or AI.
DeepDelver also alleged that nearly all of Delve’s clients appear to have used two audit firms, Accorp and Gradient, which they described as part of the same operation, based mainly in India with only a nominal U.S. presence.
Those firms, they said, are merely rubber-stamping reports created by Delve. As a result, DeepDelver claimed the startup inverts the normal compliance structure: "By generating auditor conclusions, test procedures, and final reports before any independent review takes place, Delve positions itself as both implementer and examiner. This is not a technicality; it is a structural fraud that invalidates the entire attestation."
Beyond accusing Delve of misleading its clients, DeepDelver said the startup is also helping those clients mislead the public by hosting trust pages that list security measures that were never actually implemented.
As for their own relationship with Delve, DeepDelver said their company has unpublished its trust page and no longer depends on the startup for compliance.
Delve responded to the accusations by stating that it does not issue compliance reports. Instead, it describes itself as an "automation platform" that ingests compliance-related information and then gives auditors access to that data.
"Final reports and opinions are issued solely by independent, licensed auditors, not Delve," the company said.
Delve also stated that its customers can choose to work with an auditor of their own selection or with one from Delve’s network of independent, accredited third-party audit firms. Those firms, the startup said, are "established firms widely used across the industry, including by other compliance platforms."
In response to the accusation of providing customers with fake evidence, Delve countered that it simply offers "templates to help teams document their processes in line with compliance requirements, as other compliance platforms do."
"Draft templates are not the same as 'pre-filled evidence'," the company said.
Delve added that it is "actively investigating any leaks" and is "still reviewing the Substack post."
TechCrunch sent an email requesting additional comment to the media contact address listed on Delve's website, but the email bounced. We have also contacted DeepDelver for further comment.
Related article
LiteLLM AI platform abandons partnership with startup Delve
LiteLLM, creators of a widely-used AI gateway trusted by millions of developers, has publicly stated it is ending its relationship with compliance startup Delve and will pursue its security certifications anew with a different provider and auditor. T
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Related Special Topic Recommendations
Comments (0)
0/500

A recent anonymous Substack post accuses compliance startup Delve of misleading hundreds of customers into believing they were compliant with privacy and security regulations, potentially exposing them to criminal liability under HIPAA and substantial GDPR fines.
Delve, a Y Combinator-backed startup, announced a $32 million Series A last year at a $300 million valuation (the round was led by Insight Partners). On Friday, the startup attempted to refute the accusations on its blog, calling the Substack post "misleading" and claiming it contains a number of inaccurate statements.
The Substack post is attributed to "DeepDelver," who described themselves as a former employee of a Delve client.
DeepDelver described receiving an email in December stating that the startup had leaked a spreadsheet containing confidential client reports. Although Delve CEO Karun Kaushik reportedly assured customers in a follow-up email that they remained compliant and that no external party accessed sensitive data, DeepDelver said they and other clients grew suspicious.
"Having all been underwhelmed by the Delve experience and sensing something questionable, we decided to combine our resources and investigate together," they wrote.
Their conclusion? That Delve achieves its claimed status as the fastest platform by producing fake evidence, generating auditor conclusions for certification mills that rubber-stamp reports, and skipping major framework requirements while telling clients they have achieved full compliance.
DeepDelver elaborated on these claims, accusing the startup of supplying customers with fabricated evidence of board meetings, tests, and processes that never occurred, then forcing them to choose between adopting that fake evidence or performing largely manual work with minimal real automation or AI.
DeepDelver also alleged that nearly all of Delve’s clients appear to have used two audit firms, Accorp and Gradient, which they described as part of the same operation, based mainly in India with only a nominal U.S. presence.
Those firms, they said, are merely rubber-stamping reports created by Delve. As a result, DeepDelver claimed the startup inverts the normal compliance structure: "By generating auditor conclusions, test procedures, and final reports before any independent review takes place, Delve positions itself as both implementer and examiner. This is not a technicality; it is a structural fraud that invalidates the entire attestation."
Beyond accusing Delve of misleading its clients, DeepDelver said the startup is also helping those clients mislead the public by hosting trust pages that list security measures that were never actually implemented.
As for their own relationship with Delve, DeepDelver said their company has unpublished its trust page and no longer depends on the startup for compliance.
Delve responded to the accusations by stating that it does not issue compliance reports. Instead, it describes itself as an "automation platform" that ingests compliance-related information and then gives auditors access to that data.
"Final reports and opinions are issued solely by independent, licensed auditors, not Delve," the company said.
Delve also stated that its customers can choose to work with an auditor of their own selection or with one from Delve’s network of independent, accredited third-party audit firms. Those firms, the startup said, are "established firms widely used across the industry, including by other compliance platforms."
In response to the accusation of providing customers with fake evidence, Delve countered that it simply offers "templates to help teams document their processes in line with compliance requirements, as other compliance platforms do."
"Draft templates are not the same as 'pre-filled evidence'," the company said.
Delve added that it is "actively investigating any leaks" and is "still reviewing the Substack post."
TechCrunch sent an email requesting additional comment to the media contact address listed on Delve's website, but the email bounced. We have also contacted DeepDelver for further comment.
LiteLLM AI platform abandons partnership with startup Delve
LiteLLM, creators of a widely-used AI gateway trusted by millions of developers, has publicly stated it is ending its relationship with compliance startup Delve and will pursue its security certifications anew with a different provider and auditor. T
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur





Home






