Close Menu
  • Home
  • AI
  • Art & Style
  • Economy
  • Entertainment
  • International
  • Market
  • Opinion
  • Politics
  • Sports
  • Trump
  • US
  • World
What's Hot

Treasury yields flat as traders prepare for March CPI release

April 10, 2026

Chinese President Xi issues ‘threat’ of Taiwan independence during first cross-strait opposition talks in 10 years

April 10, 2026

Chinese President Xi touts peace, points to global conflict in unusual meeting with Taiwanese opposition leader

April 10, 2026
Facebook X (Twitter) Instagram
Smart Breaking News on AI, Business, Politics & Global Trends | WhistleBuzz
Facebook X (Twitter) Instagram
  • Home
  • AI
  • Art & Style
  • Economy
  • Entertainment
  • International
  • Market
  • Opinion
  • Politics
  • Sports
  • Trump
  • US
  • World
Smart Breaking News on AI, Business, Politics & Global Trends | WhistleBuzz
Home » Delve accused of misleading customers with ‘false compliance’
AI

Delve accused of misleading customers with ‘false compliance’

Editor-In-ChiefBy Editor-In-ChiefMarch 21, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email


An anonymous Substack post published this week accuses compliance startup Delve of “falsely” convincing “hundreds of customers” that it complies with privacy and security regulations, potentially exposing those customers to “criminal liability under HIPAA and significant fines under GDPR.”

Delve is a Y Combinator-backed startup that announced last year that it would raise $32 million in Series A at a valuation of $300 million. (The round was led by Insight Partners.) On Friday, the startup sought to refute the accusations on its blog, saying Substack’s post was “misleading” and “contains a number of inaccurate claims.”

The Substack post is attributed to “DeepDelver,” who claims to work for the (now former) Delve client.

DeepDelver recalled receiving an email in December claiming that the company had “leaked spreadsheets containing confidential customer reports.” Although Delve CEO Karun Kaushik appeared to clarify in a subsequent email that the customers were compliant and that sensitive data would not be accessed by outside parties, DeepDelver said they and other customers had doubts.

“With a shared experience of being overwhelmed by the Delve experience and an overall sense that something fishy was going on, we decided to pool our resources and investigate together,” they wrote.

Their conclusion? That Delve “achieves its claim to be the fastest platform by creating false evidence, deriving auditor conclusions on behalf of rubber-stamp-reported certified factories, and skipping key framework requirements while telling customers it’s 100% compliant.”

DeepDelver looked into these claims in considerable detail, accusing the startup of providing customers with “fabricated evidence of board meetings, tests, and processes that never happened,” and forcing those customers to “choose between adopting fake evidence or doing the work mostly manually with little actual automation or AI.”

tech crunch event

San Francisco, California
|
October 13-15, 2026

DeepDelver also claimed that virtually all of Delve’s clients appear to go through two audit firms, Accorp and Gradient, which it said are “part of the same practice” and which operate primarily in India and have only a nominal presence in the United States.

They said those companies were just rubber-stamp reports created by Delve. As a result, DeepDelver said, the startup has “inverted” the usual compliance structure: “By producing auditor conclusions, testing procedures, and final reports before independent reviews occur, Delve assumes the role of both implementer and assessor. This is not a technicality. It is a structural fraud that invalidates the entire certification.”

In addition to accusing Delve of misleading customers, DeepDelver said the startup helps customers “mislead the public by hosting trust pages that contain security measures that are never implemented.”

DeepDelver said that while his company was discussing the issue with Delve, the startup “already sent us boxes of donuts to keep us happy.” Nevertheless, DeepDelver’s employers have likely made their trust pages private and are no longer relying on the company for compliance.

Delve responded to the accusations by saying it had not issued any compliance reports. Instead, it is an “automation platform” that captures compliance information and provides auditors with access to that information.

“Final reports and opinions will be issued only by independent licensed auditors and not by Delve,” the company said.

Delve also said that customers “can choose to work with an auditor of their own choice or with an auditor from Delve’s network of independent, certified third-party audit firms.” The company says these auditors are “established companies that are widely used across the industry, including by other compliance platforms.”

In response to accusations that it provides “fake evidence” to customers, Delve countered that it only provides “templates to help teams document processes in accordance with compliance requirements, like other compliance platforms.”

“Draft templates are not the same as ‘pre-populated evidence,'” the company said.

Delve added that it is “actively investigating any breaches” and is “still considering Substack.”

Following the initial Substack post, an X user named James Zhou said Delve had access to sensitive information such as employee background checks and stock vesting schedules. Dvuln founder Jamison O’Reilly shared details of what he said was a conversation O’Reilly had with Chou about “some major security holes in Delve’s external attack surface.”

TechCrunch sent an email seeking additional comment to the media contact address listed on Delve’s website. The email bounced, but then I received a calendar invite to a “Delve Demo” later this week. TechCrunch also reached out to DeepDelver for additional comment.

This post has been updated with additional information about the alleged security vulnerability provided by Jamieson O’Reilly and additional details regarding Delve’s response to TechCrunch.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Editor-In-Chief
  • Website

Related Posts

Is Anthropic restricting the release of Mythos to protect the internet? Or Anthropic?

April 9, 2026

Meta AI app rises to #5 in App Store after Muse Spark launch

April 9, 2026

Mercor, startup valued at $10 billion, has one-month grace period after data breach

April 9, 2026
Add A Comment

Comments are closed.

News

Iran War: What’s happening 42 days after the US and Israeli attack? |US-Israel war against Iran News

By Editor-In-ChiefApril 10, 2026

explainerA Pakistan-brokered ceasefire between the United States and Iran has gone into effect, but disputes…

US First Lady Melania Trump denies any relationship with Epstein in rare speech | Donald Trump News

April 9, 2026

April 9, 2026
Top Trending

Is Anthropic restricting the release of Mythos to protect the internet? Or Anthropic?

By Editor-In-ChiefApril 9, 2026

Anthropic announced this week that it has restricted the release of its…

Meta AI app rises to #5 in App Store after Muse Spark launch

By Editor-In-ChiefApril 9, 2026

Meta’s AI apps have seen a significant increase in installs since the…

Mercor, startup valued at $10 billion, has one-month grace period after data breach

By Editor-In-ChiefApril 9, 2026

Six months ago, Mercor was flying high after raising a whopping $350…

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Welcome to WhistleBuzz.com (“we,” “our,” or “us”). Your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://whistlebuzz.com/ (the “Site”). Please read this policy carefully to understand our views and practices regarding your personal data and how we will treat it.

Facebook X (Twitter) Instagram Pinterest YouTube

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Advertise With Us
  • Contact US
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
  • About US
© 2026 whistlebuzz. Designed by whistlebuzz.

Type above and press Enter to search. Press Esc to cancel.