Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

H1 secures $40M from CVS, proving SaaS startups can still attract investment

Waymo’s newest robotaxi is Chinese-made, built to make money, and is now accepting riders

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Coders refuse to work without artificial intelligence – and it could bite them

    30 May 2026

    This chip startup just raised $135 million on a bet that AI’s biggest bottleneck isn’t computation — it’s memory

    29 May 2026

    Glean’s top line tops $300M as AI budget cut becomes its main selling point

    29 May 2026

    How long is Anthropic’s lease with SpaceX? Opinions vary.

    28 May 2026

    Why Google’s AI Can’t Type Google (or Anything)

    28 May 2026
  • Apps

    YouTube adds new podcast features, including an AI recommendation tool and ‘Auto Speed’

    30 May 2026

    A sneak peek at the new Siri app reveals Apple’s plans to tackle ChatGPT and more

    29 May 2026

    Bluesky embraces long-form content to tackle X articles

    29 May 2026

    Sesame, the AI ​​chat startup from the founders of Oculus, is launching its iOS app

    28 May 2026

    Airbnb-backed WeRoad raises $58 million to bring its group travel platform to the US

    28 May 2026
  • Crypto

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026
  • Fintech

    Last 24 hours to save up to $410 on your Disrupt 2026 ticket

    29 May 2026

    2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

    28 May 2026

    Robinhood now allows your AI agents to trade stocks

    28 May 2026

    Disrupt 2026 Early Bird ticket savings expire in 3 days

    27 May 2026

    Disrupt 2026 Early Bird ticket prices end May 29

    26 May 2026
  • Hardware

    Kiwibit’s artificial intelligence bird feeder is my new backyard friend

    29 May 2026

    Vertu wants CEOs to run companies from a foldable AI starting at $6,880

    29 May 2026

    Oura unveils its Ring 5 with a thinner, lighter design starting at $399

    28 May 2026

    The Dreamie alarm clock made me stop using my phone in bed

    26 May 2026

    6 kitchen gadgets that make adult life easier

    25 May 2026
  • Media & Entertainment

    YouTube will automatically flag videos with artificial intelligence

    28 May 2026

    Meta launches Instagram, Facebook and WhatsApp subscriptions, with more to follow, including AI plans

    27 May 2026

    Spotify now lets you view narrated magazine articles as well

    26 May 2026

    Spotify launches an audiobook creation tool powered by ElevenLabs

    22 May 2026

    New York City Mayor Zohran Mamdani Takes To Twitch To Chat With New Yorkers

    21 May 2026
  • Security

    Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

    30 May 2026

    Microsoft is under fire for threatening a security researcher with a criminal investigation

    29 May 2026

    A security flaw in prison payphone service Pay Tel exposed publicly the driver’s licenses of more than 300,000 callers

    29 May 2026

    Hackers are trying to steal Signal users’ backups in new wave of phishing attacks

    28 May 2026

    CrowdStrike and Google take down botnet used by hackers to target open source software developers

    28 May 2026
  • Startups

    H1 secures $40M from CVS, proving SaaS startups can still attract investment

    30 May 2026

    Cognition’s Scott Wu says AI coding agents shouldn’t replace humans

    29 May 2026

    How to apply to Startup Battlefield 2026, what you need before the June 8 deadline

    29 May 2026

    At Disrupt 2026: Databricks co-founder on what’s killing AI business deals

    28 May 2026

    Tech CEOs apparently suffer from AI psychosis

    28 May 2026
  • Transportation

    Waymo’s newest robotaxi is Chinese-made, built to make money, and is now accepting riders

    30 May 2026

    Slate Auto will announce pricing and take pre-orders for its EV on June 24

    29 May 2026

    Waymo dominates autonomous vehicle registrations as Tesla follows

    29 May 2026

    Slate Auto will begin taking orders for its affordable EV on June 24

    28 May 2026

    FAA orders SpaceX to investigate Starship V3 booster failure

    27 May 2026
  • Venture

    Corgi Announces $106M Raise at $2.6B Valuation — Double What It Was Worth 3 Weeks Ago

    30 May 2026

    In just 3 weeks, StrictlyVC is coming to Los Angeles

    29 May 2026

    Why Paris might be the most important AI city outside of Silicon Valley

    29 May 2026

    ClickHouse triples annual revenue to $250 million, charting a path to an IPO

    28 May 2026

    Triomics raises $22 million to bring oncology AI to cancer centers

    28 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Delve accused of misleading customers with ‘false compliance’
Security

Delve accused of misleading customers with ‘false compliance’

techtost.comBy techtost.com22 March 202605 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Delve Accused Of Misleading Customers With 'false Compliance'
Share
Facebook Twitter LinkedIn Pinterest Email

A anonymous substack post published this week blames the compliance startup Dig to “falsely” convince “hundreds of customers that they were in compliance” with privacy and security regulations, exposing those customers to “criminal liability under HIPAA and heavy fines under GDPR.”

Delve is a Y Combinator-backed startup that last year announced it would raise a $32 million series at a $300 million valuation. (The round was led by Insight Partners.) On Friday, the startup attempted to counter the allegations on her blogcalling the Substack post “misleading” and saying it “contains a number of inaccurate claims.”

The Substack post is credited to “DeepDelver”, who described himself as working on a (now former) Delve client. In response to questions via email from TechCrunch, DeepDelver said that they and their partners “have chosen to remain anonymous for fear of retaliation from Delve.”

In their post, DeepDelver recounted receiving an email in December that claimed the startup had “leaked a spreadsheet of confidential customer reports.” While Delve CEO Karun Kaushik apparently assured customers in a follow-up email that they were in compliance and no outside parties had access to sensitive data, DeepDelver said they and other customers had become suspicious.

“Having the shared experience of being overwhelmed by the Delve experience and having a general sense that something terrible was going on, we decided to pool resources and investigate together,” they wrote.

Their conclusion? That Delve “achieves its claim of being the fastest platform by producing bogus data, generating auditor conclusions on behalf of certification factories that report seals, and bypassing basic framework requirements, telling customers they’ve achieved 100% compliance.”

DeepDelver went into significant detail about these allegations, accusing the startup of providing customers with “fabricated evidence of board meetings, tests and processes that never happened,” then forcing those customers to “choose between adopting fake evidence or performing mostly manual tasks with little real automation or AI.”

Techcrunch event

San Francisco, California
|
13-15 October 2026

DeepDelver also claimed that nearly all of Delve’s clients appear to have gone through two auditing firms, Accorp and Gradient, which they described as “part of the same business,” one that operates primarily in India, with only a nominal presence in the United States.

These companies, they said, are simply reports created by Delve. As a result, DeepDelver said the startup is “inverting” the normal compliance structure: “By creating auditor conclusions, test procedures and final reports before any independent review, Delve places itself in the role of both implementer and examiner. This is not a technicality. It is a structural fraud that invalidates the entire certification.”

In addition to accusing Delve of misleading its customers, DeepDelver said the startup helps those customers “mislead the public by hosting trust pages that contain security measures that were never implemented.”

DeepDelver said that while their company was discussing its issues with Delve, the startup “sent us several boxes of donuts […] to keep us happy.” However, DeepDelver’s employer has reportedly taken down the trust page and no longer relies on the startup for compliance.

Delve responded to the accusations by saying that it does not issue compliance reports at all. Rather, it is an “automation platform” that ingests information about compliance and then provides auditors with access to that information.

“Final reports and opinions are issued solely by independent, authorized auditors, not by Delve,” the company said.

Delve also said that its customers “can choose to work with an auditor of their choice or choose to work with one of Delve’s network of independent, accredited third-party auditing firms.” These auditors, the startup said, are “established companies that are widely used across the industry, including other compliance platforms.”

Responding to accusations that it provides customers with “fake data,” Delve responded that it simply offers “templates to help teams document their processes against compliance requirements, just like other compliance platforms.”

“Drafts are not the same as ‘careful evidence,'” the company said.

Delve added that it is “actively investigating any leaks” and “still looking into Substack.”

When asked about Delve’s response, DeepDelver told TechCrunch that they were “confused by its laziness, clumsiness, and insolence.”

“They are trying to escape [of] they are held responsible by denying that they have ‘pre-populated evidence’, but call them ‘standards’, effectively shifting the onus to customers to adopt the ‘standards’ as they are, DeepDelver said.

They added that there are “some very serious allegations” that Delve didn’t look into at all: “The India category, the lack of AI (they only talk about ‘automations’) and the trust page (lol) containing controls that were never implemented.”

Apparently DeepDelver isn’t done with their review, as they promised, “Part II will follow soon.”

In addition, after the initial publication of Substack, an X-user named James Zhou he said were able to access sensitive information from Delve, such as employee background checks and stock vesting schedules. Dvuln founder Jamieson O’Reilly shared more details from what O’Reilly said was a conversation with Zhou about “several security gaps in Delve’s external attack surface.”

TechCrunch sent an email seeking additional comment to the media contact address listed on Delve’s website. The email bounced, but after this article was published, I received a calendar invite for a “Demo Demo” later this week.

This post was originally published on March 21, 2026. It has been updated with email responses from DeepDelver, additional information about alleged security vulnerabilities provided by Jamieson O’Reilly, and additional details about Delve’s response to TechCrunch.

Accused compliance customers Delve Dig false misleading
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe features powered by Gemini in Google Workspace that are worth using
Next Article Apps that distract you from the endless cycle of scrolling
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

30 May 2026

Microsoft is under fire for threatening a security researcher with a criminal investigation

29 May 2026

A security flaw in prison payphone service Pay Tel exposed publicly the driver’s licenses of more than 300,000 callers

29 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

30 May 2026

H1 secures $40M from CVS, proving SaaS startups can still attract investment

30 May 2026

Waymo’s newest robotaxi is Chinese-made, built to make money, and is now accepting riders

30 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Last 24 hours to save up to $410 on your Disrupt 2026 ticket

29 May 2026

2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

28 May 2026

Robinhood now allows your AI agents to trade stocks

28 May 2026
Startups

H1 secures $40M from CVS, proving SaaS startups can still attract investment

Cognition’s Scott Wu says AI coding agents shouldn’t replace humans

How to apply to Startup Battlefield 2026, what you need before the June 8 deadline

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.