Policy & Regulation
Delve faces new allegations over compliance audit evidence
Delve, a startup automating security certifications, faces fresh allegations from an anonymous whistleblower claiming the company faked evidence for customer compliance audits.
The anonymous whistleblower, who goes by the name DeepDelver, has doubled down on allegations that the startup was faking evidence for its customers’ compliance audits. This escalation comes just one day after Delve founder and CEO Karun Kaushik published a lengthy post on X denying the accusations. In response, the anonymous accuser posted again, releasing alleged receipts including a video and Slack messages to support the claims. DeepDelver also warned that there would be more posts like this one in the future.
Delve automates work for obtaining security certifications and proving compliance with laws like the General Data Protection Regulation (GDPR), the European Union’s data privacy framework. Founded by 21-year-old dropouts from the Massachusetts Institute of Technology (MIT), the startup graduated from the Y Combinator accelerator program in 2023. Last summer, the company raised a $32 million Series A round—an early-stage venture capital funding phase—led by investment firm Insight. This funding round followed just a few months after the startup’s $3 million seed round.
The controversy has intensified broader industry skepticism regarding the actual value of automated security certifications and compliance audits in protecting against security incidents. Many industry observers believe that security certifications, audits, and compliance in general are rather meaningless in terms of protecting against incidents. These concerns became particularly acute after LiteLLM, a customer of Delve, suffered a viral incident last week in which its open source project was infected with malware. LiteLLM had previously used Delve’s platform to obtain two security certifications, highlighting the gap between passing automated compliance checks and maintaining actual operational security. The incident has turned LiteLLM’s security situation into a viral case study, illustrating how a company can remain vulnerable to malware despite holding multiple active compliance certifications.
Why it matters
The allegations against Delve raise questions about the validity of automated compliance audits, especially after a customer suffered a malware infection despite holding certifications obtained through the platform. If compliance platforms can be shown to bypass actual security checks, the entire market for automated regulatory and security certifications could face a crisis of trust.