Apps & Consumer
LiteLLM drops compliance partner Delve after security incident
LiteLLM is switching its security compliance vendor to Vanta after a credential-stealing malware incident and allegations of misconduct against its previous partner, Delve.
LiteLLM, an AI gateway startup that provides a tool developers use to access multiple large language models, is ditching compliance startup Delve. The company, which makes a popular AI gateway used by millions of developers, has publicly announced that it will redo its security certifications with another company and auditor. On Monday, LiteLLM Chief Technology Officer Ishaan Jaffer posted on X that the company will use Vanta, a compliance automation platform and competitor to Delve, to re-certify. Jaffer also stated that LiteLLM will find its own independent third-party auditor to verify its compliance controls.
The decision to switch compliance vendors follows a security incident last week, when LiteLLM’s open source version fell victim to “horrific credential-stealing malware.” Prior to this security failure, LiteLLM had obtained two security compliance certifications by hiring Delve. These certifications are intended to verify that a company has procedures in place to minimize potential incidents. Following the malware compromise, LiteLLM is choosing to redo the entire certification process. The company is taking these steps to ensure its compliance controls are thoroughly and independently verified.
The vendor change also comes amid serious allegations against Delve. The compliance startup has been accused of “misleading its customers about their true compliance” by “generating fake data” and “using auditors that rubber-stamped their reports.” Delve’s founder has denied these allegations of misconduct and offered free re-tests and audits to all of its customers. However, this denial encouraged an anonymous Delve whistleblower to double down. Over the weekend, the whistleblower released alleged receipts to support the claims of misconduct, prompting LiteLLM to vote with its feet and transition to Vanta to secure its certifications.
Why it matters
This move highlights the critical importance of third-party security verification for AI infrastructure providers, as LiteLLM seeks to restore trust after a significant security failure. It also underscores the growing scrutiny on compliance automation startups and the validity of the security certifications they issue to tech companies.