Delve: when compliance "in a few clicks" turns out to be hot air
A 300-million-dollar startup accused of fabricating compliance certifications. Hundreds of companies potentially exposed. And a lesson the cybersecurity world stubbornly refuses to learn.

You are the founder of a B2B startup. Your enterprise prospects ask you for a SOC 2 Type II before they sign. An ISO 27001. Maybe a HIPAA if you touch healthcare. The classic process? Months of work, tens of thousands of euros, and enough documentation to make an archivist cry.
And then someone tells you about Delve. Backed by Y Combinator. 32 million dollars raised in Series A. Valued at 300 million. More than 1,700 clients claimed across 50 countries. The pitch: connect your tools, let the "agentic" AI do the work, get your certification in a few days.
Too good to be true? Apparently, yes.
How did the Delve affair break?
On 18 March 2026, a pseudonymous account, DeepDelver, published a devastating article on Substack titled "Fake Compliance as a Service." This was not a rant on a forum. It was a structured investigation, with screenshots, archived documents and an entire evidence file hosted on Mega.nz.
The author presents themselves as a former client. Not a competitor, not a journalist. A client who paid for the service and who, along with other companies in the same situation, decided to dig. Asked about the anonymity, they told TechCrunch they had chosen to stay masked out of fear of retaliation from Delve.
Delve is not an obscure startup. Founded in 2023 by Karun Kaushik and Selin Kocalar, two former MIT students, it had made itself the darling of the Y Combinator ecosystem, with the promise of landing a SOC 2 or an ISO 27001 faster and cheaper than anyone else thanks to "AI agents."
Their conclusion is unequivocal: Delve does not do automated compliance. Delve does automated compliance theater.
What exactly is Delve accused of?
DeepDelver's article is long, detailed and methodical. Here is the essence.
Reports generated before the client had even provided their data. The audit conclusions, the test procedures and the final reports were reportedly produced by Delve itself, before any independent review. Which, in the world of auditing, is called a total inversion of the process. When it is the audited platform that writes the auditor's report, you are no longer doing compliance. You are doing comedy.
Near-identical templates from one client to the next. Of 494 SOC 2 reports examined, 493 were reportedly practically identical, same wording, same grammatical mistakes. Absurd test values like "g," "sdf" or "Render" were reportedly still lying around in supposedly finalized reports. This is a long way from the revolutionary AI promised in the pitches.
Fabricated evidence. Minutes of board meetings that reportedly never took place. Employee training that was never delivered. Pre-filled vulnerability scans. The client had a choice: accept the templates as they were, or do the work manually, which canceled out the entire point of the platform.
Two audit firms for everyone. Nearly all clients were reportedly steered toward Accorp (for SOC 2) and Gradient (for ISO 27001), described as two linked entities operating mainly out of India, with a nominal presence in the United States. The role of these firms? To stamp reports already written by Delve.
Misleading Trust Center pages. The public portals displaying the security status of Delve's client companies reportedly listed controls as "live monitored" that had never been implemented. In plain terms: a security storefront with nothing behind it.
Does Delve have security flaws of its own?
As if the accusations of fictitious compliance were not enough, the affair took on an additional dimension. An X user named James Zhou claimed he had been able to access sensitive Delve information: employee background checks, stock vesting schedules. The founder of Dvuln, Jamieson O'Reilly, then detailed what he described as "several gaping holes in Delve's external attack surface."
The irony is almost too perfect. A company that sells compliance in IT security and that reportedly has security holes of its own in its own infrastructure. You cannot make this up.

What is Delve's answer to the accusations?
On 20 March, Delve published a blog post titled "Response to Misleading Claims." The defense rests on three arguments: Delve does not issue compliance reports, it is an automation platform. The auditors are independent and accredited. And the templates are "starting points" that the client is supposed to customize. Speaking to TechCrunch, the company insisted that final reports and opinions are issued solely by independent, licensed auditors and not by Delve, and that draft templates are not the same thing as pre-filled evidence.
CEO Karun Kaushik sent an email to clients calling the accusations "falsified" and suggesting that the article might be AI-generated.
DeepDelver's rebuttal, relayed by TechCrunch, was not long in coming: they say they were stunned by the laziness and the nerve of the response, noting that Delve calls "templates" what are in reality pre-filled evidence, and shifts the responsibility onto the clients who adopted them as they were. The startup claims it does not "issue" the reports, which is easy to argue if you define issuing as applying the final stamp. But when you generate the auditor's conclusions, the test procedures and the final report before any independent review, you are both the implementer and the examiner. And that is the exact inversion of what compliance is supposed to guarantee.
The most serious allegations went unaddressed: the ties with the Indian firms, the actual absence of AI (Delve talks about "automations" in its response, not AI), and the Trust Center pages displaying controls that were never implemented.
One telling detail: when DeepDelver and other clients started asking questions, Delve reportedly sent them boxes of donuts. The gesture would have been touching had it not been so laughable against the scale of the problem.
Did Delve steal open source code from Sim.ai?
The story did not stop there. In late March, DeepDelver published a part 2, this time with an accusation of an entirely different order: Delve had reportedly resold as its own a piece of open source software developed by another Y Combinator startup.
The tool in question is called SimStudio, a no-code platform for building AI agents, published by Sim.ai. According to DeepDelver, Delve forked it, meaning copied and modified it just enough, to present it to prospects under the name Pathways, as an in-house building block. But SimStudio is distributed under the Apache 2.0 license, which allows commercial use while requiring that the original author be credited, something Delve reportedly did not do.
The best part: Sim.ai was itself a Delve client. Its founder, Emir Karabeg, confirmed to TechCrunch that no licensing agreement existed between the two companies. Sim.ai was paying Delve, but Delve was not paying Sim.ai. Karabeg says he first consoled his friends at Delve after the initial publication, before cutting ties when he discovered this second affair.
A platform that sells compliance and documentary rigor, caught out on a simple open source attribution requirement: the symbolism is hard to miss.
Why did Y Combinator drop Delve?
The warning signs piled up fast. Delve disabled the "Book a demo" button on its site. Insight Partners, the fund that led the Series A, deleted its promotional post about the investment (the original is still visible via the Wayback Machine). And when TechCrunch tried to reach Delve through its media contact email, the message bounced back.
Then the axe fell. In early April 2026, Y Combinator removed Delve from its company directory and pushed it out the door. COO Selin Kocalar announced the news on X with a laconic formula: "YC and Delve have parted ways." For an accelerator that had made Delve a showcase for its own startups, the break says a great deal.
At the same moment, Delve hardened its tone. In a post titled "Delve sets the record straight on anonymous attacks," the company argues that an attacker bought the service under false pretenses in order to exfiltrate data and orchestrate a coordinated smear campaign, with the indicators pointing, in its view, to a malicious attack rather than a genuine whistleblower. In the same breath, Karun Kaushik concedes that the company grew too fast and failed to hold itself to its own standard, apologizes to clients, and offers free re-audits and penetration tests to all active accounts. Conceding that you grew too fast while pinning the affair on a lone hacker means defending two versions that cannot both be true at once.
When your accelerator wipes you from its directory and your investor cleans up its own tracks, it is usually not because everything is fine.
Why should the Delve affair worry you?
This is not just a story about an American startup that took shortcuts. The implications are concrete and serious.
For companies using Delve that handle health data, false HIPAA compliance can lead to criminal prosecution. Not fines. Criminal prosecution. For those operating in Europe, a GDPR compliance that is only for show exposes you to fines of up to 4% of annual worldwide revenue. And for everyone else, it is commercial credibility that is at stake. When an enterprise client discovers that your SOC 2 certificate was "generated" rather than audited, the contract usually does not survive the conversation.

Can compliance really be automated?
Beyond the Delve case, this affair illustrates a systemic problem that I keep pointing to in my work: compliance is a process, not a product.
You cannot "buy" conformity the way you buy a SaaS subscription. Conformity demands a deep understanding of your business context, your data flows, your real risks. It requires controls that are tailored, tested and maintained over time. And it rests on an independent audit, the word "independent" being the key to the whole structure.
When a platform promises to automate all of that "in a few days thanks to AI," you have to ask the uncomfortable question: what is actually being automated, compliance or the appearance of compliance?
I am not the only one who thinks so. Since the affair broke, risk governance specialists have argued that SOC 2 itself is collapsing into a checkbox. As Clarence Chio writes in Corporate Compliance Insights, the risk has always been that once speed and cost become a compliance product's main selling points, something eventually gives. And he restates the obvious: a document is only as good as the process behind it. His conclusion shifts the question entirely. The right thing to ask was never "does this vendor have a SOC 2?" but "does this vendor actually do what its SOC 2 claims?"
It is exactly the same pattern we see everywhere in the ecosystem: the pressure to "scale fast" pushes people to optimize the display rather than the substance. You are not protecting users' data. You are protecting the ability to sign contracts.
This is what I call, in Être en cybersécurité, "performative compliance": organizations that tick boxes to satisfy an audit, without ever embedding security into their operational culture. Delve merely industrialized that problem.
What should you do if your company used Delve?
If your company used Delve to obtain a certification, the path forward is straightforward.
Check your audit reports immediately. Compare them with those of other Delve clients if possible. If the structure, the wording and even the mistakes are identical, you have your answer. Have an independent audit carried out by a firm with no ties to Delve, Accorp or Gradient. Yes, it is going to be expensive. But that is the price of reality versus the price of illusion. Be transparent with your clients and partners: if you presented a Delve certificate as proof of conformity, it is better to get ahead of it than to wait for a prospect or a regulator to ask the question. And review your Trust Center pages. If they display controls you never implemented, remove them immediately.
The last word
Regulatory compliance is a pain. It is slow. It is expensive. And that is exactly why it has value. Because it represents a real, verifiable commitment to protecting the data of the people who trust you.
When someone promises to make that process fast, easy and cheap, the question is not "is this innovative?" The question is: what was cut to get there?
Delve wanted to disrupt compliance. So far, it has mostly demonstrated why compliance is not disrupted as easily as a meal delivery service.
The investigation continues: after part 2 on the alleged code theft, DeepDelver has announced further revelations. Delve, for its part, has left Y Combinator and watched its investors back away. Regulatory investigations could follow. In the meantime, the message is clear: a nice certificate is worth nothing if all that sits behind it is hot air. And donuts.
Sources
- DeepDelver, 18 March 2026, "Delve: Fake Compliance as a Service, Part I" (Substack)
- DeepDelver, March 2026, "Delve: Fake Compliance as a Service, Part II" (Substack)
- TechCrunch, 22 March 2026, "Delve accused of misleading customers with 'fake compliance'"
- TechCrunch, 1 April 2026, "The reputation of troubled YC startup Delve has gotten even worse"
- TechCrunch, 4 April 2026, "Embattled startup Delve has 'parted ways' with Y Combinator"
- Inc., 23 March 2026, "The Delve Scandal: A Y Combinator Darling Just Got Hit With a Bombshell Fraud Accusation"
- Corporate Compliance Insights, 21 May 2026, "SOC 2 Is Broken. The Delve Scandal Is Showing Us How"
- Delve, 20 March 2026, "Response to Misleading Claims"
Frequently asked questions
What is Delve and what is it accused of?
Delve is an automated compliance startup backed by Y Combinator, valued at 300 million dollars. It is accused by a former client, DeepDelver, of fabricating security certifications: reports generated before the data was even provided, identical templates from one client to the next, and pre-filled evidence.
Why is this described as an "inversion" of the audit process?
Because the audit conclusions, the test procedures and the final reports were reportedly written by Delve itself before any independent review. The audited platform becomes both the implementer and the examiner, the exact opposite of what compliance is supposed to guarantee.
Did Y Combinator cut ties with Delve?
In early April 2026, Y Combinator removed Delve from its company directory. COO Selin Kocalar announced on X that "YC and Delve have parted ways." Insight Partners, the investor that led the Series A, had already deleted its promotional post about the deal.
Did Delve really take open source code?
A second DeepDelver investigation accuses Delve of forking SimStudio, an open source tool from Sim.ai, and reselling it as its own under the name Pathways, without honoring the Apache 2.0 license that requires crediting the original author. Sim.ai founder Emir Karabeg confirmed to TechCrunch that no licensing agreement existed, and that Sim.ai was itself a paying Delve client.
What are the risks for a company that used Delve?
False HIPAA compliance can lead to criminal prosecution, a GDPR compliance that is only for show exposes you to fines of up to 4% of annual worldwide revenue, and the discovery of a certificate that was "generated" rather than audited destroys your commercial credibility in front of enterprise clients.
What should I do if my company used Delve?
Check and compare your audit reports, have an independent audit carried out by a firm with no ties to Delve, Accorp or Gradient, be transparent with your clients and partners, and remove from your Trust Center pages any control that was never implemented.
What is the deeper lesson to draw from the Delve affair?
That compliance is a process, not a product. Conformity requires controls that are tailored, tested and maintained, and above all an independent audit. A promise to automate everything "in a few days thanks to AI" should make you ask the question: what was cut to get there?
Sources & methodology
- DeepDelver, 18 March 2026, 'Delve: Fake Compliance as a Service, Part I' (Substack)
- DeepDelver, March 2026, 'Delve: Fake Compliance as a Service, Part II' (Substack)
- TechCrunch, 22 March 2026, 'Delve accused of misleading customers with fake compliance'
- TechCrunch, 1 April 2026, 'The reputation of troubled YC startup Delve has gotten even worse'
- TechCrunch, 4 April 2026, 'Embattled startup Delve has parted ways with Y Combinator'
- Inc., 23 March 2026, 'The Delve Scandal: A Y Combinator Darling Just Got Hit With a Bombshell Fraud Accusation'
- Corporate Compliance Insights, 21 May 2026, 'SOC 2 Is Broken. The Delve Scandal Is Showing Us How'
- Delve, 20 March 2026, 'Response to Misleading Claims'

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
