Delve Faces Allegations of Misleading Customers on Compliance Practices
Delve, a Y Combinator-backed compliance automation startup, has been accused of misleading hundreds of customers into believing they were fully compliant with privacy and security regulations, potentially exposing them to legal risks under HIPAA and GDPR. An anonymous Substack post by a former client, credited to ‘DeepDelver,’ alleges that Delve produced fabricated evidence, generated auditor conclusions prematurely, and bypassed major framework requirements. The post claims Delve provided fake documentation of processes and board meetings, while pressuring clients to adopt this evidence instead of performing genuine compliance work. Additionally, the post alleges that audit firms linked to Delve, primarily based in India, merely rubber-stamped these reports. Delve responded by stating it does not issue compliance reports but rather provides an automation platform for clients and auditors, who remain independent and licensed. The company also clarified that templates offered to clients are meant to guide documentation and are not pre-filled evidence. Further concerns arose after a user on X, James Zhou, reportedly accessed sensitive internal information, highlighting potential security gaps. The situation remains under scrutiny as DeepDelver promises additional follow-up posts and Delve continues investigating the claims.
