Compliance startup Delve has been accused of misleading customers about their privacy and security compliance status after an anonymous whistleblower, identifying as “DeepDelver,” alleged the company used fabricated evidence, pre-generated auditor conclusions, and weak control implementations to help clients appear compliant with frameworks and regulations including HIPAA and GDPR. The allegations also said Delve worked with audit firms Accorp and Gradient to rubber-stamp reports and enabled customers to publish misleading trust pages, potentially exposing those organizations to regulatory, legal, and contractual risk.
Delve has publicly denied the claims, saying the allegations are misleading and inaccurate and that it operates as an automation platform rather than a report issuer. The company said final compliance opinions are produced only by independent licensed auditors, that customers can choose their own auditors or use firms from Delve’s network, and that the disputed materials are standard documentation templates rather than fake evidence. The dispute widened with additional claims that confidential client reports were leaked and that security weaknesses may have exposed sensitive company data to outside parties, raising broader questions about the integrity of Delve’s audit relationships and compliance attestations.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
LiteLLM announced it is ending its relationship with Delve and will redo its security certifications with competitor Vanta and an independent third-party auditor. The public move by a Delve customer marked a concrete business fallout from the whistleblower allegations and loss of confidence in Delve's compliance work.
Following the whistleblower allegations, Delve disabled the 'book a demo' feature on its website, and Insight Partners appeared to remove a post about its $32 million investment in the company. The changes suggested public damage control and possible investor distancing amid the controversy.
Follow-on claims amplified the dispute by alleging that Delve leaked confidential client reports and that security weaknesses allowed external parties to access sensitive company data. These claims expanded the story beyond compliance practices to possible data exposure.
Delve responded publicly by calling the claims misleading and inaccurate, saying it is an automation platform rather than a report issuer and that final compliance opinions are produced only by independent licensed auditors. The company also said its templates are standard documentation aids, customers may choose their own auditors or use firms in Delve's network, and it is investigating any referenced leaks.
An anonymous Substack post by a person identifying as 'DeepDelver' alleged that Delve falsely represented customers as compliant with privacy and security regulations by fabricating evidence, pre-generating auditor conclusions, and relying on audit firms to rubber-stamp reports. The allegations said these practices could expose customers to HIPAA and GDPR liability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.