Observed Signal · Apr 11, 2026 · Investigation · Source: DEV Community · Impact: 3/5 · Sentiment: Negative

Investigation: Delve Allegedly Faked SOC 2 Certifications

Executive Signal Summary

A Substack investigation alleges that Delve, a compliance automation platform, systematically manufactured false SOC 2 and ISO 27001 certifications by pre-populating audit evidence, generating test procedures internally, and sending finished packages to auditing firms that allegedly rubber-stamped results without independent verification. Named auditors in the report include Accorp, Gradient Certification, Glocert, and DKPC. The report says multiple companies — including venture-backed startups and at least one NASDAQ-listed firm — received these certifications, collectively handling millions of customer records. The article warns that automated compliance can become misleading when evidence is fabricated, and it outlines verification steps for buyers: request full SOC 2 Type II reports under NDA, verify the auditor on the AICPA directory, prefer Type II over Type I, look for exceptions in reports, and evaluate security independently. It also lists other compliance automation vendors (Vanta, Drata, Secureframe, Thoropass) and frames the issue as a systemic trust risk for developer tools.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Allegations describe systemic compliance fraud in automation platforms used across developer tools; this undermines trust in SOC 2/ISO badges, poses supply-chain security risk for any service that accesses source code or customer data, and creates actionable verification steps for buyers.

SIGNAL RADAR

Track Substack Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • A Substack investigation alleges Delve systematically manufactured false SOC 2 and ISO 27001 certifications for clients.
  • Alleged methods include pre-populating audit evidence, generating internal test procedures, and routing finished packages to auditors for rubber-stamping.
  • Auditing firms named in the investigation include Accorp, Gradient Certification, Glocert, and DKPC.
  • Multiple companies, including venture-backed startups and at least one NASDAQ-listed firm, reportedly received these certifications and collectively handled millions of customer records.
  • The article recommends verification steps: obtain full SOC 2 Type II reports under NDA, verify auditors via the AICPA firm directory, prefer Type II over Type I, and evaluate security beyond badges.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Apr 11, 2026
Original Coverage Title: “Fake SOC 2 and ISO 27001 Certifications Are Spreading Across Dev Tools”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Privacy & ComplianceMar 21, 2026

Delve Accused of Fabricating Compliance Evidence

An anonymous Substack author using the handle “DeepDelver” accused Delve, a Y Combinator‑backed compliance automation startup, of convincing hundreds of customers they were regulatory‑compliant by providing fabricated evidence and pre‑generated auditor conclusions, potentially exposing clients to HIPAA and GDPR liability. The accuser alleges Delve generated false board minutes, tests and reports and used two audit firms — Accorp and Gradient — that allegedly rubber‑stamped those reports. Delve, which raised a $32M Series A led by Insight Partners at a reported $300M valuation, denied the claims in a blog post, saying it is an automation platform that supplies templates and auditor access but does not issue final reports. Additional posts on X and comments from security researcher Jamieson O’Reilly raised possible data‑exposure issues (employee background checks, equity schedules). TechCrunch updated its piece with emailed answers from DeepDelver, additional security details, and Delve’s responses; DeepDelver has promised follow‑up reporting.

Read assessment
Privacy & ComplianceApr 4, 2026

YC severs ties with Delve amid compliance controversy

Y Combinator has removed Delve from its portfolio after a public controversy over the compliance startup’s practices. Delve’s COO Selin Kocalar posted on X that “YC and Delve have parted ways,” and the company no longer appears in YC’s directory. The dispute stems from anonymous Substack posts by a source calling itself “DeepDelver,” alleging Delve misled customers about privacy and security compliance, auto-generated reports, and relied on “certification mills.” Insight Partners briefly removed social posts referencing its investment. Delve’s executives (COO Selin Kocalar and CEO Karun Kaushik) deny the claims, say they hired a cybersecurity firm, accuse an attacker of exfiltrating internal data, and say they will offer re-audits and penetration tests to customers. TechCrunch contacted Y Combinator and DeepDelver for comment.

Read assessment
Large Language Models (LLM) & AIMar 26, 2026

LiteLLM Malware Exposes Delve Compliance Claims

A severe supply‑chain malware infection was discovered in LiteLLM, a popular open‑source project that provides unified access to many AI models. Research scientist Callum McMahon of FutureSearch found the malware after his machine shut down following a LiteLLM download; the malicious code entered via a dependency, stole login credentials and propagated to other packages. Security firm Snyk reported LiteLLM downloads as high as 3.4 million per day and noted the project had ~40K GitHub stars. LiteLLM displayed SOC 2 and ISO 27001 certifications obtained through Delve, an AI‑powered compliance startup now accused elsewhere of misleading customers about conformity (Delve denies the allegations). LiteLLM says it is investigating with Mandiant and performing a forensic review; CEO Krrish Dholakia declined to comment on Delve’s role. The incident highlights risks in dependency management and limits of certification-based assurances.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.