Observed Signal · Mar 30, 2026 · Partnership / Vendor Change · Source: techcrunch · Impact: 2/5 · Sentiment: Negative
LiteLLM Drops Delve, Re-certifies Security With Vanta
LiteLLM, the provider of a widely used AI gateway, announced it is ending its relationship with compliance startup Delve and will re-run its security certifications with competitor Vanta and an independent third‑party auditor. The move follows a recent incident in which LiteLLM’s open‑source offering was compromised by credential‑stealing malware. Previously, LiteLLM had obtained two compliance certifications through Delve. Delve has been accused by an anonymous whistleblower of fabricating data and using lax auditors; Delve’s founder denies the claims and offered free re‑tests. LiteLLM CTO Ishaan Jaffer posted on X that the company will seek fresh certification and independent verification after the security breach and surrounding controversy.
Security breach and vendor swap affect trust and compliance for a widely used AI gateway; relevant to companies and developers that integrate LLM infrastructure but not industry‑shifting for AdTech broadly.
Track LiteLLM Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- LiteLLM publicly ended its compliance relationship with Delve.
- LiteLLM will re-certify security controls using Vanta and an independent third‑party auditor.
- LiteLLM’s open‑source version was recently hit by credential‑stealing malware.
- Delve has been accused by an anonymous whistleblower of generating fake data and using auditors that rubber‑stamped reports; Delve’s founder denies the allegations and offered free re‑tests.
- LiteLLM CTO Ishaan Jaffer announced the vendor change on X.
Connected Companies & Entities
2 Entities mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
LiteLLM Malware Exposes Delve Compliance Claims
A severe supply‑chain malware infection was discovered in LiteLLM, a popular open‑source project that provides unified access to many AI models. Research scientist Callum McMahon of FutureSearch found the malware after his machine shut down following a LiteLLM download; the malicious code entered via a dependency, stole login credentials and propagated to other packages. Security firm Snyk reported LiteLLM downloads as high as 3.4 million per day and noted the project had ~40K GitHub stars. LiteLLM displayed SOC 2 and ISO 27001 certifications obtained through Delve, an AI‑powered compliance startup now accused elsewhere of misleading customers about conformity (Delve denies the allegations). LiteLLM says it is investigating with Mandiant and performing a forensic review; CEO Krrish Dholakia declined to comment on Delve’s role. The incident highlights risks in dependency management and limits of certification-based assurances.
Investigation: Delve Allegedly Faked SOC 2 Certifications
A Substack investigation alleges that Delve, a compliance automation platform, systematically manufactured false SOC 2 and ISO 27001 certifications by pre-populating audit evidence, generating test procedures internally, and sending finished packages to auditing firms that allegedly rubber-stamped results without independent verification. Named auditors in the report include Accorp, Gradient Certification, Glocert, and DKPC. The report says multiple companies — including venture-backed startups and at least one NASDAQ-listed firm — received these certifications, collectively handling millions of customer records. The article warns that automated compliance can become misleading when evidence is fabricated, and it outlines verification steps for buyers: request full SOC 2 Type II reports under NDA, verify the auditor on the AICPA directory, prefer Type II over Type I, look for exceptions in reports, and evaluate security independently. It also lists other compliance automation vendors (Vanta, Drata, Secureframe, Thoropass) and frames the issue as a systemic trust risk for developer tools.
Delve Accused of Fabricating Compliance Evidence
An anonymous Substack author using the handle “DeepDelver” accused Delve, a Y Combinator‑backed compliance automation startup, of convincing hundreds of customers they were regulatory‑compliant by providing fabricated evidence and pre‑generated auditor conclusions, potentially exposing clients to HIPAA and GDPR liability. The accuser alleges Delve generated false board minutes, tests and reports and used two audit firms — Accorp and Gradient — that allegedly rubber‑stamped those reports. Delve, which raised a $32M Series A led by Insight Partners at a reported $300M valuation, denied the claims in a blog post, saying it is an automation platform that supplies templates and auditor access but does not issue final reports. Additional posts on X and comments from security researcher Jamieson O’Reilly raised possible data‑exposure issues (employee background checks, equity schedules). TechCrunch updated its piece with emailed answers from DeepDelver, additional security details, and Delve’s responses; DeepDelver has promised follow‑up reporting.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
