Observed Signal · Apr 4, 2026 · Partnership · Source: techcrunch · Impact: 2/5 · Sentiment: Negative

YC severs ties with Delve amid compliance controversy

Executive Signal Summary

Y Combinator has removed Delve from its portfolio after a public controversy over the compliance startup’s practices. Delve’s COO Selin Kocalar posted on X that “YC and Delve have parted ways,” and the company no longer appears in YC’s directory. The dispute stems from anonymous Substack posts by a source calling itself “DeepDelver,” alleging Delve misled customers about privacy and security compliance, auto-generated reports, and relied on “certification mills.” Insight Partners briefly removed social posts referencing its investment. Delve’s executives (COO Selin Kocalar and CEO Karun Kaushik) deny the claims, say they hired a cybersecurity firm, accuse an attacker of exfiltrating internal data, and say they will offer re-audits and penetration tests to customers. TechCrunch contacted Y Combinator and DeepDelver for comment.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Signals reputational, security and trust risks in privacy/compliance vendors; investor and accelerator distancing may prompt buyers to increase due diligence on compliance providers.

SIGNAL RADAR

Track Y Combinator Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Delve is no longer listed in Y Combinator’s directory of portfolio companies and Delve’s page was removed from YC’s website.
  • Delve COO Selin Kocalar posted on X that “YC and Delve have parted ways.”
  • An anonymous Substack author using the handle “DeepDelver” accused Delve of misleading clients, auto-generating compliance reports, and skipping requirements.
  • Insight Partners temporarily deleted posts referencing its investment in Delve before restoring a primary blog post.
  • Delve’s CEO Karun Kaushik and COO Selin Kocalar say they hired a cybersecurity firm, accuse a malicious actor of data exfiltration, and are offering re-audits and penetration tests to customers.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Apr 4, 2026
Original Coverage Title: “Embattled startup Delve has ‘parted ways’ with Y Combinator | TechCrunch”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Privacy & ComplianceMar 21, 2026

Delve Accused of Fabricating Compliance Evidence

An anonymous Substack author using the handle “DeepDelver” accused Delve, a Y Combinator‑backed compliance automation startup, of convincing hundreds of customers they were regulatory‑compliant by providing fabricated evidence and pre‑generated auditor conclusions, potentially exposing clients to HIPAA and GDPR liability. The accuser alleges Delve generated false board minutes, tests and reports and used two audit firms — Accorp and Gradient — that allegedly rubber‑stamped those reports. Delve, which raised a $32M Series A led by Insight Partners at a reported $300M valuation, denied the claims in a blog post, saying it is an automation platform that supplies templates and auditor access but does not issue final reports. Additional posts on X and comments from security researcher Jamieson O’Reilly raised possible data‑exposure issues (employee background checks, equity schedules). TechCrunch updated its piece with emailed answers from DeepDelver, additional security details, and Delve’s responses; DeepDelver has promised follow‑up reporting.

Read assessment
Compliance & Security for Dev ToolsApr 11, 2026

Investigation: Delve Allegedly Faked SOC 2 Certifications

A Substack investigation alleges that Delve, a compliance automation platform, systematically manufactured false SOC 2 and ISO 27001 certifications by pre-populating audit evidence, generating test procedures internally, and sending finished packages to auditing firms that allegedly rubber-stamped results without independent verification. Named auditors in the report include Accorp, Gradient Certification, Glocert, and DKPC. The report says multiple companies — including venture-backed startups and at least one NASDAQ-listed firm — received these certifications, collectively handling millions of customer records. The article warns that automated compliance can become misleading when evidence is fabricated, and it outlines verification steps for buyers: request full SOC 2 Type II reports under NDA, verify the auditor on the AICPA directory, prefer Type II over Type I, look for exceptions in reports, and evaluate security independently. It also lists other compliance automation vendors (Vanta, Drata, Secureframe, Thoropass) and frames the issue as a systemic trust risk for developer tools.

Read assessment
Security & Compliance (AI/LLM)Mar 30, 2026

LiteLLM Drops Delve, Re-certifies Security With Vanta

LiteLLM, the provider of a widely used AI gateway, announced it is ending its relationship with compliance startup Delve and will re-run its security certifications with competitor Vanta and an independent third‑party auditor. The move follows a recent incident in which LiteLLM’s open‑source offering was compromised by credential‑stealing malware. Previously, LiteLLM had obtained two compliance certifications through Delve. Delve has been accused by an anonymous whistleblower of fabricating data and using lax auditors; Delve’s founder denies the claims and offered free re‑tests. LiteLLM CTO Ishaan Jaffer posted on X that the company will seek fresh certification and independent verification after the security breach and surrounding controversy.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.