📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

$300M YC Startup Accused of Being Completely Fake

Anthony Sistilli17:21

Transcription

10 years ago, if you told me you got into MIT, then dropped out because you got into Y Combinator for your hot AI startup, and then made Forbes 30 under 30, I would have said, "Wow, you're going places." And well, I'd still say you're going places today, except that place is now jail instead of listing your company on the NASDAQ in a couple years from now.

Because surprise surprise, a YC backed company named Delve, who raised $32 million at a valuation of 300 mil last year with both founders being Forbes 30 under 30 is under a ton of scrutiny because, well, they've allegedly been faking their compliance.

Basically, Delve's whole pitch is they take something really hard for startups to get, which is sock 2 compliance, and they promise that in days as opposed to the normal audits, which could sometimes take up to a couple months. And while they claim they do that by having cuttingedge AI agents that eliminate compliance busy work and that they're trusted by 1,500 different fast growing companies, this anonymous beast of a Substack article that dropped a couple days ago seems to say otherwise.

And while the author is anonymous, calling themselves Deep Delver, they claim that they're an employee at a company who was one of Delve's clients, and that they saw firsthand how Delve enables you to do things like create precreated fake board meeting notes, fake risk assessments, security incident simulations, and employee evidence that was copy pasted from client to client.

And just so I don't have to keep saying allegedly in this video, everything I'm going to talk about and have talked about is from this report. While they provide evidence, nothing has actually been proven in a court of law and therefore everything I'm talking about is completely alleged and these are sort of just what the accusations are.

Now, this whole story actually starts a couple months ago and it only got this crazy recently. But in December, a spreadsheet with around 600 Delve paying customers got leaked where you could find a link to every single one of their compliance report. And when it leaked and these Google links were actually public, someone took a look into it and found, wow, a lot of these look kind of similar, almost like they're the exact same report with company names copy and pasted to change things up.

Not only did the spreadsheet drop, but someone went around emailing all the customers of Delve with this report saying, "Hey dude, I think your [ __ ] might not be as secure as you think it is." And yeah, it made a little splash on LinkedIn and a couple people responded, but no one really took this too seriously.

And you have to understand this is such a big deal. Not just because this one YC company was allegedly committing fraud, because every single startup that got their Sock 2 security compliance stamp from them. If these allegations are true, well, those companies are also liable.

And because I'm not a security expert to sort of verify what all this means, I actually talked to someone who does this for a living. Mike Kim, who is the founder of Minecraft, who does something similar to what Delve does, except for real, explained the situation of how startups could be liable extremely well.

>> So 2 is basically a report card on saying how well you're doing on a cyber security posture and it's a way to basically help enterprises to know that you're not going to be negligent with your data because technically management has to sign off on that report. You are liable for it. Likely that your contracts get invoided. I'm pretty sure there are companies that just signed it because they didn't know and they wanted to get the report really quick, but like there's a likelihood that your name is on that report.

>> So, what did Delve actually do that was that bad? Are they just copy and pasting reports and submitting it to auditors? The whole idea of sock 2 is the auditor has to be independent of your company, which means the person that audits your company and actually prepares you for that audit should be two separate entities. And to even do those audits, you have to be a real accredited firm, which Delve is not.

But in classic founder mode fashion, they allegedly found a way to circumvent that. Delve achieves its claim of being the fastest platform by producing fake evidence, generating auditor conclusions on behalf of the certification mills that rubber stamp reports, and skipping major framework requirements while telling clients they have achieved 100% compliance. Their US-based auditors are Indian certification mills operating through empty US shell companies and mailbox agents.

The audit process is supposed to be fully independent. The way that it works, that structure is actually surprisingly sophisticated. There's actually a states, Montana, that actually allows you to create an US-based CPA license even if you're international. So, that's like the loophole that they took advantage of to basically rubber stamp everything.

Just to make it clear, it's from the report and the allegations associated with that report. But, yeah, it's it appears that the auditors never looked at anything. And then it also appears that Dell also didn't look at it. So basically instead of delve going in, finding all the shitty cyber security rules that you're breaking, getting you to fix them, and then getting you ready to submit to a real auditor, the substack article saying they pretty much generate the conclusions that the auditor would have to generate themselves on behalf of your company submits them to these fake auditors that are Indian companies running through US shell corporations. And those US shell corporations just rubber stamp your sock 2 compliance and send you on your way.

And these are some pretty serious accusations. If you're an enterprise company trusting a startup to deal with this super sensitive data that Sock 2 exists to help you have peace of mind about, you've sort of just been lied to and you have no idea how your data is being used in these startups.

And when all of this was circulating around 2 months ago before this Substack article dropped, you would think that they would sort of get their [ __ ] together and address what was happening. And well, they did, but they did it in the exact fashion that you would expect two people that are Forbes 30 under 40 to do it.

Basically, Delve's CEO Karun sent an email to all their customers with the subject line, "Email with falsified claims sent to Delve customers." Yesterday, an AI generated email was sent to Delve customers with falsified claims and an alert about a publicly accessible internal audit automation document. And while it's not from a credible source, in the spirit of transparency, we want to proactively address the situation.

And of course, he says things like, "I personally assure you we're in compliance and there's no impact to the validity of your audit report." When we found out, we immediately reviewed the situation and determined that the document had been shared with public visibility. It contained highle customer information and links to their draft audit report. And upon further review, they determined that in human error, the document aka that spreadsheet was being made publicly available and it was a mistake. That document didn't really mean much because it just contained high-level customer information and links to draft audit reports and they resolved it by just revoking access to that document immediately.

And the key thing here is they mentioned that no external party gained access to the Delve platform integrations or any databases where sensitive data reside. And as the Substack points out that spreadsheet was kind of a database in itself. Not only did the reports contain private data, but also signatures and architectural diagrams of literally their actual customers. Like literal architectural diagrams of how their customers entire core systems work and their signatures.

And as if the email wasn't enough, they then did what I consider to be absolutely hilarious. They put out this sort of vague blog post on their website addressing the claims without really addressing the claims. Because remember, nobody really knew they were going through all this other than the customers they had that got that email with the spreadsheet link.

So in this entire article, not only does it not really address all the rumors that were going around, they sort of just used it to be like, "Oh, you know, here's like a reassuring summary of how we work, it wasn't enough to just sort of do that and have it out there." They also had to throw in the most salesy [ __ ] you could [ __ ] think of. Like literally maybe a fifth of the article is talking about the actual security process they do. And even there, they try to weave in every single little sales tactic they can. Like here's how the Delve team verifies your actual audit information. But also, you should know companies normally spend weeks back and forth and they missed deal deadlines. Here's how Bland AI avoided this issue and unlocked $500,000 in contracts by using Dell and eventually you scroll down far enough and the whole thing is just, by the way, here's this case study we did with this company that shows how good we are. And here's how other companies helped save 143 hours in manual compliance work and unlock $2.3 million in enterprise contracts. I mean, come on. You came in worried that we were doing some shady [ __ ] but we kind of showed you why we're the best and we help you save all this time.

On the topic of time, promising sock 2 compliance in a couple of days is kind of already outlandish.

>> Their messaging is compliance in days. To even review a sock report, it takes like a day or two. With Microoft, if we're hyper efficient and the company is super focused, at least 2 to 3 weeks to like literally explain to the auditors what what's being done, we always say prepare for at least 2 to 3 months because there's going to be things that we find.

And even if we were to just stop here, this shit's already kind of crazy. But it gets even worse when you look into how they prepare those audits in the first place. First of all, as soon as you get access to their platform, you would think that means the first thing you're going to do is solve all your like security issues. And then maybe you could provide a trust page for your customers that shows how you handle all this. But no, even before you do any real work, you can go into the trust tab and activate and publish a trust page for your company. You'd think it'd probably be pretty minimal with everything failing at first since you haven't done any work, but nope. You immediately get a fully populated trust page that would have you believe you're running the most secure company on Earth. And sure enough, if you click on one of these random companies sock 2 icon on their landing page, it takes you to trust.dev.co where it walks you through all the crazy [ __ ] that they are doing to be sock 2 compliant and all the things that they done and are compliant about. You can literally generate one of these as soon as you get access to the platform. It's literally a madeup list of security measures of which more than half are not implemented or even supported or addressed by Delve's process and platform.

And it gets worse because when you actually do decide to do some work and become compliant, it's broken down into these four parts, which is policies, team, tech, and company. Policies are all pre-created, and Delve recommends adopting them as they are. Unless you spend a week manually revising them to be accurate, you'll have inaccurate policies full of false promises. Every single one of Dell's policy claims to have measures in place that Delve's process and platform don't even address themselves. And remember, companies that help you get compliant so you can pass these audits are supposed to actually go into your system and find the things that are wrong with you, not give you a checklist that their own platform themselves doesn't even check whether you're compliant or not with.

And when it comes time to say that you've implemented these policies, a lot of it is just sitting there seeing their things and just clicking accept. You do the risk assessment by adopting the 10 default risks. You accept Delve's prefabricated fake board meeting minutes. Like part of getting so compliant, I guess, involves having board meeting minutes where you show you've talked about risk assessments and they just generate fake ones for you. Darn. Delve promised me during sales we wouldn't have to do board meetings. Luckily, we can just hit accept on these pre-created fake board meeting notes.

One of the real concerns they had was that they knew it would never pass a real audit. But we were explicitly told Dev never failed a single audit in the past and auditors have never flagged a single issue with their processes. And on top of that, they kept on reminding them that they sold to Fortune 500 companies using the exact same process. Companies like Lovable and Bland. It's like if you had to take a driving test and you found some driving school that was like, "Listen, bro. If you take your driving test at this really remote location where our driving instructors are, you'll never fail a single test. In fact, all our students have passed. And don't worry, some of the biggest drivers in the world have used our process. So, you know, we're legit."

I don't know how that doesn't raise red flags, but again, a lot of their customers are these startups. And I'm not trying to say they're all YC startups, but a lot of YC startups that just want to start selling to enterprise as fast as possible. So, paying 10 to 20 grand to do this as quickly as possible and getting that stamp on your landing page so you can land some major deals. I mean, I can see why people weren't exactly asking questions here.

And even when it came to auditing team members, well, Delve was like, "Don't worry about it. If you forgot to onboard existing employees before the observation period started, that's okay. It wouldn't jeopardize the audit. And later on, they realized dev just marks all checks as passing for employees who never did anything. So people that didn't actually do their background checks, every employee had identical fake boilerplate evidence. And at the end of the observation period, despite knowing you didn't do any real work and adopted fake evidence left and right, you get this wonderful message informing you that you passed your sock 2 audit with flying colors and that you just received an incredibly high quality report. Congratulations.

When demo day rolls around, you're now ready to raise an insane seed round at a crazy valuation cuz you just got all these enterprise companies signed up cuz you're sock 2 compliant. Except it wasn't that easy for a lot of companies. Because while some enterprise companies will look at your sock 2 report from Delve and just be like, "Okay, I guess it's fine." Apparently, there exists other enterprise companies that want to take a bit of a deeper look into what your compliance report says. They'll want you to prove and defend what you're claiming.

What do you do when those pesky enterprise companies send a questionnaire? You drop it into Delve's questionnaire AI and it answers around 70% of the questions for you and you fill out the remaining 30% manually. But the trouble starts when you look at the answers that their AI provides. Sometimes the AI will just tell your customer that you have had a 200hour pen test performed and that you do regular backup restoration simulation. And if the majority of the companies haven't actually done that, I guarantee you they probably don't even know what that means. And for some companies, that's when the realization sinks in. They realize they messed up. Unable to answer a lot of these compliance answers honestly without jeopardizing the deal. And when they brought it to Delve, customer support kept promising to get back to us, then ended up just giving them nonsense solutions that felt chat GBD generated or at times even ghosting them.

And that's what I love about the new wave of startup founders that are 18 and 19 years old. A lot of the times they don't have real actual technical prowess or business acumen to fall back on. They fall back to what got them into YC or that investment money in the first place, which is storytelling. aka when they announced they were going to leave Delve, one of the founders got on a call and kept reiterating how unique it was that they were going through this and that companies like Lovable and Bland coast through all security reviews with their Delve reports that practically all Fortune 500 companies just accept the reports blindly.

And well, now that all this is starting to get to the forefront of people's minds and that Substack article went viral, people are finally starting to talk about it. I worked for a YC startup that is Sock 2 and ISO compliant with Dell. It's definitely [ __ ] With basically no security measures in place at time, we managed to speedrun compliance in weeks by uploading complete garbage into their portal. I've been waiting for them to get hit with a massive lawsuit. Not surprised to see this is trending right now. Forbes 30 under 30 never misses.

How could this level of blatant fraud make it past a VC firm led by this executive team? And look, if you have a $32 million funded company and you've run compliance sock 2 reports for all these Fortune 500 companies, part of you has to ask yourself, why aren't we just doing this legit? Like, this is clearly a giant ticking time bomb if the allegations are true. Why can't we just sort of like, you know, leave founder mode behind and start doing things honest?

And well, I just maybe don't think they had time to really think about all that cuz they were super busy. I mean, someone's got to be taking the Forbes 30 under 30 interview and posting about it on LinkedIn. And how else would the founder be able to have time to go to the Ford versus Ferrari movie track?

You >> might be wondering, why is a compliance company standing on the Ford versus Ferrari track?

Yeah, I think that's probably exactly what a lot of people are looking at this thinking about now. And yeah, you have some other YC companies coming out and supporting Delve like just PSA. We use Delve. Delve does exactly what every other company does. They provide a checklist and help you automate your compliance. We are still responsible for our security, not Dell. Industry is shady if and this anon is 100% a competitor.

And look, if your best defense is, well, everyone else is doing it, so we did it as well. And at the end of the day, like we told you you guys should be compliant and you're the one that clicked the little check box on our platform that said that you do all these different security measures and we just submit the audit to the same place everyone else is doing it. So, we're not really liable for this. If that is the best defense that you have, especially when your primary customers are these like YC companies, these 18, 19 year olds that don't even know what Sock 2 is, and they're likely to just take that YC deal for Delve, click through the platform, and try to get compliant in a couple days so they can start landing enterprise clients. Well, it doesn't matter if the onus was completely on them. Your platform is like the place that enables this kind of shady behavior.

Appreciate that YC is a family and you feel obligated to defend them, but Drada and Vanta, who are other YC companies doing so compliance, are definitely not farming out prefilled findings for rubber stamps from some Indian shell company. Bro, they definitely are. Like, I don't even know what to think about this anymore. It's just such a cluster [ __ ] back and forth.

And when it comes time for my startup to do sock 2 compliance, I'm just going to hire a real [ __ ] compliance firm that will look at all the [ __ ] we're doing, tell us if it's not really sock 2 compliant and tell us what we have to do and change to get sock 2 compliance. Something like Mike Kim's micro or do something like what Jesse said, not using a company to actually drive the process, but getting someone to actually help us do the compliance thing and then finding our own auditor oursel.

Yeah, let me know what you guys think. Is this just another case of Forbes 30 under 30 being the best indicator to fraudulent activities allegedly? Or are we just entering a new stage of startups where it starts to feel like being in founder mode just means how can you sort of scam your customers and not have them realize it? And make sure you hit that subscribe button, follow me on Twitter, and I'll see you guys in the next.