Monday, August 3, 2026

Policy & Regulation

Delve accused of misleading customers with fake compliance

Delve, a compliance startup valued at $300 million, faces allegations of structural fraud and providing fake evidence, potentially exposing customers to significant regulatory and legal risks.

Delve accused of misleading customers with fake compliance
Photo: Delve

An anonymous report published on March 21, 2026, has accused Delve, a compliance startup backed by Y Combinator (the US-based startup accelerator) and valued at $300 million, of engaging in structural fraud. The accuser, writing under the pseudonym DeepDelver, claims that Delve is misleading customers with ‘fake compliance’ by falsely convincing hundreds of customers they were compliant with privacy and security regulations. DeepDelver, a former client who chose to remain anonymous out of fear of retaliation by Delve, stated that the investigation began after clients pooled resources due to a shared underwhelming experience with the platform. According to DeepDelver, the startup produces fake evidence and generates auditor conclusions on behalf of certification mills that rubber-stamp reports.

On Friday, Delve attempted to refute the accusations on its blog, calling the claims misleading and stating that the post contains inaccurate claims. The company, which previously raised $32 million in Series A funding led by Insight Partners, defended its business model by contrasting its practices against the allegations:

  • The Accuser’s Claim: DeepDelver alleges that Delve produces fake evidence and generates auditor conclusions on behalf of certification mills. The accuser claims these audit firms, Accorp and Gradient, operate primarily in India with only a nominal presence in the United States, rubber-stamping reports generated by Delve.
  • The Company’s Defense: Delve countered that it is an automation platform providing templates to help teams document their processes. Delve stated, “Draft templates are not the same as ‘pre-filled evidence’” to distinguish its templates from fabricated data, maintaining that final reports are issued solely by independent, licensed auditors.

Beyond the fraud allegations, Delve faces claims of security holes in its external attack surface. An X user named James Zhou claimed to gain access to sensitive information from Delve. Jamieson O’Reilly, the founder of security firm Dvuln, reported several gaping security holes in Delve’s external attack surface following conversations with Zhou. Critics argue these alleged practices and vulnerabilities could potentially expose Delve’s customers to criminal liability under HIPAA (the US health privacy regulation) and hefty fines under GDPR (the European Union’s General Data Protection Regulation).

Why it matters

The allegations against Delve, a startup backed by Y Combinator (the US-based startup accelerator), involve claims of structural fraud and fake compliance evidence. If proven true, these practices could expose customers to severe legal and regulatory risks.