Delve accused of misleading customers with ‘fake compliance’
An anonymous Substack post accuses compliance startup Delve of “falsely” convincing “hundreds of customers they were compliant ” with privacy and security regulations.

TL;DR
- A Substack post accuses Delve of falsely claiming customer compliance with privacy and security regulations.
- The post alleges Delve generated fake evidence, used 'certification mills,' and skipped major requirements.
- Delve denies the accusations, stating it provides templates and that independent auditors issue final reports.
- The anonymous author claims Delve's process constitutes 'structural fraud' by acting as both implementer and examiner.
- Concerns were also raised about Delve's network of audit firms and the potential for data leaks.
- Delve stated it is investigating leaks and reviewing the Substack post.
- Additional reports emerged regarding sensitive data access and security vulnerabilities.