Delve compliance report fraud allegations

Developing StoryLast updated
SUMMARY

Delve, a compliance startup, is facing a class action lawsuit as of July 15, 2026, following allegations of providing fake compliance reports to hundreds of clients, leading to potential legal risks for those clients, including HIPAA criminal liability and GDPR fines. As of July 10, 2026, Delve was expelled from the Y Combinator program due to loss of trust and is also accused of intellectual property theft. The FBI has reportedly contacted a former product manager for Delve amidst these allegations, which have raised significant concerns about the integrity of the SOC 2 framework. Delve's CEO Karun Kaushik previously called the claims "falsified," despite leaked reports containing real client signatures.

Timeline

Want updates on this thread?

Track this story

Timeline of developments

July 2026 2 developments

  1. Delve Faces Class Action Lawsuit Amidst Fake Compliance Report Allegations

    Delve is now facing a class action lawsuit following allegations of providing fake compliance reports to hundreds of clients. Clients who relied on these reports are now migrating to alternative platforms and face potential legal risks, including HIPAA criminal liability and GDPR fines.

  2. Delve Expelled From Y Combinator Amidst Fake Audit Report and IP Theft Allegations

    Delve has been expelled from the Y Combinator program due to a loss of trust, following allegations of fabricating compliance audit reports for hundreds of clients. The startup is also accused of intellectual property theft, including the alleged misappropriation of open-source code from Sim.ai. Companies that used Delve's services are now advised to unpublish their trust pages and obtain new audits from legitimate CPA firms.

June 2026 1 developments

  1. Delve Accused of Fabricating Hundreds of SOC 2 Reports; FBI Contacts Former Employee

    The AICPA Peer Review Board has issued guidance to flag identical SOC 2 reports following allegations that compliance startup Delve systematically fabricated audit reports for hundreds of clients. The FBI has reportedly contacted a former product manager for Delve amidst these allegations, which have raised significant concerns about the integrity of the SOC 2 framework and the broader compliance industry.

May 2026 1 developments

  1. Delve halts product demos, loses Y Combinator amid compliance report fraud allegations

    Delve has reportedly halted product demonstrations and lost its largest investor, Y Combinator, due to allegations of fabricating compliance reports. Multiple clients are migrating to competing services, with accusations suggesting Delve produced fake SOC 2 and ISO 27001 evidence.

April 2026 3 developments

  1. Delve removed from Y Combinator directory over alleged fabricated compliance reports

    Delve has been removed from Y Combinator's directory following allegations of fabricating compliance reports for clients. The company denies the claims, stating they provide data to auditors rather than pre-filled reports.

  2. Delve Accused of Faking Compliance Reports for 500 Clients, Repackaging Open-Source Tool

    Delve is accused of faking compliance reports for nearly 500 clients, with investigations revealing that some audit firms used by the company have failed AICPA peer reviews. A whistleblower also alleges that Delve repackaged an open-source platform as its own proprietary tool, adding to existing concerns about the company's compliance practices.

  3. Whistleblower "DeepDelver" Releases More Evidence of Delve's Fabricated Compliance Reports

    Whistleblower "DeepDelver" has released further evidence, including purported Slack messages and video, related to Delve's alleged fabrication of compliance reports. Audit firms Accorp and Gradient are named as "certification mills" that allegedly rubber-stamped Delve's reports without independent verification. Companies like LiteLLM have begun severing ties with Delve.

March 2026 3 developments

  1. LiteLLM terminates partnership with Delve after credential-stealing malware attack

    LiteLLM has terminated its partnership with Delve following a credential-stealing malware attack, intensifying concerns about the reliability of Delve's compliance certifications. Delve is accused of fabricating reports for clients, potentially exposing them to significant legal risks.

  2. Delve accused of systematically producing fake evidence to mislead clients on compliance

    Delve is accused of systematically producing fake evidence, including fabricated board meeting minutes and tests, to mislead clients about their compliance with regulations like HIPAA, GDPR, SOC 2, and ISO 27001. Some affected clients have reportedly unpublished their trust pages and abandoned the platform.

  3. Delve CEO Karun Kaushik denies compliance report faking allegations

    Delve's CEO Karun Kaushik has responded to allegations of faking compliance reports, calling the claims "falsified" and from an "AI-generated email," despite leaked reports containing real client signatures. An anonymous investigator, "DeepDelver," published a detailed report on Substack alleging that Delve's "US-based auditors" are actually Indian certification mills using shell companies. Delve maintains they are an automation platform, not an auditor, and that licensed auditors issue final reports.

January 2026 4 developments

  1. Delve Accused of Faking Compliance Certifications for Hundreds of Clients

    Compliance startup Delve is accused of faking SOC 2, ISO 27001, HIPAA, and GDPR certifications for hundreds of clients. An investigation revealed systematic fabrication of compliance reports, including pre-written audit conclusions and fabricated security check evidence. The CEO reportedly called the allegations 'falsified claims,' but leaked documents contained real client signatures and confidential data.

  2. Hacker News thread 'Delve AI Audit Fraud' increases public pressure on Delve

    The allegations against Delve gained further traction on Hacker News, where a thread titled 'Delve AI Audit Fraud' emerged. Participants in the discussion shared detailed analyses and evidence, bringing the accusations to a wider tech audience and significantly increasing public pressure on the company.

  3. Reddit users debate 'Delve scandal' over alleged fake SOC 2 reports and client impact

    Discussions intensified on Reddit with a post titled 'Real or Fake? The Delve scandal or conspiracy deepens,' indicating a rapidly growing awareness and debate surrounding the allegations. The post referenced information circulating about allegedly fake SOC 2 reports and a spreadsheet confirming impacted clients, further fueling public scrutiny.

  4. Reddit Users Allege Fraudulent Compliance Practices by Delve

    Initial allegations of fraudulent compliance practices by Delve began to surface on Reddit's r/soc2 subreddit. Users expressed growing skepticism and shared suspicions regarding the legitimacy of Delve's claims, particularly its promise of achieving 'SOC 2 in days,' indicating early public concern.

November 2025 1 developments

  1. Google Spreadsheet Exposes Delve's Confidential Audit Reports, Triggering Fraud Allegations

    In late 2025, a critical vulnerability was discovered when a publicly accessible Google Spreadsheet was found, containing links to hundreds of confidential draft audit reports from Delve's internal pipeline. This discovery became the initial catalyst for the subsequent widespread fraud allegations against the company, exposing potential irregularities.

July 2025 2 developments

  1. Delve Announces Serving Over 500 Companies, Highlighting Rapid Growth and Market Penetration

    Concurrent with its Series A funding announcement, Delve claimed to be serving over 500 companies across various industries. The company marketed its platform as a solution that could help customers achieve compliance rapidly, build robust security, and expedite deal closures, highlighting its rapid growth and market penetration.

  2. Delve Raises $32 Million in Series A Funding Led by Insight Partners

    Delve announced a substantial Series A funding round, raising $32 million led by Insight Partners, with additional participation from CISOs at Fortune 500 companies. This funding round valued the company at $300 million and was intended to accelerate its AI capabilities, expand its team, and support more compliance frameworks.

February 2024 1 developments

  1. Delve Launches HIPAA Compliance as a Service on Hacker News

    Delve publicly launched its HIPAA compliance as a service on Hacker News, marking one of its first major product offerings. This launch underscored the company's early focus on regulated industries and its ambition to simplify complex compliance frameworks using AI-driven solutions.

January 2024 1 developments

  1. Delve Secures $3.3 Million Seed Funding for AI Compliance Platform Development

    In 2024, Delve successfully secured $3.3 million in seed funding. This initial capital provided the necessary resources to develop its AI-native compliance platform, enabling the company to begin building its core technology and expand its foundational team.