A YC-backed compliance startup raised $32M, allegedly faked customer data, and may have stolen an open source tool from a customer. Here is what the Delve scandal reveals about an industry that rewards marketing over actual security.
By now you have seen the headlines. Delve, the AI compliance certification startup co-founded by Karun Kaushik and Selin Kocalar (both Forbes 30 Under 30 honorees), is under fire from a whistleblower known as "DeepDelver."
The allegations are damning: faked customer data, rubber-stamping auditors, and a tool called "Pathways" that was allegedly a rebranded fork of an open source project called SimStudio -- built by a company that was actually a Delve customer.
Sim.ai's founder Emir Karabeg confirmed to TechCrunch that Delve had no license agreement with them. "We knew they planned to use Sim for something and later tried unsuccessfully to sell them an agreement. I didn't realize they were going to sell it out of the box as a stand-alone solution."
The irony writes itself. A compliance startup that may have violated an open source license. A company that sells audit readiness that allegedly faked customer data. A $32M Series A from Insight Partners that apparently did not catch any of this.
The real problem is not Delve
Delve is just the latest example of a broken system. The compliance industry has a structural problem: it rewards appearance over substance.
Here is how it works today. You pay $15K-$50K/year to a platform like Vanta or Drata. They give you a dashboard that checks boxes. You hire an auditor who spends a few hours reviewing screenshots. You get a certificate. Everyone moves on.
The incentives are aligned wrong. The platform wants to close your deal. The auditor wants to issue your report. Nobody wants to find something that slows the process down. And because the whole thing is a black box -- you pay for the audit, you get the report, nobody else sees the actual evidence -- there is no real accountability.
Delve allegedly took this to an extreme. But the pattern is not new. It is the logical endpoint of an industry that treats compliance as a product to be sold rather than a practice to be lived.
What transparency actually looks like
At Compliance Copilot, we took a different approach from day one. Instead of a black box, we built a platform where every piece of evidence is visible to the customer, the auditor, and anyone the customer chooses to share it with.
Here is what that means in practice:
Evidence is not hidden. Every control, every test result, every piece of documentation is stored in a sharable workspace. No screenshots submitted in a one-way email. No "trust us, we checked."
Pricing is not gated. $49/mo for the full SOC 2 module. Not $15K/year. Not "contact sales." Not a demo call that turns into a high-pressure pitch. You can see the entire product, including the price, before you sign up.
The auditor works alongside you. Our platform generates an audit-ready report that your auditor can review in real time. No back-and-forth email chains. No "we need you to resubmit that screenshot."
No vendor lock-in. Your evidence is yours. Export it anytime. Take it to any auditor. The platform should serve you, not trap you.
This is not charity. It is a better business model. When you remove the smoke and mirrors, the only thing left is actual value. Either you are compliant or you are not. Either the evidence proves it or it does not.
The real cost of broken compliance
The Delve scandal has a direct cost for every legitimate compliance startup. Enterprise procurement teams are going to ask harder questions. Auditors are going to scrutinize more closely. The "garbage in, certificate out" era is ending.
But the bigger cost is the one you already pay without realizing it. Every dollar you spend on compliance theater is a dollar you could have spent on actual security. Every hour your team spends preparing screenshots for an auditor is an hour you could have spent shipping features.
The micro-SaaS founders I talk to are not looking for a way to cheat the system. They want to build secure products that enterprises will buy. They just cannot afford the $15K/year tax that the legacy compliance platforms charge for a dashboard and a handshake.
What to do instead
If you are a micro-SaaS founder who needs SOC 2 certification, here is a three-step plan that costs less than a monthly AWS bill:
Set up the controls. Use our platform (or any automated tool) to configure your infrastructure, policies, and monitoring. This takes a weekend, not a quarter.
Collect evidence automatically. Let the platform do the ongoing evidence collection. Every login, every config change, every access request gets logged and mapped to the relevant control.
Share the workspace with your auditor. Instead of a PDF dump, give them live access to the evidence. They can verify in minutes what would have taken days.
The result is the same SOC 2 Type II report. The same auditor sign-off. The same enterprise deals. Just without the $15K/year tax and the black box.
The Delve lesson
The Delve scandal is not a reason to give up on compliance. It is a reason to demand better. The fact that a startup could allegedly fake its way to a $32M valuation and a Forbes 30 Under 30 feature is proof that the system needs fixing, not that compliance is meaningless.
Real compliance is boring. It is automated tests, access logs, and policy reviews. It is not a secret sauce. It is not a competitive moat you can buy for $15K/year. It is a process that either works or it does not, and the only way to know is to look at the evidence.
That is what we built. Not a black box. A window.
Start your SOC 2 journey at $49/mo ->
This article is informational, not legal advice. Consult qualified counsel for compliance decisions specific to your business.