We've been deep in the compliance space building Mitigata, and the Delve scandal hit close to home.
In case you have 0 idea - a YC-backed startup Delve faked 493 compliance audits.
Those SOC 2 reports were virtually identical, with the same boilerplate, the same grammatical errors, only the logo swapped. All 259 Type II reports claimed zero security incidents across an entire year. Statistically impossible for real audits.
The broader problem is that Delve isn't unique. The "compliance in days" marketing is a red flag that the industry has been ignoring for too long.
Five quick checks if you have an existing certificate:
Can you independently verify your auditor's accreditation online?
Did your auditor conduct live interviews or site visits?
Does your report show zero incidents across an entire year?
Was your compliance achieved suspiciously fast?
Can your auditor provide a full evidence log without hesitation?
If you have any such doubts, I'd be happy to answer your questions.
P.S. I wrote about this in more detail on my Substack if anyone wants to go deeper.