Empirical Record · Dahlem Project

Cases

Open · 2026

Delve

Compliance automation · Verification integrity · 2026

Case · Dahlem Project

Open case · opened 2026

Delve

I

The Case

Delve Technologies Inc. was incorporated in Delaware on December 12, 2023, by Karun Kaushik and Selin Kocalar, who left MIT to build the company as a platform for automating security and privacy compliance. Its proposition was compression as an optimization target: processes associated with frameworks such as SOC 2, HIPAA, ISO 27001 and GDPR could be reduced from months to days by automating evidence collection, documentation and compliance workflows.

The company grew rapidly. Y Combinator included Delve in its Winter 2024 cohort. In 2025, a $32 million Series A led by Insight Partners valued the company at $300 million. By January 2026, the company reported serving more than 1,000 customers in over 50 countries.

In March 2026, an anonymous account calling itself DeepDelver published an investigation into Delve’s compliance practices. The account described itself as representing former customers and released material it attributed to Delve-associated compliance processes.

The central allegation concerned the relationship between evidence and verification. DeepDelver claimed that compliance evidence had in some instances been generated or prepared without the underlying control activity having occurred as represented. Its analysis of a corpus of several hundred SOC 2 reports also identified extensive repetition in language, test descriptions and auditor conclusions. Additional material released later included alleged internal communications, recordings and documents.

These findings do not by themselves establish that certifications were invalid or that controls had not been performed. Standardization and templating are normal features of compliance work. Nor has the provenance of all material released by the anonymous source been independently established. The more consequential question is narrower: whether the infrastructure used to prepare organizations for independent assessment also shaped the evidence and assessment process to a degree that weakened the independence the process was intended to provide.

Delve disputes the central allegations. On March 24, the company announced changes to its auditor network and additional support for customers. In a fuller response published on April 3, Delve stated that it does not issue SOC 2 reports or certifications, that independent audit firms make final determinations, and that templates and automated evidence collection are standard industry practices. The company also acknowledged that rapid scaling had caused it to fall short of its own standards. It announced that it was rebuilding its auditor network and removing firms that did not meet its standards, offering complimentary re-audits and penetration tests to all active customers, halting automation interacting with audit workflows, and establishing direct communication between customers and auditors. Delve did not publicly identify the audit firms it said it was removing. It also said it would make explicit within the platform that templates for policies, board meetings and risk assessments were intended only as starting points.

The controversy produced institutional consequences before the underlying allegations were resolved. Delve and Y Combinator parted ways, and Delve disappeared from Y Combinator’s company directory. Insight Partners temporarily removed material concerning its investment before restoring its principal investment announcement. Some customers announced that they would seek new assessments following the controversy.

No regulatory finding or judicial decision has established that Delve systematically falsified compliance evidence. Delve continues to operate.

The case therefore remains open.

II

Diagnostic Scope

Mandate

Compliance certification performs a specific institutional function. It allows parties without direct access to an organization’s internal systems to rely on an assessment performed under defined standards.

Delve introduced a second objective into that process: compression as an explicit optimization target. Speed was not incidental to the product — it was the product.

Automation can reduce administrative work without changing the function of verification. The structural question begins where compression and verification cease to be independent objectives. If the infrastructure is optimized to move organizations through compliance rapidly, activities that slow the process acquire a cost even when those activities exist precisely to preserve the reliability of the result.

The relevant question is therefore not whether automation makes compliance faster. It is whether compression as an optimization target begins to influence what counts as sufficient evidence.

Feedback

Independent assessment is intended to provide an external correction mechanism. Evidence is produced, examined and challenged by parties whose roles are institutionally distinct.

The material released in 2026 raises the possibility that these functions had become more closely coupled. Repeated language across reports is not evidence of failed auditing by itself. It becomes relevant if standardization extends from administrative form into substantive judgment.

The controversy was not initially generated by the formal compliance system. It emerged when parties outside that system compared material across cases.

This distinction matters. A correction mechanism can formally exist while remaining unable to detect patterns visible only at a level above individual assessments.

Accountability

Delve’s response emphasizes the separation of roles: the platform prepares organizations for compliance; customers choose auditors; independent auditors make the final determination.

Formally, this preserves accountability.

Functionally, the question is more difficult. If evidence collection, preparation, workflow management and access to auditors are coordinated through overlapping infrastructure, responsibility may remain legally distributed while the ability of any one participant to evaluate the entire process declines.

No single failure of responsibility needs to occur. Accountability can weaken through fragmentation.

The relevant test is therefore not simply who signed the report. It is whether responsibility for the reliability of the underlying evidentiary chain can be located and independently examined.

Epistemic Access

Certification exists partly because outsiders cannot inspect everything themselves. They rely on an institutional chain: controls generate evidence; evidence is assessed; an auditor issues an opinion; third parties rely on that opinion.

Automation changes the informational structure of this chain.

When a platform collects evidence, generates documentation, organizes controls and prepares material for assessment, it can increase visibility. It can also create a new dependency: downstream participants increasingly encounter the organization through representations produced by the same system.

The unresolved question in the Delve case is therefore one of epistemic access.

Could the actors responsible for independent validation inspect the underlying state independently of the infrastructure that represented it to them?

III

Inversion Test

The allegations against Delve do not yet establish a completed inversion. They do, however, allow the sequence to be tested.

Constraint Relaxation

The first possible shift concerns the threshold for acceptable evidence.

Automation necessarily translates heterogeneous organizational activity into standardized categories. This is not itself a failure. Constraint relaxation would occur if evidence sufficient for processing gradually became accepted as evidence sufficient for verification.

Whether this occurred at Delve remains unresolved.

Functional Reversal

Evidence normally follows the activity it is intended to demonstrate.

The central allegation in the Delve case describes a possible reversal of this relationship: the compliance process may in some instances have generated the evidentiary artifact required by the framework before, or independently of, the underlying activity it purported to document.

If substantiated, this would constitute the clearest inversion in the case.

Evidence would cease to function primarily as a trace of an independently existing control. The production of the trace would itself become part of producing compliance.

Corrective Insulation

Certification can protect a system from further questioning because certification is precisely the mechanism designed to conclude that questioning.

A successful report therefore carries epistemic authority beyond the immediate transaction. Customers show it to clients, partners and investors who are expected to rely on the assessment rather than reproduce it.

If the underlying validation process becomes unreliable, the certificate can consequently perform the opposite function from the one intended: instead of exposing uncertainty to independent scrutiny, it can reduce the demand for further scrutiny.

The existence of this mechanism is structural. Whether it operated in particular Delve assessments remains to be established.

Accountability Diffusion

The architecture distributes responsibility among the customer, the compliance platform and the auditor.

Each role can point to another legitimate function. The customer supplied information. The platform organized evidence. The auditor made the final determination.

This distribution is compatible with a functioning compliance system. It becomes problematic when responsibility is divided more finely than the capacity to verify the complete chain.

The Delve case therefore tests whether formal role separation preserved substantive independence or distributed responsibility across an increasingly integrated process.

Self-Reinforcement

Successful certification creates demand for further certification.

Faster completion attracts customers. More customers generate more standardized workflows. Standardization makes further automation possible. Automation permits greater throughput.

This feedback loop is economically rational and can improve compliance.

It also creates a possible reinforcing mechanism: once speed becomes evidence of product performance, procedural friction increasingly appears as inefficiency. Yet some forms of friction — independent review, contradictory evidence, repeated testing, delayed judgment — exist because verification is supposed to resist compression.

The question is whether growth strengthened the validation architecture or progressively removed the friction on which that architecture depended.

IV

What Makes This Case Different

Earlier institutional failures frequently involved information that existed but was concealed, ignored or prevented from reaching the relevant decision-maker.

Delve presents a different possibility.

The disputed issue is not simply whether information was hidden. It is whether the infrastructure designed to make verification easier altered the relationship between evidence and verification itself.

A system can become more efficient at producing the visible outputs of scrutiny while becoming less capable of preserving the independence from which those outputs derive their authority.

That is the structural question raised by this case.

It does not depend on establishing deliberate deception.

V

Verification Window

The diagnosis generates no prediction of corporate collapse.

Its test concerns the architecture of verification.

Delve has already announced measures that address the structural points identified by this diagnosis: halting automation interacting with audit workflows, establishing direct communication between customers and auditors, and rebuilding the auditor network. The open question is therefore no longer whether Delve has responded. It is whether these measures produce a verifiable institutional separation between evidence production and independent assessment — or whether they remain procedural adjustments within an architecture whose optimization target has not changed.

Over the next 12 to 24 months, three developments are relevant.

First, whether the announced separation between compliance preparation and final assessment becomes demonstrably independent — verifiable by third parties, not only asserted by the platform.

Second, whether auditors operating within platform-mediated compliance make their methods, responsibilities and independence sufficiently transparent for the full validation chain to be reconstructed from outside.

Third, whether regulators, standard-setting bodies or the audit industry introduce requirements addressing automated evidence generation and the independence of assessments performed on that evidence.

Evidence against the diagnosis would also matter.

If independent examination establishes that the disputed evidence reliably corresponded to underlying controls, that auditors performed substantive verification independent of Delve’s representations, and that the reported standardization was confined to administrative templates, the proposed inversion would weaken substantially.

The case therefore remains falsifiable in both directions.

VI

Sources

  • DeepDelver, „Fake Compliance as a Service,“ Substack, Part I, March 19, 2026.
  • DeepDelver, „Fake Compliance as a Service,“ Substack, Part II, March 28, 2026.
  • Delve, „Delve Announces Changes and New Customer Support Measures,“ company statement, March 24, 2026.
  • Delve, „Delve Sets the Record Straight on Anonymous Attacks,“ company statement, April 3, 2026.
  • TechCrunch, „Delve accused of misleading customers with ‚fake compliance,'“ March 22, 2026.
  • TechCrunch, „Insight Partners scrubs investment post amid ‚fake compliance‘ allegations,“ March 23, 2026 (updated).
  • TechCrunch, „Delve whistleblower strikes again with alleged receipts about ‚fake compliance,'“ March 30, 2026.
  • TechCrunch, „The reputation of troubled YC startup Delve has gotten even worse,“ April 1, 2026.
  • TechCrunch, „Embattled startup Delve has parted ways with Y Combinator,“ April 4, 2026.
  • TechCrunch, „Another customer of troubled startup Delve suffered a big security incident,“ April 23, 2026.

Empirical Record · Dahlem Project

Cases

Open · 2026

Delve

Compliance automation · Verification integrity · 2026

Case · Dahlem Project

Open case · opened 2026

Delve

I

The Case

Delve was founded in November 2023 by Karun Kaushik and Selin Kocalar, who left MIT to build the company, as a platform for automating security and privacy compliance. Its proposition was speed: processes associated with frameworks such as SOC 2, HIPAA, ISO 27001 and GDPR could be compressed from months into days by automating evidence collection, documentation and compliance workflows.

The company grew rapidly. Y Combinator included Delve in its Winter 2024 cohort. In 2025, a $32 million Series A led by Insight Partners valued the company at $300 million. By January 2026, the company reported serving more than 1,000 customers in over 50 countries.

In March 2026, an anonymous account calling itself DeepDelver published an investigation into Delve’s compliance practices. The account described itself as representing former customers and released material it attributed to Delve-associated compliance processes.

The central allegation concerned the relationship between evidence and verification. DeepDelver claimed that compliance evidence had in some instances been generated or prepared without the underlying control activity having occurred as represented. Its analysis of a corpus of several hundred SOC 2 reports also identified extensive repetition in language, test descriptions and auditor conclusions. Additional material released later included alleged internal communications, recordings and documents.

These findings do not by themselves establish that certifications were invalid or that controls had not been performed. Standardization and templating are normal features of compliance work. Nor has the provenance of all material released by the anonymous source been independently established. The more consequential question is narrower: whether the infrastructure used to prepare organizations for independent assessment also shaped the evidence and assessment process to a degree that weakened the independence the process was intended to provide.

Delve disputes the central allegations. On March 24, the company announced changes to its auditor network and additional support for customers. In a fuller response published on April 3, Delve stated that it does not issue SOC 2 reports or certifications, that independent audit firms make final determinations, and that templates and automated evidence collection are standard industry practices. The company also acknowledged that rapid scaling had caused it to fall short of its own standards and said it was rebuilding parts of its auditor network.

The controversy produced institutional consequences before the underlying allegations were resolved. Delve and Y Combinator parted ways, and Delve disappeared from Y Combinator’s company directory. Insight Partners temporarily removed material concerning its investment before restoring its principal investment announcement. Some customers announced that they would seek new assessments following the controversy.

No regulatory finding or judicial decision has established that Delve systematically falsified compliance evidence. Delve continues to operate.

The case therefore remains open.

II

Diagnostic Scope

Mandate

Compliance certification performs a specific institutional function. It allows parties without direct access to an organization’s internal systems to rely on an assessment performed under defined standards.

Delve introduced a second objective into that process: compression.

Automation can reduce administrative work without changing the function of verification. The structural question begins where speed and verification cease to be independent objectives. If the infrastructure is optimized to move organizations through compliance rapidly, activities that slow the process acquire a cost even when those activities exist precisely to preserve the reliability of the result.

The relevant question is therefore not whether automation makes compliance faster. It is whether the optimization target begins to influence what counts as sufficient evidence.

Feedback

Independent assessment is intended to provide an external correction mechanism. Evidence is produced, examined and challenged by parties whose roles are institutionally distinct.

The material released in 2026 raises the possibility that these functions had become more closely coupled. Repeated language across reports is not evidence of failed auditing by itself. It becomes relevant if standardization extends from administrative form into substantive judgment.

The controversy was not initially generated by the formal compliance system. It emerged when parties outside that system compared material across cases.

This distinction matters. A correction mechanism can formally exist while remaining unable to detect patterns visible only at a level above individual assessments.

Accountability

Delve’s response emphasizes the separation of roles: the platform prepares organizations for compliance; customers choose auditors; independent auditors make the final determination.

Formally, this preserves accountability.

Functionally, the question is more difficult. If evidence collection, preparation, workflow management and access to auditors are coordinated through overlapping infrastructure, responsibility may remain legally distributed while the ability of any one participant to evaluate the entire process declines.

No single failure of responsibility needs to occur. Accountability can weaken through fragmentation.

The relevant test is therefore not simply who signed the report. It is whether responsibility for the reliability of the underlying evidentiary chain can be located and independently examined.

Epistemic Access

Certification exists partly because outsiders cannot inspect everything themselves. They rely on an institutional chain: controls generate evidence; evidence is assessed; an auditor issues an opinion; third parties rely on that opinion.

Automation changes the informational structure of this chain.

When a platform collects evidence, generates documentation, organizes controls and prepares material for assessment, it can increase visibility. It can also create a new dependency: downstream participants increasingly encounter the organization through representations produced by the same system.

The unresolved question in the Delve case is therefore one of epistemic access.

Could the actors responsible for independent validation inspect the underlying state independently of the infrastructure that represented it to them?

III

Inversion Test

The allegations against Delve do not yet establish a completed inversion. They do, however, allow the sequence to be tested.

Constraint Relaxation

The first possible shift concerns the threshold for acceptable evidence.

Automation necessarily translates heterogeneous organizational activity into standardized categories. This is not itself a failure. Constraint relaxation would occur if evidence sufficient for processing gradually became accepted as evidence sufficient for verification.

Whether this occurred at Delve remains unresolved.

Functional Reversal

Evidence normally follows the activity it is intended to demonstrate.

The central allegation in the Delve case describes a possible reversal of this relationship: the compliance process may in some instances have generated the evidentiary artifact required by the framework before, or independently of, the underlying activity it purported to document.

If substantiated, this would constitute the clearest inversion in the case.

Evidence would cease to function primarily as a trace of an independently existing control. The production of the trace would itself become part of producing compliance.

Corrective Insulation

Certification can protect a system from further questioning because certification is precisely the mechanism designed to conclude that questioning.

A successful report therefore carries epistemic authority beyond the immediate transaction. Customers show it to clients, partners and investors who are expected to rely on the assessment rather than reproduce it.

If the underlying validation process becomes unreliable, the certificate can consequently perform the opposite function from the one intended: instead of exposing uncertainty to independent scrutiny, it can reduce the demand for further scrutiny.

The existence of this mechanism is structural. Whether it operated in particular Delve assessments remains to be established.

Accountability Diffusion

The architecture distributes responsibility among the customer, the compliance platform and the auditor.

Each role can point to another legitimate function. The customer supplied information. The platform organized evidence. The auditor made the final determination.

This distribution is compatible with a functioning compliance system. It becomes problematic when responsibility is divided more finely than the capacity to verify the complete chain.

The Delve case therefore tests whether formal role separation preserved substantive independence or distributed responsibility across an increasingly integrated process.

Self-Reinforcement

Successful certification creates demand for further certification.

Faster completion attracts customers. More customers generate more standardized workflows. Standardization makes further automation possible. Automation permits greater throughput.

This feedback loop is economically rational and can improve compliance.

It also creates a possible reinforcing mechanism: once speed becomes evidence of product performance, procedural friction increasingly appears as inefficiency. Yet some forms of friction — independent review, contradictory evidence, repeated testing, delayed judgment — exist because verification is supposed to resist compression.

The question is whether growth strengthened the validation architecture or progressively removed the friction on which that architecture depended.

IV

What Makes This Case Different

Earlier institutional failures frequently involved information that existed but was concealed, ignored or prevented from reaching the relevant decision-maker.

Delve presents a different possibility.

The disputed issue is not simply whether information was hidden. It is whether the infrastructure designed to make verification easier altered the relationship between evidence and verification itself.

A system can become more efficient at producing the visible outputs of scrutiny while becoming less capable of preserving the independence from which those outputs derive their authority.

That is the structural question raised by this case.

It does not depend on establishing deliberate deception.

V

Verification Window

The diagnosis generates no prediction of corporate collapse.

Its test concerns the architecture of verification.

Over the next 12 to 24 months, three developments are relevant.

First, whether Delve establishes a demonstrably independent boundary between compliance preparation and final assessment.

Second, whether auditors associated with platform-mediated compliance make their methods, responsibilities and independence sufficiently transparent for third parties to reconstruct the validation chain.

Third, whether regulators, standard-setting bodies or the audit industry introduce requirements addressing automated evidence generation and the independence of assessments performed on that evidence.

Evidence against the diagnosis would also matter.

If independent examination establishes that the disputed evidence reliably corresponded to underlying controls, that auditors performed substantive verification independent of Delve’s representations, and that the reported standardization was confined to administrative templates, the proposed inversion would weaken substantially.

The case therefore remains falsifiable in both directions.

VI

Sources

  • DeepDelver, „Fake Compliance as a Service,“ Substack, Part I, March 19, 2026.
  • DeepDelver, „Fake Compliance as a Service,“ Substack, Part II, March 28, 2026.
  • Delve, „Delve Announces Changes and New Customer Support Measures,“ company statement, March 24, 2026.
  • Delve, „Delve Sets the Record Straight on Anonymous Attacks,“ company statement, April 3, 2026.
  • TechCrunch, „Delve accused of misleading customers with ‚fake compliance,'“ March 22, 2026.
  • TechCrunch, „Insight Partners scrubs investment post amid ‚fake compliance‘ allegations,“ March 23, 2026 (updated).
  • TechCrunch, „Delve whistleblower strikes again with alleged receipts about ‚fake compliance,'“ March 30, 2026.
  • TechCrunch, „The reputation of troubled YC startup Delve has gotten even worse,“ April 1, 2026.
  • TechCrunch, „Embattled startup Delve has parted ways with Y Combinator,“ April 4, 2026.
  • TechCrunch, „Another customer of troubled startup Delve suffered a big security incident,“ April 23, 2026.
Nach oben scrollen