order and chaos at work

825 posts

order and chaos at work banner
order and chaos at work

order and chaos at work

@mrdevelopersir

Software Engineer working on Salable, a platform for SaaS developers to monetise their products. DM to book a demo.

Beigetreten Ocak 2026
587 Folgt172 Follower
Angehefteter Tweet
order and chaos at work
order and chaos at work@mrdevelopersir·
I have no idea which of you is AI anymore. Could be a straight-up bot, or a human using LLMs to compose tweets, or AGI utilising its human slaves to shit post.
English
1
0
15
726
ThePrimeagen
ThePrimeagen@ThePrimeagen·
you got to check out my latest project, its so good
ThePrimeagen tweet media
English
53
0
158
41.2K
Aman
Aman@Amank1412·
I just got banned from Claude Code So now I have to go back to the primal days… either writing code by hand or using Cursor/Codex
Aman tweet media
English
66
4
248
90.8K
Suhas
Suhas@zuess05·
@mrdevelopersir That is the best isn’t it But also takes the most effort to get that haha
English
1
0
1
88
Suhas
Suhas@zuess05·
Be brutally honest. What is your favorite way to get users for your app?
English
59
0
52
4.8K
order and chaos at work
order and chaos at work@mrdevelopersir·
tsk tsk, if you're going to fake it til you make it, don't go near security/privacy compliance.
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
0
0
1
33
Uzair
Uzair@uzair_dev_·
What type of developer are you? - Frontend - Backend - Full stack - DevOps
English
154
4
106
7K
⭕ Brock Pierson
⭕ Brock Pierson@brockpierson·
Is your profile picture really you?
English
213
3
141
5.5K
Sick
Sick@sickdotdev·
Name a career that AI can steal.
English
44
1
19
2.3K
Matt Pocock
Matt Pocock@mattpocockuk·
Why did you start following me on X?
English
37
0
37
9.6K
Lasker
Lasker@Lasker169631·
@mrdevelopersir @wagslane There is no game, Anthropic is suing them, what the hell are they supposed to do?
English
2
0
0
45
Sick
Sick@sickdotdev·
AI can write code. What can it NOT do?
English
24
0
15
1.1K
Dmitrii Kovanikov
Dmitrii Kovanikov@ChShersh·
When people look at my pfp, they think I don’t have hands. When they look at the code I produce, the theory sounds even more plausible. However, to address the common misconception, I actually have hands. Here’s the original.
Dmitrii Kovanikov tweet media
English
37
0
159
9.3K
order and chaos at work
order and chaos at work@mrdevelopersir·
I'm testing out bribe coding where I give money to other devs to write the code for me, the results so far leave a lot to be desired.
English
0
0
1
19
Dominik Koch
Dominik Koch@dominikkoch·
does this mean I need go get soc 2 certified?
Dominik Koch tweet media
English
5
0
25
1.5K