Ben Anthony

4.2K posts

Ben Anthony banner
Ben Anthony

Ben Anthony

@benjamin_ACD

Se unió Haziran 2023
333 Siguiendo313 Seguidores
Milo Smith
Milo Smith@mil0theminer·
@theCTO Sorry a man has opinions. And yes I like my girlfriend, she’s very nice.
English
1
0
30
628
adam
adam@theCTO·
has @mil0theminer ever liked a company/person? anyone?
English
2
0
16
14.6K
Ben Anthony
Ben Anthony@benjamin_ACD·
@kallasmaa @Lovable one thing I have learned is that once someone has done something obviously wrong, don't expect any of their surrounding choices to be the choice you would make lol
English
0
0
1
2.4K
Lovable
Lovable@Lovable·
We're aware of recent reporting about Delve’s compliance practices. Lovable is not a Delve customer. We proactively moved to Vanta in late 2025, before any of this came to light. Our SOC 2 Type II was independently audited by Prescient Assurance. We’re currently undergoing an independent internal audit of our ISMS, recertifying ISO 27001, and have our next SOC 2 Type II scheduled for Q3 2026. Security is not an afterthought at Lovable. It's a company-wide commitment backed by a dedicated team and continuous investment. Our current compliance practices are all here: trust.lovable.dev
English
46
44
1.2K
104.3K
Paul Butler
Paul Butler@paulgb·
Thank god I skipped Delve and just had Claude generate a SOC-2 report directly.
English
24
27
1.2K
28.5K
Doug
Doug@magnumdong1992·
Uh oh! 🚨 🚨Sneaker Police checkpoint 🚨 🚨 Answer these questions immediately or delete your posts. 1. List every shoe ever. 2. Whats Michael Jordan’s favorite pizza topping.? 3. Is it Bred or Black/Red? 4. Did you watch my friends 24 minute video analysis on ____ ?
English
7
1
44
2K
Milo Smith
Milo Smith@mil0theminer·
. @cursor_ai please stop running undisclosed ads on Instagram. It’s scummy and blatantly illegal
Milo Smith tweet media
English
37
9
728
50.9K
Ben Anthony
Ben Anthony@benjamin_ACD·
How Delve clients are going to be in court
Ben Anthony tweet media
English
0
0
1
80
Feifan Zhou
Feifan Zhou@FeifanZ·
We talked to Delve last summer. Heard a few concerning stories behind the scenes; decided to go with someone else for our SOC II. Glad we did. We take security seriously at Tanagram.
Feifan Zhou tweet media
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
12
6
262
55.3K
Ben Anthony
Ben Anthony@benjamin_ACD·
Seemed like this company was too good to be true as soon I heard about it didn't think it'd fall apart quite that quickly though
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
0
0
0
52
Holly Guevara
Holly Guevara@hollylawly·
Claude is extra unhinged today i stg 😮‍💨
Holly Guevara tweet mediaHolly Guevara tweet media
English
2
0
11
1.5K
Ben Anthony retuiteado
Fred
Fred@Grand_handsomer·
Now that Afroman has saved free speech he should turn his attention to destroying qualified immunity
English
21
268
3.4K
26K
Ben Anthony
Ben Anthony@benjamin_ACD·
@BenjDicken @hollylawly I've had it for a while. Seems to be that claude does not recognize PS as a Postgres provider. It's gotta research it first
English
1
0
1
16
Ben Anthony
Ben Anthony@benjamin_ACD·
Taylor Frankie Paul daughter or Afroman son
English
0
0
0
102
Ben Anthony
Ben Anthony@benjamin_ACD·
Afroman is playing in my city next week, feel like that's a must-go
English
0
0
0
28
Wilson Wilson
Wilson Wilson@euboid·
Has anybody figured out how to do this? - @getsentry issue reported - codex agent spun up with access to sentry + axiom logs & traces - Draft PR auto-created w/ root cause analysis + fix
English
35
1
86
27.8K