Fiona Small

57.8K posts

Fiona Small banner
Fiona Small

Fiona Small

@FionaSmall

Irishposting

Dublin, Ireland Katılım Aralık 2010
248 Takip Edilen5K Takipçiler
yeshiva frat leader
yeshiva frat leader@TullamoreJew_·
Any bluechecks need to make rent there's money on the table with a 'light of Islam accepted chuck norris' format joke
English
2
1
17
541
Fiona Small
Fiona Small@FionaSmall·
Not remotely surprising
English
0
0
0
48
Brian Flanagan
Brian Flanagan@MrBrianFlanagan·
@I_amMukhtar They participated in several parades around Mayo in Ireland 🤣🤣🤣
English
3
4
28
809
Mukhtar
Mukhtar@I_amMukhtar·
This is absolutely wild.
English
30
206
1.2K
40.7K
Fiona Small retweetledi
Yashar Ali 🐘
Yashar Ali 🐘@yashar·
Trump Friend Asked ICE to Detain the Mother of His Child Paolo Zampolli, a former modeling agent and a longtime Trump ally, was in a custody battle over his son. An ICE official agreed to help. Full Story: nyti.ms/4bDpop4
Yashar Ali 🐘 tweet media
English
19
239
620
56.4K
Fiona Small
Fiona Small@FionaSmall·
@SpicyGaullism Thats not population of a country but specific ethnic group (Jews also have a lower global population)
English
1
0
0
30
Fiona Small
Fiona Small@FionaSmall·
Chuck Norris dead at 86
Fiona Small tweet media
English
3
4
49
743
Fiona Small retweetledi
McKay Coppins
McKay Coppins@mckaycoppins·
Last year, I met a Mexican athlete who told me an incredible story—that he’d been kidnapped in 2023 and forced to compete for his life in a secret tournament of cartels. Once I started reporting, the story only got more surreal. For the May issue: theatlantic.com/magazine/2026/…
English
68
528
2.7K
341.3K
Fiona Small retweetledi
Alex Cohen
Alex Cohen@anothercohen·
Incredible. At this point we need to put the Forbes editors in charge of the FBI
Alex Cohen tweet media
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
76
447
8.4K
844.2K