NoNamesPlease

444 posts

NoNamesPlease banner
NoNamesPlease

NoNamesPlease

@OnChainOnlyy

does it matter what this says? ||||| crypto stuff, formerly @uniswap @alchemy

Katılım Nisan 2024
212 Takip Edilen152 Takipçiler
Sabitlenmiş Tweet
NoNamesPlease
NoNamesPlease@OnChainOnlyy·
Talk to me about @Uniswap Labs products! We're kicking off new user research & looking for folks to participate! User feedback can make @Uniswap better for all, and we'd love thoughtful insights Whether you're a full-on 🐋 or swap infrequently, DM if interested in details.
English
1
1
19
1.1K
NoNamesPlease
NoNamesPlease@OnChainOnlyy·
NoNamesPlease tweet media
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

ZXX
0
0
1
26
dar
dar@radbackwards·
The East Bay has this energy force field around it that’s telling me to go back to Palo Alto
English
15
1
118
8.3K
Brie Wolfson
Brie Wolfson@zebriez·
who posts about the cool work they're doing in a way that you enjoy? who sounds smart and impactful but not ick and self-promotional?
English
15
1
36
3.8K
guille
guille@angeris·
@OnChainOnlyy nice ok, not sure yet if i’ll restrict to mutuals only but
English
1
0
1
36
guille
guille@angeris·
ok, weird, but I have a list of sci-fi books I've been meaning to read for a while, but it seems kind of boring to read them and then write some post about it or whatever so, any mutuals interested in a (hard-ish) sf mini-book club like thing
English
15
1
24
1.7K
dar
dar@radbackwards·
@OnChainOnlyy Lil b, Nef tha Pharaoh, slimmy b, da boi, Andre nikitina, p-lo, Larry June, too short (not bay but sounds like he should be), Guap Dad, g-easy but doesn’t count, Larussel, etc etc etc. I grew up on Bay Area sound. Seattle rap is pretty much just a fork of it.
English
5
0
12
380
NoNamesPlease
NoNamesPlease@OnChainOnlyy·
@ThogardPvP @trentdotsol I didn't read the original SCP version but apparently the book is reworked enough that it's worth "re-reading" in the new format!
English
1
0
1
13
TACEO
TACEO@TACEO_IO·
The TACEO Network is live! A private execution layer for digital rails. The cryptographic infrastructure behind it already secures personal data for nearly 18 million people.
English
34
31
148
20.3K
Joseph Alessio
Joseph Alessio@alessio_joseph·
composing a tweet that will get twelve (12) likes
Joseph Alessio tweet media
English
6
1
101
2.5K
Joel John
Joel John@joeljohn·
Things I'm excited by in crypto rn - Hyperliquid, fringe fintech primitives on Solana, RWAs that are scaling (maple, cfg, ondo), zk native financial apps, fintech primitives built on these rails Trying to put more focus on these vs random foundation essays and vanity pieces.
English
15
1
95
8.1K
Ian Lapham
Ian Lapham@ianlapham·
Combining body building training, marathon prep, and hyrox training into one chaotic 7 day program rn Will see how this goes
English
6
0
15
1.1K
NoNamesPlease
NoNamesPlease@OnChainOnlyy·
@sur4js Can you still run your note taker and then share key insights here though?
English
0
0
1
36
sur4js
sur4js@sur4js·
Free idea: Dinner party but you DON'T take pictures of everyone that attended to post online and you DON'T tell anyone about it
English
15
1
124
5K