Sam Miorelli

5.3K posts

Sam Miorelli banner
Sam Miorelli

Sam Miorelli

@SamMiorelli

🇺🇸🏳️‍🌈 lawyer. Worked on 3 continents in mega energy deals. Now recovering as a global biz lead in Cybersecurity. My tweets aren't my employer's viewpoint.

Florida, USA Katılım Temmuz 2008
1.6K Takip Edilen789 Takipçiler
Sam Miorelli retweetledi
Benn Eifert 🥷🏴‍☠️
new rule: jail time for Garry Tan every time a YC startup is convicted of fraud
English
54
147
3.4K
143.8K
Sam Miorelli retweetledi
Paul Butler
Paul Butler@paulgb·
Thank god I skipped Delve and just had Claude generate a SOC-2 report directly.
English
39
60
2.5K
65.1K
Sam Miorelli retweetledi
Dimitry Yakoushkin
Dimitry Yakoushkin@decadimitry·
How could this level of blatant fraud make it past a VC firm led by this executive team?
Dimitry Yakoushkin tweet media
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
65
233
4.3K
261.3K
Sam Miorelli retweetledi
Cline
Cline@cline·
AI inference lock-in is harder to see than cloud lock-in. You're not locked into a data center. You're locked into prompt architecture, evaluation logic, and institutional knowledge built against one model's behavior.
Saoud Rizwan@sdrzn

every major ai lab is losing money on you right now. openai lost $5B in 2024 on $3.7B revenue. they burned ~$8B on inference alone in the first 3 quarters of 2025. and they're forecasted to burn $218B in cash from 2026 to 2029. For comparison, uber burned $18.2 billion over six years before turning profitable. the strategy is subsidize inference to near-zero, get every engineering team dependent on their models, let switching costs build up quietly, then close the subsidy window once you're locked in. here's the part people get wrong. "but inference costs are falling! tokens are cheaper than ever!" yes, per-token costs dropped ~10x year over year. but that's for them, not for you. these companies have tens of billions in losses to recoup. cheaper infrastructure doesn't mean cheaper pricing when you're $218B in the hole. and as coding agents become the default way software gets built, the volume of tokens per developer is exploding. agentic loops hit the model 10-20x per task. context windows keep growing. your ai bill scales with every user, every feature, every agent running in the background. the unit cost goes down but the total spend goes up - that's the trap. this is why we built cline to be model-agnostic, because vendor lock-in to a single inference provider is dangerous. you should be able to swap models, run open source on your own infra, use whatever provider gives you the best price-performance for your workload - and never worry about a pricing rug pull.

English
0
2
17
3.1K
Sam Miorelli retweetledi
Varunram Ganesh
Varunram Ganesh@varunram·
Delve's response to the substack is finally out
Varunram Ganesh tweet media
English
88
13
536
316.9K
Sam Miorelli
Sam Miorelli@SamMiorelli·
Love @btfitzpat ideas on this. I mostly identify with his skepticism that the revealed preferences of university leadership completely contradicts their statements supporting ideological diversity. I also think this is less about hearts and more about ego: particularly for those under 50 years old, most elite leftists do not recognize many/any areas of good faith disagreement. They believe conservatives/libertarians only disagree with them *because they are stupid.* As such I expect this problem to get worse over time without intervention.
Brian Fitzpatrick@btfitzpat

Is it really possible to get more conservatives in academia? I have some bad news: it is going to be difficult. lawliberty.org/diversifying-t…

English
0
1
2
465
Sam Miorelli
Sam Miorelli@SamMiorelli·
@LCal60 It’s always a boomer white woman being nasty in the replies! Go away Karen!
English
0
0
0
3
Sam Miorelli retweetledi
Jonathan McDowell
Jonathan McDowell@planet4589·
Encouraged to see the provisions in the Senate's NASA authorization bill (reported out of ctee today) supporting @chandraxray : #SaveChandra
Jonathan McDowell tweet mediaJonathan McDowell tweet media
English
1
19
159
6.9K
Sam Miorelli
Sam Miorelli@SamMiorelli·
Epic. Short $FIG.
Danila Poyarkov@dan_note

Figma shipped a silent patch specifically to kill figma-use — my open-source tool that did what they wouldn't: an MCP server that creates and modifies designs, JSX export, design linting. Then they scrambled to catch up with their own MCP server. So I spent the weekend recreating @Figma from scratch. OpenPencil: reads and writes .fig files, AI chat with full design tools, P2P collaboration with zero servers, ~7 MB app. No account, no subscription. Three days, one developer, MIT license. openpencil.dev

English
0
0
1
315
OSINTtechnical
OSINTtechnical@Osinttechnical·
The UK, France, and Germany have announced their intention to potentially carry out strikes on Iran to destroy its missile and drone launch capabilities if Iranian forces persist in their attacks.
OSINTtechnical tweet mediaOSINTtechnical tweet mediaOSINTtechnical tweet media
English
439
1.1K
7.5K
756.9K
Sam Miorelli
Sam Miorelli@SamMiorelli·
So they breached multiple layers of the security perimeter and were armed and returning fire indiscriminately on the small contingent of Marines defending the Consulate. All things considered I’m surprised more of them weren’t killed. Certainly not “protesters.”
Mustafa מוסטפא 🇺🇸 Μασταφα@CombatJourno

Video purportedly showing US Consulate in Karachi having been swarmed by protestors. Individuals are seen firing into the crowd and into the consulate as they come outside.

English
1
1
19
4.4K
Ursula von der Leyen
Ursula von der Leyen@vonderleyen·
Off the phone with Sheikh Tamim bin Hamad Al Thani of Qatar. We discussed the aftermath of Iran’s reckless and indiscriminate strikes on the country. With the region in deep upheaval, Qatar can count on strong European solidarity. Just as we could count on Qatar’s support to European citizens, and I thanked the Sheikh for this. The risk of further escalation is real. This is why a credible transition in Iran is urgently needed. One that restores stability and paves the way for a lasting solution. This must mean the halt of Iran's military nuclear and ballistic missile programmes and the end of destabilising actions on air, land and at sea. Above all, it must reflect and support the democratic aspirations of the brave people of Iran.
English
2.1K
318
1.8K
1M
Sam Miorelli
Sam Miorelli@SamMiorelli·
@GDNonline So it was a strike from Iran but you’re not allowed to say that?
English
0
0
1
74
GDN Online
GDN Online@GDNonline·
Firefighters have contained a blaze in Crowne Plaza Hotel which damaged its facade today. It follows after loud explosions were heard across the country. No further details have been released. The GDN has contacted hotel officials for a comment.
English
3
14
66
26.4K