bone

84.1K posts

bone banner
bone

bone

@boneGPT

the wrapper eater

Cape Canaveral, FL Katılım Nisan 2023
8.1K Takip Edilen53.1K Takipçiler
Shobhit Bakliwal
Shobhit Bakliwal@shobhitic·
saw this interview of founder of delve yesterday on instagram
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
52
48
861
103.9K
Nikita Bier
Nikita Bier@nikitabier·
I feel bad for any reporter that has to write about my deranged shitposts.
Nikita Bier tweet media
English
297
41
867
38.3K
bone
bone@boneGPT·
This game has a guy that buys used ducks
bone tweet media
English
8
0
22
1.2K
bone
bone@boneGPT·
@yacineMTB They'll need gstack more than ever now
English
0
0
42
2.1K
bone retweetledi
MACHO Δ
MACHO Δ@MachoXV·
@boneGPT That guy probably shouldn't have posted that. Jack Ma moment incoming
English
4
2
81
11.9K
James Grugett
James Grugett@jahooma·
Introducing Freebuff: the free coding agent 100% free, up to 10x as fast as Claude Code npm install -g freebuff
English
73
54
527
55K
Spin Effect
Spin Effect@spineffect1983·
@boneGPT I just downloaded, been hooked on the new BF6 map. whats your steam handle broski?
English
1
0
1
149
bone
bone@boneGPT·
Crimson desert is an impressive game.
English
17
1
80
2.3K
Moongazer
Moongazer@joeybeastmarket·
@boneGPT It looked kind of vacant when I saw some gameplay I’m glad if it isn’t
English
1
0
1
281
bone
bone@boneGPT·
@DOJNatSec Holy shit they actually did it. There was that video going around of the Chinese unloading supermicro boxes.
English
3
4
289
9.3K
National Security Division, U.S. Dept of Justice
Three Charged with Conspiring to Unlawfully Divert Cutting Edge U.S. Artificial Intelligence Technology to China “The indictment unsealed today details alleged efforts to evade U.S. export laws through false documents, staged dummy servers to mislead inspectors, and convoluted transshipment schemes, in order to obfuscate the true destination of restricted AI technology—China,” said John A. Eisenberg, Assistant Attorney General for National Security. “These chips are the product of American ingenuity, and NSD will continue to enforce our export-control laws to protect that advantage.” 🔗: justice.gov/opa/pr/three-c…
National Security Division, U.S. Dept of Justice tweet media
English
215
1.2K
3.8K
3.2M
bone
bone@boneGPT·
@andyfang UBI will be recording yourself for the computer
English
1
2
33
660
Andy Fang
Andy Fang@andyfang·
Introducing Dasher Tasks Dashers can now get paid to do general tasks. We think this will be huge for building the frontier of physical intelligence. Look forward to seeing where this goes!
Andy Fang tweet media
English
267
149
3K
1.2M
bone
bone@boneGPT·
@tbpn @mcuban i do this, have a few five letter domains and a bunch of randoms ones
English
1
0
5
992
TBPN
TBPN@tbpn·
After buying broadcast dotcom for $8,000 in 1997, @mcuban went on a domain name buying spree when he realized he could use simple URLs to route traffic to the site. As a result, he says he now owns democracy dotcom, baseball dotcom, mrpresident dotcom, sandwich dotcom, finalfour dotcom, and more. "You name it, I've bought it."
English
29
27
524
252.7K
erin griffith
erin griffith@eringriffith·
A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…
English
120
144
2K
1.7M
bone retweetledi
Not Samantha A
Not Samantha A@Samhain948689·
every day you stray further from god
Not Samantha A tweet media
English
1
1
25
688
bone
bone@boneGPT·
@9mmsmg during the daytime, never middle of the night hell yeah
English
1
0
30
664
9mmSMG
9mmSMG@9mmsmg·
Drove by a Taco Bell, and there was actually a line at the drive-through. How are people eating this stuff? Fast food is trash in general, but Taco Bell is bottom rung for me. Wouldn't eat it if it were free. What's wrong with you people?
English
1.2K
29
1.2K
157.2K