letsbuildmore

3.7K posts

letsbuildmore

letsbuildmore

@letsbuildmore

Oppression always has two sides to it. The one who does it. And the one who silently watches it. Don't be on either side. Society, Philosophy, tech in pinned!

Katılım Aralık 2019
220 Takip Edilen463 Takipçiler
Sabitlenmiş Tweet
letsbuildmore
letsbuildmore@letsbuildmore·
Life, Society, Technology: 🧵 1. On Things that really matter in Life !
letsbuildmore tweet medialetsbuildmore tweet medialetsbuildmore tweet media
English
1
0
1
1.3K
Feifan Zhou
Feifan Zhou@FeifanZ·
We talked to Delve last summer. Heard a few concerning stories behind the scenes; decided to go with someone else for our SOC II. Glad we did. We take security seriously at Tanagram.
Feifan Zhou tweet media
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
8
3
160
35.5K
letsbuildmore retweetledi
Ryan
Ryan@ohryansbelt·
Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor
Ryan tweet media
erin griffith@eringriffith

A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…

English
216
314
3.8K
1.3M
letsbuildmore retweetledi
Nostra, House of Gold
Nostra, House of Gold@Nostre_damus·
the laundry room on the F-35 caught fire
English
337
3.7K
28.6K
402.3K
letsbuildmore retweetledi
Steve Sweeney
Steve Sweeney@SweeneySteve·
Today I$rael tried to kill me in a targeted airstrike in southern Lebanon as I was reporting on was the targeting of bridges and the forced displacement of 1 million people, an ethnic cleansing operation on a larger scale than the Nakba I have absolutely no doubt that this was deliberate. Despite claims there were no warnings ahead of the strike and no notifications sent to the Lebanese Army who allowed us to film As we have seen in Gaza they want to silence journalists who document and report their war crimes It is the western powers who provide political and military support for I$rael, arming it to the teeth to carry out genocide in Gaza and ethnic cleansing here in Lebanon. They are not simply complicit, but active participants and should be held accountable for their actions. But if I$rael thinks today’s strike will silence us and keep us out of the field they are very, very mistaken
English
5.5K
58.4K
192.8K
5.9M
letsbuildmore
letsbuildmore@letsbuildmore·
@devahaz @holman They all did it because they could openly grift the ppl of America. Biden govt at least had laws and DOJ was about to file fraud charges against Elon.
English
0
0
1
19
Deva Hazarika
Deva Hazarika@devahaz·
Elon, Andreesen, Sacks, Ackman, Chamath, Vivek, on and on, I remember when for all these guys it was critical to elect Trump because our national debt was a crisis and existential threat to the future of America only he would tackle. Don’t hear so much about that anymore.
English
186
886
7.4K
219.8K
letsbuildmore retweetledi
First Squawk
First Squawk@FirstSquawk·
SAUDI REPORTS SEVERAL SAUDI ARAMCO REFINERIES ON FIRE #BREAKING
Català
48
720
3.2K
313.8K
letsbuildmore retweetledi
Haytham Kaafarani
Haytham Kaafarani@hayfarani·
I am a US citizen & Surgeon who took care of the Boston Maraton Bombing victims in 2013. I paid for 7 years to own a small apartment in downtown #Beirut for my 3 kids to enjoy summers there. Today, #Israel reduced my dream home to rubble, with american weapons, paid by my taxes.
English
8.9K
46.3K
197.7K
9M
letsbuildmore retweetledi
Dean
Dean@DJPopil·
Or they simply cannot get fuel. I spoke with my brother who lives in Bangkok, and he can’t find diesel anywhere. Every gas station is out. He drove to 14 different gas stations.
Anas Alhajji@anasalhajji

Oil Demand Destruction!

English
23
165
1.2K
144.7K
letsbuildmore
letsbuildmore@letsbuildmore·
@CaitlinBigelow @zainjaffer The day u all wud get my take, Blazel wud become a decent product. Not everything in life needs to seek virality at all costs. I guess ppl have still not learnt the lesson from Cluely.
English
0
0
0
9
Caitlin Bigelow
Caitlin Bigelow@CaitlinBigelow·
@letsbuildmore @zainjaffer I agree. 100%. Terrible idea. Whoever came up with this viral joke should definitely be fired immediately. Zero 2nd chances.
English
1
0
0
7
Zain Jaffer
Zain Jaffer@zainjaffer·
Did a tough performance review with our CMO today. Decided to post the full video online in the spirit of transparency and building in public.
English
22
10
369
169.8K
letsbuildmore
letsbuildmore@letsbuildmore·
@JacobShap @robsonjackie3 he is not wrong. If China really wants to take Taiwan, this is the best moment. US is already weak in ammunition and engaged with Iran. China won't have a better time than this. Is it correct? Does China care what is correct or not? Of course not.
English
1
0
0
34
letsbuildmore retweetledi
𝙎👼🏻
𝙎👼🏻@SZade15·
@WhiteHouse Trump knew it. Trump was in on it.
𝙎👼🏻 tweet media
English
17
104
1.4K
51.2K
letsbuildmore retweetledi
letsbuildmore retweetledi
Attaqa Breaking News عاجل الطاقة
عاجل... حرائق في عدة منشآت غاز مسال بدولة قطر إثر هجمات صاروخية قبل قليل بيان لشركة قطر للطاقة يؤكد وقوع أضرار جسيمة
Attaqa Breaking News عاجل الطاقة tweet media
العربية
0
23
46
62.5K
letsbuildmore retweetledi
Arnaud Bertrand
Arnaud Bertrand@RnaudBertrand·
This is probably the most important article of the month: an op-ed by Oman's Foreign Minister, who mediated the talks between the U.S. and Iran, in which he writes that the U.S. "has lost control of its foreign policy" to Israel. He repeats that a deal was possible as an outcome of the talks (something confirmed by the UK's National Security Advisor, who also attended: x.com/i/status/20341…) and that the military strike by the U.S. and Israel was "a shock." Interestingly, given he is one of Iran's neighbors and given that Oman has been struck multiple times by Iran since the war began (en.wikipedia.org/wiki/2026_Iran…), he writes that "Iran’s retaliation against what it claims are American targets on the territory of its neighbours was an inevitable result" of the U.S.-Israeli attack. He describes it as "probably the only rational option available to the Iranian leadership." He says the war "endangers" the region's entire "economic model in which global sport, tourism, aviation and technology were to play an important role." He adds that "if this had not been anticipated by the architects of this war, that was surely a grave miscalculation." But, he adds, the "greatest miscalculation" of all for the U.S. "was allowing itself to be drawn into this war in the first place." In his view this was the doing of "Israel’s leadership" who "persuaded America that Iran had been so weakened by sanctions, internal divisions and the American-Israeli bombings of its nuclear sites last June, that an unconditional surrender would swiftly follow the initial assault and the assassination of the supreme leader." Obviously, this proved completely wrong, and the U.S. is now in a quagmire. He says that, given this, "America’s friends have a responsibility to tell the truth," which is that "there are two parties to this war who have nothing to gain from it," namely "Iran and America." He says that all of the U.S. interests in the region (end to nuclear proliferation, secure energy supply chains, investment opportunities) are "best achieved with Iran at peace." As he writes, "this is an uncomfortable truth to tell, because it involves indicating the extent to which America has lost control of its own foreign policy. But it must be told." He then proposes a couple of paths to get back to the negotiating table, although he recognizes how difficult it would be for Iran "to return to dialogue with an administration that twice switched abruptly from talks to bombing and assassination." That's perhaps the most profound damage Trump did during this entire episode: the complete discrediting of diplomacy. If Iran was taught anything, it is: don't negotiate with the U.S., it's a trap that will literally kill you. The great irony of the man who sold himself as a dealmaker is that he taught the world one thing: don't make deals with my country. Link to the article: economist.com/by-invitation/…
Arnaud Bertrand tweet media
English
303
8.2K
18.9K
1.2M
letsbuildmore retweetledi
BuccoCapital Bloke
BuccoCapital Bloke@buccocapital·
Wow. Anthropic is eating OpenAI’s lunch in the enterprise
BuccoCapital Bloke tweet media
English
75
117
1.5K
202.6K