Matt Popovich

23.7K posts

Matt Popovich banner
Matt Popovich

Matt Popovich

@mpopv

dad. staff engineer @forge_global, webmaster @makeemoji, ex @awscloud. tech, housing, and future enjoyer. radical normie lib extremist

🌁 Bay Area, California, USA Katılım Mart 2014
4.5K Takip Edilen6.6K Takipçiler
Ramp Capital
Ramp Capital@RampCapitalLLC·
The fuck is going on here
Ramp Capital tweet media
English
127
45
775
91.3K
Matt Popovich
Matt Popovich@mpopv·
@barrald if that article is to be believed, their customers were essentially co conspirators
English
1
0
21
1.5K
Barry McCardel
Barry McCardel@barrald·
there's something truly sublime about cluely being scammed on their SOC 2
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
14
37
1.3K
72.3K
Matt Popovich retweetledi
Ryan Moulton
Ryan Moulton@moultano·
The American west is currently seeing all time record temperatures for March, temperatures it doesn't typically see until the middle of summer. The Sunrise Movement has not posted about climate change in weeks. Nearly every post mentions AIPAC.
Sunrise Movement 🌅@sunrisemvmt

BREAKING: Rep. DeGette gets heated with a constituent pressing her on why she voted to send bombs to Israel: "If this the only issue that you care about is this issue, then you should not vote for me" DeGette, who's 68, is facing a primary challenge from @MelatKirosCO.

English
14
79
944
24.1K
Matt Popovich retweetledi
Matt Popovich
Matt Popovich@mpopv·
@0xCharlota I’ve started saying “I don’t think so, chief” a lot, hoping they’ll catch on
English
0
0
0
43
charlota
charlota@0xCharlota·
a reminder that you have free will and can teach your toddler to yell "mamma mia" whenever they drop something I did this. so cute. no regrets.
English
4
1
55
1.6K
Matt Popovich retweetledi
larrikin
larrikin@HELLLLHOOOOLE·
Got my horse to water. Now for the easy part
English
98
6.1K
88K
2.8M
Sen. Bernie Sanders
Sen. Bernie Sanders@SenSanders·
I spoke to Anthropic’s AI agent Claude about AI collecting massive amounts of personal data and how that information is being used to violate our privacy rights. What an AI agent says about the dangers of AI is shocking and should wake us up.
English
1.4K
3.4K
21.6K
5.2M
Matt Popovich retweetledi
۟
۟@4NGELWING·
no bro don’t buy airpods. you need the Sony WH-1000XM5-WHCH720N-WF1000XM5-CH520
English
1.1K
19.2K
307.7K
5.6M
Matt Popovich
Matt Popovich@mpopv·
In the future the only jobs will be - robot car door closer - one person billion dollar company vibe coder - federal government claude deleter - agi lab acquihired dev tooling founder - sea mine removal specialist
English
0
0
9
248
Emio
Emio@mrtomeoni·
@mpopv @ja3k_ They hate knowing what they are paying The LOVE spending
English
2
0
6
263
ja3k
ja3k@ja3k_·
Idk why gas prices are so culturally salient in america. You could drive an hour a day and it probably comes to less than $3k/year. Is it because they put the price on billboards along the road?
English
652
47
5.5K
1.7M
Cooper
Cooper@enlightenedcoop·
if you asked chatgpt/claude/llms for relationship advice, has it been correct in hindsight?
English
3
0
4
2.2K