Sebastian

310 posts

Sebastian banner
Sebastian

Sebastian

@schaseba

Building software that builds other software @Lovable_dev

Stockholm, Sweden เข้าร่วม Eylül 2024
247 กำลังติดตาม1K ผู้ติดตาม
Ben Nash
Ben Nash@bennash·
@Lovable What are you doing about your SOC Delve problem?
English
1
0
0
52
Lovable
Lovable@Lovable·
Some ideas are too loud to ignore.
English
55
55
672
222.9K
Nelson Lee
Nelson Lee@NelsonXLee·
All of these blah blah companies… and then @Lovable??? They can’t afford more than $10K a year on compliance after raising every month for the past year? Hmm
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
4
0
13
2.7K
ahmetb
ahmetb@ahmetb·
you should beware of using @Lovable @cluely @wisprflow for anything confidential/PII because they most likely obtained compliance through Delve and got frauded themselves.
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
12
10
274
35K
Sebastian รีทวีตแล้ว
Anton Osika – eu/acc
Anton Osika – eu/acc@antonosika·
Introducing Lovable for more general tasks. Lovable has always been for building apps. Today it also becomes your data scientist, your business analyst, your deck builder, and your marketing assistant. This is a big step toward what Lovable is becoming: a general-purpose co-founder that can do anything. See examples below.
English
246
159
2.1K
1.1M
Sebastian
Sebastian@schaseba·
RT @Lovable: To celebrate International Women's Day on March 8th, we're making Lovable completely free to use for the day, powered by @Anth
English
0
7
0
33
Sebastian
Sebastian@schaseba·
@Lovable First unicorn built on Lovable in 2026, let's go
English
0
0
4
297
Lovable
Lovable@Lovable·
Introducing a smarter Lovable that is 71% better at solving complex tasks. Lovable can now do more work, more autonomously—using deeper planning, browser testing, and prompt queuing. Below is how it works.
English
129
97
1K
338K
Felix Haas
Felix Haas@felixhhaas·
Most companies have messy email signatures. So I built a tiny app for Lovable that fixes it 🔥 Everyone gets: → A consistent, on-brand signature → A live preview → One-click copy for Gmail, Superhuman, etc. Sharing the exact prompt below so you can build the same thing for your team 👇 Lovable prompt: "Build a minimal, professional email signature generator. 1/ Features: → Form inputs: Name, Title, Phone, Twitter/X → Live signature preview that updates while typing → Copy button that copies the signature as HTML for email clients → “How to import?” modal with steps for Gmail, macOS Mail, and iOS Mail → Light and dark mode toggle for the preview 2/ Design: → Clean, minimal layout with warm muted colors → Centered content with generous whitespace → Rounded inputs with clear (X) buttons → Subtle fade-up animation on load → Fully responsive on mobile 3/ Signature output: → Company logo at top linking to website → Name in bold → Title and company in muted gray → Phone and Twitter/X separated by a bullet if both exist → Pure HTML with inline styles for maximum email compatibility"
English
49
41
1K
110.2K
Sebastian
Sebastian@schaseba·
See your 2025 recap in Lovable now
Sebastian tweet media
English
1
0
7
407
David Pantera
David Pantera@davidpantera_·
After a non-technical person builds a prototype in @Lovable , any suggestions for tools to use to take it to prod? This is a problematic user journey I'm seeing over and over again at @StanfordGSB . Super awesome prototype...then, no idea what to do next. My suggestion of "take a CS class" is losing its comedic value.
English
85
7
177
30.1K
Sebastian รีทวีตแล้ว
Anton Osika – eu/acc
Anton Osika – eu/acc@antonosika·
We’ve started a new internal series at Lovable: 1. We invite the world's best founders to join virtual sessions with the team 2. The team can ask questions 3. Lovable becomes a place for the team to keep learning First speaker was Patrick Collison from Stripe, who should we invite next?
Anton Osika – eu/acc tweet media
English
50
17
396
108.2K
Sebastian
Sebastian@schaseba·
@importdhruv @Henrik_wes Same interview, he does love Cursor too and everyone at nvidia uses it -- hopefully Lovable too ;-)
English
0
0
1
15
Sebastian รีทวีตแล้ว
Henrik
Henrik@Henrik_wes·
“I love Lovable” - Jensen Huang
English
52
35
627
130.8K
Lovable
Lovable@Lovable·
Introducing Lovable Cloud & AI, a new chapter for vibe coding. Anyone can now build apps with complex AI and backend functionality, just by prompting. 100k+ new ideas, tools, and sites are built on Lovable daily. Today, we're redefining what's possible:
English
685
946
8.7K
4M
Sebastian
Sebastian@schaseba·
@antonosika Come join our team if you're an engineer and are passionate about democratizing building products! 🚀
English
1
1
10
563
Sebastian รีทวีตแล้ว
Anton Osika – eu/acc
Anton Osika – eu/acc@antonosika·
Exactly one year ago, Sebastian joined us as our first hire outside of product engineering. He had started to build his own similar product at the time, but after several lunch discussions with me, he joined our team to build together with us instead. Since then, he’s worked on everything from business operations to the first launch of Lovable. An entrepreneur at heart, Sebastian has shaped countless parts of the company, championed our culture, and continues to push us forward. Super happy to have him on board. PS. If you want to work with Sebastian and the rest of the Lovable team, we're hiring engineers into our product and growth teams. Apply on our website.
Anton Osika – eu/acc tweet media
English
17
6
189
23K
Sebastian
Sebastian@schaseba·
Who is the best product / web designer or design agency you know? Share their name or best work in the comments
English
170
13
325
43.2K
Sebastian
Sebastian@schaseba·
thinking about hiring a Head of Performance & Longevity at @lovable mission: maximize everyone's energy, focus and well-being with the right nutrition, daily rituals, tools, and smart use of health data
English
35
7
159
23.1K