Mycroft

29 posts

Mycroft banner
Mycroft

Mycroft

@Mycroftsecurity

Mycroft offers a cybersecurity and compliance platform that serves as your personal virtual security officer, while providing your full security stack.

Toronto, Canada شامل ہوئے Kasım 2025
12 فالونگ8 فالوورز
Henrick Johansson
Henrick Johansson@compliantvc·
Sorry to all the folks dealing with this. If you've been affected, email the Comp AI team at sales@trycomp.ai before the end of March with your Delve invoice, and they'll give you a year of @compai for free.
erin griffith@eringriffith

A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…

English
58
202
355
245K
Evis Drenova
Evis Drenova@evisdrenova·
I will never use @TrustVanta again after how they just treated us. My company was acquired in August of 2025. We promptly emailed Vanta to inform them that we are shutting down our business and need to cancel. After 1 month, they finally replied with direction. "Can you send us acquisition documents?" I replied back and said "I can't legally share our acquisition documents with a vendor, what do you need?" They then ghosted us until January of 2026 (5 months later). During this time, they charged us for 2 quarterly payments (about $5K total). In January 2026, they finally said they need a certificate of dissolution, which I sent to them. They then refunded us $700. I asked for a refund dating back to August 26th when we initially sent the cancellation email. They responded with, "we cannot refund you because the Vanta software was still running until January of 2026. " It was running BECAUSE YOU GHOSTED US AND DIDN'T PROCESS OUR CANCELLATION. @christinacaci is this how you do business and treat your customers who trusted you for 2+ years?
English
79
19
1.3K
219.9K
Mycroft
Mycroft@Mycroftsecurity·
@evisdrenova @TrustVanta Wow this sounds a lot like @deeptrustAI and what they've gone through. Alongside a few others. It's true that they are abandoning the SMB market btw.
English
0
0
2
4.6K
Kim Chi
Kim Chi@KimChiSpicey·
Delve’s trying to make a comeback. After saying they’ll actually do real compliance now. Then he ends with an invite to get on a sales call veiled as a lunch and learn.
Karun Kaushik@karunkaushik_

Over the past week, you may have seen an anonymous post about Delve. While we responded to it in a day, we want to provide more details about what’s true, what's not, and some changes we’ve made. There’s one question behind everything: did Delve fabricate compliance evidence or issue fraudulent audit reports? No. We did not. → Delve is an AI compliance platform that connects customers with independent auditors. We are not an auditor, just as tax preparation software is not an accountant. We have never signed an audit report. → Using default templates for our customers, just like any other compliance platform, is not “faking evidence.” These are meant to serve as a starting point for customers. → Delve does have automation in the platform, with 600+ automated integration tests, an AI Copilot to guide customers through compliance, AI code scanning, and more. -- We built Delve to accelerate innovation by bringing AI to compliance. In doing that, we pushed hard on automation. However, we now realize we didn’t provide enough clarity about what is automated, what is customer-provided, and what is independently audited. We have been working relentlessly to make improvements over the last week. -- On our auditor network: Delve connects customers with independent auditors. Some customers choose their own auditors, but many use firms in our network. Questions have been raised about some of those firms, including ones used by other platforms. Going forward we will set a higher bar in how our auditor relationships are structured and how the process is experienced by customers. Delve is rebuilding our auditor network, removing firms that don’t meet our standards, and offering complimentary re-audits and penetration tests to every customer. On platform templates for our customers: Delve provides default templates, just like many other platforms, for policies, board meetings, risk assessments, and more. These are designed to be starting points only. We should have been more explicit about how they are meant to be reviewed and customized by customers. We are making that indisputably clearer within the platform. On draft audit reports: Third-party auditors are responsible for independently reviewing all evidence and issuing final reports. We built automation that interacts closely with independent audit workflows to help expedite the process on behalf of our customers. However, this contributed to confusion about where automation ends and independent judgment begins. From now on, Delve will no longer automate these parts of the process. Furthermore, customers have a direct line of communication with their auditor to enhance transparency in any audit communications. -- We started Delve because we went through compliance ourselves and saw how slow, expensive, and manual it was. To anyone that wants to sit down and discuss our product philosophy and improvements, please reach out and let’s chat about it.

English
3
0
36
8.8K
Mycroft
Mycroft@Mycroftsecurity·
@BryanOnel86 Yes I think they took that from Complementary User Entity Controls so they learned something about SOC 2
English
0
0
0
99
Mycroft
Mycroft@Mycroftsecurity·
@ZackKorman SOC 2 isn't even a certification, it's an attestation.
English
0
0
1
50
Zack Korman
Zack Korman@ZackKorman·
How do we feel about companies removing the Delve logo but continuing to brag about being SOC2 certified?
Zack Korman tweet media
English
47
22
599
35.4K
Mycroft
Mycroft@Mycroftsecurity·
@BryanOnel86 That is pretty damn accurate but also the other crazy part is customers don't even have an engagement letter with the auditors either.
English
0
0
2
1.3K
Bryan Onel
Bryan Onel@BryanOnel86·
I've talked to dozens of Delve customers wanting to switch to Oneleet over the past two days. One thing that stands out, which is wild to me, is that all of Delve's clients who were in the middle of their SOC 2 observation period, did not know who their auditor was. They thought auditors were assigned/selected after the observation period. Let that sink in.
English
9
7
172
21.9K
Mycroft
Mycroft@Mycroftsecurity·
@KimChiSpicey @pulse_petal We have a pristine track record but by no means are we perfect. Honestly this space is meant to be hard to break into and build trust. I say only ones who haven’t had any audit mill connections are Drata, Vanta, Thoropass (they have their own audit firm), and Mycroft.
English
0
0
0
36
Kim Chi
Kim Chi@KimChiSpicey·
@Mycroftsecurity @pulse_petal Yikes... So I’m guessing your take is that Mycroft is the best option? Lol The compliance and security space sounds pretty savage.
English
1
0
3
150
Kim Chi
Kim Chi@KimChiSpicey·
Been reading up on the Delve drama. What I’m gathering so far: > The Delve CEO pretended to be a prospect with Oneleet > Turns around and rips off their entire business model > Builds an AI slop clone that’s “faster and cheaper” because they’re fraudmaxxing fake audits > Delve gets exposed by the anonymous leak > Now Oneleet’s scooping up Delve’s customers offering discounts and celebrating their downfall Did Bryan (Oneleet founder) go full-blown Mr Robot on Delve and drop that hit piece? That would be so based.
Bryan Onel@BryanOnel86

Oh this story goes way back. Blood was first drawn well over a year ago now.

English
1
3
31
7.3K
Mycroft
Mycroft@Mycroftsecurity·
@KimChiSpicey @pulse_petal OneLeet has also used the same audit mills as disclosed by Deepdelver and actually lied that their processes were different (and also said the audit mill passed AICPA quality review - spoiler - they didn't).
English
1
0
1
129
Kim Chi
Kim Chi@KimChiSpicey·
@pulse_petal Spicy. It sounds like Oneleet is doing actual security reviews at least. What’s the best option? And is 100% slop-free even possible anymore?
English
1
0
1
486
Mycroft
Mycroft@Mycroftsecurity·
Things to do based on @getdelve 's situation: 1) Don't panic. 2) Pull out every agreement that references your SOC 2. 3) Review your cure period for those contracts that's your timeline to fix (usually 30-60 days). 4) Communicate, proactive communication wins trust always.
English
0
1
3
108
Mycroft
Mycroft@Mycroftsecurity·
@wolfofbaystreet Did you know that in fraud, indemnification clauses don't apply?
English
0
0
1
120
Mycroft ری ٹویٹ کیا
kazi
kazi@wolfofbaystreet·
If this goes to court I sense one cofounder will throw the other under the bus next week.
English
6
1
246
19.8K
kazi
kazi@wolfofbaystreet·
If you were affected by the Delve scam there’s hope. It took 9 emails and threat of lawsuit/Stripe chargeback, but we got it done.
kazi tweet mediakazi tweet media
English
40
34
1.1K
145.9K
Mycroft ری ٹویٹ کیا
Moin Nadeem
Moin Nadeem@moinnadeem·
Wait, hold on, Delve left a bucket with the screenshots of our network architecture diagram open to the public? That's a lot of IP!
Moin Nadeem tweet media
English
12
14
307
49.1K
Mycroft
Mycroft@Mycroftsecurity·
@andriy_mulyar @secureframe @getdelve As a team who lived through that process many times - it’s definitely hard as we are 90% there but not 95%. I know the vision and the promises, if you’re looking for something that’s not fake - let’s chat.
English
0
0
0
32
Andriy Mulyar
Andriy Mulyar@andriy_mulyar·
My take on Delve and experience after 3 audit cycles as a founder -> We've been a decently happy customer of @secureframe the last few years but were considering migrating to @getdelve this January (took some sales calls, got some data in to feel the experience). Here's my take on the situation: I've done 3 audit cycles now where my team (and originally just me) spent weeks every quarter pulling data, filling out spreadsheets, etc to adhere to SOC 2 controls. This was followed by a painful 2-3 month audit period where I felt auditors and the underlying platform were heavily out of sync - auditors would request things that we had already synced/uploaded into the compliance tool, escalatory meetings would happen just to resolve to 'that is ok, sorry we missed it'. The promise of Delve, for me, was AI-native compliance. A platform that didn't just do 80% of the work (controls auto-synced to cloud infra, evidence pulled via vendor APIs) but got us to 95%: where agents did the annoying stuff that the other platforms couldn't handle (auto checking access roles in every vendor, filling out excel sheets first to then to hand over for human verification). Where auditors actually understood the platform holding the evidence they were auditing. I was really onboard with the vision of Delve their team and sales folks pitched me. My gripe with all the existing vendors (@TrustVanta , @DrataHQ, @secureframe ) was this: They built their tech stack and process up up pre-AI. I felt their product roadmap moved very slow, lots of small bugs everywhere and so much silly stuff has to be done manually. One hour my team is orchestrating coding agents and the next hour huddled in a call filling out an Excel sheet - it felt like these existing platforms were 'on the wrong exponential'. We're obviously sticking with Secureframe for now but the above facts still haven't changed. Im certain someone will disrupt the space by achieving the above vision - it's unfortunate that it probably won't be Delve.
English
11
2
103
23.7K
Bryan Onel
Bryan Onel@BryanOnel86·
Good morning! Fun fact of the day: Accorp made a public statement that none of the hundreds of Accorp reports part of the Delve leak ARE THEIRS. (Link in comments).
Bryan Onel tweet media
English
16
9
211
31.9K
Mycroft
Mycroft@Mycroftsecurity·
@shiftj Compliance theater is what the industry has led to, the actual purpose is independent assessment and verification. CPAs with CISA (Certified Information Systems Auditor) are typically ones that issue SOC 2 reports (if they're decently reputable). People started gaming SOC 2.
English
0
0
0
20
JC
JC@shiftj·
Unpopular Opinion: SOC 2 is a scam. It's not just Delve. The entire system is flawed. 👇 1/ Why are CPAs auditing your security?
English
31
9
298
50K