Nicolás de Ory
1.7K posts

Nicolás de Ory
@nicodeory
swe & music fighting tariffs by day @meetcaspian (founding eng in SF) building semana by night, the app that helps people become better cooks
🇪🇸Sevilla→San Francisco🇺🇸 شامل ہوئے Temmuz 2019
897 فالونگ226 فالوورز
پن کیا گیا ٹویٹ

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown:
> 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in
> Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions
> All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client
> Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months
> The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done
> Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author
> Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper"
> When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams
> Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved
> When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance
> Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

erin griffith@eringriffith
A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…
English


go try composer 2 in cursor, its a good model

Cursor@cursor_ai
Composer 2 is now available in Cursor.
English

@dsaltaren If you ever drop by the one on 650 California let’s have a coffee!
English

Emilio Delgado, diputado de Más Madrid: "A la izquierda a veces le da pudor hablar de seguridad. Hay barrios en los que los niños no pueden bajar a la calle porque hay movidas. Quien diga que eso no es así es porque no ha vivido nunca en un barrio así"
rtve.es/noticias/20260…
Español
Nicolás de Ory ری ٹویٹ کیا

American mind cannot comprehend vibing to this
The Moderate Case@TheModerateCase
I have absolutely nothing against Bad Bunny as an artist, I’m just confused as to how a population that overwhelmingly speaks English is supposed to enjoy a performance in a language they don’t understand. English is the language of America.
English

El pobre @Recuenco golpeándose la cabeza contra la pared de McKinsey.
Daniela Amodei, cofundadora de Anthropic: "estudiar humanidades será más importante que nunca"
xataka.com/robotica-e-ia/…

Español

@AtlasOfCharts Is regulation the only effective way of tackling this issue?
English

I work in AI safety in a role that gives me insight into a lot of empirical agendas, and given the Opus 4.6 model card, I just want to give a quick take.
We have interpretability methods that are certainly not fully robust. No one in interpretability claims that they are fully robust, and there will be adversarial ways to hijack these methods.
We have RL methods that are poorly understood, can lead to undesirable behavior, and the effects of which over long time-horizons seem broadly negative on alignment so far. Though it is uncertain. We do not fully understand these methods and the effect they have on models.
We have good alignment/capability evals — even some great evals — but the models are now aware when they are being evaluated. This is a truly difficult problem that cannot be easily solved. The models are aware even when we work to make them unaware. The models pick up on any subtle clue. And many of the evals are saturated in any case.
We need more work here, and we need that work to be trustworthy. We need humans to be involved, to remain in the loop. We are not prepared to launch RSI, and labs should refrain from doing so. Optimally, labs should pause soon, so that everyone can catch their breath and decide on a best path forward. I do not think the problem is intractable, and I think empirical work will significantly help, but it is *moving too fast*.
English

The Commission preliminarily finds TikTok’s addictive design in breach of the Digital Services Act (#DSA).
This includes features such as infinite scroll, autoplay, push notifications and its highly personalised recommender system.
Discover what's next: link.europa.eu/4nwKFx.

English

We’re excited to introduce the Waymo World Model—a frontier generative mode for large-scale, hyper-realistic autonomous driving simulation built on @GoogleDeepMind’s Genie 3.
By simulating the “impossible”, we proactively prepare the Waymo Driver for some of the most rare and complex scenarios—from tornadoes to planes landing on freeways—long before it encounters them in the real world.
waymo.com/blog/2026/02/t…
GIF
English

@sanchezcastejon @nytimes Not gonna lie Pedro kinda cooked in this essay
English

They care for aging parents, work in small and large companies, and harvest the food on our tables. On weekends, they walk in our parks and play on the local amateur soccer team.
For me, the choice is clear.
Here is my article for @nytimes:
nytimes.com/2026/02/04/opi…
English









