Paul Xue

26.8K posts

Paul Xue banner
Paul Xue

Paul Xue

@pxue

I distribute content on Reddit. 100M+ views across 20 niches. Co-host @gregoryandpaul show. Previously, startup CTO.

🇨🇦 Tham gia Şubat 2010
1.6K Đang theo dõi6.6K Người theo dõi
Gregory Kennedy
Gregory Kennedy@gregorykennedy·
@pxue Bro, with this attitude you will for sure get 30u30
English
1
1
3
120
Paul Xue
Paul Xue@pxue·
Whole SOC2 debacle just shining a light on the industry as a whole. First of all Type 1 is literally a spreadsheet you fill out yourself with the promise to get actual audit done in the next 12 months. If you done it once it literally takes 30 minutes to “pass” type 1. Then kick the tire down the road for next 18 months to properly get it done.
English
1
0
4
320
Paul Xue
Paul Xue@pxue·
Frontier models were hyped as the value center, but Cursor proved harness > model. But so much money has been poured into the big AI narrative, now Cursor must burn billions to pivot the story. No better way than trial by fire.
English
0
0
2
68
Trace Cohen
Trace Cohen@Trace_Cohen·
@pxue Yes @lulumeservey is the best right now I agree but this doesn’t really apply here. Cursor got caught with kimi referenced in their code which is sloppy and admitted it but the damage was really done. And by damage I mean Twitter noise that 99% of users don’t care about.
English
1
0
1
46
Jamon
Jamon@jamonholmgren·
Not going to lie, last night I couldn't sleep hardly at all. A lot of anxiety about how the game would be received. You all have been SO KIND. I'm blown away by the positive responses!
English
13
1
111
2K
Paul Xue
Paul Xue@pxue·
@thekitze Something something not sending your data to China is worth the $25
English
0
0
0
93
kyzo
kyzo@ky__zo·
Fluar just got acquired in an all cash, 6-figure deal I built it solo for 14 months, now it’s going to an industry leading team that can really scale it this is the second startup I’ve sold since I learned to code 3 years ago life is incredible, what a time to be alive 🫡 LFGG
kyzo tweet media
English
132
3
440
24.2K
Paul Xue
Paul Xue@pxue·
@harpreetchatha_ it's the state of the market right now and profound is trying to roll everything into zero click. my guess is they'll eventually roll out some synthetic audience and then double dip into the measurement
English
0
0
2
144
Harpreet
Harpreet@harpreetchatha_·
This case study between Profound & Zapier is genuinely mandatory reading if you want to understand the grift behind GEO / AEO. The growth analytics manager at Zapier said that without the AI visibility tool, "they have zero visibility into what LLMs said about them". I wonder if these people use AI themselves? Then "Standing up an AEO program". Profound says that Zapier's AEO program entails "alternative and head-to-head articles". Zapier wanted to own listicles. They have a quote in there which says "they made the decision to double down on AI search as a net-new channel, not a sidecar to SEO". They doubled down via lisicles. I'm gonna leave it at that. Scaling listicles is not an AEO program lol. If VPs, CMOs & marketing leaders are dumb enough to fall for this type of stuff them good luck to those companies. Stay safe out there.
Harpreet tweet media
English
7
2
39
2.8K
Koby Conrad 🌻
Koby Conrad 🌻@kobyjconrad·
These compliance companies are ripping each other apart in a dirty as hell fight and I absolutely guarantee you this is some black hat oppo mud slinging The guy who wrote this literally emailed me which is a CANSPAM violation & half this shit is made up and misleading
English
3
0
67
12.5K
Koby Conrad 🌻
Koby Conrad 🌻@kobyjconrad·
Just a PSA we use Delve. Delve does EXACTLY what EVERY other company in this space does, they provide a checklist and help you automate your compliance. WE are still responsible for our security. Not Delve. This industry is shady AF and this anon is 100% a competitor 🫡
erin griffith@eringriffith

A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…

English
52
9
395
156.6K
Paul Xue
Paul Xue@pxue·
@ohryansbelt Reddit knows man. soc2/cybersecurity subreddit got swarmed with their astroturfing posts
English
0
0
2
81
Paul Xue
Paul Xue@pxue·
But gotta say they got a kickass Reddit strategy
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
2
0
6
2.1K
chris
chris@chrislevan·
gm all, pleased to announce i’ve earned the absolute badge of honour. i also am a toronto accelerator.
chris tweet media
English
21
1
92
3.9K
Jonathan Wilke
Jonathan Wilke@jonathan_wilke·
Holy crap... with the @nextjs 16.2 update the next server is now using 10GB+ of memory and my MacBooks fan is running constantly (before it never even turned on). What's going on here...
Jonathan Wilke tweet media
English
71
10
544
77.8K
Paul Xue
Paul Xue@pxue·
Low key the highest leverage activity you can do for any business is to invest 6 month into SEO/AEO from day 1. Do it yourself, then when things are working, hire an agency. It shouldn't cost more than $3K a month.
English
1
0
10
407
Abby Grills
Abby Grills@AGrillz·
I added Founder profiles! Filter and search ALL @ycombinator founders. You can see: - Repeat YC founders - Career path (eng/product/sales/consulting) - Years work experience - Prev. notable employers - Education - College Dropouts Check it out --> yc-update-tracker.lovable.app/founders
Abby Grills@AGrillz

I made a free web app that tracks @ycombinator companies. It updates when: - A new company is listed to YC’s website - A company does a launch post - A company changes their name or tagline/one-liner You can even download the full list of all the companies YC has ever funded.

English
5
1
10
2.7K
Paul Razvan Berg
Paul Razvan Berg@PaulRBerg·
This is the most annoying thing in Claude Code. Hiding raw text when you paste more than 4 lines. Terrible UX decision.
Paul Razvan Berg tweet media
English
383
13
1.5K
215.1K
nico
nico@nicochristie·
@tryshortcutai is growing ~50% MoM and we are looking for a world-class technical GTM person to join the team. Looking for someone relentless, and passionate about profoundly solving spreadsheet work. DM me (bonus for a referral!) TC $220-$300K Cash + Equity
nico tweet media
English
13
10
109
9.9K
Paul Xue
Paul Xue@pxue·
Claude just casually creating visualizations directly in chat from database and API data. Why even vibe code anymore..
Paul Xue tweet media
English
0
1
10
371