Policy & Regulation
Delve faces scrutiny as more customers report security incidents
Compliance startup Delve faces mounting scrutiny after multiple customers, including Context AI and Vercel, reported security incidents following the firm's certification processes.
Delve, an embattled compliance startup, is under fire after TechCrunch confirmed the company performed security certifications for Context AI. Last week, Context AI, an AI agent training startup, disclosed a security incident which led to a data breach at Vercel, an app and website hosting giant. According to Vercel, hackers had breached its internal systems and accessed customer data last weekend. The breach occurred after an employee downloaded an app made by Context AI and connected it to Vercel’s corporate account hosted by Google. Gergely Orosz, author of The Pragmatic Engineer, identified Delve as the firm that handled Context AI’s security certification. Context AI has since confirmed it was a Delve customer but has transitioned its compliance program to Vanta and engaged Insight Assurance, an independent audit firm, to conduct new examinations.
The incident follows a pattern of security issues among Delve’s clients. Last month, the troubled startup came under fire when an anonymous whistleblower, DeepDelver, alleged that Delve was faking customer data and using rubber-stamping auditors in its compliance and certification processes. Following these allegations, several of Delve’s customers reported security issues or severed ties:
- LiteLLM: Hackers attacked LiteLLM and planted malware in its open source code. Following the incident, the open source tool provider dumped Delve. Delve was also accused of taking an open source tool and passing it off as its own work without proper license attribution.
- Lovable: The vibe-coding platform—a term for AI-assisted coding—suffered its own security incident. Lovable, which is no longer a Delve customer, ditched the startup in late 2025.
- Y Combinator: The accelerator severed ties with Delve following the controversy.
Delve has denied the allegations of faking customer data. The company stated that it only helps customers prepare for audits like SOC 2—a common security compliance framework. According to a statement from Delve, “Customers fully build and manage their own codebases, infrastructure, and day to day security operations.” Meanwhile, DeepDelver has reported that Delve was denying refunds to customers while taking a team of more than 20 people to an offsite meeting in Hawaii between April 15 and April 19.
Why it matters
Delve’s situation highlights the risks of relying on automated compliance certifications, as multiple customers face security breaches and questions arise regarding the efficacy of the firm’s auditing processes.