Startups & Funding
Delve parts ways with Y Combinator amid controversy
Compliance startup Delve has parted ways with startup accelerator Y Combinator as the company faces allegations of misleading clients and a reported malicious data attack.
Delve is no longer listed in the directory of portfolio companies for Y Combinator, a startup accelerator. The separation was confirmed by Delve’s chief operating officer, Selin Kocalar, who stated that the accelerator and the startup had parted ways. Kocalar expressed gratitude to the community and recalled their initial interview at MIT. The move follows the removal of Delve’s page from the accelerator’s website. Insight Partners, an investor that distanced itself from Delve, also appeared to delete posts regarding its investment in the startup, though its primary blog post was later restored.
The split follows serious allegations published by an anonymous accuser known as DeepDelver. The accuser claims that Delve misled clients by telling them they were compliant with privacy and security regulations while allegedly skipping important requirements and auto-generating reports for “certification mills that rubber stamp reports.” DeepDelver, who described themselves as a former customer, published what they claimed were internal Slack messages and video posts from the startup. The accuser also accused Delve of using an open-source tool without proper credit. Additionally, a security researcher reportedly accessed sensitive Delve data, and malware was discovered in an open source project developed by LiteLLM, a customer of Delve.
Delve’s leadership has strongly rejected the accusations. In a joint statement, Kocalar and CEO Karun Kaushik claimed the company was targeted by a security breach rather than a legitimate whistleblower. The executives stated that it appears an attacker purchased Delve under false pretenses, maliciously exfiltrated data, including Delve’s internal company data, and used it to launch a coordinated smear campaign. They characterized the anonymous claims as a mix of fabricated assertions and cherry-picked screenshots, noting that the accuser dismissed their AI technology despite acknowledging it automated 70% of a security questionnaire. Regarding the open-source software, Delve stated it built upon an Apache 2.0 repository that permits commercial use. However, Kaushik also acknowledged operational shortcomings, stating, “[W]e grew too fast and fell short of our own standard. To our customers, we deeply apologize for the inconveniences caused.”
Why it matters
The controversy surrounding Delve’s compliance practices has escalated, resulting in the startup losing its backing from Y Combinator, a significant signal of reputational damage in the startup ecosystem.