7 ms·
I'm getting the impression that a lot of people in this thread think this is because they violated an open-source license and saying things to the effect of, "t
by maxbond 6mo ago
I'm getting the impression that a lot of people in this thread think this is because they violated an open-source license and saying things to the effect of, "they're just the ones who got caught". I also thought that was the scandal initially. (And when it comes to license violations, yes, there's absolutely more where that came from.)
But that's just the cherry on top. I don't think they're being thrown out because they violated a license. There are really serious fraud allegations. Allegedly they were rubber-stamping noncompliant customers, leaving them exposed to potential criminal liability under regulations like HIPPA.
https://deepdelver.substack.com/p/delve-fake-compliance-as-a-service https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
I've only skimmed this so I do not endorse these allegations, but I think it's context missing from this discussion.
- deleted 6mo ago[deleted]
- fontain 6mo agoYC has no problem with morally questionable behavior, many YC startups do things that are just as shady. YC is, ultimately, not responsible for what these startups choose to do. Delve’s problem is that they betrayed so many other YC companies in the process. An important value of being in YC is access to a ready-made customer base. The licensing issue is nothing compared to their fake audits but it is an affront to the YC community, hence, kicked from the community. I’m sure if Delve has only engaged in fraudulent audits or had only resold another YC company’s product, they would have been allowed to stay, the problem is all of that combined pissed off enough other YC companies.
- throwaway27448 6mo ago> YC is, ultimately, not responsible for what these startups choose to do. Of course they're responsible for their investments; they're just not liable. YC has a lot to answer for in the damage it's wreaked over the years.
- hdgvhicv 6mo agoThe “I just have the arsonist the match, I didn’t tel him to strike it” approach of tech bros has caused untold damage to the world over the last 20 Years.
- senko 6mo ago> YC has a lot to answer for in the damage it's wreaked over the years. What damage is that? (excluding the present case)
- officialchicken 6mo ago> What damage is that? (excluding the present case) That seems to be an introspective question.
- 1attice 6mo agoExtrospection is valid spection
- barry-cotter 6mo ago
- madaxe_again 6mo agoI think it’s partly that, but also that when you have something that is toxic, radioactive and on fire on your ship, you shove it overboard, and assess just how bad the damage was afterwards.
- PunchyHamster 6mo agoOf course, giving money to terrorists also doesn't make the side giving money responsible /s The delusions people establish to feel better about their or someone else they like mistakes...
- dvfjsdhgfv 6mo ago> YC is, ultimately, not responsible for what these startups choose to do. Formally they might not be (depends on the case), but morally they are.
- alanknguyen 6mo agoThis is definitely why they're removed from YC. Their practices affect other YC companies like Lovable and such and that's absolutely unacceptable.
- JasonHEIN 6mo agolol strongly agree it is just cherry on top. In big tech they also copy but just copy in a smart way so I don't believe that's the reason they got removed.
- johnwheeler 6mo ago[flagged]
- bombcar 6mo agoIt looks like a form of covering their ass - they basically (explicitly?) say they've been violating the law and it's Delve's fault.
- trhway 6mo agoit may be anybody. Even somebody at YC wanting to create a background to drop Delve if suppose Delve were shady and they discovered it (i really don't know anything here and am simply speculating, heard about Delve today first time, just googled and read some techcrunch article - it says Delve has 1000 clients - googled employee count - sub-50, and until it is "an Uber for auditors" i have hard time to believe that 50 Silicon Valley people can do even one compliance certification for one client, with AI or without)
- jweir 6mo agoIf you see a fraud and do nothing you are part of the fraud.
- hobofan 6mo agoYes, the way this is being pushed online seems like there is a competitor involved. If not in the initial disclosure, then in the daily rehashing of it. It's also still unclear to me how much fraud they actually were involved in, and how much of the fault falls on them. SOC2 Type II and ISO 27001 are not audited by them, but by actual accredited auditors (apparently mainly Accorp and Gradient), which must have been just as complicit/negligent. As customers of Delve are free to chose their auditors I'm wondering how this hasn't blown up earlier.
- maxbond 6mo agoIf there were not a manipulative competitor, if people just found fraud and abuse of open source compelling and the story was circulating organically, how would that look different? What do you observe that leads you to believe a manipulative competitor is a better hypothesis?
- jacquesm 6mo agoI came across a top tier compliance auditor doing the same thing recently. I tried to talk to them about it and rather than approaching this from a constructive point of view they wanted to know the name of the company that got certified so they could decertify them and essentially asked me to break my NDA. That wasn't going to happen, I wanted to have a far more structural conversation about this and how they probably ended up missing some major items (such as: having non-technical auditors). They weren't interested. They were not at all interested in improving their processes, they were only interested in protecting their reputation. I'm seriously disgusted about this because this was one of the very few auditors that we held in pretty high esteem. Pay-to-play is all too common, and I think that there is a baked in conflict of interest in the whole model.
- vasco 6mo agoIt's auditing, nobody that is good at doing anything goes to auditing, unfortunately its one of those jobs. I haven't interacted with any auditor that actually understood all they were auditing, some are better than others but the average is worse than almost any other job description I have dealt with.
- bob1029 6mo agoYou should check out the banking industry sometime if you'd like to interact with a competent auditor. Compliance gets taken quite seriously in an industry where one of your principal regulatory bodies has the power to unilaterally absorb your business and defenestrate your entire leadership team in the middle of the night.
- jacquesm 6mo agoThey could. But they don't. I've seen this up close. The regulatory bodies as a rule are understaffed, overworked and underpaid. I'm sure they'd love to do a much better job but the reality is that there are just too many ways to give them busywork allowing the real crap to go unnoticed until it is (much) too late.
- miki123211 6mo agoThere's an excellent podcast and writeup on this from Patrick mcKenzie, which explains the story in more detail, including an interpretation of their statement and background on why this is a scandal in the first place. https://www.complexsystemspodcast.com/episodes/delve-into-compliance-theatre/ https://www.complexsystemspodcast.com/episodes/delve-into-co...
- whatever1 6mo agoAll LLMs do this, yet nobody bats an eye.
- deleted 6mo ago[deleted]
- tankenmate 6mo agoLLMs can't be held legally liable, only the people who use them.
- tim333 6mo agoThere's quite a good summary of the allegations here https://www.reddit.com/r/startups/comments/1rz15ui/i_will_not_promote_psa_delve_yc_w24_startup/ https://www.reddit.com/r/startups/comments/1rz15ui/i_will_no... >Pre-written audit conclusions. The "Independent Service Auditor's Report" and all test conclusions were already filled in before clients had even submitted their company descriptions... >Copy-paste templates. 493 out of 494 leaked SOC 2 reports (99.8%) had identical text, same grammatical errors, same nonsensical descriptions...
- Craighead 6mo agohipaa*
- maxbond 6mo agoOops. Thanks for the correction.
- ragall 6mo ago> But that's just the cherry on top. That's not the right metaphor here.
- maxbond 6mo agoWhat should I have used instead?
- ragall 6mo agoIt's "the last straw" or "the drop that overflows the cup". The "cherry in the cake" is in need to be a good thing.
- maxbond 6mo agoI appreciate the feedback. I'll consider how I can be more clear in the future. My usage was ironic. I don't think those fit my meaning because I think the situation would be largely the same without the licencing dispute.
- PeterStuer 6mo agoYou are overcomplicating this. They were ejected because they got caught. What for or how they got caught, does not matter.
- maxbond 6mo ago> You are overcomplicating this. They were ejected because they got caught. I don't see how "they got caught doing X" is more complicated than "they got caught doing Y", but at any rate think it's worth being correct and precise in order to reason from accurate premises. If you absorb a lot of false information you'll start coming to incorrect conclusions and it'll be difficult to understand why. It took me years to unlearn all the bullshit I absorbed from when I used to spent a lot of time watching History channel documentaries. > What for or how they got caught, does not matter. So if they were ejected for jaywalking or for murder, that's all the same to you?