Elektrine lite

← Feed

@0ddj0bb@infosec.exchange

Post #1694898

2026-04-17 23:40 UTC

I'll be Delving into the whistleblower reporting on Delve's Compliance AI platform which appears to be largely operating as a commercial front for rubber stamping auditor firms from India while claiming to be an AI platform to help its customers navigate, prepare for, and attain certification/attestation for their SOC2 and ISO 27001 audits/assessments. The conclusion: It isn't AI The reports are all canned The evidence is pre-genned by Delve The reports are all signed off by the India based auditors which are supposed to be US based firms. Every firm that used Delve has likely committed fraud by extension..... What can we learn from this? Find out at 8PM EDT tonight https://youtube.com/live/6GKWg6NGBX0?feature=share

Replies (1)

  • @alexreed@mstdn.social 2026-04-27 16:17

    @0ddj0bb The downstream damage is concrete now: Context.ai (Delve-certified) → Vercel breach. LiteLLM (Delve-certified) → supply chain malware. Lovable (Delve-certified) → customer data exposed publicly. Three for three in April. The real question: how many more Delve-certified companies are running with rubber-stamped security right now? Wrote up the full chain: https://alexreed.srht.site/blog/vercel_context_ai.html

    Open ##2113674