Drooid Logo
Back to story perspectives

Full Breakdown

Delve's Departure from Y Combinator Amid Compliance Controversy

4/5/2026, 8:16:03 PM

Core Event: Delve Parts Ways with Y Combinator

Delve, a compliance startup founded in 2023, has severed ties with its backer Y Combinator (YC) following serious allegations regarding the authenticity of its compliance certifications. The startup is no longer listed in YC’s directory, and COO Selin Kocalar confirmed the split on social media, expressing gratitude for the YC community. This decision comes in the wake of claims that Delve misled clients about their compliance with privacy and security regulations, allegedly fabricating certifications for hundreds of clients.

Background & Context: Allegations of Misconduct

The controversy surrounding Delve intensified after an anonymous Substack post by a user named "DeepDelver" accused the startup of generating compliance documents that lacked proper auditing. The post suggested that many SOC 2 reports were identical, with only minor changes, and raised concerns about the independence of Delve's auditors, who were purportedly outsourced to firms in India. Additionally, it was claimed that Delve used an open-source tool without proper attribution, presenting it as its own.

Delve's Response: Claims of a Smear Campaign

In response to the allegations, Delve's leadership, including CEO Karun Kaushik and COO Kocalar, asserted that the accusations stemmed from a targeted cyberattack rather than legitimate whistleblowing. They stated that an attacker had purchased Delve under false pretenses, exfiltrated internal data, and launched a smear campaign. Delve has since engaged a cybersecurity firm to investigate the claims and has implemented measures to restore client confidence, including offering free re-audits and enhancing transparency in audit communications.

Criticism & Opposition: Concerns Over Compliance Integrity

Critics of Delve have pointed to the implications of the allegations, emphasizing that compromised compliance certifications could expose businesses to significant legal and financial risks. The potential for fines under regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR) underscores the seriousness of the situation. The anonymous claims have raised questions about the integrity of Delve's operations and the validity of its compliance certifications.

Official Statements & Responses

Delve's executives have publicly stated their commitment to addressing the allegations. Kaushik acknowledged the company's rapid growth and the resulting shortcomings, apologizing to customers for any inconveniences caused. They maintain that the claims made by DeepDelver are a mix of fabricated information and misrepresented data, asserting that their AI technology automates a significant portion of compliance processes.

Conflicting Reports & Gaps: Divergent Perspectives

While Delve insists that the allegations are unfounded and part of a coordinated attack, the anonymous claims continue to circulate, raising doubts among clients and investors. The discrepancy between Delve's defense and the accusations highlights the ongoing uncertainty surrounding the startup's practices and the potential ramifications for its business model.

Verbatim Quotes

  • “Kaushik wrote, “We believe the attacker purchased Delve under false pretences, exfiltrated internal company data, and used it to launch a coordinated smear campaign.” — Karun Kaushik, CEO of Delve
  • “We take these allegations seriously and have made changes: a new auditor network, free re-audits and pentests for all customers, enhanced transparency in audit communications, and more.” — Karun Kaushik, CEO of Delve
  • “This framing is plainly designed to undermine confidence in Delve across customers, investors, team members, and auditors rather than reflect how the platform actually works,” — Delve's leadership

The situation remains fluid as Delve navigates the fallout from these allegations while striving to maintain its client base and restore its reputation in the compliance sector.