Delve
delve.co
Critical Compliance Incident: Fabricated SOC 2 Reports
Delve was found to have systematically generated 494 fabricated SOC 2 reports for 378+ companies. Reports were 99.8% identical boilerplate. All compliance attestations issued through this platform should be treated as invalid.
Category
Security
Website
Description
Y Combinator-backed compliance automation startup (valued at $300M) found to have systematically generated fabricated SOC 2, HIPAA, ISO 27001, and GDPR compliance reports for 378+ client companies. Reports were 99.8% identical boilerplate with only company names swapped.
Compliance
Published Security Advisories
Published 2026-03-27 06:38
Active Incident
criticalDelve Fabricated SOC 2 Reports Scandal
Delve, a Y Combinator-backed compliance automation startup, systematically generated 494 fabricated SOC 2 reports for 378+ companies. Reports were 99.8% identical boilerplate with fabricated Type 2 monitoring data. Seven audit firms were identified routing work through the platform, with Accorp Partners handling the majority.
Affected Companies
351
Started
Dec 2025
Status
Active