
Work Here?
Work Here?
Work Here?
Delve Technologies provides an AI-native compliance automation platform that helps fast-growing companies achieve and maintain regulatory certifications such as SOC 2, HIPAA, ISO 27001, GDPR, and PCI DSS. The platform uses AI agents that act like team members to automate tasks such as collecting evidence, gathering screenshots, writing reports, and completing security questionnaires. Unlike traditional tools that rely on API integrations, Delve’s agents can pull evidence from a wide range of web apps and internal tools and continuously monitor for compliance gaps in real time. Its subscription-based model scales with company size, required frameworks, and support level, targeting startups and mid-market customers aiming for enterprise-grade certifications. Delve’s goal is to reduce manual effort and accelerate audit readiness by turning compliance into automated, ongoing processes.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
AI & Machine Learning
Company Size
11-50
Company Stage
Series A
Total Funding
$35.4M
Headquarters
San Francisco, California
Founded
2023
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$35.4M
Above
Industry Average
Funded Over
3 Rounds
Industry standards
Health Insurance
Dental Insurance
Vision Insurance
401(k) Retirement Plan
Unlimited Paid Time Off
Flexible Work Hours
Hybrid Work Options
GrubHub stipend + all meals covered in-office
Gym Membership
Conference Attendance Budget
Professional Development Budget
Family Planning Benefits
Fertility Treatment Support
Stock Options
Company Equity
Phone/Internet Stipend
Home Office Stipend
Health Savings Account/Flexible Spending Account
Wellness Program
Mental Health Support
Paid Holidays
LiteLLM CVE-2026-42271 flaw actively exploited for unauthenticated RCE. Security researchers on Tuesday disclosed a critical vulnerability in LiteLLM's open-source AI gateway software, tracked as CVE-2026-42271, that is already being exploited in the wild to achieve unauthenticated remote code execution (RCE). How CVE-2026-42271 chains to unauthenticated RCE. The flaw resides in LiteLLM's proxy server component, which normally handles API request routing for large language models. According to a technical advisory published Tuesday, the vulnerability allows an attacker to send specially crafted HTTP requests that bypass authentication checks. When chained with a separate server-side request forgery (SSRF) issue in the same component, the weakness grants full unauthenticated command execution on the host server. The vulnerability carries a CVSS severity score of 9.8, rated critical. Active exploitation spotted in the wild. Multiple threat intelligence teams confirmed Monday that the flaw has been under active attack since at least June 6, 2026. Attackers are chaining the exploit to drop webshells, deploy cryptocurrency miners, and harvest API keys and credentials from compromised instances. The attacks appear opportunistic, scanning the internet for exposed LiteLLM installations, researchers said. One security operations firm described seeing over 900 exploitation attempts within the first 48 hours of the initial disclosure. This pattern mirrors recent incidents like the Palo Alto Networks firewall zero-day that was exploited for weeks before a fix arrived. LiteLLM issues emergency patch and guidance. LiteLLM released an emergency security update late Monday, urging all users to immediately upgrade to LiteLLM version 1.32.1 or later. The company posted a security bulletin on its GitHub repository and official blog, confirming the CVE and outlining mitigation steps for organizations that cannot immediately patch. These include restricting network access to the admin interface and applying a Web Application Firewall rule to block malformed requests. The disclosure comes just months after LiteLLM ended its partnership with Delve amid controversy over data handling, putting the startup's security practices under renewed scrutiny. Wider AI Infrastructure Security concerns. CVE-2026-42271 adds to a growing list of security gaps discovered in AI service platforms. In May, researchers flagged a Vertex AI blind spot that exposed Google Cloud customer data. The incident highlights a systemic risk: as organizations rush to integrate AI APIs, the middleware gateways that manage access often become high-value targets. Security experts advise enterprises to treat AI gateways with the same rigor as any critical infrastructure component, applying regular patching, network segmentation, and runtime integrity monitoring. With exploitation continuing, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is expected to add CVE-2026-42271 to its Known Exploited Vulnerabilities catalog in the coming days, giving federal agencies a strict 14-day patch deadline. Editor & Founder Mudassir Ijaz is a BS Computer Science graduate and seasoned writer with over 6 years of experience contributing to networkustad.com, editorialdiary.com, and articlebench.org. An expert in artificial intelligence, SEO, web development (HTML, CSS, Python), cloud computing, and hosting, he is also a passionate entrepreneur who views blogging as a creative performance. Mudassir loves exploring diverse topics and helping readers navigate technology and business with clarity and insight. No spam. Unsubscribe anytime. Free Daily updates
LiteLLM drops Delve after security compliance dispute. LiteLLM is replacing Delve and redoing its security certifications after a malware incident and escalating allegations around Delve's compliance practices. The company plans to use Vanta and an independent third-party auditor to verify its controls. LiteLLM, makers of a popular Artificial Intelligence gateway used by millions of developers, said it is severing ties with compliance startup Delve and will redo its security certifications with another provider and auditor. The move follows a damaging week in which LiteLLM's open source version was hit by credential-stealing malware. Before that incident, LiteLLM had obtained two security compliance certifications by hiring Artificial Intelligence compliance startup Delve. Those certifications are meant to confirm that a company has procedures in place to reduce the likelihood of security incidents. The reversal now raises fresh questions about the reliability of the earlier compliance work and about how LiteLLM intends to validate its controls going forward. Delve has been accused of misleading customers about their actual compliance status by allegedly generating fake data and relying on auditors that rubber-stamped reports. Delve's founder has denied those allegations and offered free re-tests and audits to all customers. The dispute intensified after an anonymous whistleblower renewed the claims and released alleged supporting receipts over the weekend. On Monday, LiteLLM CTO Ishaan Jaffer posted on X that his company will be using Delve competitor Vanta to re-certify and will find its own, independent third-party auditor to verify its compliance controls. The decision signals a clear break from Delve as LiteLLM responds to both the fallout from the malware incident and the broader controversy surrounding Delve's certification process. 52. Impact score. April 1, 2026 OpenAI says GPT-5 produces fewer false claims than earlier models, especially when it can browse the web. The gains look smaller without web access, underscoring how much reliability still depends on live sourcing. April 1, 2026 ARC-AGI-3 introduces interactive, instruction-free environments designed to test whether frontier Artificial Intelligence systems can adapt to genuinely novel situations. Early results show top models performing near zero, highlighting a sharp gap between pattern recognition and open-ended exploration. April 1, 2026 NVIDIA is reportedly running into manufacturing problems with Rubin Ultra as its planned package pushes beyond current TSMC capabilities. The issue centers on CoWoS-L packaging for a much larger multi-die, high-bandwidth memory design. April 1, 2026 Intel's Binary Optimization Tool is changing how executable applications run on Arrow Lake Refresh systems, with measurable gains in some workloads. Primate Labs found that the tool cuts instruction counts and aggressively shifts execution from scalar code to vector instructions, prompting Geekbench to label BOT-enhanced results. April 1, 2026 Medical chatbots from major tech companies are arriving quickly as questions grow about how little outside testing they receive before public release. A judge has also temporarily halted the Pentagon's effort to label Anthropic a supply chain risk, exposing a dispute escalated outside normal government channels.
Delve faces allegations of fake compliance reports and security gaps amid customer backlash. 2026-03-31 20:03 A whistleblower-style article on Substack has thrust Delve into scrutiny, alleging it misrepresented its alignment with key privacy frameworks like GDPR and HIPAA. Though unverified, the claims suggest numerous clients were led to believe they met regulatory requirements when they might not have. With little public response so far, questions grow over how thoroughly those assurances were vetted before being offered. Some affected firms could now face fines or lawsuits due to reliance on Delve's stated compliance. Details remain sparse, yet the situation highlights vulnerabilities in trusting third-party validation without deeper checks. A report surfaced online, attributed to someone using the name "DeepDelver," said to have ties to one of the firm's past clients. Following claims of a security lapse exposing private documents, unease started spreading among users. Security compliance service While executives at Delve stated there was no external breach of information, trust started fraying regardless. Questions about stability emerged even though official statements downplayed risk. Some say Delve speeds up compliance using methods that stretch credibility - like creating fake board minutes, false test results, or made-up operational records. Reports appear ready long before audits begin, prepared ahead of time without clear verification. A small circle of auditing partners handles most reviews, which invites questions. Close ties between these firms and Delve blur lines. Oversight might be weaker than it should be. Doubts grow when proof of activity emerges only after approval deadlines pass. What stands out is how clients reportedly faced pressure to use ready-made documents instead of carrying out their own compliance checks. It turns out the platform might have displayed public trust pages outlining security measures that weren't entirely in place, leaving regulators and others possibly misinformed. Delve hit back hard at the allegations, labeling the document "misleading" while pointing out factual errors. What followed was a clear distinction: certification isn't something they deliver. Their role? Streamlining compliance information through automated systems. Independent auditors - licensed professionals - not Delve sign off on final evaluations. These third parties alone hold responsibility for approved documentation. Organization of data is their core function, nothing more. Not long ago, Delve dismissed accusations about fabricated proof, explaining it offers uniform templates so users can record procedures - much like peers across the sector. Clients decide independently whether to pick external auditors or go with those linked to its ecosystem. Still, the unnamed informant insisted several issues linger - audit independence, how data is secured. Yet more allegations emerged; outside analysts pointed to weak spots in Delve's setup, adding pressure. Scrutiny grows. With every new development, questions about reliability begin to surface more clearly. Though designed to assist, these systems now face scrutiny over openness and responsibility. Where once efficiency was praised, doubt has started to take hold instead. Read the original article:
Popular AI gateway startup LiteLLM ditches controversial startup Delve. LiteLLM, makers of popular AI gateway used by millions of developers, has publicly announced that it is ditching compliance startup Delve and will redo its security certifications with another company and auditor. The announcement comes after LiteLLM's open source version fell victim to some horrific credential-stealing malware last week. Prior to the incident, LiteLLM had obtained two security compliance certifications by hiring AI compliance startup Delve. Such certifications are intended to verify that a company has procedures in place to minimize potential incidents. Delve has been accused of misleading its customers about their true compliance by allegedly generating fake data and using auditors that rubber-stamped their reports. Delve's founder has denied those allegations and offered free re-tests and audits to all of its customers. That denial encouraged the anonymous Delve whistleblower to double down, including releasing alleged receipts over the weekend. On Monday, LiteLLM CTO Ishaan Jaffer posted on X that his company will be using Delve competitor Vanta to re-certify and will find its own, independent third-party auditor to verify its compliance controls. After such a harsh week, LiteLLM is voting with its feet.
Delve faces allegations of fake compliance practices. News summary. Delve, a compliance startup backed by Y Combinator, is facing allegations of fabricating compliance certifications for its clients. The accusations were made by an anonymous whistleblower, DeepDelver, who claims to be a former client. These allegations have led Insight Partners to remove an article about their $32 million investment in Delve. Delve, which automates security and regulatory certifications, has responded by disabling the 'book a demo' feature on its website. The company is accused of fabricating evidence of compliance processes and forcing clients to use fake data or perform manual tasks. Delve denies these allegations, stating it provides automation tools for compliance documentation and allows clients to choose their auditors. Despite the company's denials, the situation has prompted investor caution. Story coverage. techcrunch.com
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
AI & Machine Learning
Company Size
11-50
Company Stage
Series A
Total Funding
$35.4M
Headquarters
San Francisco, California
Founded
2023
Find jobs on Simplify and start your career today