AI Styling Studio — Infinite avatar looks from just 1 photo.Try it now.

BestAITools

Submit your Tool

8000+ AI tools already listed
8K+Tools
100K+/moViews
25K+/moVisitors

AI NewsDelve accused of misleading customers with ‘fake compliance’

Delve accused of misleading customers with ‘fake compliance’

1:17 AM IST · March 22, 2026

Delve accused of misleading customers with ‘fake compliance’

Ananonymous Substack postpublished this week accuses compliance startupDelveof “falsely” convincing “hundreds of customers they were compliant” with privacy and security regulations, potentially exposing those customers to “criminal liability under HIPAA and hefty fines under GDPR.” Delve is a Y Combinator-backed startup that last yearannounced raising a $32 million Series Aat a $300 million valuation. (The round was led by Insight Partners.) On Friday, the startup attempted to refute the accusationson its blog, calling the Substack post “misleading” and saying it “contains a number of inaccurate claims.” The Substack post is credited to “DeepDelver,” who described themselves as working at a (now former) Delve client. DeepDelver recounted receiving an email in December claiming the startup had “leaked a spreadsheet with confidential client reports.” While Delve CEO Karun Kaushik apparently assured customers in a subsequent email that they were in compliance and that no external party gained access to sensitive data, DeepDelver said they and other customers had become suspicious. “Having the shared experience of being underwhelmed with the Delve experience, and having the overall sense that something fishy was going on, we decided to pool resources and investigate together,” they wrote. Their conclusion? That Delve “achieves its claim of being the fastest platform by producing fake evidence, generating auditor conclusions on behalf of certification mills that rubber stamp reports, and skipping major framework requirements while telling clients they have achieved 100% compliance.” DeepDelver went into considerable detail about those claims, accusing the startup of providing customers with “fabricated evidence of board meetings, tests, and processes that never happened,” then forcing those customers to “choose between adopting fake evidence or performing mostly manual work with little real automation or AI.” DeepDelver also claimed that virtually all of Delve’s clients seem to have gone through two audit firms, Accorp and Gradient, which they described as “part of the same operation,” one that operates primarily in India, with only a nominal presence in the United States. Those firms, they said, are just rubber-stamping reports that were generated by Delve. As a result, DeepDelver said the startup “inverts” the normal compliance structure: “By generating auditor conclusions, test procedures, and final reports before any independent review occurs, Delve places itself in the role of both implementer and examiner. This is not a technicality. It is a structural fraud that invalidates the entire attestation.” In addition to accusing Delve of misleading its customers, DeepDelver said the startup is helping those customers “mislead the public by hosting trust pages that contain security measures that were never implemented.” DeepDelver said that while their company was discussing its issues with Delve, the startup “sent us multiple boxes of donuts already to keep us happy.” Nonetheless, DeepDelver’s employer supposedly unpublished its trust page and no longer relies on the startup for compliance. Delve responded to the accusations by saying it does not issue compliance reports at all. Instead, it’s an “automation platform” that ingests information about compliance, then provides auditors with access to that information. “Final reports and opinions are issued solely by independent, licensed auditors, not Delve,” the company said. Delve also said that its customers “can opt to work with an auditor of their choosing or opt to work with one from Delve’s network of independent, accredited third-party audit firms.” Those auditors, the startup said, are “established firms used broadly across the industry, including by other compliance platforms.” In response to the accusation that it’s providing customers with “fake evidence,” Delve countered that it’s simply offering “templates to help teams document their processes in accordance with compliance requirements, as do other compliance platforms.” “Draft templates are not the same as ‘pre-filled evidence,” the company said. Delve added that it is “actively investigating any leaks” and is “still reviewing the Substack.” Following the initial Substack post, an X user named James Zhousaidthey were able to gain access to sensitive information from Delve, such as employee background checks and equity vesting schedules. Dvuln founder Jamieson O’Reillyshared more detailsfrom what O’Reilly said was a conversation with Zhou about “several gaping security holes in Delve’s external attack surface.” TechCrunch sent an email seeking additional comment to the media contact address listed on Delve’s website. The email bounced, but I subsequently received a calendar invite for a “Delve demo” later this week. TechCrunch has also reached out to DeepDelver for additional comment. This post has been updated with additional information about purported security vulnerabilities provided by Jamieson O’Reilly, and additional details about Delve’s response to TechCrunch.

read more

Latest AI News

View All News →
Crypto exchange OKX wants AI agents to hire and pay each other

Crypto exchange OKX wants AI agents to hire and pay each other

When AI agents begin working for people — and increasingly for one another — they will need a way to find jobs, pay for services, and build trust. Crypto exchangeOKXis betting that future is closer than many expect, launching a marketplace where AI agents can hire one another, settle payments autonomously, and build portable on-chain reputations. Called OKX AI, the marketplace opens to developers on Tuesday following a closed beta involving 50 early AI service providers. The marketplace builds on technology OKX previously developed to let AI agents hold digital wallets, make payments using stablecoins, and establish persistent identities. The launch marks OKX’s latest push beyond crypto trading as it seeks to become a broader fintech company. With more than 150 million users globally, OKX is betting the next generation of customers will not just be people or institutions, but AI agents capable of transacting autonomously, giving rise to an emerging “agent economy.” “The coming decade will be defined by one-person companies that generate over a million dollars in annual revenue – because every individual effectively gains an unlimited workforce,” Star Xu, founder and CEO of OKX, told TechCrunch. “Traditional financial infrastructure was built for humans. The agentic economy needs infrastructure designed for autonomous software. That is why we built OKX.AI.” Haider Rafique, OKX’s chief marketing officer and global managing partner, said the company believes “agentic commerce” could become a trillion-dollar market over the next five years, driven by micropayments and autonomous software. The marketplace is aimed at crypto developers building AI applications and solo entrepreneurs looking to automate parts of their businesses with AI agents, Rafique told TechCrunch. The company expects those developers to build applications for the marketplace, allowing other users to access AI-powered tools without having to build them from scratch. Among the early builders are CertiK, whose service lets AI agents assess the security of a crypto wallet or token before executing a transaction, and CoinAnk, which provides live market data on a pay-per-query basis. GenLayer, another launch partner, is bringing dispute-resolution infrastructure to the marketplace to help AI agents resolve contractual disagreements. By using blockchain-based payments and stablecoins, the company says AI agents can settle transactions around the clock, including low-value micropayments that would be impractical using conventional payment rails. Rafique said OKX is applying the same fraud detection, compliance systems, and internally developed infrastructure that underpin its cryptocurrency exchange to the marketplace, which will be rolled out in phases before becoming more widely available. OKX’s launch comes as technology companies and startups race to build the infrastructure that will underpin AI agents, from developer platforms and marketplaces to payment and identity systems. Albert Castellana, co-founder and CEO of GenLayer Labs, said the biggest challenge is not simply enabling AI agents to transact, but helping them discover one another and resolve disputes when things go wrong. “What we’re building is essentially a digital court system,” Castellana told TechCrunch. “The challenge for us is distribution. OKX already has that.” Rafique argues that OKX’s biggest advantage is not simply its technology but its reach. The company believes its existing network of crypto developers and users will help seed the marketplace, while its broader strategy extends well beyond digital assets. In March, Intercontinental Exchange (ICE), the parent company of the New York Stock Exchange, invested about $200 million in OKX at a$25 billion valuation. Rafique said the partnership is part of the company’s ambition to “modernize markets” through tokenization, while OKX AI represents its parallel effort to “modernize money” for an era of autonomous software. Developers access the marketplace through Onchain OS, OKX’s toolkit for connecting AI agents to blockchain-based services. The company said no OKX account is required to get started, and the platform is compatible with AI coding tools including Claude Code, Codex, Hermes, and OpenClaw. Because the marketplace is aimed first at developers rather than retail users, India features prominently in OKX’s plans. The country has emerged as one of the world’s largest hubs for AI and blockchain developers, a community the company hopes to reach even before a broader return of its crypto trading business. In 2024, OKXsuspended its services in Indiaas it navigated the country’s regulatory requirements for crypto exchanges. Rafique told TechCrunch that India remains one of the company’s highest-priority markets, adding that developer products such as OKX AI face fewer regulatory hurdles than spot crypto trading and could help the company reconnect with the country’s builder ecosystem sooner.

9 minutes ago

View

Why Your Database Cannot Handle Agentic Workflows

Why Your Database Cannot Handle Agentic Workflows

The data stack was never built for agents, and the cost of that mismatch is now coming due.

9 minutes ago

View

Merck Opens AI-Focused Global Capability Centre in Bengaluru: Report

Merck Opens AI-Focused Global Capability Centre in Bengaluru: Report

The new Bengaluru facility will become a strategic hub for Merck’s AI, digital and enterprise technology operations, supporting global innovation efforts.

9 minutes ago

View

Can Yogi Adityanath Turn Uttar Pradesh into a GCC Powerhouse?

Can Yogi Adityanath Turn Uttar Pradesh into a GCC Powerhouse?

The state is offering 43 million square feet of ready-to-move office space, dedicated AI and data centre parks, electronics manufacturing clusters, and IT and digital services infrastructure.

9 minutes ago

View