On March 22, 2026, TechCrunch dropped a bombshell report that sent a chill through the boardrooms of hundreds of HIPAA and GDPR-compliant startups.
The subject of the investigation? Delve, a Y Combinator-backed compliance automation platform once valued at $300 million and trusted by hundreds of customers. According to an anonymous whistleblower posting as "DeepDelver," the platform's meteoric growth wasn't fueled by superior code. It was allegedly fueled by systemic fraud.
The allegations suggest that Delve didn't just automate compliance; it fabricated it. If your organization relies on automated compliance platforms for high-stakes frameworks like ITAR, CMMC, or EAR, this isn't just a news story. It's an extinction-level event for your audit trail.
Inside the Allegations: The "Certification Mill"
The "DeepDelver" report outlines a sophisticated operation designed to invert the compliance process. Traditionally, compliance is an outcome of rigorous implementation and independent third-party review. Delve allegedly flipped the script, acting as both the implementer and the de facto examiner.
Fabricated Evidence
Alleged automatic generation of fake board meeting minutes, security tests, and employee training records that never occurred.
Certification Mills
Partnering with offshore firms (Accorp, Gradient) that allegedly rubber-stamped reports without U.S. jurisdictional presence or review.
Inverted Audits
System allegedly generated final auditor conclusions and test procedures before any live data was ever reviewed.
Perhaps the most damaging claim is that Delve partnered with offshore audit firms, Accorp and Gradient, to rubber-stamp Delve-generated materials. These firms, despite claiming a major U.S. presence, were allegedly operations based in India that executed final reports before any live security tests or independent reviews occurred.
The whistleblower alleges that Delve hosted customer trust pages advertising security controls the customers had never put in place.
Automation Theater vs. Audit-Ready Reality
The "Delve way" represents what experts call Automation Theater. It offers the comfort of a dashboard and a badge without the burden of actually doing the work. For low-stakes marketing compliance, this might survive a cursory check. For regulated industries under the jurisdiction of the DoD, OFAC, or the State Department, it is a criminal liability.
At SecurePoint USA, we have watched the rise of "one-click compliance" with skepticism. There is a fundamental difference between a platform that fabricates an answer and a platform that collects an answer.
SecurePoint USA: The Integrity Alternative
Built for high-stakes regulatory environments (CMMC, ITAR, EAR)
What Delve Allegedly Did
- Fabricated board minutes and security tests that never happened.
- Inverted process: generated reports before independent review.
- Promised "100% compliance" via pre-filled template shortcuts.
What SecurePoint USA Does
- Collects Real-Time Visitor Data: Real logs, real IDs, real adjudications.
- No Inverted Audits: We provide the evidentiary toolset for your auditors to sit in judgment.
- Audit-Ready Reality: Working visitor controls that support ITAR/EAR and CMMC programs, not just templates.
The Critical Infrastructure Standard
In industries like Aerospace, Defense, and Energy, compliance is not about a logo for your website. It is about protecting national security assets and preventing prohibited parties from accessing sensitive facilities.
Fabricating a visitor log for an ITAR-controlled facility is not a paperwork shortcut. Knowingly giving false records to federal officials can be a federal crime. SecurePoint USA ignores the shortcuts. We focus on providing the defense industrial base with hard evidence of who was in the building, what screening was performed, and exactly who adjudicated the match.
We emphasize AI-assisted but human-approved processes. When our engine flags a sanctioned entity, we don't "automate away" the decision. We present the data to a Compliance Officer, record their decision, and generate the immutable audit log. That is substantive compliance.
Don't Gamble with Automation Theater
The Delve scandal is a wake-up call for every organization that values its operating license. Stop taking shortcuts and start building a real, audit-ready evidentiary record.
Stay Informed on Compliance Scandals
Subscribe for our notes on regulatory updates, whistleblower cases, and export controls.
Get compliance alerts
Occasional notes on sanctions, export controls, and visitor compliance when we publish them.



