In March 2026 an anonymous investigation published on Substack made a series of allegations about Delve, a Y Combinator-backed compliance automation company that had raised $32 million. The allegations were picked up by industry publications through April.

We are not in a position to establish what happened. What follows is alleged, and it is written that way throughout, because a company whose entire argument is that a claim must carry its evidence does not get to make an exception for a claim it finds convenient.

But one line from the coverage is worth reading twice, and it does not depend on any allegation being true.

The line

No regulatory body caught it. No system exists to verify that claimed auditors exist, and no automated check flags identical reports across companies.

Read that as a statement about the industry rather than about one company. There was no mechanism. Not a failed mechanism, not a mechanism somebody bypassed: none. Hundreds of reports could allegedly share the same text, including the same errors, and nothing in the chain between the producer and the reader was in a position to notice.

What was alleged

The investigation alleged, according to the published coverage, that of 494 SOC 2 reports examined, 493 shared the same boilerplate, reported as 99.8% identical, down to the same grammatical mistakes, with the company name, logo and signature the only things that changed. It further alleged that auditor conclusions and test results were populated before clients had submitted their descriptions, diagrams or evidence.

The company left Y Combinator. The reports had customers, and those customers had enterprise deals and regulatory exposure standing on them.

Every one of those reports looked complete.

Why this is not a story about fraud

It is easy to read this as a story about bad actors, and that reading is comfortable because bad actors are somebody else. The harder reading is the one the line above forces:

A report that looks complete and a report that can be verified are two different objects, and almost nothing in the industry distinguishes them.

That is not about dishonesty. It is about a property that most assurance artefacts simply do not have. A PDF asserts. It does not carry the evidence its assertions were made from, it does not say what it could not read, and it cannot be checked by the person holding it without going back to whoever produced it.

Ask an honest question of an honest report: how do I know this conclusion followed from something that was actually observed? For most reports the answer is that you trust the producer. That is a perfectly reasonable answer right up until the moment it is the only one available.

The three things a report has to carry

None of these is a product feature. They are properties an artefact either has or does not.

The evidence each conclusion was decided from. Not summarised, not described: present. A finding that says this site allows anonymous sharing should be reachable to the raw value it read and the moment it was read.

What could not be read. This is the one almost nobody carries, and it is the one that matters most, because an absence of findings and a clean result are not the same thing. A report that cannot tell you which questions its evidence could not answer is a report whose silence you cannot interpret.

A way to check it without the producer. If verifying the artefact requires the vendor's platform, the vendor's account or the vendor's word, then the artefact has not been verified. It has been re-asserted.

The third one is what would have made the allegations checkable by anybody holding two of those reports.

We publish one you can check

There is a specimen assessment on this site. It is built from the fixtures our engine ships, so no tenant is behind it and no credential was involved , the tenant in it is invented and says so. What it demonstrates is the shape:

Every finding carries the evidence it was decided from, the kind of claim it is making (whether Microsoft requires it, documents a limit, recommends it, or whether it is a convention or an opinion) and what it does not establish. What could not be read is named rather than counted as fine. And it comes with the instructions to verify all of it, with software that is open source, needs no licence, no account, and no contact with us.

You do not have to believe us about any of that. That is the point of it.

Read the specimen assessment

Sources

The allegations described above are reported by the following. We have not independently verified them and do not assert them as established.

Tags#evidence#governance#privacy

Comments