On this page
- Where does Delve’s evidence become a CPA opinion?
- What are the Delve allegations, and what have Delve and Accorp said?
- What can public Delve reviews tell a SOC 2 buyer?
- How can you test the original evidence and CPA handoff in Delve?
- Who writes which part of a Delve-supported SOC 2 report?
- How much does Delve cost alongside the CPA?
- When should Delve make the shortlist?
Delve can stay on a SOC 2 shortlist only if it can show your original records, your exceptions, and an independent CPA's own test work before you sign. Skip it if you need a vendor whose evidence process and auditor relationships are not under unresolved public dispute, or if the proposed CPA will not answer independence questions in writing.
In March 2026, an anonymous poster called DeepDelver alleged that Delve fabricated evidence and pre-wrote auditor conclusions that audit firms then signed, as TechCrunch reported. Delve denied the claims, saying independent, licensed auditors test controls and issue reports, and Accorp, one of the two firms named, denied issuing any unaudited report. The allegations remain unresolved in the public record as of September 29, 2026.
Compare with: our Vanta review or our Drata review when you want to evaluate software and auditor procurement as separate choices; our Secureframe review when guided implementation is the main draw.
Pros
- Vendor-described connected evidence collection
- Vendor-described AI questionnaire assistance
- Delve-described expert coordination
Cons
- Evidence and auditor-independence allegations unresolved
- Named as a defendant in two pending 2026 lawsuits
- Audit-workflow automation halted in April 2026
- SSO and SCIM support unestablished in public sources
- CPA and audit-fee scope require written confirmation
Delve is a San Francisco SOC 2 compliance platform founded in 2023 by Karun Kaushik and Selin Kocalar; it raised a $32 million Series A led by Insight Partners in July 2025. It sells connected evidence collection, security-questionnaire help, a shareable trust report, and expert coordination with the audit firm. The buyer mistake is reading a finished Delve dashboard, trust page, or report cover as proof that an independent CPA tested your controls. Several unrelated products share the name, including board games and a qualitative-research app, and employer reviews describe working at the company rather than buying it. The Delve software profile holds the dated capability record. Our SOC 2 software guide compares Delve with the other platforms by buyer fit.
Where does Delve’s evidence become a CPA opinion?
Delve can help collect and organize material for an examination; the buyer and the named CPA must still establish what the original evidence proves. Use one real control from your proposed scope to trace all four handoffs.
| Handoff | What it can establish | Proof to retain |
|---|---|---|
| Original system and owner | An in-scope system held a particular state or event at a particular time; the buyer owns its configuration and control operation. | Source-system record, system identity, timestamp, owner, relevant fields, and the access path used to retrieve it. |
| Delve collection and template | Delve's proposed workflow can collect, map, and present that item. A template is a starting point, not evidence that the control operated. | Collected fields, collection and test logs, control mapping, template version, sync failure and rerun history, and export. |
| Buyer review and exception | A named buyer-side owner checked scope, accepted or rejected the item, and documented a failed or missing control. | Reviewer, decision date, comments, exception owner, remediation, approval, and retained prior versions. |
| Named independent CPA | The CPA's own procedures, samples, follow-up, and evaluation support its opinion and the test results it reports; a platform status alone cannot. | Firm and signing-CPA names, licence and peer-review check, engagement letter, the CPA's written account of who drafted the opinion and test results, evidence requests, and final report. |
Source boundaries: Delve's March 24, 2026 statement describes customer visibility into evidence and integration-test JSON logs; its April 3 statement calls templates starting points and says Delve was halting automation that interacts with audit workflows. The AICPA's public SOC overview identifies SOC reports as CPA assurance work. The table is a buyer test, not an observation of a Delve tenant or a conclusion about any report.
What are the Delve allegations, and what have Delve and Accorp said?
The allegations come from DeepDelver, an anonymous author who says they work at a former Delve client, in posts published from March 19, 2026. Delve denies them, and Accorp denies them for its own reports. Neither side’s account had been resolved in the public record as of September 29, 2026, so the useful question for a buyer is what each claim lets you check.
| DeepDelver alleged | Response | What a buyer can check |
|---|---|---|
| Delve supplied pre-filled board minutes, test reports, and forms that customers adopted as evidence of processes that did not happen. | Delve: these are templates and starting points that customers must review, modify, and finalize; "draft templates are not the same as pre-filled evidence." | Open one templated artifact and match it to the real meeting, test, or process it records, with its own date and attendees. |
| Draft SOC 2 reports already contained the auditor's opinion, test procedures, and results before the customer supplied any details, and final reports matched those drafts. | Delve: it gives auditors dashboard access and provides "a draft report for customers to edit," uses "templates provided by auditors," and licensed auditors independently test controls and issue final reports. | Ask the CPA in writing who drafted the opinion and test results, and when. See who writes each report section. |
| Nearly all clients went through two firms, Accorp for SOC 2 and Gradient Certification for ISO 27001, described as one India-based operation with nominal US presence that signed Delve-written reports. | Delve: customers can choose any auditor or one from its network of "established firms." Accorp: every report it issues is prepared and reviewed by its own team, and any circulating report that appears unaudited was not issued by Accorp. | Verify the signing firm and CPA licence yourself, and confirm the engagement directly with the firm rather than through the platform. |
| A later post published what it describes as internal Delve video and Slack messages about report generation and one audit firm's review. | Delve: cybersecurity firms it hired point to an attacker who bought Delve under false pretenses, exfiltrated internal data, and ran a coordinated smear campaign. | Neither account is established here. Judge Delve on what it demonstrates in your proposed tenant and what your CPA confirms. |
Sources: DeepDelver Part I (March 19, 2026) and Part II (March 28); Delve's March 20 response and April 3 statement; Accorp Partners' LinkedIn statement (March 2026). DeepDelver's posts name further audit firms and Delve employees; those claims are not repeated here. Allegations and responses are shown as each party stated them, not as findings.
Delve’s responses also changed the product and service it sells. On March 24, it offered existing customers a complimentary re-audit through “an independent, peer-reviewed, AICPA-accredited SOC 2 auditor,” a penetration test, and engagement letters from auditors on request. On April 3, it apologized to customers, said that as it scaled it “fell short of the standard we hold ourselves to,” and listed changes: rebuilding its auditor network and removing firms “that don’t meet our standards,” halting “any automation that interacts with audit workflows,” and opening direct communication lines between customers and their auditors. Delve did not name the firms it removed. The halt wording does not establish that evidence collection or questionnaire automation stopped, so ask Delve to show what is enabled in the proposed tenant now.
The dispute also reached Delve’s investors and customers. TechCrunch reported on March 23 that Insight Partners briefly removed, then restored, its post about the Series A. LiteLLM said on March 30 that it would re-certify with Vanta and its own auditor, and Context AI told TechCrunch on April 23 that it had moved to Vanta and engaged Insight Assurance for new examinations. Delve and Y Combinator parted ways in April 2026. A separate March 31 post alleged that Delve’s Pathways workflow tool was an unattributed fork of Sim.ai’s open-source SimStudio; Sim’s chief executive told TechCrunch there was no licence agreement, and Delve says it built on an Apache 2.0 repository that permits commercial use.
Delve entities are also named defendants, alongside Mercor and LiteLLM’s developer, in two federal lawsuits filed in April 2026. Ananthula v. Mercor.io Corporation (N.D. Cal., No. 3:26-cv-03362, filed April 21) is a proposed class action over the March 2026 Mercor data breach; its complaint alleges that Delve misrepresented whether its clients complied with security standards. White v. Delve Technologies, Inc. (N.D. Tex., No. 6:26-cv-00143) was filed April 5. Both dockets were open on September 29, 2026, and the complaints’ allegations have not been adjudicated.
What can public Delve reviews tell a SOC 2 buyer?
Public ratings describe how some customers felt about the workflow; none of them establish whether an independent CPA tested those customers’ controls. G2 showed Delve at 4.7/5 across 136 reviews on September 29, 2026. We did not establish how many of those reviews post-date the March 2026 allegations, so treat the score as a view of onboarding and support rather than of audit quality. The Capterra listing titled “Delve” (4.9 from 205 reviews, last updated September 28, 2026) belongs to the qualitative-research coding app of the same name, not this SOC 2 product.
Community threads show what practitioners argued about, not how common any experience is. In the Hacker News discussion of DeepDelver’s first post (March 19–20, 2026), some commenters said pre-filled policies and templates are common across compliance tools and that the company signing them still owns any misstatement; another suggested the post was a competitor’s attack. An earlier r/sysadmin thread raises lean-team workload questions, but its commenters include people without direct Delve use. Competitor-written reviews on the same results can suggest demo questions; their verdicts and quoted ratings are not our findings.
Ask Delve for a reference customer with your company size, systems, observation period, and intended CPA, and ask how exceptions and auditor follow-up worked. A customer who re-audited after March 2026 can tell you what the new auditor asked for.
How can you test the original evidence and CPA handoff in Delve?
Bring one representative control for each system you cannot replace, plus one manual control. Use your intended CPA in the walkthrough. Keep the artifacts from each step:
- Original record: Choose a real source-system event or setting. Open it in the original system, then locate the same fields, timestamp, and system identity in Delve. Keep both records.
- Collection failure: Revoke a test integration permission or use a stale item. Show the failed collection, alert, owner, fix, rerun, and retained failure history. Keep the log and before-and-after export.
- Template and mapping: Follow one generated control, policy, or board-minutes template to the buyer’s approved wording and underlying evidence. Keep the template version, changes, reviewer, and the reason the evidence fits the control.
- Buyer exception: Introduce a failed control or missing manual artifact. Show who can reject it, assign remediation, approve the replacement, and retrieve the earlier version. Keep the exception trail.
- Current workflow scope: Ask Delve to demonstrate which collection, questionnaire, and audit-facing automations are enabled in your proposed tenant after its April statement. Keep the written feature and human-review boundary in the proposal.
- Identity access: If SSO, SCIM, or role separation matters, connect your intended identity provider or run a bounded test. Show provisioning, deprovisioning, reviewer permissions, and any manual fallback; retain the edition and access terms. Public sources do not establish these capabilities.
- Named CPA: Obtain the firm and signing practitioner’s names before signature. Check the individual’s licence on CPAverify or the issuing state board, and the firm’s result in the AICPA peer review public file. Contact the firm through its own published details, read the engagement letter, and ask about independence, scope, sampling, exceptions, fees, and any referral or revenue arrangement with Delve. Keep its written response.
- Report authorship: Before you sign management’s assertion, ask the CPA in writing who drafted the opinion and the test procedures and results, and on what date. Stop if a draft already shows test results or “no exceptions noted” before the CPA has requested your evidence.
- Auditor request and change: Have the CPA request a source record and a challenged item through the proposed Delve handoff, and keep its assessment of what it still needs outside Delve. If Delve proposes moving an in-progress Type 2 to another firm, get that firm’s written statement of the period it will examine and the evidence it will re-test.
- Order and exit: Reconcile the signed order with the demonstrated systems, frameworks, expert help, CPA work, evidence retention, renewal, and bulk-export rights. Export controls, mappings, original-source references, exceptions, comments, and history; have the CPA confirm it can use the package outside Delve.
Run these proofs before contract signature. A successful demo of a clean control does not answer how the workflow preserves a failed one.
Who writes which part of a Delve-supported SOC 2 report?
Your company writes and signs the system description and management’s assertion; the CPA alone writes the opinion and the tests and results. A platform may help draft your parts. It should not draft the auditor’s. That line is where the Delve dispute sits, so check it section by section.
| Report section | Who owns it | Where Delve may help | Stop if |
|---|---|---|---|
| Section I: independent service auditor's report | The CPA firm, signed by a licensed CPA | Delivering the final report | Opinion text exists before the CPA has requested or tested your evidence. |
| Section II: management's assertion | Your company, signed by an officer | Template wording | You are asked to sign before the system description matches your system. |
| Section III: system description | Your company | Drafting from templates and your inputs | It describes tools or controls you do not run, such as a VPN or bastion host you never deployed. |
| Section IV: controls, tests, and results | Controls: your company. Tests and results: the CPA | Control list and criteria mapping | Test procedures or results appear in a draft before the CPA's fieldwork. |
Section structure follows the AICPA SOC 2 reporting model described in our SOC 2 report guide. AICPA ethics staff published guidance on business arrangements with SOC tool providers on April 13, 2026, warning that such arrangements can threaten independence and objectivity. The "Stop if" column is a buyer screen, not a finding about any Delve report.
Delve says buyers may choose their own auditor or use its network. Either route calls for the same direct checks, and a referral, vendor assurance, or dashboard badge does not replace them. If you already hold a Delve-era report, the SOC 2 report authenticity checks show how to test it; to find a CPA firm you contract with directly, start from the SOC 2 auditor directory and confirm the firm’s experience with Delve before signing.
How much does Delve cost alongside the CPA?
An AWS Marketplace Foundation Package listing showed a $12,000 starting price for 1–20 employees on a 12-month contract on September 29, 2026. That scoped listing is not a complete SOC 2 project price. Delve’s services licence agreement makes the Order control fees, scope, and term.
Get separate written amounts for software, implementation, expert coordination, frameworks, any penetration test or re-audit, the named CPA’s examination, renewal, and export or transition work. Confirm which party contracts with and pays the CPA, and whether the auditor can require additional procedures at additional cost. The Delve pricing guide covers the Marketplace reference and quote questions in more detail.
When should Delve make the shortlist?
Shortlist Delve when its coordinated model saves buyer-side work and the source-to-CPA proof succeeds with your records and intended auditor. If the source trail, exceptions, report authorship, or CPA appointment remain unclear at signature, defer the choice.
| Buying situation | Shortlist direction | Reason to test |
|---|---|---|
| Small team wants one coordinated readiness workflow and can vet the proposed CPA directly | Delve | The promised coordination has value only if original records, exceptions, and CPA requests remain traceable, and the CPA confirms it wrote its own sections. |
| Team wants to choose software and auditor through separate procurements | Vanta or Drata | Compare each product's evidence export and auditor access with Delve's handoff, then price the CPA separately; the Vanta vs. Delve comparison sets the two side by side. |
| Guided implementation matters, but current CPA and evidence-provenance answers remain incomplete | Secureframe or defer Delve | Compare the contracted human help and require the same original-record and CPA proofs from either vendor. |
This compares buying models, not a claim that another platform's controls or auditor relationships have been verified here. Use each linked review for its own evidence and limits.
Leave the evaluation with a retained original-to-export sample, an exception trail, the CPA’s direct written answers on independence and report authorship, and an itemized order. To run the same checks against other platforms, compare SOC 2 compliance software.
More in Compliance Tools