AI-native SOC 2 compliance automation platform Β· verified
Delve
Trading normally, but under an unresolved public controversy: in March 2026 a whistleblower alleged fabricated audit evidence and routing to affiliated audit firms, Delve denied it and attributed the leak to an attacker, and Y Combinator removed Delve from its portfolio in April 2026. Sources and detail below.
In March 2026 an anonymous whistleblower publicly alleged Delve generated fabricated audit evidence and routed clients to affiliated rubber-stamp audit firms; Delve denied the claims and said a forensic review pointed to a data-exfiltration attack behind a coordinated smear campaign (TechCrunch, Mar 22 and Apr 3, 2026).
The fallout included Y Combinator removing Delve from its portfolio in April 2026, and several Delve customers (Lovable, LiteLLM, Context AI) that separately suffered security incidents publicly said they had dropped Delve for other compliance vendors or auditors, with the incidents drawing scrutiny to how those companies' SOC 2 processes had been handled (TechCrunch, Mar 26 through Apr 23, 2026). In a post dated April 3, 2026 Delve apologised to customers, said it had fallen short of its own standard, and announced concrete changes: rebuilding its auditor network, offering complimentary re-audits and penetration tests, and halting its audit-workflow automation. That last item is a product change a buyer should weigh against the capability values on this record, which describe the platform as marketed. Delve's own website remains live and the company continues to solicit new customers as of this research date, but the underlying fraud and auditor-independence allegations remain unresolved in the public record.
Desk research against public sources. Every figure below carries its source and the date we retrieved it.
What Delve does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Core marketed function (AI agents automating evidence collection); an anonymous whistleblower disputed the authenticity of some generated evidence, reported by TechCrunch, Mar 22, 2026. Source |
| Auditor workspace | Yes | Delve told TechCrunch it is an automation platform that gives auditors access to compiled information; final reports are issued by separate licensed audit firms. Source |
| Trust center | Yes | Vendor markets a hosted "Trust Report" page for sharing compliance status with prospects. Source |
| Security questionnaire answering | Yes | Delve's own rebuttal (quoted by TechCrunch, Apr 4, 2026) states its AI "automated 70% of a security questionnaire"; a third-party review site independently describes AI-assisted questionnaire response. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Not established | No primary or independent source found confirming SSO/SCIM/RBAC support. |
| SCIM 2.0 provisioning | Not established | No mention of SCIM or of SSO for Delve's own platform anywhere we could find. |
| Continuous control testing | Partial | Vendor markets "continuous monitoring"; not independently verified, and whistleblower allegations (TechCrunch, Mar 2026) specifically disputed whether some monitoring/evidence was genuine. Source |
| Native multi-framework support | Not established | A third-party review (ComplyJet, Apr 30, 2026) describes "limited cross-framework control mapping," implying frameworks are largely handled separately, but this is not vendor-confirmed. Source |
6 frameworks, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Delve markets itself as a SOC 2 automation platform; the integrity of its evidence and audit-handoff process is independently disputed (see notes/auditorNetworkNote). Source |
| HIPAA | Vendor-claimed | Source |
| ISO 27001 | Vendor-claimed | Source |
| GDPR | Vendor-claimed | Source |
| PCI DSS | Vendor-claimed | Source |
| ISO 42001 | Vendor-claimed | Source |
Delve does not publish a price.
Getting a number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.
- Disclosure model
- Quote-based (reported $10Kβ$30K/yr)
- Observed range (reported)
- USD 10,000β30,000 / year
- Basis
- Estimate, 2026-07-24
Auditor fees are separate from all of these. See the SOC 2 audit cost guide for what the audit itself runs.
Who actually issues the report.
Delve states it does not itself issue attestations: "Final reports and opinions are issued solely by independent, licensed auditors, not Delve," and customers can choose their own auditor (Delve statement to TechCrunch, Mar 22, 2026). An anonymous whistleblower ("DeepDelver") alleged in March 2026 that most Delve clients were routed through two affiliated audit firms, Accorp and Gradient, that rubber-stamped Delve-generated conclusions rather than performing independent review; Delve has denied this characterization and TechCrunch stated it could not independently verify the core fraud allegations.
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Delve is for, and who it is not.
Good fit
An early-stage startup that needs the fastest, lowest-cost path to a first SOC 2 attestation and is willing to independently vet the audit firm Delve pairs it with rather than relying on Delve's recommendation alone.
Poor fit
Companies that need a compliance vendor whose evidence pipeline and auditor relationships are beyond public dispute, or that cannot absorb reputational risk from an unresolved credibility controversy, should not pick Delve without independent verification.
Typical buyer: A very early-stage SaaS startup pursuing its first SOC 2 report to unblock a specific enterprise deal on a tight budget and timeline..
Where every figure on this page came from.
10 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.
- Reports the whistleblower's fake-compliance allegations and Delve's on-the-record denial/statement. https://techcrunch.com/2026/03/22/delve-accused-of-misleading-customers-with-fake-compliance/
- Confirms Y Combinator removed Delve from its portfolio and quotes Delve's rebuttal blog post, including the '70% of a security questionnaire' claim. https://techcrunch.com/2026/04/04/embattled-startup-delve-has-parted-ways-with-y-combinator/
- Confirms Delve performed Context AI's security certification, that Context AI has since switched to Vanta + Insight Assurance, and recaps the LiteLLM/Lovable fallout timeline. https://techcrunch.com/2026/04/23/another-customer-of-troubled-startup-delve-suffered-a-big-security-incident/
- Confirms the $32M Series A led by Insight Partners at a $300M valuation, announced July 22, 2025. https://techcrunch.com/2025/07/22/21-year-old-mit-dropouts-raise-32m-at-300m-valuation-led-by-insight
- Investor-side confirmation of the Series A terms and use of funds. https://www.insightpartners.com/ideas/delve-raises-32m-series-a-to-build-ai-agents-for-compliance
- Delve's own account (Apr 3, 2026) attributing the leak to a malicious attacker and disputing the whistleblower's characterization. https://delve.co/blog/delve-sets-the-record-straight-on-anonymous-attacks
- Third-party estimate of ~100 integrations and limited cross-framework control mapping. https://www.complyjet.com/blog/delve-soc-2-customer-experience
- Third-party pricing estimate (~$12k/year automation platform + ~$12k audit). https://www.complyjet.com/blog/delve-pricing
- Reports Delve's G2 rating as 4.7/5 based on 135 reviews (G2's own page could not be directly crawled; see openQuestions). https://sprinto.com/blog/delve-review
- Company profile confirming category and identity. https://www.crunchbase.com/organization/delve-8733
β All SOC 2 compliance software Β· How we verify
Some links to compliance platforms on this page are affiliate links: if you sign up through one, the vendor may pay us a commission at no cost to you. It never changes our ranking, our review, or which platform we recommend.
3 facts on this page we could not establish.
Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Delve, send us the sources and we will fill them.
Verification is free and always will be. It does not change where Delve appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.