Logo Menu

AI-native SOC 2 compliance automation platform Β· verified

Delve

Trading normally, but under an unresolved public controversy: in March 2026 a whistleblower alleged fabricated audit evidence and routing to affiliated audit firms, Delve denied it and attributed the leak to an attacker, and Y Combinator removed Delve from its portfolio in April 2026. Sources and detail below.

In March 2026 an anonymous whistleblower publicly alleged Delve generated fabricated audit evidence and routed clients to affiliated rubber-stamp audit firms; Delve denied the claims and said a forensic review pointed to a data-exfiltration attack behind a coordinated smear campaign (TechCrunch, Mar 22 and Apr 3, 2026).

The fallout included Y Combinator removing Delve from its portfolio in April 2026, and several Delve customers (Lovable, LiteLLM, Context AI) that separately suffered security incidents publicly said they had dropped Delve for other compliance vendors or auditors, with the incidents drawing scrutiny to how those companies' SOC 2 processes had been handled (TechCrunch, Mar 26 through Apr 23, 2026). In a post dated April 3, 2026 Delve apologised to customers, said it had fallen short of its own standard, and announced concrete changes: rebuilding its auditor network, offering complimentary re-audits and penetration tests, and halting its audit-workflow automation. That last item is a product change a buyer should weigh against the capability values on this record, which describe the platform as marketed. Delve's own website remains live and the company continues to solicit new customers as of this research date, but the underlying fraud and auditor-independence allegations remain unresolved in the public record.

Desk research against public sources. Every figure below carries its source and the date we retrieved it.

Capabilities

What Delve does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes Core marketed function (AI agents automating evidence collection); an anonymous whistleblower disputed the authenticity of some generated evidence, reported by TechCrunch, Mar 22, 2026. Source
Auditor workspace Yes Delve told TechCrunch it is an automation platform that gives auditors access to compiled information; final reports are issued by separate licensed audit firms. Source
Trust center Yes Vendor markets a hosted "Trust Report" page for sharing compliance status with prospects. Source
Security questionnaire answering Yes Delve's own rebuttal (quoted by TechCrunch, Apr 4, 2026) states its AI "automated 70% of a security questionnaire"; a third-party review site independently describes AI-assisted questionnaire response. Source
Enterprise admin (SSO, SCIM, RBAC) Not established No primary or independent source found confirming SSO/SCIM/RBAC support.
SCIM 2.0 provisioning Not established No mention of SCIM or of SSO for Delve's own platform anywhere we could find.
Continuous control testing Partial Vendor markets "continuous monitoring"; not independently verified, and whistleblower allegations (TechCrunch, Mar 2026) specifically disputed whether some monitoring/evidence was genuine. Source
Native multi-framework support Not established A third-party review (ComplyJet, Apr 30, 2026) describes "limited cross-framework control mapping," implying frameworks are largely handled separately, but this is not vendor-confirmed. Source
Frameworks

6 frameworks, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed Delve markets itself as a SOC 2 automation platform; the integrity of its evidence and audit-handoff process is independently disputed (see notes/auditorNetworkNote). Source
HIPAA Vendor-claimed Source
ISO 27001 Vendor-claimed Source
GDPR Vendor-claimed Source
PCI DSS Vendor-claimed Source
ISO 42001 Vendor-claimed Source
Pricing

Delve does not publish a price.

Getting a number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.

Disclosure model
Quote-based (reported $10K–$30K/yr)
Observed range (reported)
USD 10,000–30,000 / year
Basis
Estimate, 2026-07-24

Auditor fees are separate from all of these. See the SOC 2 audit cost guide for what the audit itself runs.

Auditor handoff

Who actually issues the report.

Delve states it does not itself issue attestations: "Final reports and opinions are issued solely by independent, licensed auditors, not Delve," and customers can choose their own auditor (Delve statement to TechCrunch, Mar 22, 2026). An anonymous whistleblower ("DeepDelver") alleged in March 2026 that most Delve clients were routed through two affiliated audit firms, Accorp and Gradient, that rubber-stamped Delve-generated conclusions rather than performing independent review; Delve has denied this characterization and TechCrunch stated it could not independently verify the core fraud allegations.

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who Delve is for, and who it is not.

Good fit

An early-stage startup that needs the fastest, lowest-cost path to a first SOC 2 attestation and is willing to independently vet the audit firm Delve pairs it with rather than relying on Delve's recommendation alone.

Poor fit

Companies that need a compliance vendor whose evidence pipeline and auditor relationships are beyond public dispute, or that cannot absorb reputational risk from an unresolved credibility controversy, should not pick Delve without independent verification.

Typical buyer: A very early-stage SaaS startup pursuing its first SOC 2 report to unblock a specific enterprise deal on a tight budget and timeline..

Source ledger

Where every figure on this page came from.

10 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.

← All SOC 2 compliance software Β· How we verify

Some links to compliance platforms on this page are affiliate links: if you sign up through one, the vendor may pay us a commission at no cost to you. It never changes our ranking, our review, or which platform we recommend.

For Delve

3 facts on this page we could not establish.

Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Delve, send us the sources and we will fill them.

Verification is free and always will be. It does not change where Delve appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.

Correct this record