Delve SOC 2 compliance software
Delve is a SOC 2 and adjacent-framework compliance automation platform that markets AI agents for evidence collection. Its website also markets control monitoring, trust-center, and questionnaire workflows for startups, mid-market teams, and enterprises.
Trading normally, but under an unresolved public controversy: in March 2026 a whistleblower alleged fabricated audit evidence and routing to affiliated audit firms, Delve denied it and attributed the leak to an attacker, and Y Combinator removed Delve from its portfolio in April 2026. Sources and detail below.
By Peter Korpak, Lead Editor ยท independently researched ยท Methodology
- Pricing
- Quote-based (reported $10Kโ$30K/yr)
- Source-checked frameworks
- 6
- Integrations
- 100+
- G2 (2026-07-24)
- 4.7 ยท 135 reviews
In March 2026 an anonymous whistleblower publicly alleged Delve generated fabricated audit evidence and routed clients to affiliated rubber-stamp audit firms; Delve denied the claims and said a forensic review pointed to a data-exfiltration attack behind a coordinated smear campaign (TechCrunch, Mar 22 and Apr 3, 2026). The fallout included Y Combinator removing Delve from its portfolio in April 2026, and several Delve customers (Lovable, LiteLLM, Context AI) that separately suffered security incidents publicly said they had dropped Delve for other compliance vendors or auditors, with the incidents drawing scrutiny to how those companies' SOC 2 processes had been handled (TechCrunch, Mar 26 through Apr 23, 2026). On March 24, 2026, Delve said it was adding complimentary re-audits and penetration tests for active customers, independent-auditor introductions on request, and customer access to evidence and integration-test logs. In a post dated April 3, 2026 Delve then apologised to customers, said it had fallen short of its own standard, and announced further changes: rebuilding its auditor network and halting its audit-workflow automation. That last item is a product change a buyer should weigh against the capability values on this record, which describe the platform as marketed. Delve's own website remains live and the company continues to solicit new customers as of this research date, but the underlying fraud and auditor-independence allegations remain unresolved in the public record.
Delve (founded 2023 by Karun Kaushik and Selin Kocalar) raised a $3.3M seed round (announced Jan 2025, Y Combinator/General Catalyst/FundersClub/Soma Capital) followed by a $32M Series A led by Insight Partners at a $300M valuation, announced July 22, 2025; total disclosed funding is reported at $35.3M.
Delve has scoped marketplace prices.
Direct pricing still requires a sales conversation. The public figures below are scoped marketplace or catalog prices, not a universal rate card; third-party procurement evidence is kept separate.
- Disclosure model
- Quote-based (reported $10Kโ$30K/yr)
- Sourced annual range (reported)
- USD 10,000โ30,000 / year
- Basis
- Estimate, 2026-07-24
Published catalog evidence
These prices are tied to the named channel and scope. A missing direct price remains unknown; it is not inferred from the marketplace listing.
| Plan or add-on | Published price | Channel and scope |
|---|---|---|
| Foundation Package Plan | USD 12,000 / 12-month contract | Starting at. 1โ20 employees; Foundation Package ยท AWS Marketplace |
Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.
Read the Delve pricing guide for the current source table and quote checklist.
What Delve does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Core marketed function (AI agents automating evidence collection); an anonymous whistleblower disputed the authenticity of some generated evidence, reported by TechCrunch, Mar 22, 2026. Source |
| Auditor workspace | Yes | Delve told TechCrunch it is an automation platform that gives auditors access to compiled information; final reports are issued by separate licensed audit firms. Source |
| Trust center | Yes | Vendor markets a hosted "Trust Report" page for sharing compliance status with prospects. Source |
| Security questionnaire answering | Yes | Delve's own rebuttal (quoted by TechCrunch, Apr 4, 2026) states its AI "automated 70% of a security questionnaire"; a third-party review site independently describes AI-assisted questionnaire response. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Not established | No primary or independent source found confirming SSO/SCIM/RBAC support. |
| SCIM 2.0 provisioning | Not established | No mention of SCIM or of SSO for Delve's own platform anywhere we could find. |
| Continuous control testing | Partial | Vendor markets "continuous monitoring"; not independently verified, and whistleblower allegations (TechCrunch, Mar 2026) specifically disputed whether some monitoring/evidence was genuine. Source |
| Native multi-framework support | Not established | A third-party review (ComplyJet, Apr 30, 2026) describes "limited cross-framework control mapping," implying frameworks are largely handled separately, but this is not vendor-confirmed. Source |
6 frameworks checked individually, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Delve markets itself as a SOC 2 automation platform; the integrity of its evidence and audit-handoff process is independently disputed (see notes/auditorNetworkNote). Source |
| HIPAA | Vendor-claimed | Vendor-claimed HIPAA workflow: custom program by company size/tools/risk profile; white-glove setup; AI evidence capture, questionnaire automation, infrastructure scanning, policy assistance, and a trust report. Source |
| ISO 27001 | Vendor-claimed | Source |
| GDPR | Vendor-claimed | Source |
| PCI DSS | Vendor-claimed | Source |
| ISO 42001 | Vendor-claimed | Source |
Who actually issues the report.
Delve states it does not itself issue attestations: "Final reports and opinions are issued solely by independent, licensed auditors, not Delve," and customers can choose their own auditor (Delve statement to TechCrunch, Mar 22, 2026). An anonymous whistleblower ("DeepDelver") alleged in March 2026 that most Delve clients were routed through two affiliated audit firms, Accorp and Gradient, that rubber-stamped Delve-generated conclusions rather than performing independent review; Delve has denied this characterization and TechCrunch stated it could not independently verify the core fraud allegations.
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Delve is for, and who it is not.
Good fit
An early-stage startup pursuing its first SOC 2 attestation on a tight budget and timeline that will independently vet Delve's recommended audit firm.
Poor fit
Companies that need a compliance vendor whose evidence pipeline and auditor relationships are beyond public dispute, or that cannot absorb reputational risk from an unresolved credibility controversy, should not pick Delve without independent verification.
Typical buyer: A very early-stage SaaS startup pursuing its first SOC 2 report to unblock a specific enterprise deal on a tight budget and timeline.
Compare Delve with three alternatives.
- Comp AI Sponsored
An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.
-
A founder or CTO running a first SOC 2 who wants software with a dedicated consultant: Build DFY includes up to six months; Build Stronger includes 12 months and ongoing policy support. Build Starter is platform-only.
-
Startups running one or two frameworks (e.g. SOC 2 plus HIPAA or ISO 27001) that want the fastest guided path to a first audit without per-user pricing or a large software bill.
Sources
If a claim on this page is out of date, this is the list to re-check.
| Establishes | Source | Retrieved |
|---|---|---|
| Reports the whistleblower's fake-compliance allegations and Delve's on-the-record denial/statement. | TechCrunch Press | |
| Confirms Y Combinator removed Delve from its portfolio and quotes Delve's rebuttal blog post, including the '70% of a security questionnaire' claim. | TechCrunch Press | |
| Confirms Delve performed Context AI's security certification, that Context AI has since switched to Vanta + Insight Assurance, and recaps the LiteLLM/Lovable fallout timeline. | TechCrunch Press | |
| Confirms the $32M Series A led by Insight Partners at a $300M valuation, announced July 22, 2025. | TechCrunch Press | |
| Investor-side confirmation of the Series A terms and use of funds. | Insight Partners Press | |
| Delve's own account (Apr 3, 2026) attributing the leak to a malicious attacker and disputing the whistleblower's characterization. | Vendor blog (Delve) Vendor docs | |
| Dated March 24, 2026; records Delve's promised re-audits, penetration tests, independent-auditor introductions, and customer visibility into evidence and integration-test logs. | Vendor blog (Delve) Vendor docs | |
| Third-party estimate of ~100 integrations and limited cross-framework control mapping. | ComplyJet Editorial | |
| Third-party pricing estimate (~$12k/year automation platform + ~$12k audit). | ComplyJet Third-party estimate | |
| Lists Delve's Foundation Package at $12,000 starting for 1โ20 employees on a 12-month contract; package scope and audit inclusion require confirmation. | AWS Marketplace Marketplace | |
| States that the Order controls the license fees, scope, and term, so a marketplace starting price is not a universal rate card. | Vendor terms (Delve) Vendor docs | |
| Reports Delve's G2 rating as 4.7/5 based on 135 reviews. | Sprinto Editorial | |
| Company profile confirming category and identity. | Crunchbase Review platform | |
| HIPAA framework support recorded as vendor-claimed. | Delve Vendor docs | |
| Vendor-claimed HIPAA workflow: custom program by company size/tools/risk profile; white-glove setup; AI evidence capture, questionnaire automation, infrastructure scanning, policy assistance, and a trust report. | Delve Vendor docs | |
| Not established. The reviewed Delve framework page describes HIPAA program support but does not establish the vendor's own PHI permission or customer BAA route. | SOC2Auditors.org Editorial |
3 facts on this page we could not establish.
Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Delve, send us the sources and we will fill them.
Verification is free and always will be. It does not change where Delve appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the sources list above alongside the date.