Delve Faces Fraud Claims Over Compliance Audits
Allegations of fabricated audit evidence and unlicensed open-source use have put this compliance automation startup under scrutiny.
BusinessAllegations Against a Company That Was Supposed to Help With Compliance
Delve is a company that automates the work companies need to do to prepare for SOC 2 audits1 and comply with regulations like HIPAA2 and GDPR3. It marketed itself as using AI to cut down the time spent gathering evidence and drafting documentation. In 2025, it raised a $32 million Series A at a $300 million valuation.
But starting in March 2026, a string of allegations emerged claiming the company produced shoddy audit materials and used customers’ open-source code without attribution. On April 4th, co-founder Celine Kocalar announced the company’s split from YC. The company pushed back, saying the reports had distorted the facts. The core questions at stake are whether the audit materials actually reflect real inspections, and under what terms the open-source code was used.
From Founding to the April 2026 Split with YC
Here’s the company’s growth trajectory and the timeline of the allegations, laid out chronologically. Where a claim relates to material the whistleblower released, I’ve noted the source separately.
2023: Karun Kaushik and Selin Kocalar, who met at MIT, founded the company. The founders say the experience of building healthcare services—and burning enormous time and money on HIPAA compliance in the process—is what pushed them toward building a compliance business instead.
Early 2024: The company joined YC’s Winter 2024 batch. Its public description at the time said it helped companies handle HIPAA compliance through infrastructure setup, policy documentation, and monitoring.
January 2025: News broke of a $3.3 million seed round that included General Catalyst.
April 2025: According to material released by DeepDelver, Sim.ai became a Delve customer, agreeing to pay $15,000 for SOC 2 and HIPAA compliance services. Around the same time, the whistleblower alleges, Delve began applying Sim.ai’s public project SimStudio to its own product, Pathways. The whistleblower also produced an internal planning document listing which components were to be ported over.
July 2025: Delve announced a $32 million round led by Insight Partners, at a valuation of $300 million.
The fundraising history and YC pedigree gave Delve credibility it could lean on in sales conversations. But neither, on its own, verifies the actual quality of its compliance checks.
Late 2025: DeepDelver says that after receiving an email flagging a leaked spreadsheet linked to customer reports, they teamed up with other customers to investigate. Around the same time, the founders were named to Forbes’ 2026 “30 Under 30” list in the AI category.
March 19, 2026: The anonymous account DeepDelver published its first post, claiming that hundreds of draft SOC 2 reports contained identical language and audit conclusions. One specific sentence cited as an example appeared in 493 of 494 reports—roughly 99.8%. This is distinct from a separate claim that entire report contents were 99.8% similar.
March 20, 2026: Delve denied the allegations on its official blog. It explained that final reports and opinions are issued by independent auditors, and that customers are free to choose their own auditor. Its position was that the document templates are drafts meant to be reviewed and completed by customers to match their actual circumstances, and that shared language naturally arises among reports that follow the same standard.
March 23, 2026: It was reported that Insight Partners’ investment announcement post had briefly gone offline. The post was later restored. The fact that it disappeared, by itself, doesn’t tell us whether the firm withdrew its investment or reached any final judgment on the allegations.
March 31, 2026: DeepDelver published a follow-up post addressing the relationship between SimStudio and Pathways. Sim.ai responded that it had not entered into any separate agreement allowing its product to be offered under another company’s branding without attribution. The whistleblower alleged that Pathways was being sold to enterprise customers.
April 1, 2026: TechCrunch confirmed the controversy with Sim.ai CEO Emir Karabeg and reported on it. On April 3, Delve issued an official rebuttal, stating that it had heavily modified an Apache 2.0-licensed project for compliance purposes. At the same time, it announced it was overhauling its network of auditors, offering free re-audits and penetration testing to active customers, and halting automation tied to audit work.
April 4, 2026: Kocalar announced the company’s split from YC, and reports noted that Delve had also disappeared from YC’s public company directory. None of this settles the truth of the individual allegations or any question of legal liability.
Looking at the fragment, I compared it carefully against the Korean source. The structure, headings, footnotes, links, and image all match. I found no Hangul characters, and all numbers (4, three questions) are preserved correctly. The translation reads naturally and captures the meaning accurately.
One minor issue: “told customers from the outset that this was a product built entirely in-house” is slightly redundant (“from the outset” + “built entirely in-house” both implying originality) but this doesn’t distort meaning. I’ll leave the draft largely as-is since it’s already solid, with one small polish for flow.
Using open-source code and what you tell customers are two separate questions
Copying and modifying published code is called a fork.4 If it falls within what an open-source license permits, it can be used commercially without a separate paid contract. So the mere fact that no money changed hands doesn’t, by itself, make it unauthorized use.
The Apache 2.0 license cited in this case allows commercial use, modification, and redistribution. Applying a different license to the modified portions is also permitted, within set conditions. The real issue is what conditions apply to how this particular code was used and distributed, and whether Delve complied with them.
Section 4 of Apache 2.0 requires the following when redistributing the original or a derivative work:
- You must give recipients a copy of the license.
- You must mark any modified files as changed.
- Any derivative source you distribute must retain the copyright, patent, trademark, and attribution notices relevant to that portion.
- If the original includes a NOTICE file, you must include the applicable attribution notices in the prescribed location.
The core of the exposé’s allegation is that while using SimStudio, the company told customers from the start that this was a product it had built itself. We need to check both the code’s provenance and what was actually told to customers. Still, without cross-checking the actual distributed artifacts against the required notices, we can’t conclude that all four license conditions were violated.
The customer relationship matters too. Sim.ai was a client that hired Delve for compliance work. Even when a service provider uses that same client’s own published code, if the purpose and the explanation given to the client are opaque, a trust problem can arise. Nothing in this case confirms that private code or security information belonging to the client was taken, so that shouldn’t be conflated with the allegations about open-source code use.
Here’s my view: whether the license terms were honored and whether the counterparty was told the truth are two separate things that each need to be checked on their own. Using open source isn’t inherently wrong, and the fact that commercial use is permitted doesn’t automatically make every explanation given to customers legitimate.
If the tip is accurate, we need to examine whether there was a gap between the service promised to customers and the service actually delivered. Delve has pushed back, saying the leaked material was taken out of context and was disclosed maliciously. That claim, too, should be read as the company’s own account of events.
The questions to verify boil down to three:
- Did the audit documents reflect the client’s actual systems and inspection results?
- Did the auditor reach independent conclusions based on sufficient evidence?
- Did the code used in Pathways and its attribution notices satisfy the applicable license conditions?

When trust in shared networks substitutes for due diligence
Companies that come out of YC buy from and recommend each other’s products. It’s natural to look first at a company whose background you know well, rather than an unfamiliar vendor. That kind of relationship existed in the deal between Sim.ai and Delve.
But funding from a well-known investor, or participation in a startup accelerator, isn’t a guarantee that an individual customer’s security controls actually work. In its rebuttal on March 20, Delve stated that it has more than 1,700 customers. A large customer count alone tells you nothing about whether your company’s audit was done thoroughly.
The community has offered various interpretations of why YC responded the way it did. Rather than speculate about the reasons for removal, which are hard to verify from the outside, I think it’s more useful to examine what checks a buyer skipped by relying on a well-known name.
Recommendations among alumni reduce the cost of finding a vendor. What comes after that is verifying the scope of the contract, the auditor’s independence, and the actual deliverables yourself. A recommendation can be a reason to start due diligence, but it’s never grounds to end it.
Oswarld’s Lens
Watching this case unfold, I found myself thinking about how the market would actually evaluate the fast turnaround speed Delve had marketed as its selling point.
From my own experience building go-to-market strategies, a pitch that promises to compress months of work into days is a compelling one for customers. But you have to be able to explain exactly what got compressed. Automating data collection or repetitive data entry is genuinely useful, but you still need evidence that controls actually worked in practice, plus an auditor’s independent judgment. Automation and independent verification aren’t mutually exclusive — they need to be designed together.
Cutting product development time by using open-source code is also a reasonable choice. But the more you lean on it, the more carefully you need to document which code you used and what disclosures are required. When speed-to-market and regulatory compliance get treated as competing goals, the first casualty, in my view, is exactly the documentation you’d need if something went wrong.
I also noticed that the anonymous poster who identified as a customer, along with other tipsters, raised the controversy publicly. That’s worth using as an occasion to ask whether customers have adequate channels to question audit materials, and whether there’s a real way to verify things directly with the auditor. That said, it’s hard to conclude from a single incident that regulatory and industry oversight failed across the board.
When a well-known investor’s backing, media coverage, and award recognitions all line up, it’s easy for a company to project the impression that it’s already been thoroughly vetted. I’ll admit that when I evaluate a business, those kinds of names can catch my eye first too. That’s exactly why we need a separate process for checking reputational signals apart from evidence that the product actually works as claimed. In judging the allegations against Delve, too, actual audit records and code usage history are far more direct evidence than an investor track record.
The draft matches the Korean source well in meaning, structure, and terminology. No corrections needed.
Closing
When using open source commercially, you need to check that license’s conditions. How you describe the development’s origins to customers has to match what was actually used, too.
When outsourcing security and compliance work, I’d want to first check what exactly the vendor and the auditor each do. You’d also need to look at what systems and time period a report covers, and what items were checked along with any exceptions noted. SOC 2 is an audit report on these kinds of controls, while HIPAA or GDPR are legal obligations that covered entities must follow. Bundling all of this together under one label of “security certification” blurs where responsibility actually lies.
For a vendor proposing faster processing, you can ask specifically what work was actually reduced. It matters a great deal whether the time saved was in gathering materials, or whether it extended to cutting back the scope of human review itself.
Specifically regarding HIPAA, the U.S. Department of Health and Human Services states that it does not recognize or endorse “certifications” from private organizations. Using an outside vendor doesn’t make a covered entity’s legal obligations disappear.
What concerns me is a way of running a business that rewards speed of growth alone, without clearly defining the time and accountability that verification requires. Separate from whatever final judgment is reached about the allegations raised against Delve, this is a question we can already apply when choosing and evaluating services. Alongside how fast something got done, let’s also ask what was actually checked, and who reached the conclusion.
The English draft matches the Korean source accurately with correct structure, numbers, links, and glossary terms. No corrections needed.
Keep the perspective, not the noise.
We choose one consequential shift and trace what sits beneath it, every other day.
Confirm once to finish subscribing.
Already a subscriber? Sign in to join the conversation
References & Further Reading
- DeepDelver, Delve – Fake Compliance as a Service – Part I, March 19, 2026. Contains the whistleblower’s claims and a frequency analysis of suspicious phrasing.
- DeepDelver, Part II – Day 2 of 5, March 31, 2026. Follow-up claims about Sim.ai and Pathways, along with Sim.ai’s response.
- Delve, Response to Misleading Claims, March 20, 2026. The company’s rebuttal on audits, document formats, and automation.
- Delve, Delve sets the record straight on anonymous attacks, April 3, 2026. An explanation of its open-source usage and the follow-up steps announced.
- Julie Bort, The reputation of troubled YC startup Delve has gotten even worse, TechCrunch, April 1, 2026.
- Anthony Ha, Embattled startup Delve has ‘parted ways’ with Y Combinator, TechCrunch, April 4, 2026.
- Delve, Series A funding announcement, July 22, 2025. The founders’ 2024 service introduction, Forbes profile.
- Apache Software Foundation, Apache License, Version 2.0. The original text on permitted use and redistribution terms.
- AICPA, Introduction to SOC 2. US HHS, Guidance on the HIPAA Security Rule and private certification.

Footnotes
-
SOC 2: a framework in which an independent accounting firm evaluates and reports on a service provider’s controls around security, availability, processing integrity, confidentiality, and privacy. It’s not a guarantee that all security incidents will be prevented. ↩
-
HIPAA: a US law governing the protection of health information, among other things. It sets obligations for covered healthcare and health insurance entities and their business associates. It doesn’t apply uniformly to every service that handles health data. ↩
-
GDPR: the EU’s data protection regulation. What matters isn’t just where a business is located, but the scope of its processing activities and where the regulation applies. ↩
-
Fork: starting a separate line of development based on an existing project’s code. Even with open-source code, using, modifying, or redistributing it must comply with the relevant license. ↩
Your take shapes the next issue
What resonated most in this issue, or where has your experience been different?