Yeah, ok. BRB to start a bank where I template everyone a billion dollars, its up to you to be honest with how much money you have.
— patio11 about this response (https://x.com/patio11/status/2035115379169677717)
> No small amount of criticism of LLMs is downstream of past decisions to reify form over function, resulting in the substance having been optimized out. Now the LLM threatens to make the form available in seconds
Wow, what a way to end the document.
None of their ISO 27001 certificates, aside from the premium one-offs with the vCISO, are accredited by any reputable ISO accreditation body. I would even argue that IAS, who accredited Prescient Security (mentioned as a reputable body in the article), has a questionable reputation and certainly gives off a pay-to-play impression.
You can look up the names of their partners below. The one body I found that is on the register (Accorp) is accredited by UAF, a known cert-mill accreditation body, and I’m not even sure it’s the same Accorp that Delve has partnered with.
For reference, you want a ISO certificate issued by a body accredited by UKAS (UK gov. adjacent non-profit), ANAB (ANSI), or equivalent, all government-recognised. This is normally the first thing I check whenever someone claims ISO 27001 certification and it is a great heuristic to validate certification rigour.
https://www.iafcertsearch.org/search/certification-bodies
Shockingly low levels of DD by everyone involved here.
"Below are just some of the many inaccuracies in the story and then the truth."
"[G]iven how competitive this industry is, attacks like this sadly come with the territory."
"We are actively investigating any leaks and are still reviewing the Substack. If there are more attacks to respond to we will do so."
When you have a PR problem, you don't hire your marketing intern to write the response. You hire a PR consultant. Their funders' Rolodexes are probably full of them. If the Board approved the response, I'd be frankly shocked.
That, plus their willingness to arrange an essentially fraudulent auditor network (try to find who the real CPA is behind Accorp, for example), and also massively upcharge the prices of the SOC reports that they offered as a bundled service within the platform. There was no separation here. Del is the transfer agent. Del was always the intermediary and the transfer agent. There is no independence in their default auditor relationships.
At very best, this is a massive AICPA transgression.
At worst, blatant fraud.
I would wager that discovery would show the latter.
In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility.
Very, very bad.
But really all you have to do is look at the reports themselves. They are so shoddily written that it's hard to believe any legitimate firm would issue them. If you Ctrl F for Clueley in this thread, you will see my comment with a sample excerpt from the assertion of management for one of their reports.
6.7 Misled auditor - Prescient
With this conclusion:
Looking at that report, there are clear signs that Delve either knowingly misled Prescient, or that Prescient accommodated Delve’s deficient process. Given their reputation and by the small number of Delve/Prescient reports out there, I’m assuming it is the former.