Another customer of troubled startup Delve suffered a big security incident
Compliance startup Delve faces cascading reputational and business damage as multiple customers—including Context AI, whose security certification preceded a Vercel breach—have terminated relationships and sought alternative vendors following whistleblower allegations of fake certifications and rubber-stamp audits. This incident underscores a critical risk for IT leaders: third-party security certification providers may lack integrity, and certifications alone cannot prevent breaches, requiring organizations to implement independent validation and assume primary responsibility for their security posture. The situation signals broader vendor reliability concerns in the compliance ecosystem and highlights the dangers of over-relying on single compliance partners.
