We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

119 points by fadijob a day ago on hackernews | 77 comments

LIVE DATABASE

Trust Compliance on Product Hunt

The Biggest Compliance Fraud
in SOC 2 History

Your vendor's audit might be worthless. 533 reports. 455 companies. One copy-pasted template.

Trending Now

Most Checked Companies

What People Are Saying

Trusted by Security Teams

Just checked all 12 of our vendors. 3 of them used Delve. This tool saved us weeks of manual review.

The game is weirdly addictive. Got my whole security team playing it.

Shared this with our compliance team. They ran every vendor through the scanner within an hour.

Finally, someone made SOC 2 verification accessible to non-security people.

84ISO 27001

251SOC 2 Type 1

198SOC 2 Type 2

What Happened

The Anatomy of a Compliance Scam

The Scheme

Delve sold SOC 2 and ISO 27001 certifications as a service. Companies paid, received reports, and displayed compliance badges -- without any real audit taking place.

The Leak

533 audit reports from 455 companies were leaked publicly. Forensic analysis revealed 99.8% identical boilerplate text across every single report.

The Fallout

Every company in the database now faces existential questions about their security posture. Customers, investors, and partners deserve to know the truth.

Last updated: March 21, 2026|14 new reports indexed this week

Tools

Verify. Scan. Assess.

Free tools to check your vendor's compliance integrity.

Discussed on

YHacker News

𝕏X / Twitter

r/Reddit

SSubstack

inLinkedIn

Don't wait until your customers ask.

If your vendor is in this database, you need to know now -- before it becomes a board-level conversation.

Check Your Vendor Now