{"id":624178,"date":"2026-04-23T21:51:16","date_gmt":"2026-04-23T21:51:16","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/624178\/"},"modified":"2026-04-23T21:51:16","modified_gmt":"2026-04-23T21:51:16","slug":"another-customer-of-troubled-startup-delve-suffered-a-big-security-incident","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/624178\/","title":{"rendered":"Another customer of troubled startup Delve suffered a big security incident"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The story of embattled compliance startup Delve keeps hitting twists and turns. <\/p>\n<p class=\"wp-block-paragraph\">TechCrunch has confirmed that Delve was the compliance company that performed the security certifications for Context AI, the AI agent training startup that last week disclosed a security incident which <a href=\"https:\/\/techcrunch.com\/2026\/04\/20\/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai\/\" rel=\"nofollow noopener\" target=\"_blank\">led to a data breach at popular app and website hosting giant Vercel<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">On the other hand, Lovable, which had its own security incident, is no longer a Delve customer.<\/p>\n<p class=\"wp-block-paragraph\">To recap: Last month, Delve came under fire when an anonymous whistleblower alleged that <a href=\"https:\/\/techcrunch.com\/2026\/03\/22\/delve-accused-of-misleading-customers-with-fake-compliance\/\" rel=\"nofollow noopener\" target=\"_blank\">the startup was faking customer data<\/a> and using rubber-stamping auditors in its compliance and certifications processes. Delve has denied those allegations.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Soon afterwards, hackers attacked <a href=\"https:\/\/techcrunch.com\/2026\/03\/30\/popular-ai-gateway-startup-litellm-ditches-controversial-startup-delve\/&#039;\/\" rel=\"nofollow noopener\" target=\"_blank\">one of Delve\u2019s security certification customers, LiteLLM<\/a>, and planted malware in its open source code. After the incident, LiteLLM told TechCrunch it was dumping Delve and getting re-certified.<\/p>\n<p class=\"wp-block-paragraph\">Delve was also <a href=\"https:\/\/techcrunch.com\/2026\/04\/01\/the-reputation-of-troubled-yc-startup-delve-has-gotten-even-worse\/\" rel=\"nofollow noopener\" target=\"_blank\">accused of taking an open source tool<\/a> and passing it off as its own work without proper license attribution. The startup\u2019s reputation grew shaky, prompting <a href=\"https:\/\/techcrunch.com\/2026\/04\/04\/embattled-startup-delve-has-parted-ways-with-y-combinator\/\" rel=\"nofollow noopener\" target=\"_blank\">Y Combinator, where Delve graduated from<\/a>, to sever ties.<\/p>\n<p class=\"wp-block-paragraph\">Fast-forward to last weekend, Vercel said hackers had <a href=\"https:\/\/techcrunch.com\/2026\/04\/20\/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai\/\" rel=\"nofollow noopener\" target=\"_blank\">breached its internal systems and accessed some customer data<\/a>. The company said hackers broke in after an employee downloaded an app made by Context AI and connected that app to Vercel\u2019s corporate account hosted by Google. The hackers abused that employee\u2019s access to their Google account to break into some of Vercel\u2019s internal systems.<\/p>\n<p class=\"wp-block-paragraph\">After Context AI was named in the Vercel attack, Gergely Orosz, author of the engineering newsletter The Pragmatic Engineer, said <a href=\"https:\/\/x.com\/GergelyOrosz\/status\/2046292002225217953\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">in a post on X<\/a> that Delve was the company that handled Context AI\u2019s security certification.<\/p>\n<p class=\"wp-block-paragraph\">Context AI has now confirmed to TechCrunch that it did use Delve, but it has since ditched the startup and is in the process of getting re-certified.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cYes, Context was previously a Delve customer,\u201d a spokesperson for Context AI told TechCrunch. \u201cFollowing the reporting surrounding Delve in March, we transitioned our compliance program to Vanta and engaged Insight Assurance, an independent audit firm, to conduct new examinations. As part of the re-examination, we began updating our public materials, and we\u2019ll share the new attestation when it is complete,\u201d the spokesperson added.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Security certifications on their own don\u2019t stop security issues. They are intended to verify that a company has policies and processes in place to hinder attacks and reduce the likelihood of customer data being compromised.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Case in point: Lovable was a Delve customer, but <a href=\"https:\/\/www.linkedin.com\/posts\/vanta-share-7440811492775563265-EfbB\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">after the whistleblower\u2019s allegations came out,<\/a> the vibe-coding platform said it had ditched the startup back in late 2025. The company has already re-completed one security certification, and is in process of redoing others, it said.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Still, Lovable on <a href=\"https:\/\/x.com\/scrollvoid\/status\/2046306452462358941\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Monday admitted<\/a> that it had inadvertently shared access to customer chat data publicly. The company also said it had dismissed vulnerability reports that alerted the company to the problem months earlier. Lovable apologized for initially denying there was a data breach, though it said the issue was caused by a configuration error, rather than a hack.<\/p>\n<p class=\"wp-block-paragraph\">There\u2019s even weirder news swirling around Delve. The anonymous whistleblower, DeepDelver, has <a href=\"https:\/\/deepdelver.substack.com\/p\/delve-hawaii-edition-part-ii-post?r=7cupua\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">published another post<\/a> alleging Delve was denying refunds to customers, but still took its team of more than 20 people to an offsite meeting in Hawaii between April 15 and April 19.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The whistleblower shared some compelling receipts with TechCrunch that lend credence to the alleged Hawaii trip, but TechCrunch could not confirm other claims. <\/p>\n<p class=\"wp-block-paragraph\">After publication, Delve declined comment.<\/p>\n<p>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" rel=\"nofollow noopener\" target=\"_blank\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/p>\n","protected":false},"excerpt":{"rendered":"The story of embattled compliance startup Delve keeps hitting twists and turns. TechCrunch has confirmed that Delve was&hellip;\n","protected":false},"author":2,"featured_media":15819,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[62,276,277,49,48,234081,12001,13970,11551,61,95378],"class_list":{"0":"post-624178","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-artificialintelligence","11":"tag-ca","12":"tag-canada","13":"tag-context-ai","14":"tag-data-breach","15":"tag-delve","16":"tag-lovable","17":"tag-technology","18":"tag-vercel"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/624178","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=624178"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/624178\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/15819"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=624178"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=624178"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=624178"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}