Close Menu
TechurzTechurz
    What's Hot

    Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers

    July 31, 2026

    Fusion power darling Commonwealth Fusion Systems raises another $1B

    July 30, 2026

    When will fusion power startup Commonwealth Fusion Systems go public?

    July 30, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers
    • Fusion power darling Commonwealth Fusion Systems raises another $1B
    • When will fusion power startup Commonwealth Fusion Systems go public?
    • Synthetic-user startup Simile raises $200M at $2B valuation 5 months after $100M Series A
    • Okta buys AI security startup Permiso; source says for about $200M
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Opinion - Another customer of troubled startup Delve suffered a big security incident
    Opinion

    Another customer of troubled startup Delve suffered a big security incident

    TechurzBy TechurzApril 23, 2026Updated:May 11, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Delve accused of misleading customers with ‘fake compliance’
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The story of embattled compliance startup Delve keeps hitting twists and turns.

    TechCrunch has confirmed that Delve was the compliance company that performed the security certifications for Context AI, the AI agent training startup that last week disclosed a security incident which led to a data breach at popular app and website hosting giant Vercel.

    On the other hand, Lovable, which had its own security incident, is no longer a Delve customer.

    To recap: Last month, Delve came under fire when an anonymous whistleblower alleged that the startup was faking customer data, and using rubber-stamping auditors in its compliance and certifications processes. Delve has denied those allegations. 

    Soon afterwards, hackers attacked one of Delve’s security certification customers, LiteLLM, and planted malware in its open source code. After the incident, LiteLLM told TechCrunch it was dumping Delve and getting re-certified.

    Delve was also accused of taking an open source tool and passing it off as its own work without proper license attribution. The startup’s reputation grew shaky, prompting Y Combinator, where Delve graduated from, to sever ties.

    Fast forward to last weekend, Vercel said hackers had breached its internal systems and accessed some customer data. The company said hackers broke in after an employee downloaded an app made by Context AI and connected that app to Vercel’s corporate account hosted by Google. The hackers abused that employee’s access to their Google account to break into some of Vercel’s internal systems.

    After Context AI was named in the Vercel attack, Gergely Orosz, author of the engineering newsletter, The Pragmatic Engineer, said in a post on X that Delve was the company that handled Context AI’s security certification.

    Context AI has now confirmed to TechCrunch that it did use Delve, but it has since ditched the startup and is in the process of getting re-certified. 

    “Yes, Context was previously a Delve customer,” a spokesperson for Context AI told TechCrunch. “Following the reporting surrounding Delve in March, we transitioned our compliance program to Vanta and engaged Insight Assurance, an independent audit firm, to conduct new examinations. As part of the re-examination, we began updating our public materials, and we’ll share the new attestation when it is complete,” the spokesperson added. 

    Security certifications on their own don’t stop security issues. They are intended to verify that a company has policies and processes in place to hinder attacks and reduce the likelihood of customer data being compromised. 

    Case in point: Lovable was a Delve customer, but after the whistleblower’s allegations came out, the vibe-coding platform said it had ditched the startup back in late 2025. The company has already re-completed one security certification, and is in process of redoing others, it said. 

    Still, Lovable on Monday admitted that it had inadvertently shared access to customer chat data publicly. The company also said it had dismissed vulnerability reports that alerted the company to the problem months earlier. Lovable apologized for initially denying there was a data breach, though it said the issue was caused by a configuration error, rather than a hack.

    There’s even weirder news swirling around Delve. The anonymous whistleblower, DeepDelver, has published another post alleging Delve was denying refunds to customers, but still took its team of more than 20 people to an offsite meeting in Hawaii between April 15 and April 19.  

    The whistleblower shared some compelling receipts with TechCrunch that lend credence to the alleged Hawaii trip, but TechCrunch could not confirm other claims.

    Delve did not respond to requests for comment and confirmation, and an email sent to its media relations address bounced.

    When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

    Big customer Delve incident Security startup suffered troubled
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBeehiiv rolls out new creator tools, including webinars and customizable paywalls
    Next Article The first StrictlyVC of 2026 kicks off in a week in San Francisco
    Techurz
    • Website

    Related Posts

    Opinion

    Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers

    July 31, 2026
    Opinion

    Fusion power darling Commonwealth Fusion Systems raises another $1B

    July 30, 2026
    Opinion

    When will fusion power startup Commonwealth Fusion Systems go public?

    July 30, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.