LiteLLM Drops Delve After Malware, Will Re-Certify With Vanta

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- LiteLLM publicly announced it is cutting ties with compliance startup Delve and will redo its security certifications with a new company and auditor.
- The decision follows a credential-stealing malware incident that hit LiteLLM's open source version last week — despite the company already holding two compliance certifications obtained through Delve.
- Delve has been accused by an anonymous whistleblower of allegedly generating fake compliance data and using auditors who rubber-stamped its reports.
- Delve's founder denied the allegations and offered free re-tests and audits to all customers, prompting the whistleblower to double down over the weekend with alleged supporting receipts.
- LiteLLM CTO Ishaan Jaffer posted on X on Monday that the company will use Vanta to re-certify and will hire its own independent third-party auditor to verify its compliance controls.
- LiteLLM's AI gateway is used by millions of developers, making the public defection a notable credibility blow to Delve within the AI compliance market.
Why it matters: LiteLLM, whose AI gateway serves millions of developers, is publicly abandoning the compliance startup that certified it after a malware attack — directly undermining the value of the two security certifications Delve had issued, since those credentials existed precisely to minimize this kind of incident.


