Delve Parts Ways with Y Combinator Amid Hack Allegations

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Delve is no longer listed in Y Combinator’s portfolio directory, and its COO Selin Kocalar announced on X that “YC and Delve have parted ways.”
- Insight Partners appears to have removed posts about its investment in Delve, though its main blog post about the deal was later restored.
- DeepDelver published an anonymous Substack series accusing Delve of misleading clients about compliance and auto‑generating reports for “certification mills.”
- Delve’s leadership said a cybersecurity firm found that a malicious attacker purchased the company under false pretenses, exfiltrated internal data, and launched a coordinated smear campaign.
- Delve asserted that its platform builds on an Apache 2.0 open‑source repository, which permits commercial use, and that it significantly rebuilt the code for compliance use cases.
- Delve announced remedial steps: cleaning up its network, removing unauditing firms, offering complimentary re‑audits and penetration tests to all active customers, and clarifying that its templates are starting points only.
- Karun Kaushik apologized on X, saying the firm grew too fast and fell short of its own standards, promising to address the inconvenience caused to customers.
Why it matters: YC’s disassociation strips Delve of a high‑profile accelerator and signals investor wariness, while the company’s admission of a breach and promise of complimentary re‑audits aim to retain customers and restore confidence in its compliance services. The move also puts pressure on other compliance startups to demonstrate robust security, as the controversy could erode trust across the sector.



