Delve's Certification Linked to Vercel Data Breach

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Delve performed security certification for Context AI, whose app later gave hackers a foothold in Vercel’s Google‑hosted corporate account.
- Context AI confirmed it was a Delve customer but, after the scandal, switched its compliance program to Vanta and hired Insight Assurance for a fresh audit.
- Lovable left Delve in late 2025 and later admitted it unintentionally exposed customer chat data publicly.
- LiteLLM dumped Delve after malware was discovered in its open‑source code and began a new certification process.
- Y Combinator cut ties with Delve following whistleblower allegations of fake data and rubber‑stamped audits.
Why it matters: Vercel's breach—triggered by a Context AI app certified by Delve—cost the hosting platform access to internal systems and exposed customer data, prompting a shift toward alternative compliance providers like Vanta by late 2025.



