2026 Delve — compliance controversy; LiteLLM SOC2/ISO link; “fake compliance” whistleblower claims
Data compromised
Not a classic consumer PII dump; customers’ compliance posture and trust at risk; vendor ecosystem exposure
Technical writeup
In late March 2026, press coverage intersected Delve (Y Combinator–backed compliance automation) with the LiteLLM PyPI supply-chain malware incident: LiteLLM had obtained SOC 2 and ISO 27001 certifications through Delve, creating reputational and regulatory scrutiny after malicious packages were discovered in the LiteLLM ecosystem. Separately, anonymous whistleblower-style allegations (“DeepDelver”) and TechCrunch reporting accused Delve of misleading customers with inadequate or “rubber-stamped” compliance evidence; Delve’s founder publicly denied wrongdoing and offered re-audits. LiteLLM announced it would move compliance work to Vanta and an independent auditor. This entry tracks compliance and trust risk rather than a single exported customer database with a countable PII row count. The same March 2026 window saw separate infrastructure incidents (e.g., Railway CDN mis-caching authenticated responses) discussed alongside Delve/LiteLLM in developer circles—distinct vendors and root causes.
Root cause
Governance and compliance-process controversy; third-party audit quality disputed; adjacent to LiteLLM supply-chain incident