Another customer of troubled startup Delve suffered a big security incident

TechCrunch
Context AI, a customer of troubled startup Delve, experienced a data breach after an employee connected a Delve-certified app to Vercel's systems.

Summary

Troubled compliance startup Delve has been linked to another security incident, this time involving its customer Context AI, which led to a data breach at Vercel. Context AI confirmed it used Delve for security certification but has since switched providers and is undergoing re-certification. This follows previous controversies surrounding Delve, including allegations of faking customer data, using rubber-stamping auditors, and intellectual property theft, which led to Y Combinator severing ties. Separately, Lovable, another former Delve customer, admitted to a data exposure incident due to a configuration error, despite having dismissed earlier vulnerability reports. The whistleblower "DeepDelver" has also alleged Delve denied refunds while taking its team on an offsite trip to Hawaii.

(Source:TechCrunch)