Another customer of struggling startup Delve hit by major security breach

The compliance startup Delve continues to face a series of escalating controversies.
TechCrunch has verified that Delve conducted the security certifications for Context AI, an AI agent training firm that recently reported a security incident resulting in a data breach at the prominent app and website hosting platform Vercel.
Meanwhile, Lovable, which experienced its own security incident, is no longer using Delve’s services.
To recap: Last month, Delve faced intense scrutiny after an anonymous whistleblower claimed the startup fabricated customer data and utilized rubber-stamping auditors for its compliance certifications. Delve has denied these allegations.
Shortly thereafter, hackers targeted one of Delve’s security certification clients, LiteLLM, and injected malware into its open-source code. Following the breach, LiteLLM informed TechCrunch that it was terminating its relationship with Delve and seeking re-certification.
Delve also faced accusations of appropriating an open-source tool and presenting it as proprietary work without proper license attribution. The startup’s reputation deteriorated, leading Y Combinator, where Delve graduated, to sever ties.
Fast forward to last weekend, when Vercel announced that hackers had breached its internal systems and accessed certain customer data. The company stated that the breach occurred after an employee downloaded an application developed by Context AI and connected it to Vercel’s corporate account hosted on Google. The attackers exploited this employee’s access to their Google account to infiltrate parts of Vercel’s internal infrastructure.
Once Context AI was identified in connection with the Vercel attack, Gergely Orosz, author of the engineering newsletter The Pragmatic Engineer, posted on X that Delve had handled Context AI’s security certification.
Context AI has now confirmed to TechCrunch that it previously used Delve but has since discontinued the partnership and is currently undergoing re-certification.
“Yes, Context was previously a Delve customer,” a spokesperson for Context AI told TechCrunch. “Following the reporting surrounding Delve in March, we transitioned our compliance program to Vanta and engaged Insight Assurance, an independent audit firm, to conduct new examinations. As part of the re-examination, we began updating our public materials, and we’ll share the new attestation when it is complete,” the spokesperson added.
Security certifications alone do not prevent security incidents. Their purpose is to verify that a company has established policies and processes to mitigate attacks and reduce the risk of customer data compromise.
For example: Lovable was a Delve customer, but after the whistleblower’s allegations emerged, the vibe-coding platform stated it had terminated its relationship with Delve in late 2025. The company has already completed one security certification and is in the process of redoing others.
Nevertheless, Lovable admitted on Monday that it had inadvertently made customer chat data publicly accessible. The company also acknowledged dismissing vulnerability reports that had alerted it to the issue months earlier. Lovable apologized for initially denying a data breach, though it clarified that the problem stemmed from a configuration error rather than a hack.
Further strange developments are swirling around Delve. The anonymous whistleblower, known as DeepDelver, has published another post alleging that Delve was refusing refunds to customers while simultaneously taking its team of over 20 employees to an offsite meeting in Hawaii between April 15 and April 19.
The whistleblower provided compelling evidence to TechCrunch supporting the alleged Hawaii trip, but TechCrunch was unable to verify other claims.
Delve did not respond to requests for comment and confirmation, and an email sent to its media relations address bounced.
Related article
Delve accused of deceiving customers with 'fake compliance' scheme
A recent anonymous Substack post accuses compliance startup Delve of misleading hundreds of customers into believing they were compliant with privacy and security regulations, potentially exposing them to criminal liability under HIPAA and substantia
Lovable strikes multi-year Google Cloud deal to boost usage 5x, source says
On Wednesday, Lovable and Google announced an expanded multi-year partnership. Lovable, the fast-growing Stockholm-based vibe-coding startup, has been a Google Cloud customer for some time. Under the new agreement, its usage will increase significant
Vercel CEO Guillermo Rauch hints at IPO as AI agents boost revenue
Unlike many startups founded before ChatGPT that now struggle to find their footing in the AI era, Vercel, a decade-old development tool and website hosting platform, is thriving due to the surge of AI-generated applications and autonomous agents.“Wh
Related Special Topic Recommendations
Comments (0)
0/500

The compliance startup Delve continues to face a series of escalating controversies.
TechCrunch has verified that Delve conducted the security certifications for Context AI, an AI agent training firm that recently reported a security incident resulting in a data breach at the prominent app and website hosting platform Vercel.
Meanwhile, Lovable, which experienced its own security incident, is no longer using Delve’s services.
To recap: Last month, Delve faced intense scrutiny after an anonymous whistleblower claimed the startup fabricated customer data and utilized rubber-stamping auditors for its compliance certifications. Delve has denied these allegations.
Shortly thereafter, hackers targeted one of Delve’s security certification clients, LiteLLM, and injected malware into its open-source code. Following the breach, LiteLLM informed TechCrunch that it was terminating its relationship with Delve and seeking re-certification.
Delve also faced accusations of appropriating an open-source tool and presenting it as proprietary work without proper license attribution. The startup’s reputation deteriorated, leading Y Combinator, where Delve graduated, to sever ties.
Fast forward to last weekend, when Vercel announced that hackers had breached its internal systems and accessed certain customer data. The company stated that the breach occurred after an employee downloaded an application developed by Context AI and connected it to Vercel’s corporate account hosted on Google. The attackers exploited this employee’s access to their Google account to infiltrate parts of Vercel’s internal infrastructure.
Once Context AI was identified in connection with the Vercel attack, Gergely Orosz, author of the engineering newsletter The Pragmatic Engineer, posted on X that Delve had handled Context AI’s security certification.
Context AI has now confirmed to TechCrunch that it previously used Delve but has since discontinued the partnership and is currently undergoing re-certification.
“Yes, Context was previously a Delve customer,” a spokesperson for Context AI told TechCrunch. “Following the reporting surrounding Delve in March, we transitioned our compliance program to Vanta and engaged Insight Assurance, an independent audit firm, to conduct new examinations. As part of the re-examination, we began updating our public materials, and we’ll share the new attestation when it is complete,” the spokesperson added.
Security certifications alone do not prevent security incidents. Their purpose is to verify that a company has established policies and processes to mitigate attacks and reduce the risk of customer data compromise.
For example: Lovable was a Delve customer, but after the whistleblower’s allegations emerged, the vibe-coding platform stated it had terminated its relationship with Delve in late 2025. The company has already completed one security certification and is in the process of redoing others.
Nevertheless, Lovable admitted on Monday that it had inadvertently made customer chat data publicly accessible. The company also acknowledged dismissing vulnerability reports that had alerted it to the issue months earlier. Lovable apologized for initially denying a data breach, though it clarified that the problem stemmed from a configuration error rather than a hack.
Further strange developments are swirling around Delve. The anonymous whistleblower, known as DeepDelver, has published another post alleging that Delve was refusing refunds to customers while simultaneously taking its team of over 20 employees to an offsite meeting in Hawaii between April 15 and April 19.
The whistleblower provided compelling evidence to TechCrunch supporting the alleged Hawaii trip, but TechCrunch was unable to verify other claims.
Delve did not respond to requests for comment and confirmation, and an email sent to its media relations address bounced.
Delve accused of deceiving customers with 'fake compliance' scheme
A recent anonymous Substack post accuses compliance startup Delve of misleading hundreds of customers into believing they were compliant with privacy and security regulations, potentially exposing them to criminal liability under HIPAA and substantia
Lovable strikes multi-year Google Cloud deal to boost usage 5x, source says
On Wednesday, Lovable and Google announced an expanded multi-year partnership. Lovable, the fast-growing Stockholm-based vibe-coding startup, has been a Google Cloud customer for some time. Under the new agreement, its usage will increase significant
Vercel CEO Guillermo Rauch hints at IPO as AI agents boost revenue
Unlike many startups founded before ChatGPT that now struggle to find their footing in the AI era, Vercel, a decade-old development tool and website hosting platform, is thriving due to the surge of AI-generated applications and autonomous agents.“Wh





Home






