Delve Lawsuit and Scandal: Whistleblower, YC Expulsion, Mercor Suit

The Delve lawsuit and scandal began in March 2026, when an anonymous whistleblower accused the San Francisco compliance startup of fabricating SOC 2, ISO 27001, HIPAA, and GDPR certifications for hundreds of customers. Within weeks, Y Combinator expelled the company, several customers dropped the platform, and Delve was named as a co-defendant in a federal class action tied to a four-terabyte data breach at the AI labor platform Mercor. Delve denies the allegations and blames a “malicious actor” who it says infiltrated the company and leaked internal documents.

What the Whistleblower Alleged

On March 21 and 22, 2026, an anonymous Substack account called “DeepDelver” published a detailed exposé claiming Delve had “falsely convinced hundreds of customers they were compliant” with security and privacy regulations.1TechCrunch. Delve Accused of Misleading Customers With Fake Compliance The account identified itself as an employee at a former Delve client, working with other dissatisfied customers.

The core allegation was that Delve generated compliance evidence and audit conclusions before any independent review took place, then routed customers to a small group of audit firms that signed off without meaningful scrutiny. Evidence submitted for SOC 2 and ISO 27001 certifications allegedly included fabricated records of board meetings, penetration tests, and risk assessments that never happened.1TechCrunch. Delve Accused of Misleading Customers With Fake Compliance

A leaked spreadsheet cited by the whistleblower reportedly contained hundreds of client audit reports. According to that analysis, 493 of 494 SOC 2 reports used nearly identical boilerplate language, including the same grammatical errors, and all 259 SOC 2 Type II reports contained word-for-word identical auditor conclusions.2IANS Research. Delve Allegations Expose Weak Points in Modern Compliance

DeepDelver singled out two audit firms, Accorp and Gradient, describing them as “certification mills” that rubber-stamped Delve-generated reports.1TechCrunch. Delve Accused of Misleading Customers With Fake Compliance Prescient Assurance, another firm named in the ecosystem, later said it had “formally disengaged” from Delve in September 2025 and stood behind its own audit processes.3Lorikeet Security. Prescient Security SOC 2 Client: What Now

The SimStudio Code Allegation

In a follow-up post on March 30, 2026, DeepDelver accused Delve of repackaging an open-source agent-building tool called SimStudio, developed by fellow Y Combinator company Sim.ai, and selling it as a proprietary product named “Pathways.” The whistleblower published side-by-side screenshots and referenced internal documents, including a “Sim Studio Port Plan” from Delve’s Notion workspace.4TechCrunch. The Reputation of Troubled YC Startup Delve Has Gotten Even Worse

Sim.ai CEO Emir Karabeg confirmed that Delve had “no license agreement with Sim.ai whatsoever.” Karabeg said Delve had once explored using Sim.ai’s technology and pitched a partnership, but he was unaware it intended to market a version of SimStudio as a standalone product.4TechCrunch. The Reputation of Troubled YC Startup Delve Has Gotten Even Worse SimStudio was released under the Apache 2.0 license, which permits commercial use but requires attribution. Delve later removed all mentions of “Pathways” from its website. Sim.ai has not announced any legal action.

Delve’s Response

Delve denies the allegations. In a March 20, 2026 blog post, the company called the Substack claims “inaccurate” and said it is an automation platform that provides templates and dashboards to licensed, independent auditors who are solely responsible for issuing final opinions.5Delve. Response to Misleading Claims

In an April 3, 2026 blog post and video statement, founders Karun Kaushik and Selin Kocalar alleged that someone had “purchased Delve under false pretenses” and used the access to exfiltrate internal data used in what they called a “coordinated smear campaign.” They said the anonymous posts relied on “fabricated claims, cherry-picked screenshots, and data taken out of context.” On the SimStudio dispute, Delve said it had built upon an Apache 2.0 repository, which permits commercial use.6Delve. Delve Sets the Record Straight on Anonymous Attacks

Kaushik acknowledged in a separate statement that the company “grew too fast,” creating process gaps, and apologized for “falling short” of its own standards. As remediation, Delve said it was rebuilding its auditor network, offering complimentary re-audits and penetration tests to affected customers, halting automation in audit workflows, and strengthening internal controls.7Times of India. Malicious Actor, Not a Whistleblower: Indian-Origin Founder Karun Kaushik Reacts to Fraud Allegations Against Startup

Expulsion From Y Combinator

Around April 3, 2026, Y Combinator removed Delve from its portfolio directory and asked the founders to leave the program. YC CEO Garry Tan explained the decision in a leaked internal message: “We have asked Delve to leave YC. YC is a community, not just an accelerator. The founders in our community have to trust each other, and we have to trust them. When that trust breaks down, there’s really only one thing to do.”8Captain Compliance. The Delve Scandal: Fake SOC 2 Audits, Open-Source Code Theft, and Exit From Y Combinator

Kocalar confirmed the split on X: “YC and Delve have parted ways.”9TechCrunch. Embattled Startup Delve Has Parted Ways With Y Combinator Delve’s YC page was taken down. Insight Partners, which led Delve’s $32 million Series A at a $300 million valuation in July 2025, temporarily removed its blog post about the investment before restoring it, and declined to comment.10TechCrunch. Insight Partners Scrubs Investment Post Amid Fake Compliance Allegations

The Mercor Class Action

The scandal escalated into litigation after Mercor, an AI-driven labor platform, disclosed a massive data breach in late March 2026. On March 24, 2026, a hacking group called TeamPCP exploited a supply-chain vulnerability in LiteLLM, an open-source library maintained by Berrie AI, and used it to compromise Mercor’s systems.11Trend Micro. Inside the LiteLLM Supply-Chain Compromise The attackers exfiltrated about four terabytes of data, including 211 GB of candidate records with Social Security numbers and resumes, 3 TB of interview video recordings and facial biometric data, and 939 GB of source code.12Hall Attorneys. Mercor Data Breach

Delve was pulled in because LiteLLM had been one of its compliance customers. After the breach, LiteLLM moved its certifications to a competitor, Vanta.13TechCrunch. Mercor Says It Was Hit by Cyberattack Tied to Compromise of Open-Source LiteLLM Project

On April 21, 2026, Hausfeld LLP and Hall Attorneys, P.C. filed a putative class action in the U.S. District Court for the Northern District of California: Ananthula, et al. v. Mercor.io Corporation, et al., Case No. 3:26-cv-03362. The complaint names Mercor, Delve AI Inc., and Berrie AI (doing business as LiteLLM) as defendants, along with ten unnamed “Doe AI Lab” defendants.12Hall Attorneys. Mercor Data Breach The lawsuit accuses Delve of “fake compliance” and arranging “sham security audits” for Berrie AI.14AOL. Mercor Hit by 5 Contractor Lawsuits

The 45-page complaint asserts ten counts, including negligence, breach of implied contract, intrusion upon seclusion, violations of the federal Fair Credit Reporting Act, violations of Illinois’s Biometric Information Privacy Act, Artificial Intelligence Video Interview Act, and Consumer Fraud and Deceptive Business Practices Act, violations of Florida’s Deceptive and Unfair Trade Practices Act, unjust enrichment, and claims for declaratory and injunctive relief. As of June 2026, no motions or responses from any defendant had been publicly reported.15Hausfeld. Mercor Data Breach

This is the only known formal legal proceeding in which Delve is a named defendant. No government investigation or regulatory charge against Delve has been reported.

What It Means for Companies That Used Delve

Hundreds of companies relied on Delve-issued certifications, and some prominent organizations reportedly accepted Delve compliance documentation, including OpenAI, PayPal, Stripe, Amazon, Microsoft, and the U.S. Department of Veterans Affairs.16Kanary. SOC 2 Attestation Requires More Thoughtful Compliance According to the whistleblower, companies displaying “Secured by Delve” trust pages may have been misrepresenting their security posture to customers, partners, and regulators.

Industry analysts flagged particular exposure for regulated sectors. Healthcare organizations relying on potentially invalid HIPAA attestations could face criminal liability, and companies handling European personal data could face GDPR fines of up to four percent of global revenue.2IANS Research. Delve Allegations Expose Weak Points in Modern Compliance Some public companies had cited Delve-generated reports in SEC filings, raising possible securities disclosure risks, though no formal enforcement actions had been filed on that basis as of late May 2026.17ComplyJet. SOC 2 News

Several customers left the platform. LiteLLM, Context AI, and Lovable all dropped Delve as their compliance provider.18TechCrunch. Another Customer of Troubled Startup Delve Suffered a Big Security Incident

Where Things Stand

Delve continues to operate as of mid-2026. The company maintains that it helps customers “prepare for audits” while customers “fully build and manage their own codebases, infrastructure, and day to day security operations,” and it says it has engaged cybersecurity firms to investigate the data exfiltration it attributes to a malicious actor.18TechCrunch. Another Customer of Troubled Startup Delve Suffered a Big Security Incident Kaushik has said the company “is not going anywhere.”7Times of India. Malicious Actor, Not a Whistleblower: Indian-Origin Founder Karun Kaushik Reacts to Fraud Allegations Against Startup The Ananthula v. Mercor case remains in its early stages, with no defendant filings yet on the public docket.