You are currently viewing Delve Security Incident Fallout Deepens After Another Customer Suffers Major Breach

Delve Security Incident Fallout Deepens After Another Customer Suffers Major Breach

The Delve Security Incident controversy has taken another turn after another customer tied to the troubled compliance startup was linked to a major cybersecurity breach. Fresh revelations are adding pressure on Delve as questions continue to mount over its certification processes and customer trust.

TechCrunch confirmed that Delve was the compliance provider used by Context AI, the AI agent training startup that recently disclosed a security incident connected to a breach at app and website hosting company Vercel.

Delve Security Incident Linked to Context AI and Vercel Breach

According to the report, Vercel said hackers accessed its internal systems and some customer data after an employee downloaded an app built by Context AI and connected it to the company’s Google-hosted corporate account. The attackers allegedly exploited that employee’s Google account access to enter parts of Vercel’s systems.

After Context AI was publicly connected to the incident, industry observers identified Delve as the firm that had managed the startup’s security certification. Context AI later confirmed it had previously worked with Delve.

The company also said it has since moved its compliance program to Vanta and hired Insight Assurance, an independent audit firm, to conduct new examinations. Context AI added that it would share updated attestations once the process is complete.

Previous Customers Also Moved Away From Delve

The Delve Security Incident story follows earlier controversies surrounding the startup.

Last month, an anonymous whistleblower accused Delve of faking customer data and relying on rubber-stamping auditors during compliance and certification work. Delve denied those allegations.

Soon after, hackers compromised one of Delve’s certification customers, LiteLLM, and inserted malware into its open-source code. Following that event, LiteLLM said it would stop working with Delve and seek re-certification elsewhere.

Another former customer, Lovable, had already left Delve in late 2025, according to the report. The platform said it completed one new certification and is redoing others.

Lovable Faces Separate Data Exposure Issue

Even after changing providers, Lovable disclosed on Monday that it had accidentally exposed access to customer chat data publicly. The company also acknowledged it had dismissed vulnerability reports warning about the issue months earlier. Lovable apologized for initially denying a breach, while saying the problem stemmed from a configuration error rather than a hack.

More Allegations Surface Around Delve

Additional claims have also surfaced from the anonymous whistleblower known as DeepDelver. In a new post, the source alleged Delve denied refunds to customers while still taking a team of more than 20 people to an offsite meeting in Hawaii between April 15 and April 19.

The report said some material shared with TechCrunch appeared to support the alleged trip, though other claims could not be independently confirmed. Delve did not respond to requests for comment, and an email sent to its media relations address reportedly bounced.

Trust in Compliance Startups Faces New Test

The Delve Security Incident highlights a broader reality: certifications alone do not prevent cyberattacks. They are meant to confirm that companies have processes and controls designed to reduce risk, but they are not guarantees against breaches. As more startups reassess vendors and certifications, trust in compliance providers may face greater scrutiny.

Goodle Preferred Source

Don’t miss out on our latest news—follow us for the latest AI newsbreakthroughs, and insights that matter.