BusinessIssue #64

The Compliance Startup That Broke Compliance

YC's expulsion of Delve exposes cracks in open-source ethics and startup trust networks.

The Compliance Startup That Broke Compliance

Opening

Dear reader, let me start with an ironic story. There was a startup that promised to complete security certifications like SOC 21​, HIPAA2​, and GDPR3​ “in days, with AI.” A company valued at $300 million, with a $32 million Series A, a Forbes 30 Under 30 nod, and a “top startup” label from YC’s own president. Yet allegations have surfaced that this very company failed to comply with the most basic form of compliance of all: open-source licensing.

On April 4, 2026, YC asked Delve to leave its community. Expulsions of portfolio companies are extremely rare in YC’s history. This incident is more than a startup scandal — it simultaneously reveals the ethical boundaries of open-source forking4​, the trust architecture of accelerator networks, and the structural trap facing AI startups that sell “speed” as their core value.

A 17-Month Timeline: From Rocket Ship to Crash

Laying out Delve’s trajectory chronologically makes vividly clear how a “growth narrative” gets built in Silicon Valley — and how it can collapse.

2023: While still students at MIT, Karun Kaushik and Selin Kocalar started with a medical AI scribe. After personally suffering through the pain of HIPAA certification, they pivoted5​ to compliance automation.

Early 2024: They’re accepted into the YC Winter 2024 batch. Their pitch: AI agents that automatically handle evidence collection, report drafting, and gap monitoring.

January 2025: They raise a $3.3 million seed round from General Catalyst and others.

April–May 2025: This is where the pivotal event occurs. Delve becomes a customer of fellow YC alum Sim.ai, paying $15,000 for SOC 2 and HIPAA certification. At the same time, internally, work was reportedly underway to port Sim.ai’s open-source product, SimStudio, into Delve’s own product, “Pathways.” According to an internal whistleblower, an internal Notion document titled “Sim Studio Port Plan” specifically listed the folders to be copied — Blocks, Components, Executor, Tools, and the database schema.

July 2025: They raise a $32 million Series A led by Insight Partners, at a $300 million valuation.

September 2025: YC CEO Garry Tan retweets a post about Kaushik’s MIT talk, calling Delve a “top YC startup.” The post racks up 175,000 views.

December 2025: A Google spreadsheet containing draft SOC 2 audit reports for hundreds of client companies leaks, left publicly accessible. Kaushik emails customers stating “no external party accessed the database.” That same month, both co-founders are named to the Forbes 30 Under 30 list in the AI category.

March 18, 2026: An anonymous Substack account, ‘DeepDelver,’ publishes Part I. The core claim: of 494 SOC 2 reports, 493 are 99.8% identical — a bombshell article. It alleges rubber-stamp audits conducted through an India-based certification body, and a process built not on AI but on pre-written templates and manual labor.

March 20, 2026: Delve pushes back in a blog post: “Delve does not issue compliance reports. Final reports are issued by independent auditors.” Patio11, a well-known Hacker News commentator, calls the statement “a textbook non-denial denial6​ — one that concedes the core allegation while denying all responsibility.”

March 23, 2026: Insight Partners removes its blog post about the Delve investment from its website.

March 30, 2026: DeepDelver publishes Part II. A new allegation: Delve forked Sim.ai’s Apache 2.0-licensed7​ open-source product, SimStudio, and sold it to enterprise customers under the name “Pathways” for $50,000 to over $200,000. Sim.ai CEO Emir Karabeg confirms to TechCrunch that no licensing agreement ever existed.

April 1, 2026: TechCrunch reports on the open-source license violation allegations. The story trends on X (formerly Twitter).

April 4, 2026: YC asks Delve to leave its community. An internal Bookface8​ message from Garry Tan leaks: “YC is a community, not just an accelerator. Founders in our community must trust each other, and we must trust them. When that trust breaks, there is only one thing we can do.”

The point where most confusion arises in this case is the open-source licensing issue. DeepDelver called it “IP theft,” but the legal reality requires a more careful distinction.

SimStudio is an open-source project released under the Apache 2.0 license. Apache 2.0 is a permissive license that allows commercial use, modification, and redistribution. It even permits redistributing modified code under a different license. So the act of forking SimStudio for commercial use, by itself, is entirely permitted under the license.

That said, Apache 2.0 imposes four conditions:

First, the original copyright notice must be preserved. Second, a copy of the license text must be included. Third, if a NOTICE file exists, its attribution9​ notices must be included. Fourth, modified files must state that they have been changed.

What Delve is suspected of doing is ignoring all four of these conditions while telling prospective customers that SimStudio’s code was “built from the ground up” by Delve itself. This is both an Apache 2.0 violation and deception of customers. What I find most notable in this case is the gap between a “legal fork” and an “ethical fork.” Forking is routine in the open-source world. But most forks operate on a practice of crediting the original author and giving back to the community.

Delve’s case was different. First, it took the code from a customer. (Call it what it is: it stole it.) Sim.ai was one of Delve’s compliance clients. That means Delve likely had inside knowledge of Sim.ai’s security architecture and internal systems through the compliance work itself. Within that relationship of trust, it took its client’s core product. It used the code after rejecting a licensing offer. According to Sim.ai CEO Karabeg, Sim.ai proposed a licensing agreement to Delve, which Delve declined, citing insufficient ROI. It then sold that code to enterprise customers. Then, it outsourced maintenance. According to an internal whistleblower, Delve handed off Pathways’ maintenance to an outsourced development firm in Bangladesh — contradicting its claim of having “built it themselves.”

The open-source ecosystem functions on precisely this kind of trust. Open-sourcing code is a minimal promise — “take it and use it, but credit the source” — and the fact that a company selling compliance couldn’t even keep that minimal promise reveals something beyond irony: a structural problem.

What makes this case’s moral bankruptcy notable is that it isn’t a single act, but a structure of layered betrayals.

  • Layer 1: It took a customer’s code without permission.
  • Layer 2: It may not have even delivered proper compliance service to that customer.
  • Layer 3: It lied that it “built” the code itself and sold it to other customers.
  • Layer 4: When the original author offered a licensing deal, it declined citing ROI — then generated $50,000 to over $200,000 in revenue from that same code.
  • Layer 5: All of this happened under the banner of “we’ll automate your compliance for you.”

A company that promised to handle rule-following on your behalf couldn’t follow the most basic rule that applied to itself. This isn’t merely a license violation — it’s an inversion of fiduciary duty10​.

What the YC Network’s Trust Structure Revealed

This case transcends a mere startup scandal because it puts the trust structure of the YC ecosystem itself on trial. The YC alumni network is not just a place to swap business cards. It’s a structure where implicit trust — “I’ll use them because they’re YC alumni” — translates directly into real transactions. Sim.ai’s purchase of Delve’s compliance services, and the decisions by companies like Lovable, Brex, and Gusto to choose Delve, all happened within this trust network.

The problem is that this trust may have replaced due diligence11​ altogether. When Garry Tan called Delve a “top startup” in September 2025, it functioned as an implicit guarantee from the entire YC community. Trusting that guarantee, more than 1,700 customer companies entrusted Delve with their security certifications — a domain where HIPAA violations can carry criminal liability.

One Hacker News comment cut right to the structure at play: “YC didn’t kick out Delve for violating a license. They kicked them out for betraying other YC companies.” Would the reaction have been this severe if Delve had forked code from a company outside YC? This question is uncomfortable precisely because the answer is probably “no.”

This reveals the duality inherent in accelerator trust networks. Deals between alumni lower sales costs and accelerate growth, but they can simultaneously foster a lax culture of verification — “they’re on our side, so we don’t need to scrutinize them closely.” This isn’t a problem unique to YC. It’s a structural vulnerability of every closed, network-based business ecosystem.

Oz’s Lens

Honestly, I don’t think the scariest part of this case is the open-source license violation.

From my experience building GTM strategies, Delve’s entire business model was a “structure that sells speed.” A value proposition like “what takes months, in days” is hard for customers to refuse. But if you trace where that speed actually comes from, it can only come from skipping or automating the verification process. Compliance is a field whose value fundamentally lies in independent verification — so “automating” that verification is a structural contradiction.

The open-source fork is part of the same pattern. Under pressure to “expand the product lineup fast,” using someone else’s code is legal in itself — but the “slow process” of crediting the source and honoring the license was skipped. This is a pattern of obsession with speed eroding ethical boundaries.

And one more thing worth noting: all of these allegations were exposed not by a regulator, but by a single anonymous Substack writer. Not an SEC investigation, not an AICPA12​ sanction, not HIPAA enforcement. A private individual, once a customer, grew suspicious, gathered data, and wrote it up. This is telling evidence of just how fragile the compliance industry’s self-monitoring system really is.

Finally, I want to point out how the prestige machine13​ operates. YC batch → seed round → public endorsement from YC’s president → Series A → Forbes 30 Under 30 → billboards across San Francisco and New York. Once this flywheel starts spinning, it becomes structurally difficult for anyone inside it to ask, “does this actually work?” Raising doubt itself carries the cost of exiting the network. The Delve case is perhaps the most dramatic illustration yet of what happens when this prestige flywheel replaces due diligence.

Closing

First, using open-source code commercially is legal — but the moment you strip attribution and claim you “built it yourself,” it becomes both a license violation and a trust issue. Apache 2.0 being a permissive license doesn’t mean it’s a “use it however you want” license.

Second, network-based trust is a powerful asset, but it must never substitute for due diligence. Handing off an area with real legal liability — like security certification — for reasons as thin as “they’re YC alumni” or “they’re a portfolio company” is dangerous.

Third, any startup that sells “speed” as its core value must always ask itself — where does that speed actually come from? If a step has been skipped, you need to first ask why that step existed in the first place.

A large share of Delve’s 1,700 customer companies handle patient data every single day. Questions about the actual validity of the SOC 2 certifications they hold have only just begun.

And one question remains. Is this case simply the deviation of “one bad founding team,” or is it a structural pattern in which ethical boundaries are systematically eroded under pressure to “grow fast”? I lean toward the latter. Delve wasn’t uniquely malicious — within an incentive structure built around speed and growth, taking the “shortcut” was simply too easy. And every safeguard that should have blocked that shortcut — independent audits, investor due diligence, mutual community verification — failed to function.

References & Further Reading

The author, Kwangseob Ahn, is a professor of business administration at Sejong University and lead consultant at OBF (Oswarld Boutique Consulting Firm). He teaches statistics and data analysis — business data management and business analytics — while leading GTM and AI strategy consulting in the field, designing the seam between technology and business. He has published academic research on a memory architecture for AI dialogue systems (HEMA) and runs Daily Arxiv, a daily curation of global AI papers. He holds a master’s from Korea University’s Graduate School of Technology Management and a KMBA. He is the author of Homo Brainless: The People Who Outsource Their Thinking.

Footnotes

  1. SOC 2 (System and Organization Controls 2): a security certification in which an independent auditor verifies that a company is safely managing customer data. For B2B SaaS companies, it is effectively a prerequisite for doing business.

  2. HIPAA (Health Insurance Portability and Accountability Act): a US law protecting health information. Companies handling patient health data must comply, and willful violations can carry criminal penalties. Since many of Delve’s customers fall under this regulation, the stakes here are especially high.

  3. GDPR (General Data Protection Regulation): the EU’s personal data protection regulation. Violations can incur fines of up to 4% of global revenue, making it one of the toughest data regulations global companies face.

  4. Fork: copying an open-source project’s source code to start an independent new project. It shares the same root as the original but develops in a different direction, hence the name, borrowed from the image of a tree branching.

  5. Pivot: when a startup completely changes its core strategy or product because its original business direction isn’t working. Delve pivoted from a medical AI scribe to compliance automation.

  6. Non-denial denial: a rhetorical technique that makes something appear denied without directly denying it. Delve’s response, “we don’t issue reports,” is a textbook example — it doesn’t deny the core allegation that it generated the content, only that it wasn’t the issuing entity.

  7. Apache 2.0 license: an open-source license created by the Apache Software Foundation. It permits commercial use and modification but requires preserving the original copyright notice, including the license text, and noting any changes made. In short: “take it and make money, but credit the source.”

  8. Bookface: an internal social network accessible only to YC alumni. The name is a nod to Facebook’s early name. It’s the core platform for deals, hiring, and information exchange among YC alumni, and Garry Tan personally developed an early version of it.

  9. Attribution: crediting the original author or source. In open source, code can be freely used, but stating “who originally created this” is a baseline requirement of nearly every license.

  10. Fiduciary duty: the legal and ethical responsibility that arises in relationships where one party must act in another’s interest, such as lawyer-client or auditor-client relationships. A compliance provider that accessed a customer’s security information while simultaneously taking that customer’s product represents a fundamental breach of this relationship of trust.

  11. Due diligence: the process of thoroughly investigating a counterparty’s financial standing, technical capability, and legal risk before an investment or transaction. It stands opposite to “taking it on trust,” and this case revealed how YC network trust created a structural problem by allowing due diligence to be skipped.

  12. AICPA (American Institute of Certified Public Accountants): the US professional body that created and manages the SOC 2 framework. Under its standards, independent auditors evaluate a company’s security controls — and in the Delve case, allegations have emerged that this independence was compromised.

  13. Prestige machine: a self-reinforcing cycle in the startup ecosystem where certain signals (graduating from a famous accelerator, funding from a name-brand VC, media coverage, awards) amplify each other to inflate a company’s perceived credibility. Once this flywheel is spinning, a company can be perceived as “trustworthy” without any external verification.