← 回總覽

Delve 安全认证虚伪面纱被揭开

📅 2026-03-21 14:46 Gergely Orosz 软件编程 2 分鐘 2265 字 評分: 82
安全 合规 SOC 2 数据泄露 创业公司
📌 一句话摘要 Gergely Orosz 揭露了 Delve 这家合规创业公司的虚伪本质:它向其他公司颁发 SOC 认证,却将自身的敏感文件暴露于公众视野之下。 📝 详细摘要 这条推文是对 Delve 的批判性评论。Delve 是一家向其他公司颁发 SOC 等安全认证的合规创业公司,却未能保护自身敏感的内部文件。引用推文揭示了 Delve 的 Supabase 存储桶完全公开可访问,暴露了员工背景调查报告、股权归属计划与授予金额、绩效评估、Stripe 和 Notion 的会话令牌等敏感信息。作者用讽刺的"大厨之吻"和"氛围合规"来批评这家合规公司的虚伪本质——它给其他公司敷衍地颁发认证
![Image 1: Gergely Orosz](https://www.bestblogs.dev/en/tweets?sourceId=SOURCE_6b94cc22)

Chefs kiss. Delve issues “vibe complaince” rubberstamp SOC and other certifications, while leaving their own door wide open w sensitive documents unsecured… for who knows how long. Security 101

A cautionary tale of a complaince startup faking everything, and almost making it

!Image 2: Tweet image

!Image 3: James Zhou

#### James Zhou

@jameszhou02 · 14h ago

btw their supabase storage bucket is publicly accessible via any signed url token 😭 exposes:

> employee background checks

> equity vesting schedules and grant amounts

> performance reviews

> session tokens for stripe, notion, etc

> screenshots below 🧵

i also got access to their notion 😛

!Image 4: Tweet image

86

70

1,446

464.7K

19 Replies

16 Retweets

298 Likes

33.4K Views ![Image 5: Gergely Orosz](https://www.bestblogs.dev/en/tweets?sourceid=6b94cc22)

One Sentence Summary

Gergely Orosz highlights Delve, a compliance startup that issues SOC certifications while leaving its own sensitive documents publicly exposed.

Summary

This tweet is a critical commentary on Delve, a compliance startup that issues security certifications like SOC to other companies, yet failed to secure its own sensitive documents. The quoted tweet reveals that Delve's Supabase storage bucket was publicly accessible, exposing employee background checks, equity vesting schedules, performance reviews, and session tokens for Stripe and Notion. The author uses sarcastic 'Chefs kiss' and 'vibe compliance' to criticize the hypocrisy of a compliance company that rubber-stamps certifications for others while having fundamental security flaws itself. This serves as a cautionary tale about the authenticity of compliance startups.

AI Score

82

Influence Score 42

Published At Today

Language

English

Tags

Security

Compliance

SOC 2

Data Breach

Startup

查看原文 → 發佈: 2026-03-21 14:46:10 收錄: 2026-03-21 18:00:15

🤖 問 AI

針對這篇文章提問,AI 會根據文章內容回答。按 Ctrl+Enter 送出。