曾经估值3亿的硅谷宠儿 Delve,竟因批量制造雷同审计报告并虚报收入被 YC 扫地出门。本期带你拆解这家 AI 初创公司如何因诚信危机信誉崩塌,揭示速度崇拜下合规底线失守的惨痛代价。

合规行业的本质是信任。你可以自动化流程,但你无法自动化诚实。
调查发现,在泄露的 494 份审计报告中,有 493 份的内容几乎完全雷同,文字重合度高达 99.8%。这些报告不仅在描述不同公司的安全流程时使用了统一的语法错误(如整齐划一地漏掉单词“is”),甚至在关键的测试数据栏填写了如“sdf”、“dlkjf”等明显的键盘乱码。这表明报告并非基于实际审计生成,而是通过自动化模板预先设定的“复印件”。
根据行业准则,开发合规工具的公司与出具报告的会计师事务所必须保持独立。然而,Delve 被指控直接由内部团队生成审计内容,并利用位于印度的“认证工厂”批量生产报告。这些所谓的美国 CPA 事务所往往只有虚拟办公室,甚至在报告封面上出现了错误的审计师 ID。此外,Delve 还以远低于市场价的报价吸引客户,并宣称包含根本未实际执行的数百小时渗透测试。
Delve 被指控剽窃同为 YC 校友公司 Sim.ai 的开源产品。其标价昂贵的“Pathways”工具被发现大量克隆了 SimStudio 的核心代码库,且未按照开源协议署名。更具讽刺意味的是,Delve 的 CEO 在拒绝向原作者支付授权费的同时,转身就将这款克隆产品卖给了 Notion 和 Gusto 等知名大厂。
当合规外壳撞上真实的黑客攻击时,虚假的审计报告无法提供任何保护。例如,开源项目 LiteLLM 在通过 Delve 审计后不到 60 天,就被发现注入了恶意软件,证明了审计过程完全失效。对于企业创始人而言,合规责任是不可转让的,一旦被证实存在系统性造假,公司可能面临 HIPAA 或 GDPR 下的巨额罚金甚至刑事指控,同时还会遭遇品牌信任破产和明星客户流失。
From Columbia University alumni built in San Francisco
"Instead of endless scrolling, I just hit play on BeFreed. It saves me so much time."
"I never knew where to start with nonfiction—BeFreed’s book lists turned into podcasts gave me a clear path."
"Perfect balance between learning and entertainment. Finished ‘Thinking, Fast and Slow’ on my commute this week."
"Crazy how much I learned while walking the dog. BeFreed = small habits → big gains."
"Reading used to feel like a chore. Now it’s just part of my lifestyle."
"Feels effortless compared to reading. I’ve finished 6 books this month already."
"BeFreed turned my guilty doomscrolling into something that feels productive and inspiring."
"BeFreed turned my commute into learning time. 20-min podcasts are perfect for finishing books I never had time for."
"BeFreed replaced my podcast queue. Imagine Spotify for books — that’s it. 🙌"
"It is great for me to learn something from the book without reading it."
"The themed book list podcasts help me connect ideas across authors—like a guided audio journey."
"Makes me feel smarter every time before going to work"
From Columbia University alumni built in San Francisco
