<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: emilycg</title><link>https://news.ycombinator.com/user?id=emilycg</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 16 May 2026 10:29:42 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=emilycg" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by emilycg in "Delve – Fake Compliance as a Service"]]></title><description><![CDATA[
<p>The key problem is the audits and the auditors. I have independently verified for our vendors that they have the same templated SOC2 as all of the leaked reports, which is concerning because that shows the auditors did not actually validate the controls.<p>SOC2 is supposed to give you an INDEPENDENT evaluation of the compliance of a company "are they doing what they say they are"<p>If the SOC2 report is just a pre-populated template, it is meaningless.<p>It doesn't really matter the motivation of the "DeepDelver" - this has implications across all companies that rely on these vendors that have been "assessed" by Delve.</p>
]]></description><pubDate>Fri, 20 Mar 2026 18:11:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47458422</link><dc:creator>emilycg</dc:creator><comments>https://news.ycombinator.com/item?id=47458422</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47458422</guid></item></channel></rss>