Delve
Delve provides an AI-native compliance automation platform that uses autonomous agents to collect evidence, monitor cloud infrastructure, scan code, and prepare audits across SOC 2, HIPAA, ISO 27001, GDPR, ISO 42001, CMMC, and HITRUST for AI startups and growth-stage companies.
- Company typePrivate
- Founded2023
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Delve does
Delve is an AI-native compliance automation platform headquartered at 301 Howard St in San Francisco, founded in November 2023 by MIT dropouts Karun Kaushik (CEO) and Selin Kocalar (COO). The platform is built around autonomous browser agents that capture screenshots, validate compliance evidence, run AI-powered static application security testing on every pull request, perform daily AI infrastructure scanning against cloud configurations, and power a conversational AI policy assistant used by auditors and customers during fieldwork. Delve sells to startups, midmarket companies, and enterprises across 25+ frameworks including SOC 2, HIPAA, ISO 27001, GDPR, PCI-DSS, ISO 42001, CMMC, FedRAMP, HITRUST, EU AI Act, and NIST AI RMF, with a particular focus on AI-native companies whose products introduce governance questions (model lifecycle, data residency, prompt injection) that legacy SaaS-era security questionnaires do not address.
The business model combines a quote-based annual subscription priced per company size and framework (with a startup-tier entry price around $12,000 covering both platform and audit) with paid add-on services such as advanced penetration testing and vCISO support. Distribution is primarily direct via a book-a-demo motion on delve.co, supplemented by a multi-tier partner program (Channel Partners, Strategic Alliances with VC/accelerator partners, Ecosystem Partners, and a $1,000-per-deal Referral Partner program), a self-serve customer portal at app.delve.co, and a $750,000 out-of-home brand campaign run across San Francisco, New York City, and Austin in fall 2025. Delve has raised approximately $35 million in total funding, including a $3.3 million seed round in January 2025 and a $32 million Series A led by Insight Partners at a $300 million valuation in July 2025, with the company self-reporting profitability and revenue doubling in Q2 2025. As of March-April 2026, Delve is the subject of anonymous whistleblower allegations that it fabricated compliance evidence and used rubber-stamp auditors; multiple named customers (Lovable, LiteLLM, Context AI) have severed ties, Y Combinator removed Delve from its startup directory on April 4, 2026, and Insight Partners removed its investment thesis article, though the company remains operational and is offering complimentary re-audits and penetration tests to active customers.
Delve firmographics
Firmographics- Name
- Delve
- Legal name
- Delve Technologies Inc.
- Website
- https://delve.co
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Delve provides an AI-native compliance automation platform that uses autonomous agents to collect evidence, monitor cloud infrastructure, scan code, and prepare audits across SOC 2, HIPAA, ISO 27001, GDPR, ISO 42001, CMMC, and HITRUST for AI startups and growth-stage companies.
- Ownership category
- akta.pro rank
Delve industry classification
Industry- Product category
- Compliance Management Software (GRC)
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design Services (541512), Custom Computer Programming Services (541511), Other Computer Related Services (541519)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
- akta.pro secondary industry
- App Security, Compliance & Review Automation Platforms (BPAMADAJ)
Keywords
Where Delve is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Delve business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Compliance platform subscription: Quote-based subscription sold per company with a book-a-demo motion; pricing tiers segmented by company size (Startup, Midmarket, Enterprise) and by framework (SOC 2, HIPAA, ISO 27001, GDPR, PCI-DSS, ISO 42001, CMMC, FedRAMP, etc.). Pricing reportedly around $12,000 per year covering both platform and audits for smaller customers.
- Add-on and penetration testing services: Add-on paid services beyond the base subscription, including advanced penetration tests and vCISO support; complementary re-audits and penetration tests are offered at no cost during the post-crisis period.
- Partner referral revenue share: Referral Partners earn $1,000 per closed customer; Channel Partners receive revenue share and co-sell opportunities, creating a secondary indirect revenue stream.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based subscription priced per customer; segmented by Startup, Midmarket, and Enterprise company sizes and per framework (SOC 2, HIPAA, ISO 27001, GDPR, PCI-DSS, ISO 42001, CMMC, FedRAMP, HITRUST, EU AI Act, NIST AI RMF, etc.). |
| Subscription | Annual | Reported ~$12,000/year covering both platform and audits for a startup tier customer. |
| Other | Annual | Add-on services: advanced penetration test and vCISO support (priced separately). |
Go-to-market motion1 record
Distribution channels4 records
Delve product offering
Product offeringCore offering
Delve provides an AI-native compliance automation platform that uses autonomous browser and computer-use agents to collect audit evidence, run continuous monitoring of cloud infrastructure and code, auto-fill vendor security questionnaires, and generate policy documents across frameworks such as SOC 2, HIPAA, ISO 27001, GDPR, PCI-DSS, ISO 42001, CMMC, HITRUST, and FedRAMP. The platform is bundled with white-glove onboarding, 1:1 Slack support, and a three-layer trust verification pipeline (Delve AI + Delve human reviewer + independent licensed audit firm).
Product overview
Delve operates a single AI-native compliance platform extended through framework-specific modules (SOC 2, HIPAA, ISO 27001, GDPR, PCI-DSS, ISO 42001, CMMC, HITRUST, FedRAMP) and company-size editions (Startup, Midmarket, Enterprise). The unified core platform is built around five AI modules — Agentic AI Compliance (screenshot & evidence agents), AI Security Questionnaire Automation, AI SAST Code Scanning, AI Infrastructure Scanning, and the AI Policy Assistant — which collectively automate evidence collection, continuous monitoring, and audit preparation. Tier-specific packages add features such as the computer-use screenshot agent and dedicated MIT/Stanford AI engineer support for enterprise, while 1:1 Slack support and free Trust Reports are available across editions. The framework modules reuse the same agentic AI stack to produce framework-specific policies, controls, and audit packages, positioning Delve as a single platform-plus-modules architecture rather than separate point products.
Differentiator
Problem solved
Functional benefit
Products and services
- Delve Compliance Platform AI-native compliance automation platform that uses autonomous AI agents to collect evidence, run continuous monitoring, and prepare customers for audits across multiple regulatory frameworks (SOC 2, HIPAA, ISO 27001, GDPR, PCI-DSS, ISO 42001, CMMC, HITRUST, FedRAMP). Targets startups, midmarket companies, AI-native vendors, healthcare/PHI handlers, and defense contractors.
- SOC 2 Compliance Module Framework module for SOC 2 Type I and Type II supporting evidence collection, policy generation, and audit readiness for B2B SaaS companies required by enterprise buyers.
- HIPAA Compliance Module Compliance module covering U.S. HIPAA regulations for protecting patient health information in healthcare and related services.
- ISO 27001 Compliance Module Compliance module aligned to the ISO 27001 international standard for maintaining an information security management system.
- GDPR Compliance Module Compliance module supporting GDPR, the EU data privacy law for processing personal data of EU residents.
- PCI-DSS Compliance Module Compliance module covering PCI-DSS standards for securing credit card data when handling payments.
- ISO 42001 Compliance Module Compliance module for the ISO 42001 international framework for managing AI risks and uses; Delve itself achieved ISO 42001 compliance.
- CMMC Compliance Module Compliance module for the DoD Cybersecurity Maturity Model Certification (CMMC), providing AI-supported documentation, evidence collection, control validation, and C3PAO assessment preparation for defense contractors handling FCI/CUI.
Quantifiable outcome
- 43k hours of compliance busywork eliminated across customers
- +7 more outcomes
Companies that use Delve
Customer profileNamed customers8 records
Segments6 records
Ideal customer profiles5 records
Delve technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability10 records
Feature8 records
Delve partnerships and signals
Strategic signalScale indicators8 records
Recent moves3 records
Expansion highlights6 records
Delve competitors and assessment
Company assessmentDirect peers
- Vanta: Vanta is the leading AI-driven trust management platform, offering automated compliance for SOC 2, ISO 27001, HIPAA, and 35+ other frameworks. It is Delve's most direct competitor and the vendor LiteLLM migrated to post-scandal; both target the same startup/midmarket/enterprise compliance automation buyer.
- Drata: Drata is a direct competitor offering automated compliance monitoring, evidence collection, and audit readiness across SOC 2, ISO 27001, HIPAA, and more. Like Delve, it sells to fast-growing B2B SaaS and AI companies needing first-time certifications.
- Secureframe: Secureframe is a compliance automation platform competing for the same SOC 2 / HIPAA / ISO 27001 buyers. Recently expanded into AI governance offerings (similar to Delve's ISO 42001 positioning) and has a comparable partner-led GTM motion.
- Sprinto: Sprinto is a compliance automation platform that emerged from India with strong traction among SaaS startups pursuing SOC 2, ISO 27001, HIPAA, and GDPR. Overlaps directly with Delve's Startup and Midmarket tiers and is increasingly competing for AI-native customers.
- Laika: Laika offers compliance and security automation for SOC 2, ISO 27001, HIPAA, and PCI-DSS, with a focus on integrating compliance into the SaaS sales cycle. Direct competitor for midmarket and enterprise buyers where Delve also sells.
- Thoropass: Thoropass (formerly Laika) combines compliance automation software with in-house audit services, similar to Delve's bundled platform-plus-auditor model. Targets midmarket and enterprise compliance buyers across multiple frameworks.
- Hyperproof: Hyperproof is a compliance operations platform automating evidence collection and control monitoring across SOC 2, ISO 27001, HIPAA, FedRAMP, and more. Closely comparable to Delve's Midmarket and Enterprise offerings and goes head-to-head on multi-framework support.
- Tugboat Logic (OneTrust): Tugboat Logic (now part of OneTrust) was a direct compliance automation competitor for SOC 2 and ISO 27001 aimed at startups and mid-market. Closely analogous to Delve's pre-Series-A positioning and an instructive incumbent comparison for go-to-market and feature evolution.
Broad incumbents
- AuditBoard: AuditBoard is a larger, established GRC platform focused on audit, risk, and compliance management for mid-market and enterprise. Overlaps with Delve's enterprise tier on common control frameworks and FedRAMP/CMMC readiness, but is a broader portfolio play rather than AI-native.
- OneTrust: OneTrust is a broad privacy, security, and GRC incumbent with thousands of enterprise customers. Acquired Tugboat Logic to enter compliance automation; competes with Delve at the high end on GDPR, ISO 27001, and risk management, though Delve is more focused on the AI/startup segment.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks7 records
Key highlights7 records
Customer concentration
Delve social profiles
Digital presenceDelve compliance and trust
Trust signalCompliance2 records
Delve financial estimates
Financial estimateRevenue estimate
Valuation estimate
Delve leadership team
Management profileNumber of profiles
Profiles6 records
Delve funding detail
Funding detailFunding overview
Funding rounds3 records
Investors5 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Delve M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Delve
What does Delve do?
Delve provides an AI-native compliance automation platform that uses autonomous browser and computer-use agents to collect audit evidence, run continuous monitoring of cloud infrastructure and code, auto-fill vendor security questionnaires, and generate policy documents across frameworks such as SOC 2, HIPAA, ISO 27001, GDPR, PCI-DSS, ISO 42001, CMMC, HITRUST, and FedRAMP. The platform is bundled with white-glove onboarding, 1:1 Slack support, and a three-layer trust verification pipeline (Delve AI + Delve human reviewer + independent licensed audit firm).
Is Delve a public or private company?
Delve is a private company. It is classified as venture growth investor backed and is currently operating.
When was Delve founded?
Delve was founded in 2023. It employs 11 to 50 people.
Where is Delve based?
Delve is headquartered in San Francisco, United States, in the North America region.
How does Delve make money?
Three revenue lines are on record. Compliance platform subscription is the primary driver. The others are add-on and penetration testing services and partner referral revenue share.
Who are Delve's main competitors?
Direct peers on record are Vanta, Drata, Secureframe, Sprinto, Laika, Thoropass, Hyperproof and Tugboat Logic (OneTrust). Broad incumbents are AuditBoard and OneTrust.
Does Delve have an API?
No public API is recorded for Delve.
What industry is Delve in?
Delve's product category is Compliance Management Software (GRC). Its primary akta.pro industry code is HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII), with a secondary code of BPAMADAJ, App Security, Compliance & Review Automation Platforms. Its NAICS code is 5415 and its SIC code is 7373.