Embattled compliance startup Delve certified Context AI, whose compromised app led to a data breach at Vercel, compounding existing allegations of fraudulent auditing practices.
TechCrunch confirmed that Delve — a compliance startup already under fire for allegedly faking certifications — performed security certifications for Context AI, the startup whose compromised app triggered a data breach at Vercel. This is the second major security incident linked to a Delve customer, following a malware attack on LiteLLM. Delve has faced allegations of rubber-stamping audits, misappropriating open-source tools, and denying customer refunds while sending its team to Hawaii. Y Combinator has already severed ties with Delve.
Two Delve-certified companies (LiteLLM, Context AI) have now suffered security incidents linked to inadequate controls — and one caused a downstream breach at Vercel. If your stack includes any Delve-certified third-party tools or OAuth-connected apps in your corporate Google Workspace, those integrations are now suspect. This is a concrete supply chain security failure, not a hypothetical.
Audit all third-party OAuth app connections to your team's Google Workspace right now — pull the full list, identify any AI agent or compliance-adjacent apps, and revoke access for any you can't verify as clean.
Go to admin.google.com → Security → Access and data control → API controls → Manage third-party app access
Tags