8 ms·
This basically boils down to, "Sure, we recommended you work with scammy low-quality auditors, but if you actually use them it's your own fault... we're just an
by CityOfThrowaway 6mo ago
This basically boils down to, "Sure, we recommended you work with scammy low-quality auditors, but if you actually use them it's your own fault... we're just an automation tool!"
In other words, I'm reading this as effectively a full admission that the claims are true but the company is saying not their responsibility.
Very, very bad.
- jvwww 6mo agoWhere does it say we recommend you work with scammy low-quality auditors? They say that they use third party audit firms that are used by other compliance companies.
- sebmellen 6mo agoThis is clearly false from what I've seen. If you read the source Substack article and look through the list of auditors they have, it is impossible to trace down who the US-based CPA is that's issuing the report. These firms, for all intents and purposes, do not really exist. They use shell addresses in Wyoming and Texas that are registered agent offices, etc. But really all you have to do is look at the reports themselves. They are so shoddily written that it's hard to believe any legitimate firm would issue them. If you Ctrl F for Clueley in this thread, you will see my comment with a sample excerpt from the assertion of management for one of their reports.
- dove-3746 6mo agoPresent assurance definitely exists in the US. Outside of delve, I have seen their reports for vanta and it’s the same. it was 95% policy inspections and 5% loooked at a GRC tool.
- bigiain 6mo agoI assume you mean this "Prescient Assurance? As detailed in this section of the post? 6.7 Misled auditor - Prescient With this conclusion: Looking at that report, there are clear signs that Delve either knowingly misled Prescient, or that Prescient accommodated Delve’s deficient process. Given their reputation and by the small number of Delve/Prescient reports out there, I’m assuming it is the former.
- paulryanrogers 6mo agoI've used Prescient in the past and found them on par with others. Policy evidence is at most about 30%. Everything else is show-don't-tell. Either live screen shares, screenshots, non-policy documentation, or evidence from a shared vendor that's integrated into the environments and security tools (like Drata).
- owebmaster 6mo agoWe or they? Choose one
- joemi 6mo agoIt can be inferred the use of "we" was as a quote. The bigger issue is that they did not clearly indicate that they were quoting.
- ibero 6mo agoif you go through the original Substack post it’s clear the intention is to drive to those obfuscated auditors.