# Delve.co: The Agentic Wedge
**The Thesis:** Compliance used to be a consulting gig. Now it is a compute problem.
I have spent time on both sides of this wall. At Kaiser, compliance was the product. If you messed up a HIPAA control, it is a break-glass, all hands on deck crisis. At Datadog, security is about scale. Think enterprise customers asking, "Can you prove you are secure without slowing down my 5,000 devs?"
The gap between those two worlds is massive. Delve.co is capitalizing on that gap by betting that the only way to solve it is to stop monitoring the work and start doing it.
### 1. The Wedge: "Get In Early, Make It Easy"
Legacy players like Vanta and Drata built the "dashboard" era. They hook into APIs and scream at you when a light turns red. But you still have to fix it.
Delve's wedge is **Speed + Agency**.
- **The Pitch:** "SOC 2 in days, not months."
- **The Growth Hack:** They sent **10,000 donuts** to SF founders with the tagline _"The only hole in your security we approve of."_ It sounds gimmicky, but it worked because it targeted the emotional state of a founder: _I hate compliance, please just make it go away._
- **The Result:** They went from YC W24 to 500+ customers and a $32M Series A at a $300M valuation by July 2025. They realized the market extends beyond startups; even 10,000-person companies are tired of the "compliance tax."
### 2. The "Agentic" Shift (The Real Product)
This is where it gets interesting for a product person. Delve built **Agents** that use "Computer Use" concepts, going beyond simple `GET /config` checks.
- **Screenshots:** If an evidence artifact does not have an API (like some legacy on-prem firewall setting), a human usually has to screenshot it. Delve's agents log in, navigate the UI, take the screenshot, and upload it.
- **Questionnaires:** They ingest your entire policy stack. When a vendor sends a security questionnaire, their AI drafts the answers based on your _actual_ config.
### 3. The "Secure Variable" Parallel (Kaiser vs. Datadog)
This ties back to the "Secure Variables" PRD.
**HIPAA/Privacy:** At Kaiser, proving custody of data was the bar. If Delve's agent takes a screenshot of a database console to prove "Encrypted at Rest," and that console accidentally shows a patient's name... that is a breach.
- **The Need:** Like the "write-only" variables in the PRD, Delve needs **"Write-Only Evidence."** The agent captures the proof, locally redacts PII/PHI via computer vision, hashes it, and _then_ stores it. If the platform stores the raw screenshot, they are a liability.
**Scale/Trust:** Enterprise customers want to verify what is inside the "black box."
- **The Friction:** If I am a CISO at a Fortune 500 buying software, a PDF report is nice for collecting digital dust; a dynamic Trust Center grants confidence against real-time data. Delve built a public-facing page that shows live control status.
- **The Risk:** If the agent hallucinates and says "MFA is on" when it is not, the liability is massive. The architecture has to be Deterministic Verification.
### 4. Why It Works
Delve effectively productized the "Junior Security Analyst."
- **Old Way:** Hire a consultant ($50k) + Wait 3 months + Nag engineers for screenshots.
- **Delve Way:** Connect Agents ($) + Wait 3 days + Agents take screenshots.
They realized that for the "Datadog" persona, the pain is the sheer volume of manual labor required to prove you did it. I have enjoyed reading through NIST SP 800-53 for the organizational challenge it addressed, and Delve went the other way, offloading that labor to agents and turning compliance from a services business into a software business.
**Key Takeaway:** The "Secure Variables" mantra - Store it once. Secure it everywhere. Use it without seeing it - is the exact philosophy needed for Agentic Compliance. The agent sees the secret (the evidence), verifies it, and locks it away. Reminds me of how fun it was digging into Zero-knowledge proofs in college.
**Side note, March 2026.** An anonymous Substack investigation accused Delve of shipping templated, pre-filled evidence and leaning on rubber-stamp auditors, and Insight Partners scrubbed its investment post days later. Delve says it provides templates and that only auditors issue reports. The risk I flagged above arrived on schedule, an agent saying "MFA is on" when it is off. Write-only evidence is only worth locking away when the evidence is real.