Pinned
btw their supabase storage bucket is publicly accessible via any signed url token 😭
exposes:
> employee background checks
> equity vesting schedules and grant amounts
> performance reviews
> session tokens for stripe, notion, etc
> screenshots below 🧵
i also got access to
A detailed and brutal look at the tactics of buzzy AI compliance startup Delve
"Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite."
substack.com/home/post/p-19…















