Compliance as a Service, Fraud as a Feature

·Victor B·
compliancegovernanceAISOC 2

Section 3 of a SOC 2 report is supposed to be the company-specific description of its security programme.

In Delve's reports, 99.8% contained identical text, including the same grammatical errors ("has developed an organization-wide Information Security Policies") and the same nonsensical descriptions ("The infrastructure comprises cloud architecture including database, networking devices, virtual servers, etc."). Every client, regardless of size, industry, or technical architecture, received the same security programme description.

From systima.ai