Vercel and Context AI: Delve Client Suffers Major Security Incident

Summary: A Delve client, Context AI, suffered a major security incident that resulted in a data leak at Vercel, after using a Context AI application.

The story of the compliance startup Delve remains full of twists and turns.

TechCrunch confirmed that Delve was the compliance company that conducted security certifications for Context AI, the AI agent training startup.

This incident is linked to a data leak at Vercel, the giant hosting platform for applications and websites.

Context AI has confirmed that it had indeed used Delve's services. However, the company has since abandoned Delve and is in the process of obtaining a new certification.

The issues with Delve were already known: previously, an anonymous whistleblower alleged that Delve fabricated customer data. Furthermore, there were attacks on Delve clients, such as LiteLLM, which planted malware in its open-source code.

Finally, a Vercel employee downloaded a Context AI application and connected it to the corporate Vercel account, allowing hackers to access internal systems and customer data.

Key facts

  • Delve certified Context AI, which subsequently suffered a security incident.
  • The incident occurred at Vercel following an internal breach.
  • The breach was caused by a Vercel employee downloading a Context AI application.
  • Context AI has abandoned Delve and is in the process of re-certification with Vanta.

Why it matters

These security incidents point to significant risks in the compliance and certification supply chain.
Trust in certification firms can be compromised, leading companies like Context AI to seek alternatives such as Vanta.
The third-party data breaches expose critical vulnerabilities in technology ecosystems.