Popular AI Gateway Startup LiteLLM Ditches Controversial Startup Delve
LiteLLM Ends Partnership After Security Concerns
LiteLLM, a leading provider of an AI gateway framework used by millions of developers worldwide, has publicly announced its decision to drop compliance startup Delve. The move comes shortly after LiteLLM experienced a major security breach in its open source software, where malware was found stealing user credentials.
Background: Security Certifications in Question
Previously, LiteLLM earned two key security compliance certifications by working with Delve, a startup focused on AI compliance verification. These certifications are critical for establishing robust security practices. However, Delve has come under fire for allegedly providing fake data and using lenient auditors, which has cast doubt over the legitimacy of its compliance procedures. Delve's founder has denied these claims, offering free re-audits to clients, but the controversy persisted as anonymous sources continued to share purported evidence against the company.
Next Steps for LiteLLM
In response to the incident and ongoing doubts about Delve, LiteLLM CTO Ishaan Jaffer revealed on X (formerly Twitter) that the company will redo its security certification with Vanta, a competitor of Delve, and employ an independent third-party auditor to thoroughly check its compliance controls.
This decision highlights LiteLLM's commitment to security and its intent to regain developer trust by ensuring rigorous third-party verification after a challenging week.
For the original article, visit TechCrunch.