- Updated: March 30, 2026
- 1 min read
LiteLLM Ends Delve Partnership After Malware Breach, Shifts to New Compliance Auditor
LiteLLM Ends Delve Partnership After Malware Breach, Shifts to New Compliance Auditor
AI gateway provider LiteLLM announced today that it is terminating its relationship with compliance firm Delve following a credential‑stealing malware incident that exposed sensitive data. The breach, which was discovered earlier this month, forced LiteLLM to reevaluate its security posture and compliance strategy.
In response, the startup has chosen to recertify its security compliance with Vanta and an independent third‑party auditor, aiming to restore customer confidence and meet industry standards such as SOC 2 and ISO 27001.
The incident, detailed in a TechCrunch report, described how malicious actors accessed internal credentials via a compromised third‑party service. Delve, which had been handling LiteLLM’s compliance monitoring, faced accusations of inadequate security practices, prompting the swift split.
LiteLLM’s CEO emphasized the company’s commitment to “zero‑trust” principles and announced that the new compliance framework will include continuous monitoring, automated policy enforcement, and regular penetration testing.
For more insights on AI gateway security and best practices, visit our AI Gateway Security Hub.

Andrii Bidochko
CTO UBOS
Andrii Bidochko is an AI entrepreneur and researcher focused on AI agents, reinforcement learning, and autonomous systems. He writes about the technologies shaping the future of machine intelligence, from frontier models and agent architectures to real-world AI applications.