GTM VaultPro

Library/GTM Vault Podcast 15

Compliance Is a Moat, Not a Cost Center

From MIT Dropout to Millions—Turning Compliance into a Superpower

Selin Kocalar, Delve2025-03-122 min readWatch on YouTubeSubstack post

Welcome to GTM Vault, where 12,000+ founders unlock tech’s sharpest GTM insights. Each week, we dive into the strategies and innovations driving B2B growth—straight from the trailblazers shaping the future.

Hello GTM Vault Community,

This week, Episode 15 of the GTM Vault Podcast features Selin Kocalar, co-founder and COO of Delve—an AI platform making compliance (think HIPAA, SOC 2) fast, painless, and powerful for startups. Selin shares her wild ride from MIT to Silicon Valley, the grit behind Delve’s rise, and how they’re turning a startup headache into a game-changer.

Top 5 Takeaways

1. Pivoting from Pain to Purpose 💡
Selin and co-founder Karun hit a wall getting their MIT-born AI medical scribe HIPAA compliant—six weeks, thousands spent. That struggle birthed Delve, a mission to simplify compliance for all.

2. Grit Beyond the Grind 💪
Marathons and a Navy SEAL bootcamp forged Selin’s resilience. “A 20-mile run I didn’t quit makes hard calls feel easy,” she says, proving personal wins power startup stamina.

3. AI That Slashes Compliance Time ⚡
Delve’s AI—“TurboTax for compliance”—automates the tedious stuff, cutting months to days. Customer 11x nailed SOC 2 fast with Delve, unlocking $1.2M in ARR deals.

4. Growth via Happy Customers 😊
Word of mouth fuels Delve’s scale. In-person office visits and viral X moments (like a sales call snap) keep customers raving, driving hundreds of users—no big ad budget needed.

5. Riding the AI Compliance Wave 🌊
As AI booms, Selin sees compliance evolving. Delve’s poised to lead, syncing with standards like the EU AI Act to keep AI companies secure and ahead.

Got thoughts or guest ideas? Comment below—we’re all ears! 👇

Stay Connected: YouTube | Instagram | TikTok | Apple Podcasts | Spotify

Unlock Immediate Value: 📘
Grab your free ebook, Unified Revenue: The Future of Sales, Marketing, and Customer Success, and start driving growth today.

Top 3 Must-Read Articles: ✍️

Propel Your Growth: 🌱

With RiteGTM, we bring strategic and operational expertise as your fractional marketing partner or unified revenue architect. Book a call to accelerate your path to market leadership.

Keep building,
The GTM Vault Team 🛠️

Full transcript

Machine-generated transcript from the episode video, cleaned for punctuation and names. Speaker labels are not included.

[0:00] From YC to $3 million raised and multi-million ARR, welcome to the GTM Vault, where we dig into the stories behind Silicon Valley's most innovative minds. Today we're thrilled to have Selin Kocalar, co-founder and CEO of Delve, on the show. Selin's journey is nothing short of extraordinary, from leaving MIT to jumping into YC in San Francisco, to launching products, running marathons, and even conquering a Navy SEAL boot camp in just one year. She's built Delve into a startup that's transforming the compliance space with AI, making tedious tasks a thing of the past for hundreds of customers. Get ready to hear how she turned early hustle into groundbreaking innovation. Thanks so much for joining us, Selin. Absolutely, and thank you for having me, Rick. All right, I want to get right to it. From MIT to Silicon Valley, you made a bold leap by leaving MIT and moving to SF to BU Delve with YC. What sparked that decision, and how did you deep

[1:06] research, how did your deep research background shape your startup journey? Good question. Yeah, so I guess there's not many young founders that go into compliance as their first industry. To paint the full picture here, my first week at MIT we had these advising groups and I met someone who's now my co-founder, and we realized we were kind of all going in different directions, but we had this shared interest in biotech. So at the time I was dead set on becoming a PhD, I was working in research labs publishing papers, was dead set on becoming a doctor. So he was going the pre-med route. I guess that was until we kind of met each other, realized we had this shared interest in healthcare, biotech, building things, and kind of derailed both of those paths for each other. So we started off being like, why not, let's just start working together on a project. And that first project was an AI medical scribe to help doctors with their medical note-taking process. And as we were building that out, we actually had to get HIPAA compliant, which was our first encounter with compliance. So we went through that process, spent the 6 weeks, tens of thousands of dollars, and by the end of

[2:08] it we were kind of realizing that this is a very convoluted, complex, and just really time consuming process, and we had a lot of ideas on how to further streamline it. So then we decided to pivot into compliance. And at time we were working out of the dorm room building a platform for HIPAA compliance. We got into YC for that, and the rest is history, how this all came about. That's awesome. So your first year in SF was a whirlwind, from getting through YC to landing early customers and gearing up for demo day. What were some of the key lessons you learned during that hectic yet exciting phase? Yeah, I think as in founding any startup, there are so many highs and lows. The biggest thing is just to keep working through it, keep pushing through it, and have trust in the process that it will work out. I remember there's a lot of times where we were like, is this worth it, or what are we supposed to do here? And you'll soon find out that it's very normal. Those struggles are very normal, everyone goes through them, and you come out way stronger because of it. Great, yes. And you've taken on challenges both in business and in life, running a

[3:11] marathon in the middle of founding and even completing a Navy SEAL boot camp. How have these personal challenges influenced your leadership style and resilience as an entrepreneur? Yeah, I think I work in doing sports and being as active as possible, and so I grew up pretty active. I think when I came into a founding, obviously it's a lot of highs and lows, and so that active component of it is almost what keeps me sane. And around a couple years ago I got into running, fell in love, marathon last summer, did a Navy SEAL boot camp with my co-founder. And when you come from a very intense MIT grind environment and you don't have that much time to do athletics, and then you go into being a founder, that athletics component really became something that I hold very close to my heart. And funny enough, for my birthday about a month ago, my co-founder signed me up for another marathon, so I'm forced to train for that now. But I think it's impacted me from a leadership style in terms of kind of, even when there's hard decisions to make as a

[4:14] leader, or even when there's hard calls, hard challenges to push through, I literally just think back to my last long run and about that 1% thought of, what if I just walked back home at this point. But the fact that I kept pushing through it and made it the whole way, I think these sorts of thoughts in comparison are kind of give me that confidence that I can get it done. And so I think from a leadership perspective it's just made me more confident being able to make the hard calls. From a resiliency standpoint, what's hard doesn't seem so hard anymore when I Ed running 18, 20, 26 miles as my baseline. And Delve is revolutionizing the compliance space by automating evidence collection for standards like HIPAA, SOC 2, GDPR and more. Can you break down how your AI agents work and what makes them a true game changer over traditional manual methods? Great question. Yeah, so I guess at Delve we are taking a fundamentally different approach to compliance. We see compliance as something that's important to keep you

[5:16] secure, but at the end of the day, as a founder you are not a senior IT specialist that can sit around 24 hours a day and just watch logs or manually perform your compliance. And so at Delve what we've done is we've built an AI native platform that compliance differently. Instead of giving you a huge list of controls, which are security best practices to follow, and kind of telling you to implement every single one, we've rethought this from the ground up and built a platform that's step by step, almost like a TurboTax for compliance. And so every button you click, every action you take is helping you satisfy different compliance requirements all in one. And it puts the compliance requirements in an intuitive way, so you can understand, okay, here's what I'm actually supposed to do. It's not just some cyber security jargon, it actually explains to you and helps you implement it. And when you take this TurboTax like UI approach, it also lets you Ed a lot of aied features. And so when we are helping get your infrastructure into compliance, if we notice that there are issues, because it's not just hardcoded, we're

[6:17] able to give you AI native insights into specific to your setup. Based on AWS documentation, here's specifically what you need to do for this given instance. So it's ultra customized steps on how to bring your compliance into check, and comes with AI features left and right. Once your compliant, well, we have an AI security questionnaire autofill feature, where a lot of times your teams are at post compliance still spending hours writing up these Excel spreadsheets of just manual yes or no kind of one sentence answers, and we've been able to automate this out for a bunch of companies and help them close big contracts. I think across the board with all these AI features, it really cuts down the time needed to get compliant from weeks, months down to something that's a lot more digestible, and that's not going to block your contract, and that's also going to let you go back to your real job as a founder. Totally, yeah. Nowadays it feels like SOC 2 is almost like a license to, if I was a taxi cab, I'd need a SOC 2 to kind

[7:22] of have that permit to drive, right? All companies, in order to go up market, need to get that compliance. So I see the problem you guys are solving is huge. I mean, from months to weeks is just a game changer. Exactly, it's almost like that next step after incorporation is almost like getting SOC 2. So we're seeing more and more companies. I mean, at Delve we've skilled hundreds of companies that need to go through SOC 2. And so SOC 2, these other CL compliance frameworks are becoming ever so popular. So tell me about raising three million and hitting a multi-million revenue run rate early on is no small feat. What strategies did you use to quickly build trust among investors and customers in such a competitive industry? Yeah, good question. So I think raising really comes from just having a good business ate, and that's something we really prioritized in the middle of YC, post YC. And

[8:25] through that fundraising process we wanted to prioritize having happy customer, having a product that actually made sense, and having a product that in one look could convert someone from another competitor onto Delve. Once you had these core business fundamentals and you just had a strong operating style, then fundraising became easy. That's such a fundamentally different approach. We kind of positioned ourselves just right where there was this AI boom and there were a lot of AI companies coming out, and we were uniquely positioned to help them specifically out. I think when you combine all of these, it gave us a unique opportunity to come in and disrupt the other incumbents in this industry, and I think that really resonated with both our customers and our investors, and ended up raising that 3.3 mil on. Awesome. And Delve's journey from your YC days to launching new products and scaling in SF has been marked by rapid evolution. Can you share how your go-to-market strategy evolved over time, and what key pivots or learnings made the biggest impact? Yeah, so I really like go to market because it reminds me of my research days. It is a

[9:28] lot of experimentation. There is some strategies that haven't changed at all, and there's some strategies that have changed. So I think for starters, word of mouth is something that is our number one growth strategy. It's never changing, and not since day one when we started, and not, it's still our number one strategy, in terms of prioritizing happy customers, going the extra mile to make a customer happy, and trying to improve the product as much as possible to make it as helpful as possible to them. And so we prioritize happy customers because that lets us get incredible word of mouth. But aside from that, it's just been a whole lot of experimentation. So we tried showing up at and having Delve t-shirts. We even took a, my co-founder K took a sales call on his car one day, as I was coming out of the dentist. I took a picture, posted it on Twitter, and it ended up going B. And so people kind of remember us for these things. We've just, whenever there's an opportunity, just gone for it. Right now we do kind of the baseline things like LinkedIn outbound,

[10:31] social media marketing and social media posting. But I think the core of that is just we want to have good word of mouth, because that reflects happy customers. And you can spend as much money as you want on ads, on paid marketing, but if you're not making something that's just easily adoptable or kind of has positive reviews, it's an up constant uphill battle. Yeah, I'm pretty sure I remember that tweet. By the way, you shared it on LinkedIn as well, right? Yeah, yep. I mean, stuff like that is just so unique that it stands out from the crowd of just mundane posts. And that's awesome, I love that approach. We had another one too where I think PG posted on Twitter, kind of shaming the world the word Delve, because it sounds like it's ChatGPT, and statistically higher rates of getting up in it. And so we were like, our name is Delve. And so we ended up making a Twitter post about it that went viral, and we would still have people to this day will come up to us in person and be like, oh, you guys are the Delve company, right? And we're like,

[11:34] everyone knows us for PG's tweet. That's great. And early on you took the time to visit customer offices in person to really understand their pain points. How did these direct interactions shape your GTM approach and influence the evolution of your product? Yeah, so I think this was a natural byproduct. If we just really care about our customers, and we are willing to go to your office and help you through compliance. So when we first started we used to do this a bunch. We would sign on an early customer and then we go to their office and just help them knock out the compliance tasks with them, and then it would be lunch on us and we'll do compliance together the rest of the day. And so we not only made some really close founder friends that ended up sharing us around a bunch, but it also helped us kind of see how our product was actually used. We could actually understand the founders incentives and really understand the pain point for them. I think ultimately build a solution for founders, for people that are trying to change the industry, impact their company. I don't think anyone wants their job to be defined by filling out manual

[12:36] spreadsheets. Having that and being able to interact with these people firsthand, seeing how they view compliance, and then finding ways to automate Delve to get rid of their pain points or to make the experience even smoother for them, was critical. And actually, even though we're at hundreds of customers now, we still go to customer offices, believe it or not. This Friday, or actually tomorrow, I'll be going over to a customer office. And so it's just so important for building out those customer relationships, seeing how your product is actually used and perceived by them, and just accelerating that feedback cycle. That's phenomenal. I think PG had a write up about doing things that don't scale. I'm sure he talks about it and the YC lessons, and that's really cool that you guys are still doing that to this day, even after hundreds of customers. It's like we haven't lost sight of what matters. Can you share a specific example where Delve's automated solution, like collecting essential data across various systems, made a significant difference for one of your customers? Yeah, there's a bunch of examples. I think I'll give the story of Next. Next was on one of the

[13:39] other compliance platforms. They had spent four weeks trying to get type 1 compliant, and so it was a very very long convoluted process for them, and they needed to get SOC 2 type 2 compliant, which is an even longer, even more comprehensive type of compliance. We ran into them at the perfect time. We met them, ended up signing with them, and we were able to take so much off their plate that the lift on their team was incredibly low. They ended up unlocking huge contracts out of that, I mean $1.2 million in ARR, and so it was a huge unlock for them, all in the matter of weeks of engaging with them. And so kind of getting them onto a platform that actually let them clearly see what was needed for compliance, get help from a team like ours with that high touch service, and then have a platform that just made sense, instead of having to go through 200 different security checklists. It was a lot more streamlined. And I think 11x is among many many of our other customers

[14:41] that have had the same benefits. Remy for example, they closed contract up to 100 Mil in value. Customers that are closing these big deals left and right with Delve SOC 2 reports, and it's fantastic to see kind of founders doing what they're supposed to excel at, which is close contracts, build a great company, and not sit around all day filling out manual Excel spreadsheets or going into their AWS systems and taking manual screenshots. Absolutely. Moving into an office in FiDi and forming relationships with neighbors like UniFi and seral shows a strong sense of community. How has building a local network contributed to Delve's culture and overall success? Yeah, I think because we work in compliance and we're here to make the lives of builders easier, we've just been able to just be well connected to a lot of folks in YC, out of YC, some of these larger enterprises. And I think the real key here is that everyone's here in SF, and being able to build amongst them is such a huge unlock.

[15:43] So we moved into our SF FiDi office about 3 months, three probably four months ago now, and we made some good office friends here. UniFi, we actually were using them at the time, and then the following day we realized that hey, they're literally two floors above. So we have this small kind of family that we're building out just within this office space, but also with all the other founders here in SF, with the YC founders in Dogpatch, with the more the seos that are down in Fremont. Kind of everyone is localized to this general Bay Area, and it's been awesome just getting to meet everyone. But during a company offsite in Hawaii you found yourself in a room with the state senator, CIO and CDO. How do experiences like that shape your vision for Delve and open up new opportunities for growth? Good question. So I guess the backstory behind that one, and it looks like through that we were connected with the CIO and the CDO of Hawaii, and we're also connected with one of the Hawaiian state senators. So that was an awesome experience. We bited all three of them in person, and I

[16:47] think with the senator we had a very long, 2 hour conversation. And so I think this is very representative of kind of our approach to building a company at Delve. There's the standard get customers, build a product, but we're constantly looking for the highest leverage thing that we can do, the high risk but high reward action, like just deciding to send around an email on a Friday night and spend 10 minutes on it, and then seeing how it got us into those rooms, into things that we'd never expect. And so I think we have countless other examples like this, of that jump PG tweeted about the word Delve, deciding to come up with a funny repost, or the other day there was another satirical post about one of our LinkedIn posts, so we decided to reply. And seeing these things go, get garner attention, is kind of very representative, like hey, we're here to do the things that don't scale, but our argument here is that instead of letting us scale linearly, these things are going to help us scale exponentially, by unlock that if you're following the step-by-step path would take much longer to get to. Your background spans cutting edge research

[17:51] and intense personal challenges. What keeps you motivated through the ups and downs of startup life, and how do you balance innovation with the grid needed to overcome obstacles? Yeah, I think something inherent in me that I've always had from a young age is just this go and do it bias to action. I think my journey really began during COVID, when everyone was stuck at home and I found a local community lab that I could work out of, and I would spend all day in that lab. And I think that really carried with me through MIT, through founding, this constant eager to push, this desire to push yourself knowing that you're capable of more, has just kind of, I think, always been strong inside of me. A way to give back to my family, and kind of grow myself personally, and give back to the people around me too, especially within the Delve team. And so that's always been there. But I think it's also a kind of a process of enjoying the journey and just making good memories along the way. There's no end goal I'm chasing, po here it is maximize how happy we can make customers, how strong of aelf culture we could build, the little

[18:52] moments, the crazy things like finding yourself in a room with the CIO and CDO of Hawaii, and going for these not 10 but 11x outcomes. Looking ahead, how do you see AI transforming the compliance space even further? What exciting innovations or certifications on the horizon for Delve, and how might they change the way businesses handle compliance? I think there is a huge revolution coming in the compliance industry, and it's already here, and the reason for this is there is a boom of AI companies, and Aang is making decisions, thousands, hundreds, millions of decisions every second. And if AI can make decisions at this rate, we cannot rely on manual compliance to check every decision or regulate AI. We're going to need AI that can regulate AI and keep AI in compliance and in check. And so this is where we see this golden opportunity to come out with an AI native platform that is able to serve these AI companies of today and of the future. And I think it's not just a

[19:55] better ability to safeguard AI, it's also staying in line with all the new AI coming out, like ISO 42001, like the EU AI Act. All of these different AI related standards and regulations that are coming out this year and in the coming years are going to present an opportunity, and kind of going to change the compliance landscape, and we want to be the first there when these frameworks come out, to help companies and have the AI need of infrastructure to be able to support them, by helping use through the frameworks that are popular today, like SOC 2, which is a cyber security framework, or ISO, which is like the international version of SOC anymore. That ws, that wraps up our conversation with Selin Kocalar today. We explored her incredible journey from high-tech research labs to the fast-paced world of Silicon Valley startups, and how she's turning compliance busy work into streamlined AI powered processes. Selin's story is a powerful reminder that bold moves, relentless hustle, and a willingness to embrace challenges can drive real innovation. Thanks for join

[20:58] joining us in GTM. Stay tuned for more inspiring stories from the trailblazers reshaping our industry, and keep pushing the boundaries of what's possible. Thanks so much for joining the pod, Selin. Absolutely, thank you Rick, it's been a real pleasure. Tech founders and VCs, careers, lessons, GTM.