The Vercel and Context.ai breach keeps growing. Here is what it means for your supply chain.
The Vercel and Context.ai breach chain shows how supply chain weaknesses cascade outward, and why compliance certifications alone are no substitute for genuine, ongoing vendor due diligence.
What happened
Vercel has disclosed that the security breach linked to AI startup Context.ai is larger than first reported. After expanding its investigation with additional compromise indicators and reviewing network requests, the company found a second set of affected customer accounts. Some customer data was stolen before the initial hack was even detected.
Separately, TechCrunch has confirmed that Delve, a compliance startup already facing its own troubles, performed the security certifications for Context.ai. Another Delve customer has also suffered a significant security incident, raising pointed questions about the integrity of those certifications.
This is a textbook example of how a single weak link in a supply chain can cascade outward.
The supply chain problem in plain terms
Three organisations are now entangled. Context.ai suffered a breach. Vercel, which hosted Context.ai's infrastructure, saw its own internal systems accessed and customer accounts compromised. And Delve, the firm responsible for certifying Context.ai's security posture, is now linked to multiple incidents across its customer base.
Each connection multiplied the blast radius. If your organisation uses any platform in a chain like this, you inherit risk from every other participant, whether you chose them or not.
What organisations should take from this
Compliance certifications are not guarantees
A security certification tells you that a vendor met a set of criteria at a point in time. It does not tell you the certifier was competent, or that the vendor maintained that posture afterward. When the certifying body itself is compromised or unreliable, the certification loses meaning entirely.
Organisations should treat certifications as one input among many, not as a substitute for their own due diligence.
Third-party risk assessments need depth
Most businesses assess their direct vendors. Fewer assess their vendors' vendors. This breach chain shows why that matters:
- Direct dependency: Your hosting provider (Vercel) gets breached.
- Indirect dependency: The breach originated from another tenant (Context.ai) on the same platform.
- Certification dependency: The compliance firm (Delve) that vouched for that tenant's security is itself questionable.
You cannot control all of this, but you can ask better questions during procurement and contract reviews.
Expanding investigations matters
Vercel deserves credit for widening its investigation beyond the initial indicators of compromise. Too many organisations declare an incident contained prematurely. The second set of compromised accounts was only found because Vercel went back and looked harder. This is the right approach, and it is one that requires both technical capability and organisational willingness to keep digging when the news is bad.
Metaphor's perspective
We work with organisations across cloud, cybersecurity, and AI adoption. Incidents like this reinforce something we see repeatedly: security is not a point-in-time exercise, and trust in your supply chain must be continuously validated.
If you rely on cloud platforms, AI tooling, or third-party compliance services, now is a good time to:
- Review your vendor risk register and check for exposure to Vercel, Context.ai, or Delve.
- Ensure your incident response plan accounts for breaches that originate outside your direct environment.
- Evaluate whether your compliance certifications are backed by substantive, ongoing assurance, not just a logo on a website.
Supply chain security is not glamorous work. But when breaches keep expanding weeks after disclosure, it is clearly necessary work.
Sources: The Hacker News, TechCrunch, TechCrunch