Paragraph 1
Imagine for a moment that a company sells a powerful tool that can slip into someone’s phone, read their private messages, listen to their conversations, and track their every move. Now imagine that same company claiming it has no idea how its customers are actually using that tool—and, in fact, deliberately designing it so that the company itself cannot peek at the logs. That, in essence, is the model that Paragon Solutions has embraced. The Israeli spyware maker, known for its Graphite hacking tool, says it has struck what it believes is the right balance between privacy and security. Customers, according to Paragon, can choose to enable logging on some systems if they want to, but Paragon itself neither has access to those logs nor wants access. The company’s top leaders argue that this arrangement is a feature, not a bug, because it protects the sensitive targeting information of clients—often governments and intelligence agencies—from prying eyes, including the company’s own employees. In the words of Paragon’s CEO, there is a delicate balancing act between privacy and security, and ensuring customers are using these powerful tools correctly. He insists that the company has found the best possible equilibrium. But critics see something far less reassuring: a multi-million-dollar surveillance enterprise that has essentially chosen to look the other way, relying on word-of-mouth, trust, and external watchdogs to catch abuses that the company itself refuses to monitor. For a product that can compromise the phones of journalists, activists, and opposition figures, this hands-off approach raises uncomfortable questions about accountability, transparency, and whether the private sector can ever be trusted to police its own darkest technologies.
Paragraph 2
To be fair, Paragon does not operate in a complete vacuum. The company says that government oversight bodies, such as parliamentary committees or other independent watchdog institutions, can review the logs if they are enabled, and use them to investigate allegations of misuse among their own agencies. An Italian parliamentary committee, for example, reportedly did exactly that last year after Citizen Lab, a research group at the University of Toronto, published allegations about how Paragon’s spyware had been deployed. That sounds reasonable on its face, but it immediately reveals a troubling gap: if the company itself cannot see the logs, and if the only people who can see them are the very government agencies that may have abused the tool, then there is a serious conflict of interest. A government investigator who uncovers evidence of wrongdoing could simply lie about what the logs show, or conveniently decide not to look too hard. There is no independent party with the technical expertise and authority to verify that the records are complete, untampered, and interpreted honestly. Paragon’s CEO counters these concerns by arguing that the current model is really the only one that makes commercial sense. If Paragon had access to its customers’ sensitive targeting data, he reasons, no government would ever buy the product. Spyware, by its very nature, is used to uncover information that people desperately want to keep hidden; the last thing a government wants is for the surveillance company to know which dissidents, lawyers, or political rivals it is spying on. And so Paragon has chosen what it calls careful vetting of customers—rejecting entire countries that might be prone to abusing the spyware—rather than intrusive oversight. The company presents this as a responsible compromise: trust your clients, sell only to the right people, and rely on external researchers to raise alarms if something goes wrong. But critics say this is a bit like a bank refusing to install cameras in its vault because it doesn’t want to invade the privacy of its armored-car drivers.
Paragraph 3
John Scott-Railton, a senior researcher at Citizen Lab who has spent years tracking government misuse of commercial spyware, does not mince words. He calls Paragon’s revelations astonishing and the company’s lack of mandatory logging reckless. In his view, the way Paragon has structured its business means it has less oversight, less transparency, and less contractual protection against abuses than NSO Group—the company that became infamous for its Pegasus spyware and whose name has become synonymous with surveillance scandals around the world. That comparison is striking. NSO Group was widely condemned for enabling authoritarian governments to hack into the phones of journalists, human rights activists, and even government officials. Its reputation was destroyed by exposure after exposure, and it was eventually sanctioned by the U.S. Commerce Department. And yet, according to Scott-Railton, Paragon’s model is even further removed from accountability than NSO’s was. The CEO admitting that his customers won’t tolerate oversight, Scott-Railton says, is refreshing honesty. It reveals that accountability is bad for business, and it signals to lawmakers and regulators that the spyware industry cannot be trusted to self-regulate. He also finds it deeply ironic that Paragon depends on researchers like Citizen Lab to uncover customer misuse while simultaneously spending enormous resources on making its spyware invisible on infected devices—making discovery and detection incredibly difficult. The company actively hides its operations from the outside world, yet it seems to expect independent researchers to do the job that the company itself refuses to do. As Scott-Railton points out, researchers only ever find a very small subset of infections, and the total numbers are always larger. The spyware industry spends millions of dollars trying to hide from those who would expose it, making the entire system dangerously opaque.
Paragraph 4
The concern extends beyond academic researchers to the halls of the U.S. Senate. Ron Wyden, a Democratic senator from Oregon and a longtime champion of digital privacy and civil liberties, has been outspoken in his criticism of government surveillance and the private companies that fuel it. His response to Paragon’s approach is blunt and unambiguous: surveillance tools that lack oversight and transparency are inevitably abused. He argues that it is easy to claim your powerful hacking tool isn’t being misused if you deliberately go out of your way to ensure you don’t know how customers are using it. In Wyden’s eyes, Paragon’s refusal to audit the use of its tool—or even to try to match the work of a small team of researchers at Citizen Lab—is a massive red flag. His words carry the weight of experience: time and again, government surveillance programs that began with noble intentions and strict legal frameworks have been twisted to target political opponents, journalists, and minority groups. The temptation to use such tools is simply too great for many regimes, especially when there is no meaningful risk of getting caught. Wyden’s point cuts to the heart of the matter: transparency and oversight are not optional extras. They are the very safeguards that separate a legitimate intelligence operation from an authoritarian spying apparatus. When a company like Paragon removes those safeguards, it is not protecting privacy. It is enabling abuse. The idea that a government should be trusted to investigate its own misuse of spyware, with no external verification, is a recipe for impunity. And the fact that Paragon would rather discourage logging altogether than risk having awkward records exist at all suggests that the company understands exactly what its customers are likely doing with the tools—whether it chooses to acknowledge it or not.
Paragraph 5
The story of Paragon is rooted in the complex, secretive world of Israeli military intelligence. The company was launched in 2019 by Brigadier General Ehud Schneorson, a former commander of the Israeli military’s signals intelligence group, Unit 8200—the closest Israeli equivalent to the U.S. National Security Agency, and one of the most powerful cyber intelligence units in the world. Schneorson co-founded Paragon with three other Unit 8200 veterans, as well as former Israeli Prime Minister Ehud Barak, a legendary figure in Israeli security and politics. On paper, the pedigree is impeccable. These are people who have spent their careers defending the state of Israel through intelligence gathering and cyber operations. But that same expertise, when turned into a commercial product, creates a dangerous dynamic. Two years after its founding, Paragon reportedly had no customers, but it was already developing Graphite and hoping to break into the lucrative U.S. market. The timing, however, could not have been worse for the commercial spyware industry. The U.S. government had begun cracking down on foreign spyware companies after NSO’s Pegasus and Candiru’s DevilsTongue tools were misused by their customers against government workers, journalists, dissidents, activists, and academics. In 2021, the U.S. Commerce Department placed sanctions on both NSO and Candiru, essentially blacklisting them. The Israeli government, in a rare move, drastically reduced the number of countries to which Israeli firms could sell offensive cyber tools, cutting the list from 102 countries to just 37. The new restrictions excluded countries like Saudi Arabia, the UAE, Morocco, and Mexico—places where Israeli spyware had reportedly been used in ways that generated serious concern. Over a year later, the Biden administration and Congress imposed additional guardrails, making it difficult for the U.S. government itself to purchase foreign-made commercial spyware if it posed a national security risk or could be misused by foreign governments. For Paragon, this shifting regulatory landscape meant navigating a minefield of sanctions, export controls, and political backlash.
Paragraph 6
At its core, the debate over Paragon is a debate about whether the spyware industry can ever be responsible. The company’s leaders would like the world to believe that they are different from NSO Group, that they have learned from the mistakes of their predecessors, and that they have built a company with ethics at its center. But the evidence suggests otherwise. A surveillance company that refuses to know what its customers are doing is not a neutral technology provider; it is a willing participant in a system of unaccountable power. By choosing not to collect logs, Paragon insulates itself from legal liability and political embarrassment. It can honestly say it never saw the list of phone numbers that were hacked, never knew which journalists were targeted, never realized that an election opponent’s phone had been compromised. That plausible deniability is not a sign of good ethics. It is a carefully crafted legal shield. The company’s claim that independent researchers will catch the worst abuses is dangerously naive. Citizen Lab and other watchdog groups operate with limited funding, limited staff, and limited access to the very devices that are being hacked. They are not law enforcement agencies. They cannot subpoena records. They cannot compel testimony. They can only sift through digital breadcrumbs left behind by imperfect spyware. And as the threats become more sophisticated, those breadcrumbs will become rarer. The spyware industry, left to its own devices, will continue to evolve, becoming more stealthy, more invasive, and more resistant to outside scrutiny. What is needed, ultimately, is not private companies claiming to have found the perfect balance, but public policy that forces a real balance: mandatory logging, independent audits, legal accountability, and severe consequences for misuse. Until then, the lesson is painfully clear. Accountability may be bad for the spyware business, but it is essential for democracy. And when companies like Paragon choose comfort and profitability over transparency, they are not just selling tools—they are selling the illusion that freedom and surveillance can coexist without harm. That illusion, as history has repeatedly shown, is the first thing to fall when the tools are turned against the people they were meant to protect.