Voidly · accountability data

SpyLedger: Spyware & Surveillance Vendor Designations

An open, source-cited record of the surveillance-industry — the public corporate identity and government-designation status of the vendors who build spyware, deep-packet inspection, and mass-surveillance tooling. Every designation is rebuilt from a primary government source and linked.

Follow procurement and oversight

7 source-linked records connect agency purchases and disclosures to privacy reviews, audit findings and reported decisions. Procurement sources reviewed 2026-09-09.

Explore the procurement record

A record of official government actions, not an allegation. Most entries restate a public designation by a named authority, with a primary-source link; where a tracked vendor carries no such designation, that is stated plainly rather than implied otherwise, and any product description rests on the cited public record. SpyLedger does not itself accuse any company of wrongdoing, and a designation carries only the specific legal meaning its authority gives it. To dispute or correct an entry, contact us. Built under our data standards.

The surveillance-technology industry is documented in scattered government actions — a US Commerce export-control listing here, a Treasury sanction there, an FCC equipment rule somewhere else — each with different legal force. SpyLedger gathers those public facts into one graded, sourced record for 26 marquee vendors, so the designation status of a company can be read at a glance and cited. It tracks the watchers, not the watched: it documents vendors and the governments that regulate them, never surveillance targets.

Vendor-designation snapshot: . Procurement has its own review date and coverage.

Vendors tracked
26
Active designations
37
With ≥1 designation
21
Designations on record
40

Mercenary spyware

DPI / censorship

Forensic extraction

  • Cellebrite · UFEDnone on record
  • Meiya Pico · China · Digital forensics workstations / computer forensic laboratory equipment2 designations

Biometric / video

Network / safe-city

Method & caveats

The designation collection publishes public corporate identity and government-designation status. The separate procurement collection records documented awards, attributed agency disclosures, and oversight events. A purchase does not independently establish operational deployment or targeting. Neither collection contains individual device, location or targeting records. Designation-status claims that an entity is restricted are statements of public government record; where a vendor has no designation, that is stated plainly rather than implied otherwise. See the methodology for the authority taxonomy, the scope rules, and the corrections channel.

Designations are current as of the 2026-06-23 build; always confirm against the linked primary source before relying on a status.

Machine access

Two separately dated collections are available as keyless static JSON: vendor designations and procurement with oversight. Procurement pages and JSON publish the same reviewed records; a build does not perform a fresh source review.

import requests
data = requests.get("https://ai-analytics.org/spyledger/index.json").json()