SpyLedger
Methodology
SpyLedger is built to be cited, so the rules behind it are public. It records only facts of public government record, each rebuilt from a primary source and linked. This page documents the authority taxonomy, the scope and fairness rules, the ethical guardrail, and how to dispute an entry.
The authority taxonomy
A company can appear on several different government lists, and they do not mean the same thing. SpyLedger labels every designation with its authority and its legal type, because collapsing them — calling an export-control listing or an equipment rule a “sanction” — is both wrong and unfair. The four types in the record:
- Sanction (asset-blocking)
- Property within US jurisdiction is blocked and US persons are generally prohibited from dealings (e.g. OFAC SDN List).
- Export control
- A license is required to export US-origin items/technology to the entity, typically reviewed under a presumption of denial (e.g. BIS Entity List). It is not an asset freeze.
- Equipment-authorization restriction
- Covered equipment cannot receive new FCC authorization for certain purposes. It is not a sanction or asset freeze and does not ban all of the company’s products (e.g. FCC Covered List).
- Investment restriction
- US persons are barred from buying or selling the company’s publicly traded securities. It is not an asset freeze or a ban on ordinary commercial trade (e.g. Treasury NS-CMIC List).
Each program code on a designation (RUSSIA-EO14024, CMIC-EO13959, SDGT and the like) corresponds to a specific OFAC authority; the sanctions-programs reference explains what each one means. The clearest example is the FCC Covered List: it restricts new equipment authorizations for certain national-security-sensitive purposes. It is not an asset freeze and does not ban all of a company's products in the United States, so SpyLedger renders it as an equipment-authorization restriction with its verbatim scope, never as a flat sanction.
Scope — and fairness
- Designations are rebuilt from primary public-domain feeds — US BIS Entity List, US OFAC SDN, US Treasury NS-CMIC, the US FCC Covered List, and the EU consolidated list — each with a source link. Designation status is a statement of public government record.
- No designation is stated plainly. Where a vendor carries no designation, the record says so explicitly. Inclusion in SpyLedger is not itself an accusation — several tracked vendors have no designation at all.
- Removed listings are marked historical. A delisted or rescinded action (for example, a listing later removed after corporate reforms) is shown as historical, not active.
- Look-alike entities are not conflated. A designation against one legal entity is not attributed to a similarly named affiliate unless the primary record names that entity.
- Procurement and deployment are distinct. The procurement collection describes what a specific award, agency disclosure or oversight document establishes. A purchase alone does not establish operational use or targeting.
Procurement and oversight
The procurement collection is a curated set of institutional records. Every relationship, amount and event links to a primary source, with the document date, review date and relevant page or field. Source fingerprints are included in the JSON export.
- Evidence types stay visible. A federal award record, an agency document, an inspector-general finding, a congressional account and a policy document establish different facts. Reported cancellation remains a reported decision until the relevant instrument is verified.
- Dates describe their basis. Document dates, reported-event dates and status-check dates are labeled separately. Checking a recommendation today does not make today its closure date. Procurement review dates do not refresh the separate designation snapshot.
- Companies and products are matched narrowly. A vendor name does not establish a purchase of every product it sells. Unnamed vendors, intermediaries and products remain unknown. Inclusion does not establish a designation or unlawful conduct.
- Money keeps its meaning. Published amounts are cumulative obligations for an identified award, with a check date. They are not payment totals or product-level revenue. We do not add overlapping award snapshots or infer an amount for an unnamed contract.
- Gaps remain visible. Each record lists the details its sources do not establish. Historical disclosures are not presented as current operational status. Requirements for reports do not establish that the reports were delivered.
The initial collection is deliberately bounded and manually reviewed. It is not a complete inventory of agencies or surveillance purchases. Pages and the JSON export are built from the same canonical records; new evidence is reviewed before a subsequent release.
Ethical guardrail — track the watchers, not the watched
SpyLedger documents the surveillance industry and the governments that regulate it — the powerful side of the ledger. It is the deliberate inverse of surveillance. It carries no victim or target identities, ever; no individual personal data below the corporate-officer line; and no raw leaked material — where reporting derives from a leak, SpyLedger would cite the published analysis, never republish a dump.
Corrections & disputes
Any named entity can dispute an entry. Because every designation is sourced to a primary government record, most disputes resolve by checking the linked source. Where a status has changed — a delisting, a corrected scope, a misattributed entity — the correction is applied and the entry updated. Reach us via the contact page; substantiated corrections are reflected in the next build. SpyLedger is released under CC BY 4.0, so downstream copies should re-pull to pick up corrections.
Designation snapshot: 2026-06-23. Procurement sources reviewed: 2026-09-09. Back to SpyLedger · see also Verboten and the site methodology.