Paragon CEO says spyware firm cannot monitor customer targeting
Andrew Boyd told WIRED that Paragon cannot see customers’ targets or activity logs and has no kill switch. He said the company cancelled two Italian intelligence contracts after misuse allegations, without investigating them.

Paragon Solutions and REDLattice chief executive Andrew Boyd says the spyware maker has no technical way to monitor whom customers target or access their activity logs. He also told WIRED the company has no kill switch to disable its Graphite system.
Boyd said Paragon cancelled its two contracts with Italian intelligence agencies after WhatsApp and Citizen Lab alleged Graphite had been used against journalists and activists. He said the decision reflected business risk; the company did not investigate the claims or seek more details from either organisation. Italian authorities denied misuse, and Italian government investigators concluded the allegations were unfounded, according to WIRED.
Paragon can halt customer support and updates, Boyd said, adding that without updates the system becomes ineffective in about 12 hours. He described customer and country vetting, contractual restrictions and technical limits on targeting US phone numbers as safeguards against misuse. Those measures are based on Boyd’s account; the extent of any misuse remains unclear.
WhatsApp alleged Graphite infected more than 60 people in over 20 countries. Citizen Lab identified two journalists and two activists in Italy, while most alleged targets were not identified. Paragon’s decision to end the Italian contracts did not establish whether the allegations were true.
The company’s approach leaves it reliant on customer screening, contractual rules and outside disclosures to identify potential abuse. Boyd said Paragon has between 20 and 30 countries on its approved list and more than 100 customers across 23 countries.


