Operational notes Observatory

Two million for a “proprietary solution”, and nothing else

7 min read

A blank sheet of paper fed into the roller of a typewriter, close-up detail, black-and-white photograph
The field for a supplier’s capability exists. In too many registers, the row is left blank.

If someone asked you today for the list of suppliers who can access your employees’ or your citizens’ data, how long would it take? And which field would you search — the one for the spend category, or the one that actually says what the product does and what it reaches? If the second question leaves you without an answer, you are not an isolated case: it is the ordinary condition of a supplier register written for accounting, not for security. A public award signed in the United States, closed out sixteen months later, shows where that condition leads once someone actually asks the question.

A two-million-dollar purchase order, a description that says nothing

The US federal award registry (USAspending, FPDS data) lists PIID 70CTD024P00000012: type B, purchase order — not a framework contract. Agency: Department of Homeland Security, sub-agency U.S. Immigration and Customs Enforcement (ICE). Signed on 27 September 2024, period of performance 30 September 2024 – 29 September 2025: the potential end date matches the contractual one, no extension. $2,000,000 obligated, base plus all options included: nothing left to exercise. Recipient: Paragon Solutions (US) Inc., UEI NW6QFTZACWM7. The field reserved for the parent company, in the same record, returns the name of the company itself: it adds no information you didn’t already have.

The award’s official description, verbatim, in the capitals used in the registry: “THIS AWARD IS FOR A FULLY CONFIGURED PROPRIETARY SOLUTION INCLUDING LICENSE, HARDWARE, WARRANTY, MAINTENANCE AND TRAINING”. No product name. No function. The commodity classification doesn’t fill the gap: NAICS 541512, “COMPUTER SYSTEMS DESIGN SERVICES”, and PSC 7B22, “IT AND TELECOM - COMPUTE: SERVERS (HARDWARE AND PERPETUAL LICENSE SOFTWARE)” — the same codes used to label the purchase of any ordinary server cluster. The competition, if it can be called that (solicitation 70CTD024R00000009): extent competed C (not competed), other than full and open ONE (only one source admitted), procedure SSS (sole source), a single offer received, product classed as commercial (A). A single supplier, invited and awarded: no competition.

A three-line chronology, and no explanation

The registry doesn’t stop at the award card. The transaction history of the same award — a level almost nobody checks — shows three modifications after signing. On 8 October 2024, modification P00001 carries this verbatim description: “…IS BEING MODIFIED TO ISSUE A STOP WORK ORDER”. On 30 August 2025, P00002 revokes it: “…THIS MODIFICATION IS TO LIFT THE STOP WORK ORDER”, a month before the end of the base period of performance. On 20 January 2026, nearly four months after that deadline, P00003 closes out the contract: “THIS MODIFICATION CLOSES OUT THIS CONTRACT…”. Three actions, three dates, zero explanations: no field says why work stopped, or why it resumed. The registry records that something happened. It does not record what, or why.

Who the supplier is

Paragon Solutions has long been on our watch of surveillance and defence companies. The most solid reference is Citizen Lab report No. 183, University of Toronto, “Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations”, 19 March 2025, authored by Bill Marczak, John Scott-Railton, Kate Robertson and others.

The report describes Graphite, Paragon’s flagship product, as spyware said to provide “access to the instant messaging applications on a device” — not full control of the phone — loading itself into legitimate apps and processes already on the device rather than installing as its own app, which makes forensic detection harder. The Citizen Lab identified suspected infrastructure tied to Graphite in Australia, Canada, Cyprus, Denmark, Israel and Singapore; Italy appears in the report as a publicly admitted customer. On 31 January 2025, WhatsApp notified over 90 individuals it believed had been targeted by a Paragon zero-click exploit it had found and mitigated; among the Italian recipients named in the report: Francesco Cancellato, editor-in-chief of Fanpage.it, and activists Luca Casarini and Giuseppe Caccia, of Mediterranea Saving Humans.

Paragon presents itself as different from other vendors in the sector: according to a 2021 Forbes interview cited in the report, a Paragon executive had claimed the company sells only to governments that “abide by international norms and respect fundamental rights and freedoms”. Approached by the Citizen Lab, the company — through executive chairman John Fleming — replied that “the brief summary of the report you sent includes several inaccuracies, but without additional details we cannot be more specific or provide comment for the record”: an objection without specifying which claim was inaccurate; asked for details, the same reply. We report Paragon’s position in full: a right of reply, not an admission or a confirmation.

The point is not what ICE bought

From here the registry says no more, and this piece won’t say it on the registry’s behalf. We do not know whether it concerns Graphite, another Paragon product, or a supply entirely unconnected to what the Citizen Lab documented: the description names no product, the codes name no capability, the modifications name no reason. The point is not what ICE bought. It is that the registry, on its own, cannot tell you — and neither can the second layer, the one almost nobody checks.

See the service · Talk to an engineer

The same formula, in your own register

The story is not only about a US agency: “proprietary solution, licence, warranty, maintenance and training” is the formula behind one row in two of a large company’s or a public administration’s supplier register. As long as nobody asks, it’s enough: it pays the invoices, it clears an accounting audit, it doesn’t block a renewal. The day a rule changes — or a supplier ends up in an investigation, as with the EU sanctions designations that name directors, not the companies they run — or a board asks what is exposed, the question becomes: which suppliers access which data, under what contract, with what access? If there is no answer, it isn’t because someone hid it: it is because it was never written into a field a machine can query. The same gap, on the other side of the relationship, shows up in the AI defence contract clauses that stay secret even from a US senator: a statement of work with no substance produces the same hole as a purchase order with none.

The lesson is the one already seen when a press headline and a Pentagon order’s official description told two different stories: the commodity category is not a description. NAICS and PSC codes say which shelf the spend sits on, not what the product does, who uses it, what data it reaches.

What we put into operation

What we put into operation turns the supplier register into a control that runs on the client’s own contracts and systems, not on a yearly spreadsheet. For every supplier: what capability it actually provides — not the commodity category —, what data it accesses, under what usage clause, who approved it, when it was last reverified. What comes out is a dated trail, ready for an inspection or a board.

The same system holds an organisation’s contracts, registers, archives, business systems and documents together in a single operating model — the organisation’s data lake becoming one thing — on which AI agents execute decisions with a human operator in command, for large enterprises, defence, government and healthcare. When news breaks about a supplier, the answer to “where do we have it, under what contract, with what access” arrives in hours, not weeks — the same logic already seen for an organisation that never tested its exit from a critical supplier. Always in two modes: on-premises, on autonomous machines that require no deep integration into the client’s network, or dedicated cloud, with a data centre in Italy and shared management.

Back to the question we opened with. If someone asked you today for the list of suppliers who can access your employees’ or your citizens’ data — produced in hours, on a queryable field, not a spreadsheet rebuilt by hand — could you say yes right away? For the vast majority of organisations, the answer is still no.

From the first session, at no cost, comes the dated list of your suppliers whose register rows don’t say what capability they provide or what data they access — the ones you wouldn’t know how to use if asked. It stays with you even if we don’t go any further. Talk to one of our engineers.

Sources