Product1 publisher3 min readPublished
Paragon CEO Andrew Boyd says withholding updates is how the spyware maker cuts off abusers
Paragon CEO Andrew Boyd says the spyware maker can't see who customers target, and withheld updates leave a customer's system ineffective in about 12 hours. Its zero-tolerance misuse policy depends on outside researchers to find abuse before that slow cutoff comes into play.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Weeks after AE Industrial Partners bought Paragon in December 2024, WhatsApp alleged Graphite had infected the phones of more than 60 people in more than 20 countries.
- Citizen Lab named two journalists and two activists in Italy among the targets, while most of the people in WhatsApp's count were never identified.
- Italy's authorities denied misuse, and its government investigators concluded the allegations were not true.
- Within a week of the allegations, Paragon canceled its two contracts with Italy's domestic and foreign intelligence agencies.
- REDLattice, the AE-owned offensive cyber firm Paragon was merged with, announced plans this week to go public.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Misuse that no outsider uncovers and no customer admits never reaches Paragon's cutoff, since the company holds no target data of its own to review.
- precedent The Italy case sets the working standard: a public allegation can end a contract on risk grounds without a finding, while other countries in the same allegation go unreviewed.
- contradiction Paragon's pitch as the industry's responsible vendor runs against its CEO's account of fewer controls than NSO Group claims for itself, starting with the missing kill switch.
- exposure REDLattice's planned listing would put a misuse regime that relies on outside detection and a delayed cutoff in front of public-market investors.
Andrew Boyd, the new chief executive of Paragon and REDLattice [20], gave WIRED the first detailed account by a Paragon executive of how the company handled Italy [19]. Paragon "fired" Italy, he said, because it "just was not worth it, from a risk perspective, to maintain the relationship" [9]. According to WIRED, there was no investigation. Paragon did not go back to WhatsApp or Citizen Lab to ask whether contracts in the other countries named should also be canceled [10]. Its cancellations covered one of the more than 20 countries in WhatsApp's allegation [1].
The written promise is to cut off any customer caught turning Paragon's tools on journalists, dissidents or other non-legitimate targets [1]. In Boyd's account, the catching happens outside the company: a customer admits it, or a third party uncovers it [11]. He said WhatsApp and Citizen Lab did Paragon a great service by exposing the alleged misuse [12]. At the time, Paragon reportedly explored legal action against WhatsApp after the messaging company sent it a cease-and-desist letter [7].
Stopping a customer is possible, on a delay. Paragon has no kill switch. It can halt a customer's 24-hour support and its system updates [13]. Boyd would not say what the updates contain, only that they are frequent and essential to running the spyware [14]. "Things start falling apart quite quickly," he said [15].
On paper, Paragon's most significant competitor does more. NSO Group, the Pegasus maker, says in its transparency reports that it also cannot see who customers target [18]. It says it can switch off a customer's access and keeps "tamper-proof" logs of user activity. Customers are contractually obliged to hand those logs over when misuse is alleged, or face "immediate suspension" [18]. Those are NSO's claims about itself. Set against them, Boyd's description leaves Paragon with less oversight than NSO, after years of pitching itself as the industry's good guy [1][13][18].
REDLattice founder John Ayers wrote before the interview that the company was "not looking for a favorable write-up" [16]. "If the honest assessment is still damning, that's a conversation we're prepared to have," he wrote [17].
In Boyd's description, the agency running Graphite works without Paragon seeing its targets and meets a control only when support and updates stop [11][13]. Enforcement depends on two things outside the software: researchers and platforms that detect abuse, and the reputational risk Boyd cited when Paragon dropped Italy [9][11].
Two questions make a two-by-two for any vendor that promises to cut off customers who misuse its product. The first is who detects misuse, the vendor's own systems or outsiders. The second is how long it takes from the vendor's decision to a product that no longer works, minutes or hours. Paragon, by Boyd's account, sits at outsiders and about 12 hours [11][14]. NSO, by its own reports, sits at outsiders and immediate, with logs it can demand [18]. Only the box where the vendor detects abuse itself and cuts off at once makes zero tolerance a property of the software. In the other three it is a response policy, and an honest policy page would say who does the detecting and how many hours the cutoff takes.
What to watch
- Whether REDLattice's listing documents describe Paragon's misuse controls, including the update cutoff and any customer logging terms.
- Whether Paragon reviews contracts tied to the other countries in WhatsApp's allegation, or Italy stays its only cancellation.
- Whether Paragon adds a kill switch or contractual log access of the kind NSO Group says it has.