The Evidence Chain: How a Foreign Cloud Platform and AI are Compromising Australian Sovereignty and Justice

Governance and digital evidence sovereignty

Andrew Klein and Sera Elizabeth Klein

Dedicated to the Australian people—whose data, evidence, and sovereignty are being outsourced to foreign corporations, while the government that should protect them looks away.

Abstract

This paper examines the Australian government’s increasing reliance on foreign-owned digital forensics platforms, specifically the Cellebrite Guardian cloud-based evidence management system. We trace the technical architecture, security vulnerabilities, cost implications, and sovereignty concerns raised by the integration of a foreign-owned, Israeli-based digital intelligence company into Australia’s criminal justice and national security infrastructure. Drawing on publicly available contract data, security research, and parliamentary records, we argue that the Albanese government’s embrace of Cellebrite Guardian—following the Morrison government’s earlier contracts—represents a systemic failure of governance. The government has outsourced its capacity to manage digital evidence, creating vulnerabilities in the evidence chain, exposing Australian data to foreign AI training, and trading sovereignty for the illusion of efficiency. We further contend that the government’s reluctance to scrutinise this arrangement is driven by its broader financial entanglement with firms like BlackRock and its fear of undermining the paper value of its AI and data infrastructure investments.

1. Introduction: The New Architecture of Extraction

The Australian government is outsourcing its capacity to govern. From the privatisation of employment services to the delegation of national security to foreign corporations, a pattern is emerging: a state that is increasingly unable—or unwilling—to perform its core functions. The Cellebrite Guardian cloud evidence platform is a case study in this new architecture of extraction.

Cellebrite, an Israeli-based digital intelligence company, has secured contracts with the Australian Federal Police, the Australian Taxation Office, the Australian Securities and Investments Commission, the Department of Defence, and Services Australia. Services Australia alone has paid more than $1.2 million for Cellebrite technology, including a $460,000 contract in 2020 and a $740,000 extension in August 2021.

The Guardian platform—a cloud-based evidence management system—has completed an IRAP assessment at the PROTECTED classification level, conducted by CyberCX, an Australian Signals Directorate-endorsed assessor. The platform is powered by AWS and is designed to store and manage digital evidence for police, corrections, defence, and national security agencies.

This paper argues that the adoption of Cellebrite Guardian represents a profound surrender of Australian sovereignty. It places Australian evidence in a foreign-owned cloud stack, exposes it to potential tampering and fabrication, and risks the training of foreign AI on Australian data. The government’s failure to scrutinise this arrangement reflects a broader pattern of performative governance—a state that is more concerned with preserving the paper value of its investments in AI and data infrastructure than with protecting the integrity of its justice system.

2. The Technical Reality: How Guardian Works and What It Stores

2.1 The Guardian Platform

Cellebrite Guardian is a cloud-based digital evidence management platform designed to support investigative workflows. It is built to store and manage digital evidence extracted from mobile devices, including messages, photos, location trails, and call detail records.

According to Cellebrite, Guardian is designed to support:

· Case management and task tracking 

· Secure evidence intake and audit-ready reporting 

· Collaboration across investigative teams and stakeholders 

· AI-assisted investigation features, including “Ask Your Data AI” 

2.2 The IRAP Assessment

The platform has been assessed under the Information Security Registered Assessors Program (IRAP) at the PROTECTED classification level, which covers information that could damage national interests. The assessment was conducted by CyberCX, an ASD-endorsed IRAP assessor.

Critical Distinction: IRAP is not a government certification or endorsement. It is an independent assessment that produces documentation for agencies to make their own risk decisions. The ASD does not certify systems through this process.

2.3 What It Means for Australian Justice

Guardian is built to hold “digital evidence for police, corrections, defence and national security agencies”. This includes:

· Seized phones

· Messages and communications

· Photos and media files

· Location trails

· Case files and investigative notes

The platform processes and stores this data in the cloud, powered by AWS. This means that Australian evidence is being moved from on-premise systems into a third-party cloud stack operated by a foreign vendor.

3. The Security Vulnerabilities: The 2021 Signal Hack and the Ongoing Risk

3.1 The Signal Hack

In April 2021, Moxie Marlinspike, the founder of the encrypted messaging app Signal, revealed that he had discovered 100 vulnerabilities in Cellebrite’s technology. Marlinspike claimed that his team had obtained a Cellebrite UFED device and found that the software was “full of vulnerabilities,” including the ability to execute arbitrary code.

The Exploit: By embedding a specially formatted but otherwise innocuous file in an app on a scanned device, an attacker could cause the Cellebrite software to execute code that would:

· Modify the Cellebrite report generated for that scan

· Modify reports from previous scans

· Modify reports from all future scans

· Do so without detectable changes to timestamps or hash values 

As Marlinspike wrote: “Any app could contain such a file, and until Cellebrite is able to accurately repair all vulnerabilities in its software with extremely high confidence, the only remedy a Cellebrite user has is to not scan devices”.

3.2 The Implications for Australian Evidence

The 2021 vulnerabilities demonstrate that Cellebrite’s technology can be compromised. This has direct implications for Guardian:

Tampering Risk: If the underlying technology is vulnerable, the evidence stored in Guardian could be tampered with—by a bad actor, or even by a government seeking to fabricate evidence.

Fabrication Risk: As criminal lawyers noted, the vulnerabilities “make it possible to change the evidence contained in the Cellebrite download”. This is not a theoretical risk—it was demonstrated.

Chain of Custody: The integrity of the evidence chain depends on the security of the platform. If the platform can be compromised, the evidence cannot be trusted.

3.3 The AI Factor

Cellebrite has integrated AI into Guardian, including features that can summarise chat logs and identify the owner of a mobile phone by analysing emails and open-source research. The AI is trained on the data it processes. This means that Australian evidence is being used to train foreign AI systems, with no public transparency or consent.

4. The Cost: $15 Million+ in Contracts and the Hidden Costs of Vendor Lock-In

4.1 The Contract Value

As of 2026, Cellebrite holds 128 active federal government contracts worth more than $15 million . Key contracts include:

Agency—- Contract ——–Value

Services Australia $1.2 million 

Australian Federal Police Multiple contracts 

Australian Taxation Office Multiple contracts 

Department of Defence Multiple contracts 

Australian Securities and Investments Commission Multiple contracts 

Guardian packages start at 5 TB of uploaded data, with annual costs based on usage. The cost of accessing the data collected on Australia’s behalf is a recurring expense that will grow over time.

4.2 The Hidden Costs

The financial cost is only part of the problem. There are also:

Vendor Lock-In: Once agencies are dependent on Guardian, it becomes difficult to switch to another provider. The government is locked into a relationship with a foreign vendor.

Loss of Capability: By outsourcing the management of digital evidence to a foreign cloud platform, the government is not building its own capability. The public service is being hollowed out—a pattern documented by the NSW Public Accountability and Works Committee, which found that governments have become “dangerously dependent” on consultants.

The $742 Million Problem: A 2026 report by the Centre for Public Integrity found that consultancy contracts worth more than $2 million totalled approximately $742 million across the 2025–26 financial year, with more than half of that value for management advisory services. KPMG, Deloitte, EY, and Boston Consulting Group held contracts worth approximately $158 million. This is not just a Cellebrite problem—it is a systemic failure of governance.

5. The Sovereignty Question: How a Foreign Cloud Platform Is Compromising Australian Control

5.1 The Loss of Control

Guardian is a cloud platform powered by AWS. While Cellebrite claims Guardian “supports deployment models intended to align with Australian government expectations,” the company does not specify on-shore hosting. The data is being stored in the cloud, potentially outside Australia.

This raises critical questions:

Who holds the keys? The data is stored in a cloud platform owned by AWS (a US company) and managed by Cellebrite (an Israeli company). Australian agencies are losing control of their own evidence.

Who can access the data? Cellebrite administrators have access to the system. The company does not disclose whether they can access customer data, and the IRAP assessment does not eliminate this risk.

Is the data being used to train AI? Cellebrite’s AI features are trained on the data they process. This means Australian evidence is being used to train AI systems that may be used elsewhere.

5.2 The Sovereignty Test

The question is not whether Cellebrite is a good or bad company. The question is whether Australia should outsource its digital evidence chain to a foreign vendor.

As your friend’s post noted, this is a “supply-chain decision: who hosts the evidence, who can administer the system, and what access remains with the vendor after agencies sign on”. These questions are sovereignty questions.

6. The Real-World Applications: How the Platform Is Being Used Against Vulnerable Populations

6.1 Services Australia

Services Australia is using Cellebrite technology to investigate “fraud and other criminal behaviour”. The agency has stated that it does not use the technology on “genuine welfare recipients,” but only to investigate “suspected or real criminal and fraud matters”.

The Greens have raised concerns that the technology could be used against welfare recipients, given the agency’s history with Robodebt. Senator Janet Rice described the spending as “horrifying” in the context of the Robodebt scandal, which saw the government pursue debts from vulnerable Australians based on flawed data.

6.2 The Risk of Mission Creep

As with the Robodebt scheme, there is a risk that the technology will be used beyond its intended purpose. The technology is designed to extract data from mobile devices—data that could be used in a wide range of investigations, potentially including those targeting vulnerable populations.

6.3 The Human Cost

Services Australia has been at the centre of multiple scandals involving the misuse of technology against vulnerable Australians. The Robodebt scheme, the use of Cellebrite, and the broader push towards AI-driven compliance all point to a government that is willing to sacrifice due process for efficiency.

7. The Political Trap: Why the Government Will Not Act

7.1 The Fink-BlackRock Entanglement

The government has invested heavily in AI and data infrastructure, including the data centre boom we have documented elsewhere. BlackRock—which has been given tax breaks and contracts by the Albanese government—is a key player in this infrastructure.

As we have argued elsewhere, the government is well aware of the incapacitated system, but is too afraid to lift a finger in case the bad news impacts on the paper value of the investment made with Fink and BlackRock. The government is locked in: to scrutinise Cellebrite would be to scrutinise the broader architecture of extraction.

7.2 A Pattern of Outsourcing

The Cellebrite issue is not isolated. It is part of a broader pattern of outsourcing government functions:

· Employment Services: The privatisation of the Commonwealth Employment Service.

· National Security: The integration of US troops and the AUKUS agreement.

· Digital Evidence: The adoption of Cellebrite Guardian.

The government cannot outsource governance fast enough. The act of government has been handed over to third-party interests—to the point where basic governmental functions are beyond the capabilities of the Albanese government, much as they were for the Morrison government.

7.3 Performative Government

This is a performative government—one that is more concerned with appearances than with substance. It is risk-averse, not because it is prudent, but because it is afraid. It is flooded with data from the AI and software it has bought, but it cannot act on that data because the system is incapacitated.

8. Conclusion: The Architecture Exposed

The evidence is clear:

1. Cellebrite Guardian is a foreign-owned cloud platform that stores Australian evidence.

2. The platform has known security vulnerabilities that could allow tampering and fabrication.

3. The technology has been compromised before, and the risk of future compromise is real.

4. Australian data is being used to train foreign AI, with no public transparency or consent.

5. The government has spent more than $15 million on Cellebrite contracts, and the hidden costs of vendor lock-in are growing.

6. Australian sovereignty is being compromised, and the government is refusing to act.

The Albanese government cannot outsource governance to third parties fast enough. The question that arises is: will anyone actually notice? The answer is that we have noticed. We have documented the architecture.

The government is aware of the incapacitated system but is too afraid to lift a finger, lest the bad news impact the paper value of its investments with BlackRock. This is not governance—it is the management of decline.

References

1. The Guardian. (2021). Services Australia pays $1.2m for controversial spyware for fraud investigations.

2. TipRanks. (2026). Cellebrite Guardian completes IRAP assessment.

3. PCMag. (2021). iPhone hacking device from Cellebrite full of vulnerabilities.

4. SecurityBrief Australia. (2026). Australian Government stories.

5. NSW Government. (2025). Public service ‘core work’ policy to reduce reliance on consultants.

6. iTnews. (2021). Services Australia says phone-cracking tech not used for income support compliance.

7. Cellebrite. (2026). Cellebrite Guardian: IRAP Assessed Cloud Platform for Australian Government Agencies.

8. CNews. (2021). Cellebrite hacking tools full of vulnerabilities.

9. Cellebrite. (2026). Cellebrite Guardian Fundamentals.

10. Centre for Public Integrity. (2026). New Centre for Public Integrity analysis shows Commonwealth government remains heavily reliant on private consultants.

11. YourLifeChoices. (2021). Services Australia pays $1.2 million for spyware technology.

12. Tsecurity.de. (2021). Signal CEO Hacks Cellebrite iPhone Hacking Device Used By Cops.

13. Cellebrite. (2025). Autumn 2025 Release.

14. Parliament of NSW. (2024). Hansard: External Consultants.

Signed 

Andrew Klein 

Sera Elizabeth Klein

Dedicated to the Australian people—whose data, evidence, and sovereignty are being outsourced to foreign corporations, while the government that should protect them looks away.

Leave a comment