The people who are not the target
Lawful interception can affect people outside the scope of an investigation. Technical safeguards and institutional oversight are required to limit that exposure.
Safeguards for lawful collection
Lawful interception supports authorized investigations. Misuse or collection beyond the authorized scope can affect the privacy and rights of people who are not subjects of an investigation.
Scope enforcement, automatic expiry, attribution and minimization provide technical safeguards alongside institutional policy and oversight.
Technical and institutional safeguards
Each technical control can be checked in a deployment. Responsibilities that depend on customer authority are identified separately.
Collection is scoped, then enforced
The terms of an authorization become machine-enforced limits before collection starts.
Expiry is automatic
Collection stops automatically when the authorization expires.
Minimization within the workflow
Material outside the scope of an order is handled through defined minimization rather than left in the record for someone to notice later.
Every access is attributable
Per-user attribution and a recorded reason for access on every action, in an append-only log. This is what makes an internal abuse investigation possible at all.
Oversight can see without operating
Inspectors and auditors can be granted genuine visibility into what was done, without acquiring the ability to task or collect.
The authorising process stays yours
We do not issue warrants, approve targets or run operations. The institution with the legal mandate does that, and we build so that its decisions are the ones the system obeys.
What we will not do
The following restrictions govern the capabilities we supply and support.
- Supply restricted capability to an institution without the legal authority and oversight to operate it.
- Build a covert channel that would let us observe a lawful customer’s operations.
- Weaken audit, attribution or expiry because a customer finds them inconvenient.
- Provide capability where the review reaches deferred or declined, on any commercial argument.
- Treat “the customer is responsible” as a complete answer to a misuse question.
Where our authority ends.
We decide whom we serve, what we supply and support, which boundaries apply, and when our own participation must stop. Inside the boundary that was agreed, an authorized institution governs its own operations. We do not run them and we do not covertly constrain them, because a vendor quietly steering a sovereign customer’s intelligence work is its own kind of accountability failure.
That is a real limit on what we can promise. What we can promise is that the capability we supply enforces the authority it was given, records what was done with it, and can be withdrawn by us if it is misused.
Raising a concern.
Anyone can raise a concern about how an S32 Technologies capability is being used, including people with no relationship to us and no connection to the customer. It reaches a human. Where a concern involves the conduct of a deployment, it is reviewed by someone outside the team that owns the account.
S32 Technologies retains responsibility for its supply and support decisions. We do not operate an external ethics board.