Digital Forensics

Evidence review

Access, Disclosure and Testimony Around Restricted Mobile Forensic Tools

Buying the tool, reading its documentation, and questioning how it works are three different problems with three different answers. One vendor agreement, two product pages and two appellate opinions, read on one day.

Published 6 September 2026  ·  Sources verified 12 September 2026  ·  13 min read

DEVI Digital Forensics  ·  ORCID iD 0009-0007-6471-1759

How to read this

Entry type
Evidence review
Sources verified
12 September 2026
Evidence classes
company statement, holding

This entry reviews evidence published by other people. DEVI did not test any tool or examine any device for it. Blocks marked with an evidence class quote or summarize a source; sentences beginning “we” describe what DEVI did with those sources, which was to read them. Anything DEVI could not confirm is marked as such and left as an open question rather than written up as a finding. Sources change without notice, which is why the verification date is stated.

An examiner on the other side of a case wants to know how a phone was opened. Three different things could stand in the way, and they are routinely discussed as though they were one thing.

  • Can they buy or use the same product?
  • Can they read its technical documentation?
  • Can they ask questions about how it works, and get answers on the record?

Those have three different answers, and the answers do not line up. This entry sets out what we could establish from primary documents on 6 September 2026: one vendor agreement, four product pages and two appellate opinions, each read in full rather than summarized from secondary sources.

We did not test any tool. Nothing here is a claim about whether any product works, and nothing here is a recommendation about how any court should rule.

Product access

Two vendors state a restriction on their public pages, and one of them sells a different product to everybody else.

That is a statement about who may buy those two products. It is not a statement that a private examiner has no route to mobile extraction, and the same vendor demonstrates why. Magnet's Verakey page sells "consent-based, full file system, logical, and category extractions from the latest mobile devices" and points the other audience elsewhere: "Looking to acquire mobile data for law enforcement investigations? Explore Magnet Graykey."

So the precise finding is narrower than it is often stated. Two named products are not sold to the private sector. A private examiner may still hold other extraction tools, including one from the same company, and may or may not be able to reproduce a given result with them. Whether any particular product could be obtained by a defense examiner through some other approved arrangement is not something we could establish from public pages.

Access to the technical documentation

This is a separate question from purchase, and it has a separate answer.

We followed the two device links that post carries on 6 September 2026. Both redirected to a Magnet Forensics sign-in page. So the device list is real, the company says where it is kept, and it is not readable from outside the customer base.

That is a fact about where a document lives. It is not a claim about the company's reasons, and we make none. It also matters less than it might: a support matrix says which devices a tool covers, not how it works on them.

What the Cellebrite agreement says

Cellebrite publishes a UFED Premium Use Agreement as a PDF. We retrieved it on 6 September 2026 and read it in full.

Read the currentness limitation before the clauses. The document carries no effective date on its face; "Effective Date" is a defined term filled in per customer. Its PDF metadata records creation on 29 January 2018, which matches its file name. What we can establish is that this document exists, remains publicly retrievable at that address, is titled "UFED Premium Use Agreement", and contains the clauses below. We could not establish that it is the operative agreement for any current customer, that every Cellebrite customer signed it, that it applies to products other than the ones it names, or that current agreements contain the same terms. Treat everything in this section as describing one published document from 2018.

What it defines. "Process" means "the proprietary process by which Software may be used to unlock or extract or decrypt data from, certain mobile devices... which is protected as a confidential trade secret of Cellebrite."

Confidentiality. Section 5 provides that "All aspects of the Process (including any list of mobile devices with which the Process works, as may be updated from time to time), any technical information relating to Software or Documentation, any Software or Documentation and the terms of this Agreement are the Confidential Information of Cellebrite without any marking requirement".

Who may run it. "Authorized Personnel" are "employees of the Customer who have been trained and authorized by Cellebrite to perform Actions who are individually bound, or, in the case of U.S. government employees, whose employer organization is bound, by confidentiality restrictions at least as restrictive as those herein."

Reverse engineering. The license prohibitions bar the customer from "reverse compile, reverse assemble, reverse engineer or otherwise translate all or any portion of any Software", and separately from "disclose any results of testing or benchmarking of any Software to any Third Party". A Legal Exception clause addresses statutory interoperability rights — including under national laws implementing EC Directive 2009/24 — by requiring the customer to notify Cellebrite first, after which Cellebrite may either perform the interoperability work at its own commercial rates or "permit the Customer to reverse engineer parts of such Software only to the extent necessary to achieve such interoperability." Only if Cellebrite then denies the request may the customer exercise its statutory rights.

The litigation-support clause. This is the one most often quoted, and it is usually quoted in part. Section 10.D reads in full:

Three observations about the wording, in order of how often they are dropped.

The clause has a third limb — closed courtroom and sealing — that shorter quotations usually omit entirely.

The obligations are "best efforts", not undertakings to achieve a result.

And the whole clause is expressly bounded: "to the maximum extent permitted by applicable Law", a qualifier that appears in the operative sentence itself. Any version of this quotation that stops before those words describes a stronger obligation than the document creates.

What the agreement does not establish

This is where the discipline matters most, so we state it flatly.

A contract allocates obligations between the parties who signed it. This one is between Cellebrite and its customer. By itself it does not establish:

  • what a court will order to be disclosed in discovery;
  • what a witness must answer under oath, or when a privilege or protective order applies;
  • whether any of these terms would be enforceable against a party in a particular case, or survive a conflicting court order;
  • what any constitutional or statutory disclosure obligation requires of a prosecutor; or
  • anything at all about whether the product is accurate.

The clause itself defers to law twice, in "best efforts" and in "to the maximum extent permitted by applicable Law". We read that as the document declining to claim the authority that a shortened quotation appears to give it. Reading it the other way — as an instruction that overrides a judge — is not supported by the text.

What courts have actually held

Two published opinions bear on this, and they answer different questions. We read both in full, each from the deciding court's own published PDF.

Two things about Pickett that are easy to overstate. It concerned DNA genotyping software, and it says so. And the court set out what this defendant had done to earn the order — showing unsuccessful attempts to obtain the material from the State, providing specificity about what was sought, showing by example that a protective order could safeguard the company's intellectual property, and demonstrating that source-code review was particularly crucial to that technology. Pickett is not a rule that a defendant may have source code on request.

Pratt is the closer case on its facts — it is about a mobile extraction tool by name — and it runs in the opposite direction from the reading Pickett is often given. But the two are answering different questions. Pickett is about discovery: can the defense obtain the code to mount a reliability challenge. Pratt is about qualification: must the testifying examiner understand the internals. A court could answer yes to the first and no to the second without contradiction.

Our interpretation, offered as interpretation. Pickett's reasoning gives a defense litigant an argument by analogy where a proprietary tool's output is central and its reliability genuinely contested, and the protective-order mechanism is the part most likely to travel. Pratt suggests that an attack aimed only at what the examiner personally knows about the software's internals has already failed once, in a state supreme court, on facts involving this category of tool. Neither proposition is a holding about Graykey, Premium, or any restricted product, and we are not predicting what any court would do.

Searching for authority closer to the question

The research file behind this entry states that no appellate decision applying Pickett-style source-code disclosure to a mobile extraction tool was located. We did not repeat that. We searched again.

On 6 September 2026 we searched the CourtListener opinion database. A search for GrayKey "source code" returned no results. A search for "mobile forensic" "source code" "protective order" returned no results. A search for Cellebrite "source code" returned exactly one opinion — Pratt, above, which concerns an examiner's qualification rather than discovery of code. Broader searches combining these product names with discovery, trade secret, Frye and Daubert terms returned opinions that mention the tools without deciding a source-code disclosure question.

That is a description of one database, four query forms and one date. It is not a finding that no such decision exists. Opinions go unpublished, trial court orders are frequently not in any database, and a search phrased differently may return something ours did not.

A later search, outside those source-code queries, did locate a trial-court record about process access rather than source code. United States v. Pierce, No. 20-cr-40068-TC (D. Kan.), describes a prior order that permitted limited defense testing of GrayKey under a protective order, and records that counsel later observed a vendor demonstration on the relevant software version. The defense papers in that case stated they were not seeking source code. Pierce is not an appellate holding, and it is not a source-code disclosure order. It is evidence that at least one district court has ordered limited process access to a restricted mobile extraction tool.

What this means for an examiner

Whichever side retains you, the useful move is to keep the three questions apart and answer each one on its own evidence.

  1. Product access. Establish which specific product produced the extraction, and whether that product is sold to you. "Not available to the private sector" applies to a named product, not to a vendor or to the field.
  2. Documentation access. Ask separately whether the relevant coverage documentation is public, customer-only, or in the product interface. That answer does not follow from the first one.
  3. Process questions. A vendor agreement between a company and its customer is a document you can read and cite. It is not the rule that governs what a court will order or what a witness must answer.
  4. Know which question you are litigating. Discovery of a proprietary process and qualification of the examiner who ran it are different arguments with different authority behind them, and conflating them weakens both.

What we could not verify

Not independently verified

Whether the January 2018 UFED Premium Use Agreement is operative for any current customer, and whether current Cellebrite agreements contain the same litigation support, confidentiality or reverse engineering terms. We established that this document is published and what it says. We did not locate a current agreement to compare it against.

Not independently verified

The contents of the Graykey support matrix. The device pages linked from Magnet's public post redirected to a sign-in page when we followed them, and we did not attempt to obtain access.

Not independently verified

Whether a private or defense examiner can obtain either restricted product through some approved arrangement not described on the public pages — a court-appointed engagement, a laboratory service, or a vendor exception. The pages state a restriction; they do not enumerate exceptions, and their silence establishes neither that exceptions exist nor that they do not.

Not independently verified

Whether any court has ordered disclosure of a mobile extraction tool's source code. Our CourtListener source-code searches are stated above. Pierce ordered limited process access under a protective order, not source code, and we did not locate an order requiring production of source code for a tool in this category.

Not independently verified

How the "in the case of U.S. government employees, whose employer organization is bound" alternative in the Authorized Personnel definition operates in practice, including whether it changes what an individual examiner may say. We record the wording; we did not find material interpreting it.

Sources and evidence

Sources verified on 12 September 2026

Vendor
CellebriteMagnet ForensicsBelkasoft
Product and version
Cellebrite UFED PremiumMagnet GraykeyMagnet VerakeyBelkasoft X Forensic
Platform
iOSAndroid
Source
Cellebrite UFED Premium Use Agreement (PDF, January 2018)Magnet Graykey product pageMagnet Graykey supported mobile devices postMagnet Verakey product pageBelkasoft X Forensic product pageNew Jersey Judiciary published opinion, State v. PickettVermont Judiciary published opinion, State v. Pratt (2015 VT 89)CourtListener opinion database
Jurisdiction
New JerseyVermont
Case
State v. Pickett (N.J. App. Div. 2021)State v. Pratt, 2015 VT 89United States v. Pierce, No. 20-cr-40068-TC (D. Kan.)

Indexed under

  • iOS
  • Android
  • Mobile Extraction
  • Tool Validation
  • Cellebrite
  • Examiner Workflow

Independent and educational. DEVI Digital Forensics is an independent educational project created by digital forensic practitioners outside of their official employment. It is not sponsored, reviewed, approved, or endorsed by any contributor's employing agency.

Forensic behavior changes between operating system versions, application versions, extraction methods, and tool versions. Validate every finding against your own data, and do not interpret an artifact in isolation. Read the full statement and methodology.

← All findings