Somebody Already Made the List of Who's Watching You

There's a myth that the people watching you are faceless. A volunteer-run project called Surveillance Watch demolishes it with the least glamorous tool imaginable.

Somebody Already Made the List of Who's Watching You

What a volunteer-run map of the surveillance industry proves about the "faceless they," and why the trail runs through your own retirement account

There is a third comforting myth about privacy, and it is the most soothing of all because it absolves you of any work. The first myth says you can stay invisible if you are disciplined enough. The second says you are safe if you use the right tools. The third is quieter and more corrosive: that the watchers are a faceless "them." A shadowy apparatus, too vast and too diffuse to name, run by nobody in particular from somewhere you cannot see. It is a comforting story because if the surveillance industry is unknowable, then there is nothing to know, and nothing to do, and no one to hold responsible. You are off the hook by reason of the sheer scale of the thing.

A small, volunteer-run project called Surveillance Watch demolishes that myth as cleanly as the Skripal case demolished the first and the He and Wang case demolished the second. It does so with the least glamorous method imaginable: a list. The surveillance industry is not a fog. It is a finite set of named companies, each with headquarters, investors, customers, and cited reporting attached. Someone sat down and cataloged them, and the catalog is public. As of this writing, it holds seven hundred and eighty-four entities, and the most uncomfortable thing in it is not any single company. It is the cap table, which runs straight through the index fund in your own retirement account.

THE CORE IDEA. The surveillance industry is not a faceless "them." It is a documented "who" — a finite, named, mappable set of companies with addresses, funders, and clients. The fog is the myth. The list is the reality, and the list has already been made.

What the thing actually is

Surveillance Watch describes itself as "an interactive map that documents the hidden connections within the opaque surveillance industry," built by privacy advocates "most of whom were personally harmed by surveillance tech." It is affiliated with DAIR, the Distributed AI Research Institute, and Bruce Schneier flagged it in one line as "a fantastic project mapping the global surveillance industry," which, from Schneier, is roughly a standing ovation. It is not a government product, not a think-tank white paper, and not a commercial risk-intelligence subscription that costs forty thousand dollars a seat. It is a public-interest database, and in 2025 it did something that changes what you can do with it: it opened a public, unauthenticated API. The catalog is no longer just a website you browse. It is a dataset you can pull, query, and cross-reference. The surveillance companies built their business on making you queryable. This is the same move, pointed the other way.

That inversion is the whole spirit of the project, and it is worth saying plainly before the numbers start. Every technique the surveillance industry sells — aggregate public records, map relationships, follow the money, attach a name to a pattern — works just as well when the target is the industry itself. Surveillance Watch is what it looks like when someone runs the playbook in reverse.

The industry has a shape, and the shape is legible

The first thing a list does is turn a vibe into a distribution. "Surveillance is everywhere" is a feeling. Seven hundred and eighty-four cataloged entities, sorted by what they do and where they sit, is a map.

By category, the modern surveillance business is overwhelmingly an artificial-intelligence business. Four hundred of the entities in the dataset carry an "AI-powered" tag, a hundred and fifty-five do facial recognition, a hundred and thirty-six sell spyware, and ninety-six do social-media monitoring. Further down the list are the more specialized trades: license-plate readers, IMSI catchers that impersonate cell towers, forensic-extraction kits that pull a phone apart, drone surveillance, student monitoring, data brokerage. Sixty-four separate entities are flagged with a plain, chilling tag: "used by ICE." The catalog assigns each entity a harm score from one to four, and the weighting is top-heavy — two hundred and ninety entities sit at the maximum. That score is the project's own editorial judgment rather than an objective metric, and it should be read that way, but the shape it draws is unambiguous: this is not a fringe of bad actors around a benign core. The center of mass is heavy.

By geography, the concentration is even starker, and it maps onto exactly the places you would guess if you were being honest. The United States is home to 237 of the cataloged entities, more than the next three countries combined. Israel is second at a hundred and nine, a remarkable figure for a country of nine million people and the clearest single sign that surveillance is one of its flagship export industries. China is third at seventy, then the United Kingdom, Russia, and India. The watchers are not scattered randomly across the globe. They cluster in a handful of states with the capital, engineering talent, and political appetite to build and sell it.

KEY TAKEAWAY. A named list converts a feeling into a distribution. "Surveillance is everywhere" becomes: it is mostly AI, it is disproportionately American and Israeli, and its center of mass is the high-harm tier, not the fringe. You cannot reason about a fog. You can reason about a distribution.

Follow the customers

A surveillance company is only as dangerous as its client list, and the catalogue tracks who these firms sell to. Read as customers, the numbers tell a second story that complicates any comfortable us-and-them framing.

The single largest buyer of cataloged surveillance capability is the United States, named as a customer of three hundred and ten of these entities. After that, the client list reads like a directory of governments not famous for restraint: the United Arab Emirates, the United Kingdom, Israel, India, China, and Saudi Arabia all appear as major customers, each buying from dozens to over a hundred of the firms in the set. This is the part that resists a clean morality tale. The same democracies that publish stern reports about authoritarian spyware are, by the catalog's accounting, among its most enthusiastic buyers. Surveillance is not something foreign regimes do to their people while ours look on. It is a global market, and the biggest customer in it is the government most of this article's readers live under.

The cap table is the story

Here is the part that should change how you feel, because it implicates you personally.

Follow the money behind these seven hundred and eighty-four companies, and you do not find a rogue's gallery of shadowy sovereign-wealth funds and cutout shell companies, though those exist too. You find, at the very top of the list, the most ordinary names in American finance. The single most common funder in the entire dataset is BlackRock, recorded as a backer of twenty-three cataloged surveillance entities. Second is Vanguard at nineteen. Third is State Street at thirteen. Those three names are not exotic. They are the "Big Three" index-fund managers, the passive giants that sit inside the 401(k), the IRA, and the target-date fund of essentially every American who has ever been auto-enrolled in a retirement plan. If you own a total-market index fund — and statistically, if you own anything, you do — then you are, in the most literal and unsexy sense, an investor in the surveillance industry. Not metaphorically. On the cap table.

The list does not stop being interesting after the index funds. Fourth, backing twelve entities, is In-Q-Tel — the venture-capital arm of the Central Intelligence Agency, whose entire purpose is to seed the technologies the intelligence community wants to exist. Then come the marquee names of Silicon Valley venture capital: Andreessen Horowitz, Founders Fund, Lightspeed, SoftBank, Intel Capital, Goldman Sachs, Qualcomm Ventures. The surveillance industry is not funded from the shadows. It is funded from the center — from the passive index that holds everyone's savings, from the CIA's own chartered fund, and from the country's most celebrated venture firms. The money is the least hidden thing about it.

To make that concrete, take Palantir, the data-integration company that helped build the NSA's global collection tooling (The Intercept) and then pushed into American policing (Wired). Its funders, as the catalog records them, include BlackRock and State Street — two of the Big Three by name. The abstraction is not abstract. The index fund does not hold the surveillance industry at six degrees of remove through some tangled derivative. In this case, it holds one of the most powerful surveillance contractors in the world directly, as a line item, the same way it holds Apple and Coca-Cola. Clearview AI, the face-recognition firm below, lists Peter Thiel among its backers; Flock Safety, the license-plate network, was valued at $7.5 billion in a 2025 round led by Andreessen Horowitz (Bloomberg). These are not obscure financiers. They are the names on the buildings.

KEY TAKEAWAY. The surveillance industry's investors are not shadow financiers. They are the three index funds in your retirement account, the CIA's own venture fund, and the top tier of Silicon Valley VC. "Faceless" was always the wrong word. The faces are the most familiar ones in American finance, and one of them is holding your money.

They have names, and the names are documented

The catalogue's real power is in the specificity, so it is worth naming names, because the individual entries are not rumors. They are the best-documented companies in the set, each carrying more citations than most journalists assemble in a career of covering them. A handful of examples, each with the kind of reporting the catalog attaches to every entry:

Cellebrite (Israel) is the most heavily sourced entity in the dataset, with twenty-seven citations. Its forensic-extraction hardware is what unlocks and downloads a seized phone, and it is used by roughly 2,800 US government agencies (9to5Mac). The same tool has been turned on the press: the Committee to Protect Journalists documented its use to search the phones of journalists in Nigeria and Botswana, and Cellebrite has asked police to keep the technology "hush hush" (TechCrunch).

Clearview AI (United States) scraped billions of images off the open web to build a face-search engine the New York Times said "might end privacy as we know it." By the BBC's account it has been used nearly a million times by US police, and European regulators have repeatedly ruled its database unlawful (EDRi).

Flock Safety (United States) is the license-plate-reader network quietly bolted to light poles in thousands of American towns — sometimes, as Quartz reported, installed without permission.

Paragon (Israel) is an American-funded spyware vendor built to hack encrypted apps like WhatsApp and Signal (Forbes), acquired by a US private-equity firm in 2024. Predator (Greece), the Intellexa-consortium tool, is the subject of the "Predator Files," Amnesty International's exposé of its targeting of civil society and officials — reporting that fed directly into US sanctions. Both occupy the same mercenary-spyware niche as NSO Group (Israel), whose Pegasus Citizen Lab traced to operations in 45 countries.

Hikvision (China), which MIT Technology Review called "the world's biggest surveillance company you've never heard of," sells the cameras that track Uyghurs in Xinjiang and equip "safe cities" for the juntas in Myanmar and beyond.

None of these is a mystery. Every one is a named company with a headquarters you could address an envelope to, a set of investors you could look up, and a body of reporting the catalog has already gathered in one place. The point of the list is that the mystery was never the problem. The diffusion was. These companies were always knowable one at a time; what didn't exist, until someone built it, was the map that holds them all at once.

Watch them back

This is where the project closes the loop with the two cases that came before it, and symmetry is why it belongs in the same series.

The Skripal officers were unmasked by public and purchasable records — passport files, car registries, leaked databases — assembled by journalists with no source inside the GRU. He and Wang were undone when the forensic trail they thought they had laundered turned out to be sitting in plain sight on a public ledger. Both cases are usually read as warnings: this is how the watched get caught. Surveillance Watch reads them as instructions. The exact method that exposes a spy—aggregate the open records, map the relationships, follow the money, attach names to the pattern—is a general-purpose tool, and nothing about it requires the target to be an individual. Turn it on the surveillance industry and you get a catalogue of the catalogers. The people whose entire business is making others legible discover that legibility is not a weapon that only points one way.

THE ONE-LINE LESSON. Attribution is a technique, not a hierarchy. The same open-source method that unmasks a GRU officer or traces a laundered bribe will map the surveillance industry itself — because the industry runs on public records too, and a company is far easier to document than a ghost.

That is the deeper meaning of opening the API. A website you can browse lets you look up one company. A dataset you can query lets you do to the industry what the industry does to you: find the patterns across all of it at once. Ask which investors recur. Ask which countries both host and buy. Ask which firms cluster around ICE, a single funder, or a single harm tier. The asymmetry that defines surveillance — they can see all of you, you can see none of them — is exactly the asymmetry a public, machine-readable map is built to erode.

What a list like this cannot do

Intellectual honesty requires the counterweight, because a tool oversold is a tool that gets you hurt, and this series has never pretended otherwise.

A catalog is a starting point, not a verdict. The harm scores are editorial. The funder and customer links are as good as the reporting behind them, and reporting on a secretive industry is incomplete by definition — absence from the list is not innocence, and the true set of surveillance vendors is certainly larger than seven hundred and eighty-four. Being named as an investor through an index fund is not the same as choosing to bankroll spyware; passive funds hold nearly everything, which is precisely why the finding is more unsettling than damning. And a map of who sells surveillance does nothing on its own to protect any individual from being surveilled. It changes what you know, not what is aimed at you. The list is a lens, and a lens only matters if you actually look through it and then do something about what you see.

What to actually do with this

After reading the first two pieces in this series, my instinct was to find better tools, and each time the warning was that better tools were never the point. This piece flips the instinct. The takeaway is not defensive at all. It is that the information asymmetry you have been told is permanent is, in at least one direction, already breaking — and you can push on the crack.

THE MINDSET SHIFT. Stop treating the surveillance apparatus as an unknowable fog you can only hide from, and start treating it as a documented industry you can look up, name, and account for. You cannot opt out of being watched by pretending the watchers are anonymous. You can, at minimum, stop letting them be.

A few concrete things follow directly from the case.

Look up the tools already in your life. The license-plate reader on your town's light pole, the camera brand over your office door, the vendor behind your building's access badges — these are not abstractions, and many of them are in the catalog with sources attached. Knowing the name of the system watching you is the first thing that makes it a political object rather than a fact of nature.

Check what your money is doing. If you hold a broad index fund, you are an investor in this industry, and while you cannot un-hold the whole market, you can at least know it, raise it, and stop being surprised by it. The people who profit from surveillance are counting on the fact that their capital and your savings are the same pool, and you will never look.

Use the map before you sign the contract. This one is for the practitioners in the audience, and it is the highest-leverage habit here: before a vendor touches your data, your building, or your clients, run the name. A public catalog of who sells surveillance and who funds them is exactly the due-diligence layer that a procurement process is supposed to have and almost never does.

And feed the thing that feeds you. A volunteer catalog survives on contributions — a missing entity, a fresh source, a corrected funder. The surveillance industry was a fog for so long not because it was truly invisible. It was that no one had done the unglamorous work of writing it all down in one place. Someone finally did. The least you can do with a map that good is help keep it accurate.

The comforting version of privacy says the watchers are too big and too shadowy to name, so stop worrying about them and just protect yourself. Surveillance Watch says something harder and more useful. They are not shadowy. They are a list — of companies, of countries, of investors, one of whom is holding your retirement savings — and the list is public, queryable, and growing. Being watched is not a fog you disappear into. It is a relationship, and for the first time you can see both ends of it. The first two lessons in this series were about how thoroughly you can be seen. This one is the turn: they can be seen too, and somebody already started writing it down.

Sources and further reading

Every claim in this piece traces to reporting the catalogue itself cites. Grouped below by what they most inform, these are a starting reading list for anyone who wants to move from "surveillance is everywhere" to knowing exactly who, where, and funded by whom.

On the project itself

Privacy — face, phone, and plate

Security — the mercenary-spyware market

Policy and accountability — money, power, and abuse


Surveillance Watch is a public, DAIR-affiliated project at surveillancewatch.io, with an open API at surveillancewatch.io/docs. Entity counts, funder tallies, and customer figures in this piece are drawn from a full pull of that API and reflect the catalog as it stood at the time of writing; the dataset is community-maintained and updates continuously. The linked reporting is independent journalism that the catalog cites; figures describe what the catalog records, not an independent audit of any named company.

Subscribe to SparkForge

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe