Cape: promising privacy carrier, but the most important audit is still missing

There are legitimate reasons for privacy advocates to scrutinize Cape. Founder John Doyle spent roughly nine years at Palantir, including years running its national-security business. Doyle has said his first check to start Cape came from Horowitz — whose firm was also an early backer of Flock Safety and its police-surveillance systems.

None of that proves Cape is a honeypot. But Cape’s own message is basically “don’t trust your carrier.” We should apply that to Cape too.

What we need is a law-abiding carrier that can comply with a lawful, targeted wiretap when required, but isn’t built as a surveillance tool and doesn’t retain vast amounts of location and communications metadata that can later be searched, sold, breached, or abused.

Cape has done some genuinely encouraging things.

Most importantly, Trail of Bits audited its call-detail-record retention claims. They reviewed relevant code/infrastructure, found that supposedly pseudonymous usage data could potentially be linked back to subscribers by an internal actor, and Cape changed its system and claims. That’s what a real audit looks like.

Cape also has SOC 2 Type II coverage touching important production systems and says it conducts third-party signaling-security testing.

But the audit I most want to see is still missing:

A full independent audit of Cape’s production mobile core and lawful-intercept infrastructure under a malicious-insider threat model.

That should examine:

· subscriber/IMSI mappings and rotation

· location/signaling metadata

· logs, analytics and backups

· admin access and production controls

· partner-carrier interfaces

· Cape’s CALEA/lawful-intercept system (which they control and operate!)

And answer one simple question:

Can Cape, an executive, an administrator, or another party secretly turn the network into a surveillance system or reconstruct subscriber activity outside the documented lawful process — without independent detection?

Even better would be cryptographic attestation proving that production is actually running the audited code.

Cape’s existing audits are a positive sign, especially the Trail of Bits work. But given its origins and its privacy claims, “trust us” shouldn’t be enough.

The company that tells us not to trust our carrier has an opportunity to become the first carrier that doesn’t require that trust!

2 Likes