Inside Belkasoft: U.S. digital evidence and offshore risks

Inside Belkasoft: U.S. digital evidence and offshore risks
Belkasoft digital evidence and forensic reliability

Belkasoft deserves careful examination because digital evidence tools can influence investigations, litigation and regulatory decisions. This analysis separates documented capabilities and corporate records from unproven concerns about their use.

Related Malta Media reporting is available in our investigations, legal analysis and gambling regulation sections. Technical and enforcement context is published by NIST, Europol and the US Department of Justice.

Belkasoft digital evidence analysis

Belkasoft should be assessed through validated methods, chain-of-custody safeguards and transparent disclosure of technical limitations.

Inside Belkasoft: How a Silicon Valley Apartment Handles U.S. Evidence Trails

Across the United States, local and federal agencies now rely on privately built tools to collect, decode and preserve digital evidence. What was once done internally by specialist laboratories is increasingly outsourced to software firms that promise speed and automation. The quality of that work matters: a misplaced log entry or an unread file can destroy a prosecution case.

When investigators purchase forensic software, they often focus on product capability and price. Less visible is the corporate structure behind the code and the question of who built it, where it was written and under which jurisdiction the evidence may ultimately pass.

A residential address in California

Several technology companies publicly present a Silicon Valley presence at 702 San Conrado Terrace, Unit 1, Sunnyvale, California. Property records describe the location as a private condominium, not a commercial facility.

It has no listed business-use permit, no signage and no record of laboratory certification. Yet marketing materials for one of those companies describe worldwide law-enforcement clientele including the US Department of Transportation and the DoD Cyber Crime Center.

That incongruity, between the corporate image of a global forensics supplier and a registration inside a two-bedroom apartment, illustrates a wider problem in the technology supply chain. When legal documents or procurement listings accept a “headquarters” at face value, basic due- diligence checks can fail.

Offshore development and data routes

Public professional profiles indicate that most of the engineering staff connected to this group are based in Tbilisi, Georgia. Georgia is an independent country that has made considerable progress toward data-protection alignment with the European Union, yet it remains outside the EU legal area. Data transfers from the United States or the EU to Georgian entities are therefore subject to standard contractual safeguards rather than automatic adequacy.

For law-enforcement evidence, that distinction is critical. Digital artefacts extracted from a suspect’s device may include privileged communications, medical information or biometric identifiers. If any part of the analysis pipeline touches a non-adequate jurisdiction without explicit authorisation and audit trails, chain-of-custody could be challenged in court.

What the US test laboratories found

In 2023 the Department of Homeland Security and the National Institute of Standards and Technology evaluated multiple commercial forensic tools, among them Belkasoft Evidence Center X v1.17.12873.

The published report noted several technical shortcomings: inconsistent handling of SQLite databases, incomplete display of deleted records and difficulty reading certain binary objects. These findings did not allege misconduct, yet they demonstrated how complex such tools are and why validation must be continual.

When forensic results underpin criminal charges, any unresolved software defect can jeopardise admissibility. Agencies therefore need clear statements from vendors about known limitations, test outcomes and patch status. Silence or marketing language is not enough.

The unanswered questions

In July 2025, we requested clarification from the companies associated with the Sunnyvale address. Their questions covered the legal basis for using a residential property, registration status within US states, storage locations of client data and GDPR or HIPAA compliance. They were also asked whether customers such as US government departments and major consultancies were informed that development work occurred in Georgia. No substantive response followed.

Non-reply does not prove wrongdoing, but it leaves procurement officials and end-users without the assurance they require. Transparency about jurisdiction, data storage and staffing is a minimal expectation when the product is used to handle criminal evidence.

The geography of risk

Georgia’s legal system is modernising rapidly yet still influenced by its post-Soviet administrative structure. The country cooperates closely with both Western and regional partners, including Russia in certain technical domains. Its data-protection authority lacks the scale of EU supervisory agencies and cross-border investigations often rely on mutual-assistance treaties rather than direct oversight.

For forensic work, these structural realities matter. If software compiled or maintained in Tbilisi accesses case data from a US police server, that action constitutes an international data transfer. Unless encryption, pseudonymisation and legal mechanisms are clearly documented, opposing counsel could argue that evidence integrity was compromised through exposure to a foreign jurisdiction.

The risk is systemic rather than political. It arises whenever law-enforcement evidence leaves a secure environment without a verifiable legal pathway, regardless of the country involved.

The investment network

Archived materials show that early funding for Belkasoft came from venture sources also connected to compliance-technology start-ups in Eastern Europe, including Flint Capital and early investors in identity-verification provider Sumsub.

The existence of overlapping capital pools is not unusual in the technology sector, yet it highlights how tightly linked digital-forensics and compliance software have become. When one investor portfolio spans both industries, oversight gaps can spread across multiple platforms.

Regulators have begun to notice. The European Data Protection Board has emphasised that due diligence must extend beyond contractual partners to all processors and sub-processors. In the forensic-software context, this means that a US agency purchasing through a reseller still bears responsibility for verifying where analysis and support functions occur.

Legal accountability and corporate opacity

Searches of US corporate registers show no active domestic incorporation under the names Belkasoft, MedM or Roxosoft. That absence complicates liability assessment. Without a US entity, civil or criminal proceedings would need to target a foreign defendant, raising costs and jurisdictional hurdles.

Even if no law is being broken, such opacity is incompatible with the expectations placed on contractors that handle evidential or personal data. Federal procurement rules typically require disclosure of beneficial ownership, physical operating addresses and compliance with export- control law. Any mismatch between representations in marketing materials and actual corporate form can expose contracting authorities to audit findings.

Wider implications for compliance officers

The Belkasoft case highlights a broader compliance dilemma: technology procurement often prioritises functionality over governance. Smaller agencies may lack resources to verify company registration, review server locations or demand external audits. Yet those steps are precisely what mitigate the risks now visible in this example.

Practical measures include:

  • requiring notarised corporate-registration evidence before contract award;
  • mandating third-party code-integrity verification for forensic software;
  • ensuring that data-processing agreements specify every country where code or data may reside;
  • and maintaining an internal register of approved vendors with jurisdictional These safeguards cost far less than defending a compromised prosecution.

Market perception and self-representation

Many forensic vendors present themselves as global leaders while employing fewer than fifty staff. Outsourcing is common, but marketing exaggeration becomes problematic when it obscures who actually handles sensitive data. Transparency statements and verifiable staff- location disclosures would reduce suspicion and align expectations.

The same logic applies to compliance technology more broadly. Whether the product is an anti- money-laundering engine or a forensic toolkit, credibility rests on demonstrable governance rather than slogans about trust and security.

From forensics to policy oversight

This story underscores why regulators and procurement offices must modernise their assessment criteria. Geographic diversification of technical labour is normal, yet oversight frameworks have not caught up. An agency may audit file-format accuracy but ignore whether the developer’s build environment meets US security standards. The result is a patchwork of compliance documentation that looks complete on paper but fails to address the real risks of cross-border data handling.

The remedy is not isolationism but evidence-based policy. Governments should cooperate with allies, invest in transparent certification schemes and require that foreign vendors disclose the jurisdictions involved in every stage of evidence processing.

Our Final Thoughts and Conclusion

Digital-forensics software forms the backbone of modern criminal investigation. When the companies supplying it operate through residential addresses or offshore teams, transparency becomes a matter of public interest. The Belkasoft example, drawn from open records and verified professional data, shows how easily a vendor can appear local while functioning abroad.

Nothing in the available information proves unlawful behaviour, yet the structural weaknesses are undeniable. Absence of clear corporate registration, reliance on offshore development and lack of communication with the press all combine to erode confidence in the integrity of the evidence chain. The technical issues noted by US test laboratories further underline the need for continuous validation and independent oversight.

For agencies and corporate buyers, the lesson is straightforward. Demand clarity about where data is processed, who holds ultimate responsibility and which legal system governs the relationship. Require full documentation, not marketing assurances. Treat every transfer of evidential data across borders as a legal act requiring explicit authorisation.

Until transparency becomes the default expectation, the risk remains that digital evidence will traverse invisible routes and leaving investigators, defendants and the justice system exposed to questions that no software licence can answer.

FAQs

What is Belkasoft and what does it do?
Belkasoft is a software company providing digital-forensics tools used by law enforcement and private investigators to collect and analyze digital evidence.

Why is Belkasoft’s U.S. address significant?
Its listed address in Sunnyvale, California is a residential apartment, not a certified lab or commercial facility, raising concerns about transparency and due diligence.

Where is Belkasoft’s main engineering team located?
Most engineering and software development linked to Belkasoft occurs in Tbilisi, Georgia, outside the European Union’s legal and data-protection area.

What risks arise from offshore software development for U.S. evidence?
Offshore development can create legal challenges regarding data transfers, privacy compliance, and evidence admissibility in U.S. courts.

What did U.S. test laboratories find about Belkasoft’s tools?
The Department of Homeland Security and NIST found technical flaws such as incomplete record display and inconsistent database handling, emphasizing the need for continual validation.

Is Belkasoft officially registered as a U.S. company?
No active domestic incorporation for Belkasoft or related names was found in U.S. corporate registries, complicating legal accountability and liability tracing.

Does offshore data processing violate U.S. evidence rules?
Not automatically, but any unapproved or undocumented transfer of criminal evidence outside secure jurisdictions could undermine chain-of-custody in court.

Why is transparency vital in digital-forensics software?
Transparency ensures agencies know where data is processed, who accesses it, and under which laws—protecting both investigators and defendants from compromised evidence.

How can agencies safeguard against these risks?
They should verify corporate registration, demand jurisdictional disclosure, use third-party code audits, and confirm compliance with GDPR, HIPAA, or equivalent standards.

What does the Belkasoft case reveal about the wider industry?
It highlights systemic opacity in forensic and compliance software, showing how lack of oversight and unclear corporate structures threaten data integrity and public trust.

Share

Michael Schmitt is the founder of TRIDER.UK and Editor of Malta Media. He writes about iGaming, gambling regulation, corporate structures, financial services and market integrity, combining investigative journalism with nearly three decades of experience in corporate services and international business.