For many civil society organizations investigating spyware attacks against journalists, activists, and human rights defenders, the Mobile Verification Toolkit (MVT) and Android Quick Forensics (AndroidQF) have become essential tools. Developed and maintained by Amnesty International’s Security Lab alongside a community of contributors, these open-source tools have helped establish the field of consensual digital forensics.
Consensual digital forensics is the practice of investigating devices with the informed consent of their owners. It is a field of knowledge created by human rights defenders and technologists working in the civil society to respond to the growing threat of sophisticated spyware deployed against human rights defenders.
Today, we are pleased to share the results of an independent Mobile Verification Toolkit & Android Quick Forensics Secure Design Assessment conducted by 0xche as a contribution to the community that builds and sustains MVT and AndroidQF. The independent assessment provides a model for how security and usability analysis can reinforce each other and offer concrete improvement and enhancement opportunities to the tools.
We extend our sincere appreciation to 0xche, as well as to the many practitioners who contributed their expertise through interviews and community feedback.
An independent review of the MVT and AndroidQF workflow
Rather than examining each tool in isolation, 0xche assessed the real-world workflow used by practitioners when collecting data from a device with AndroidQF and analysing it with MVT, and combined three perspectives: secure design, code security, and usability. The assessment drew on a Consensual Digital Forensic Community Survey also led by 0xche.

The assessment concludes that MVT and AndroidQF provide significant value to the human rights community and remain the go-to open-source tools in this space, while identifying opportunities to improve security, strengthen evidence-handling, and enhance usability.
The assessment report is organised in four main sections:
- Secure Design Assessment, providing a threat model of the two-stage workflow (acquisition and analysis) and an architectural review against four core questions: untrusted input handling; forensic soundness; case isolation and network boundaries; and analytical clarity and actionability;
- Security Analysis, providing a code-level review of AQF and MVT to identify vulnerable code paths and concrete remediations;
- Heuristic Analysis, reviewing usability against ten heuristics, organized into three themes: fostering trust and transparency, optimizing critical cognition, and crafting the interaction framework;
- Appendix section with the summarized findings, the results of the Community Survey, and community operational security guidelines for consensual forensic practitioners.
Looking ahead
Independent scrutiny and community collaboration strengthen open-source tools. We welcome this assessment as an important contribution to the ongoing development of both MVT and AndroidQF. The Security Lab is analysing the recommendations provided and consulting with the community, and a detailed roadmap will be shared soon.
We are grateful to 0xche for the care and rigour they brought to this work, and to the wider community of practitioners whose feedback helped shape the assessment. The report provides a valuable pathway for future improvements and helps ensure that the tools used to investigate spyware abuses remain secure, transparent, and effective for the consensual digital forensics community.


