Request ID: a6c46d6c-b295-45b7-97f8-e9eb22834418
Audit phase: Digital
Evidence cut-off: 8 October 2026
Target: CGI Inc. (cgi.com), the Canadian global IT and business consulting/services group.
Target identity, group boundary and control
CGI Inc. is a Québec-incorporated Canadian issuer whose predecessor business was founded in 1976; its 2025 Annual Information Form identifies CGI Federal Inc. and CGI IT UK Limited among its principal wholly owned subsidiaries.1 The principal-subsidiary table explicitly omits smaller subsidiaries below stated materiality thresholds, so it cannot be used to prove that no smaller Israeli legal entity exists.1
Tim Hurlebaus has been CGI President and Chief Executive Officer and a board member since May 2026; before that appointment he had led CGI Federal and CGI’s U.S., UK and Australian operations.2 The December 2025 proxy identified founder Serge Godin as the only person holding more than 10% of the voting securities and stated that CGI and its related subsidiaries were controlled by him; at that date he held all Class B shares and approximately 55.62% of aggregate voting rights.3 The same proxy identified Julie Godin as Executive Chair at that time.3
[pre-2020] CGI completed its acquisition of Logica plc on 20 August 2012.4 UK Companies House records that today’s CGI IT UK LIMITED previously traded as LOGICA UK LIMITED and LOGICACMG UK LIMITED, which supports post-acquisition lineage while avoiding attribution of pre-acquisition Logica acts to CGI without date-specific evidence.5
A separate Israeli company using the name CGI Group at cgi.co.il states that it was founded in 1989 and is led by founder/CEO Zvika Nave.6 No corporate link to CGI Inc. was identified in the reviewed primary materials; none of that Israeli namesake’s intelligence, security, political, personnel or customer activity is attributed to CGI Inc. in this audit.1, 6
Enterprise Technology Stack & Vendor Relationships
Israeli-origin software and services
CyberArk - verified delivery/partner relationship, not verified internal dependency. In February 2024 CyberArk named CGI its Global Managed Service Protection Partner of the Year for 2023 and also listed CGI among Canadian award recipients; CyberArk said its partner programme supports customer adoption of the CyberArk Identity Security Platform.7 CyberArk’s 2023 Form 20-F identifies CyberArk Software Ltd. as an Israeli company with its principal executive offices in Petach Tikva, Israel.8 This establishes a customer-facing managed-service/partner relationship. It does not establish that CGI itself licenses CyberArk as a core internal security platform across the enterprise.7, 8
NICE - verified partner listing, product scope not public. NICE’s current business-partner directory lists CGI.9 The directory does not identify a specific CGI internal deployment, licence volume, client, contract value, or criticality, so no broader dependency is inferred.9
Verint - verified integration role for a UK public-sector client. Verint’s City of Edinburgh Council case study says the Council selected Verint Engagement Management Professional and that CGI was the integration partner, with the solution deployed in six months.10 Verint’s 2025 Form 10-K says its R&D is performed in several countries including Israel, and describes significant Israeli R&D/support operations; it also records the February 2021 spin-off of Cognyte as an independent company.11 The Edinburgh evidence concerns customer-engagement software and does not establish CGI use of former Verint intelligence/cyber products.10, 11
Panaya - historical relationship. [pre-2020] On 14 May 2012 CGI announced a global Panaya Practice for SAP engagements and said it had already used Panaya’s cloud-based tools for three years.12 Panaya’s current company page identifies its headquarters in Hod HaSharon, Israel and notes its 2015 acquisition by Infosys.13 The evidence establishes a historical CGI service-delivery relationship; no public evidence identified that this relationship remains current in 2026.12, 13
Palo Alto Networks - verified Australian education partnership only. CGI Australia documents a partnership with Palo Alto Networks and South Australia’s Department for Education around a “Cyber Escape Experience” for students.14 This is evidence of a cybersecurity-education partnership, not of CGI internal procurement, CGI-wide infrastructure dependency, an Israeli customer, or Israeli-state technology provision.14
Focused searches were also conducted for Check Point, Wiz, SentinelOne and Claroty and for internal CGI licensing of CyberArk, NICE, Verint and Palo Alto Networks. No public evidence identified of a CGI-wide internal licence/subscription or critical-infrastructure dependency on those named vendors in the reviewed public materials.1, 7, 9
Scale of dependency
The public records support customer-facing integration, managed-service, partner and historical SAP-practice relationships, but do not quantify a CGI enterprise-wide dependency on Israeli-origin technology.7, 9, 10, 12 The strongest documented operational integration found is instead a third-party client deployment: Glasgow City Council’s CCTV/PSIM chain, discussed below.15, 16
Procurement and integrator relationships
CGI itself acts as an integrator and managed-service provider in several of the verified records.7, 10, 15 Beyond the Glasgow Qognify chain, no public evidence identified that another systems integrator mandated or deployed an Israeli-origin vendor into CGI’s own core infrastructure.1, 15
Surveillance, Biometrics & Retail Technology
Glasgow public-space CCTV: Qognify / NICE lineage through CGI
[pre-2020] CGI announced in December 2017 that Glasgow City Council had awarded it a seven-year transformational ICT outsourcing contract.17 A Glasgow City Council internal audit dated 25 January 2023 provides the strongest technical description of the public-space CCTV arrangement: the Council’s PSIM used Situator and NiceVision as its two primary applications; both were developed and managed by Qognify, which the audit said was “contractually managed” by the Council’s IT partner CGI.15 The same audit recorded 429 fixed public-space cameras, 98 traffic cameras and eight redeployable cameras and stated that PSCCTV images could be shared with other Council services, Police Scotland and occasionally HMRC and DWP.15
A Scottish Information Commissioner decision issued in April 2025 independently records Glasgow City Council’s evidence that the Council’s previous ICT provider had a Qognify contract for elements of CCTV-control software, that this contract was novated to CGI at the start of the CGI contract, and that CGI was contractually responsible for obtaining and maintaining licences necessary to provide its ICT services.16 The Commissioner upheld the Council’s position that it did not hold the requested software-renewal dates and that the relevant information was not held by CGI on the Council’s behalf for FOISA purposes.16
The corporate lineage is material. [pre-2020] NICE Systems announced in 2015 that it would sell its Physical Security business, which included video-surveillance technology, to Battery Ventures.18 Hexagon states that it completed its acquisition of Qognify in April 2023 and rebranded Qognify as part of Hexagon’s physical-security business in 2024.19 Accordingly, the Glasgow applications have a NICE/Qognify lineage, but Qognify should not be treated as a currently independent Israeli company after the Hexagon acquisition without that ownership qualification.18, 19
Facial recognition and biometrics
The 2023 Council audit establishes video surveillance and PSIM use but does not identify facial-recognition, gait-analysis or biometric-identification deployment.15 A Glasgow campaign page reproducing 2024 Council FOI responses states that Person/People Search was not then in operation, had no planned activation timetable, and was installed on no cameras; the same reproduced response said operational use would require a DPIA and likely prior consultation with the ICO.20 Because that material is reproduced on a campaign site rather than an independently published Council decision, it is treated as secondary evidence. No public evidence identified that CGI operated Israeli-origin facial recognition or biometric identification for Glasgow or another reviewed client as of the cut-off.15, 20
Predictive analytics and monitoring
No public evidence identified that CGI deployed Israeli-origin predictive-policing, sentiment-analysis, social-media-monitoring or workforce-surveillance tools in the reviewed target-specific records.1, 15
Third-party deployment
There is verified indirect deployment of NICE/Qognify-origin physical-security software through CGI’s managed-service role for Glasgow: CGI contractually managed Qognify and bore licence responsibility under the outsourced ICT contract.15, 16 This is a client deployment, not evidence that CGI itself was the developer of NiceVision or Situator.15, 18
Data-exposure principle
The Glasgow internal audit identifies the Council’s UK public-sector sharing recipients and describes information-security controls, but it does not state that CCTV data is stored, routed, processed, backed up or remotely accessed in Israel.15 Qognify/NICE’s Israeli lineage therefore does not by itself establish exposure of Glasgow data to Israeli jurisdiction. No public evidence identified that this Glasgow data pipeline touched Israeli-hosted infrastructure or that Israeli authorities had legal or technical access to it.15, 19
Cloud Infrastructure, Data Residency & Sovereign Cloud Participation
CGI markets cloud-agnostic migration, hybrid/multicloud, managed-cloud and security services across major cloud ecosystems.21 Those general alliances cannot establish participation in Israel’s Project Nimbus without a target-specific contract or programme record.21
The 2025 AIF’s list of principal subsidiaries and its main office/delivery-centre disclosures do not identify Israel as a principal subsidiary jurisdiction or main operating location, while also making clear that the subsidiary list omits smaller entities.1 no public evidence identified in the reviewed sources that CGI Inc. operates, leases or co-locates a data centre in Israel.1, 21
Project Nimbus / Israeli government cloud: no public evidence identified of CGI Inc. as a Project Nimbus prime, subcontractor, reseller or systems integrator for an Israeli state agency.21, 22 Generic CGI relationships with hyperscalers are not treated as evidence of Nimbus participation.21
Data sovereignty and resilience for Israeli state bodies: no public evidence identified of CGI providing an Israeli ministry, military or security body with a sovereign-cloud, data-residency or resilience service.1, 21
Data residency / legal access: No reviewed public source establishes that CGI customer data is routinely stored or processed in Israel because CGI integrates software from Israeli-origin vendors.1, 15, 21 The verified Glasgow record identifies UK-side operational sharing but not Israeli data routing.15
Defence, Intelligence & Security Sector Technology Relationships
CGI Federal is a wholly owned U.S. subsidiary; CGI’s current federal page describes work for U.S. civilian, defence, intelligence and national-security customers, and Tim Hurlebaus’s biography records his earlier leadership of that business.1, 2, 23 This establishes substantial U.S. defence/intelligence activity but does not establish an Israeli customer or Israeli military outcome.23
Israeli military/intelligence contracts: no public evidence identified in the reviewed target-specific records of a CGI Inc., CGI Federal or CGI IT UK contract with the Israeli Ministry of Defense, Israel Defense Forces, Mossad or Shin Bet.1, 23
Dual-use technology provision in Israel or the occupied territories: no public evidence identified that a CGI commercial platform or service was deployed by Israeli military, intelligence or law-enforcement bodies in Israel or the occupied Palestinian territory.23, 22 The Glasgow CCTV engagement is a UK municipal civilian-surveillance deployment and is not evidence of Israeli state use.15
Offensive cyber / digital weapons: no public evidence identified that CGI developed, sold, licensed or maintained zero-day exploit tooling or offensive-cyber weapons for Israeli state actors.1, 23
Purpose-built autonomous targeting, fire-control, kill-chain automation or systems whose primary designed output is kinetic targeting would fall in Military rather than this Digital audit. No target-specific Israeli provision of such a system was identified during this Digital review.23
AI, Algorithmic & Autonomous Systems
CGI provides AI and digital-transformation services generally, including through its U.S. federal practice, but the reviewed sources do not connect that capability to an Israeli state, military or security customer.23
AI/ML provision to Israeli state bodies: no public evidence identified of CGI providing AI, machine learning, computer vision or autonomous decision-support systems to an Israeli state, military or security body.23, 22
Training data and model development: no public evidence identified that a CGI AI model was trained on or given access to civilian population data, intercepted communications or surveillance-derived datasets from Israel or the occupied Palestinian territory.23, 22
Autonomous systems and lethality: no public evidence identified of CGI providing autonomous target generation, automated threat detection for kinetic targeting, or autonomous tracking systems to Israeli military/security forces.23 Any verified purpose-built kinetic-targeting system would be separated into Military under the domain boundary.
Technology Ecosystem & R&D Footprint
Israeli R&D centres and engineering offices
The 2025 AIF lists CGI’s main offices and delivery centres across multiple regions but does not list an Israeli main office or delivery centre; because the filing’s subsidiary disclosure has materiality limits, this is not treated as proof that no small legal presence could exist.1 no public evidence identified of a CGI-operated Israeli R&D centre, engineering office, innovation lab or accelerator programme in the sources reviewed.1
Acquisitions and investments
[pre-2020] CGI acquired Logica in 2012, but the reviewed corporate records do not identify that transaction as an Israeli technology acquisition.4, 5 Panaya is not a CGI acquisition: CGI announced a Panaya service practice in 2012, while Panaya states that Infosys acquired it in 2015.12, 13
No public evidence identified of CGI acquiring an Israeli-origin surveillance/cyber/AI company or taking a disclosed strategic stake in an Israeli technology startup or venture fund in the reviewed records.1, 3 Likewise, focused searches did not identify a public Serge Godin, Julie Godin or Tim Hurlebaus personal/family-office stake in the named Israeli surveillance, cyber, AI, SIGINT or military-tech companies; public-source absence cannot exclude undisclosed private holdings.3, 2
Patent and intellectual-property relationships
CGI’s AIF describes proprietary solutions and alliance-based delivery, but no public evidence identified in the reviewed material of a significant CGI patent-licensing or co-development arrangement with Technion, Hebrew University, Weizmann Institute or another Israeli research institution.1
Civil Society Scrutiny & Regulatory History
UN and specialist-source screening
OHCHR’s 2024 A/HRC/57/21 is a progress report on the UN database of enterprises involved in specified settlement-related activities and explains the continuing update methodology.24 Targeted exact-name screening of the reviewed published material did not produce a CGI Inc. match; this is reported as no public evidence identified, not as proof that CGI can never appear in an unpublished or future update.24
A/HRC/59/23, the 2025 Special Rapporteur report addressing corporate involvement in the occupied Palestinian territory, was also screened for the target.22 No CGI Inc.-specific naming was identified in the reviewed report material. Its discussion of cloud, AI, surveillance and other technology companies is therefore treated as background context and not as evidence of CGI involvement.22
Focused searches of Who Profits, AFSC Investigate, Amnesty, Human Rights Watch, B’Tselem and related specialist sources did not yield a target-specific CGI Inc. technology relationship with Israeli state/military bodies or settlements that could be independently verified in this audit. No public evidence identified for such a target-specific listing in the reviewed material.24, 22
Glasgow civil-society campaign
The Gaza Genocide Emergency Committee publicly campaigned over Glasgow City Council’s CGI/Qognify surveillance chain and reproduced multiple Council FOI responses.20 The campaign’s core proposition that Glasgow’s CCTV software chain involved CGI and Qognify is independently corroborated by the Council’s own 2023 audit and the Scottish Information Commissioner.15, 16 Its stronger characterisation of Qognify as “military-grade” and its claims about Israeli military/intelligence significance are not adopted as verified CGI-specific findings here because the primary Glasgow records establish the software/contract chain, not Israeli military use.15, 16, 20
No broader organised boycott/divestment campaign specifically targeting CGI Inc. for Israeli technology provision was identified in the reviewed evidence, and no CGI corporate response to the Glasgow campaign was located. No public evidence identified beyond the local Glasgow campaign.20
Regulatory and legal actions
The Scottish Information Commissioner’s 2025 decision is a legal/FOI proceeding concerning renewal dates for Glasgow surveillance-software licences; it concluded that Glasgow City Council did not hold the requested information and had complied with FOISA.16 It did not impose a technology-sales sanction on CGI.16
No public evidence identified of an export-control enforcement action, sanctions investigation or court finding against CGI for technology sales to Israeli state entities in the sources reviewed.1, 23
Texas anti-boycott-Israel procurement terms
A distinct U.S. procurement-law nexus exists. Texas DIR contract DIR-CPO-4653 with CGI Technologies and Solutions Inc. ran from 27 October 2020 to 31 August 2024.25 The associated standard contract terms state that the successful respondent, by signature, certified that it did not boycott Israel and would not boycott Israel during the contract term.26 This is evidence of compliance with a Texas public-procurement condition; it is not evidence that CGI provided technology to Israel or endorsed a particular Israeli state policy.25, 26
Texas DIR lists DIR-CPO-6079 with CGI Technologies and Solutions Inc. as an active contract beginning 30 October 2025.27 The associated solicitation/contract terms provide a disjunctive certification: the successful respondent certifies either that it is exempt from the relevant Texas anti-boycott provision or that it does not and will not boycott Israel during the contract term.28 The public clause alone does not establish which branch CGI relied on, so no stronger political inference is made.27, 28
Constructive-notice timeline
Glasgow City Council’s 2026 business plan states that CGI delivered the Council’s ICT/transformation services from 1 April 2018 through 31 March 2025, and that a CGI contract extension was negotiated and agreed in 2024 and commenced on 1 April 2025.29 CGI’s general Glasgow ICT relationship therefore continued after 19 July 2024 and after November 2024.29 However, the same public record does not establish that the Qognify/NICE subcontract itself continued after 1 April 2025.29
The 2024 Council FOI material reproduced by the Glasgow campaign said the then-current multi-source strategy assumed retention of NICE Vision, NICE Situator and People Search, while also saying future retention was not finally determined and that the Qognify contract was between CGI and Qognify.20 This is evidence of contemplated continuation during 2024, not definitive proof of post-April-2025 Qognify service delivery.20
The current Texas DIR CGI contract began in October 2025 and therefore post-dates both notice points, but its Israel nexus is the Texas procurement certification clause described above, not technology provision to the Israeli state or occupied territories.27, 28
No public evidence identified of verified CGI technology provision to an Israeli state/military customer or settlement that continued after either notice date.23, 24, 22
Footnotes
-
U.S. Securities and Exchange Commission, CGI Inc. 2025 Annual Information Form. https://www.sec.gov/Archives/edgar/data/1061574/000119312525322911/d88305dex991.htm ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18
-
CGI, Tim Hurlebaus. https://www.cgi.com/en/about-us/leadership/tim-hurlebaus ↩ ↩2 ↩3
-
U.S. Securities and Exchange Commission, CGI Inc. 2025 Management Proxy Circular. https://www.sec.gov/Archives/edgar/data/1061574/000119312525322919/d269737dex992.htm ↩ ↩2 ↩3 ↩4
-
CGI, CGI completes Logica acquisition. https://www.cgi.com/en/CGI-completes-Logica-acquisition-new-leadership-team ↩ ↩2
-
UK Companies House, CGI IT UK LIMITED company overview. https://find-and-update.company-information.service.gov.uk/company/00947968 ↩ ↩2
-
CGI Group (cgi.co.il), About CGI Group (Israel). https://cgi.co.il/About-en.html ↩ ↩2
-
Nasdaq / CyberArk, CyberArk Announces 2023 Global Partner of the Year Award Winners. https://www.nasdaq.com/press-release/cyberark-announces-2023-global-partner-of-the-year-award-winners-2024-02-13 ↩ ↩2 ↩3 ↩4 ↩5
-
U.S. Securities and Exchange Commission, CyberArk Software Ltd. 2023 Form 20-F. https://www.sec.gov/Archives/edgar/data/1598110/000117891324000937/zk2431095.htm ↩ ↩2
-
NiCE, Find a Business Partner. https://www.nice.com/partners/partner-search ↩ ↩2 ↩3 ↩4
-
Verint, City of Edinburgh Council case study. https://www.verint.com/de/case-studies/the-city-of-edinburgh-council-increases-customer-satisfaction-from-70-to-85-with-verint/ ↩ ↩2 ↩3 ↩4
-
U.S. Securities and Exchange Commission, Verint Systems Inc. 2025 Form 10-K. https://www.sec.gov/Archives/edgar/data/1166388/000116638825000014/vrnt-20250131.htm ↩ ↩2
-
CGI, CGI deepens its SAP expertise by launching its Panaya Practice. https://www.cgi.com/en/cgi-sap-expertise-panaya-practice ↩ ↩2 ↩3 ↩4
-
Panaya, Learn About Panaya. https://www.panaya.com/company/ ↩ ↩2 ↩3
-
CGI Australia, Enhancing cyber security education in South Australia. https://www.cgi.com/au/en-au/article/cybersecurity/enhancing-cyber-security-education-south-australia ↩ ↩2
-
Glasgow City Council, NRS – Public Space CCTV Information Management. https://onlineservices.glasgow.gov.uk/CouncillorsandCommittees/viewSelectedDocument.asp?c=P62AFQDNZ3DNUTNTNT ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17
-
Scottish Information Commissioner, Decision 095/2025: Renewal dates for software licences. https://www.foi.scot/decision-0952025 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
CGI UK, Glasgow City Council awards seven-year transformational ICT outsourcing contract to CGI. https://www.cgi.com/uk/en-gb/news/glasgow-city-council-awards-seven-year-transformational-ict-outsourcing-contract-to-cgi ↩
-
U.S. Securities and Exchange Commission / NICE Systems, NICE Systems agrees sale of Physical Security business unit. https://www.sec.gov/Archives/edgar/data/1003935/000117891315002425/exhibit_99-1.htm ↩ ↩2 ↩3
-
Hexagon, Hexagon rebrands Qognify. https://hexagon.com/company/newsroom/press-releases/2024/hexagon-rebrands-qognify-reaffirming-commitment-to-physical-security ↩ ↩2 ↩3
-
Gaza Genocide Emergency Committee, Update on Glasgow City Council contractual relations with Qognify/CGI. https://ggec.org.uk/update-on-glasgow-city-councils-contractual-relations-with-military-grade-israeli-company-operating-city-centre-surveillance-system/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
CGI, Cloud services. https://www.cgi.com/en/cloud ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
United Nations / Special Rapporteur, A/HRC/59/23 - From economy of occupation to economy of genocide. https://www.un.org/unispal/document/a-hrc-59-23-from-economy-of-occupation-to-economy-of-genocide-report-special-rapporteur-francesca-albanese-palestine-2025/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
CGI United States, CGI Federal. https://www.cgi.com/us/en-us/federal ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12
-
United Nations / OHCHR, OHCHR Progress Report on Database of Businesses involved in Activities Related to Settlements (A/HRC/57/21). https://www.un.org/unispal/document/ohchr-report-02aug24/ ↩ ↩2 ↩3 ↩4
-
Texas Department of Information Resources, DIR-CPO-4653. https://dir.texas.gov/contracts/dir-cpo-4653 ↩ ↩2
-
CGI / Texas DIR, DIR-CPO-4653 Appendix A - Standard Contract Terms and Conditions. https://www.cgi.com/sites/default/files/2022-06/dir-cpo-4653-appendix-a_standard-contract-terms-and-conditions.pdf ↩ ↩2
-
Texas Department of Information Resources, DIR-CPO-6079. https://dir.texas.gov/contracts/dir-cpo-6079 ↩ ↩2 ↩3
-
CGI / Texas DIR, DIR-CPO-6079 RFO / contract solicitation terms. https://www.cgi.com/sites/default/files/2026-03/dir-cpo-6079_rfo_dir-cpo-tmp-593.pdf ↩ ↩2 ↩3
-
Glasgow City Council, Annual Business Plan 2026/27 for Chief Executive Department. https://onlineservices.glasgow.gov.uk/councillorsandcommittees/viewSelectedDocument.asp?c=P62AFQDNUT2U81T1DN ↩ ↩2 ↩3