Loadout mark

Loadout

Air-gapped Forensic Training Toolkit

Openly-synthetic forensic-training data, built for the Program-of-Record tools your lab fields.

Author openly-synthetic investigations, provision text messages, call logs, contacts, photos, and video to lab-owned training devices, and remove them cleanly between exercises. Fully offline, backed by a documented ground-truth manifest, with read-back confirming the data is cleared.

Request a capability briefing

byAccelera Solutions

Loadout Control Station: device connection and provisioning screen

The problem

Forensic training lacks realistic scenario data

Real DOMEX targets are not a single phone. They are a network of devices that talk to each other, and the mission is to follow those links. Training rarely reflects that. Trainees practice on flat surrogates that do not look or behave like a seized network, so the hardest part of the job, the link analysis, never gets rehearsed.

Without Loadout

Instructors have no reliable way to place a coherent, connected set of artifacts across several devices ahead of a practical exercise. Trainees extract phones that do not relate to each other, and the network the mission depends on is simply not there.

With Loadout

Loadout places openly-synthetic scenario data onto lab-owned training devices, so trainees practice against lifelike artifacts. Every persona is backed by a documented ground-truth manifest the instructor controls.

Capability

Openly-synthetic scenario data for forensic training

Author openly-synthetic investigations, provision text messages, call logs, contacts, photos, and video to lab-owned training devices, and remove them cleanly between exercises. Fully offline, backed by a documented ground-truth manifest, with read-back confirming the data is cleared.

Android · available now

ArtifactOn-device storeRootedUnrooted
ContactsContacts + sync accountSupported(ADB)Supported(on-device app)
Call logsCall Log providerSupported(ADB)Supported(on-device app)
PhotosMediaStore (images)Supported(ADB)Supported(on-device app)
VideoMediaStore (video)Supported(ADB)Supported(on-device app)
Text messages (SMS)Telephony (SMS)Supported(ADB)Supported(on-device app)
Picture messages (MMS)Telephony (MMS + parts)Supported(ADB)Supported(on-device app)

On unrooted, lab-owned devices, all six artifact types are written by the on-device companion app to the same on-device stores a Program-of-Record extraction parses: the app is required for text and picture messages (ADB cannot write them without root) and gives contacts, call logs, and photos a single, version-stable path across Android 10 through 16. Video, newly added on the same MediaStore path, is validated on Android 10, 13, and 15 and is being extended across the matrix. Picture-message (MMS) attachments are validated on emulators across that range, with byte-exact image fidelity being confirmed on real hardware. iOS and additional artifact types are on the roadmap.

Artifact types
6Artifact typesContacts, calls, SMS, MMS, photos, video
Android versions
7Android versionsValidated 10 through 16
Step lifecycle
4Step lifecycleAuthor, provision, verify, remove
Injection paths
2Injection pathsRoot and non-root, lab-owned devices
Residual artifacts
0Residual artifactsClean teardown, verified by read-back
CI re-verification
WeeklyCI re-verificationFive core types re-verified weekly

Persona Studio

Persona-driven scenarios

Every Loadout scenario is persona-driven. Each persona is configured for region, geofence radius, characteristics, and behaviors, so the artifacts on the device tell a coherent story.

Configure

Set a persona's region, geofence radius, timeframe, characteristics, and behaviors.

Author

Add your own media, contacts, text and picture messages, and call logs.

Generate

Generate coherent activity using on-premise, US-origin open-weight models (Llama 3.1, IBM Granite). Airgap-friendly, no external calls. Optional: Loadout runs fully without a model.

Localize

Author region-aware personas with localized place and time metadata. Multi-language authoring is on the roadmap.

Loadout Persona Studio: authoring a region-aware persona

Generation runs on-premise with US-origin open-weight models

  • OllamaOllama
  • Llama 3.1Llama 3.1

Your local runtime (Ollama, vLLM, or LM Studio) with a US-origin model such as Llama 3.1 or IBM Granite. AI authoring is optional: Loadout runs fully without a model. Prefer a managed path? An AWS Bedrock option is supported for GovCloud.

Trademarks are the property of their respective owners.

Multi-device scenarios

One scenario, the whole network

Loadout composes a single investigative scenario across multiple training devices. Define how personas relate, who supplies whom, who answers to whom, and Loadout projects that network into correlated artifacts on each device, so trainees follow the links from the edges of the network to its center.

Investigative scenario: three personas on seized devices linking through cut-outs to a single kingpin A link-analysis network diagram. Three personas on seized training devices at the bottom (a courier, a dealer, and a runner) connect through two intermediary cut-outs to one central target at the top, the kingpin. Their activity flows upward along the links toward the target.CourierDealerRunnerCut-outCut-outKingpin

Compose

Bind multiple personas across multiple training devices into one investigative scenario.

Correlate

A message one persona sends appears coherently on the other's phone. Calls and contacts match on both ends, so the network holds together across devices.

Investigate

Author a deliberate network, from peripheral figures through cut-outs to a central target, that an analyst reconstructs from on-device artifacts with their Program of Record tools.

Verify

Every linkage is checked end to end with no dead ends, so the scenario is always solvable exactly as authored.

Remove

Tear the whole multi-device scenario down cleanly between exercises, leaving no residual files.

100% on-premiseUS-origin open-weight models inside your network. Nothing leaves the enclave.

Describe the mission. Loadout drafts the network.

Write the scenario in plain language. Loadout's local model proposes the cast, their relationships, and a first network. Rearrange any node to shape the investigation, then Loadout generates the correlated artifacts for every device.

Scenario brief

Three street-level couriers move product through two cut-outs up to a single supplier. The supplier never texts the couriers directly. Build a week of contacts, calls, and messages that lead an analyst from the couriers to the supplier.

Investigative scenario: three personas on seized devices linking through cut-outs to a single kingpin A link-analysis network diagram. Three personas on seized training devices at the bottom (a courier, a dealer, and a runner) connect through two intermediary cut-outs to one central target at the top, the kingpin. Their activity flows upward along the links toward the target.CourierDealerRunnerCut-outCut-outKingpin

Drag to rearrange. Refine the model's first pass before you provision.

Scenario editor

v1

Author the whole network on one canvas

Shape the investigative network visually: drag personas, wire how they relate, mark the objective, and confirm every path is solvable with no dead-ends before you provision. The scenario editor lives in the Loadout Control Station, with the same airgapped, on-premise authoring as Persona Studio.

The Loadout scenario editor in the Control Station: a graph canvas of personas on seized devices linking through a courier and a launderer to a single kingpin (the objective), with the on-premise AI authoring panel, a node inspector, and a green Scenario-Gate PASS verdict.

Screenshots

Loadout in operation

Persona authoring

Loadout Dashboard: persona authoring screen showing archetype selection, region configuration, and generate controls123
  1. 1Pick an archetype
  2. 2Set the region and timeframe
  3. 3Generate the persona

Connect

Loadout Dashboard: device connect screen

Device connection and status

Author

Loadout Dashboard: persona authoring screen

Persona authoring and configuration

Batch

Loadout Dashboard: batch provisioning screen

Batch provisioning across devices

Read-back verification

Loadout read-back verification results, all records passed

Gate A read-back verification results

Control Station

One operator console, seven surfaces

The desktop Control Station drives the whole workflow: author a persona or a multi-device scenario, provision one device or a fleet, verify the read-back, and remove it cleanly. Every surface runs on the operator workstation, offline.

  • Provision

    Connect a device, pick the injection path (root or non-root), write a persona, and confirm every field with a read-back check.

  • Batch

    Provision many lab devices in parallel from one console, with a per-device pass or fail grid.

  • Author

    Build persona packages: contacts, text and picture messages, call logs, and media, with optional on-premise AI generation.

  • Scenario

    See a multi-device investigation as a network and timeline, with a Scenario Gate that checks the story is solvable and dead-end-free.

  • Editor

    A structured draft-then-refine editor for scenario content, with live validation before anything reaches a device.

  • Canvas

    Lay out the whole investigative network on one interactive canvas: participants, evidence links, and the solution path.

  • Deploy

    Guided multi-device deployment: bind roles to devices, pre-flight the Scenario Gate, and stream per-device progress.

How it works

Four-step lifecycle

01

Author

Compose a region-aware persona with controlled artifact counts, geofences, and time windows.

02

Provision

Install all six artifact types on the device in a single operation.

03

Verify

Loadout reads every artifact back from the device and diffs it against the documented manifest. Zero failures required.

04

Remove

Clean teardown between exercises. Every injected artifact is tracked, removed, and verified by read-back.

Hybrid provisioning

Loadout supports unrooted, lab-owned devices through a hybrid method: contacts, call logs, and photos are provisioned over ADB, and text messages, picture messages, and video are written by an on-device companion app. This delivers all six artifact types without rooting the device.

The Loadout promise

Train against lifelike artifacts.Leave the device clean.

Openly-synthetic data, a documented ground-truth manifest, and read-back-verified removal between exercises.

Program of Record

Train for the tools you field

Loadout writes each artifact into the device's native Android content providers, so Program-of-Record forensic tools parse it through their standard extraction workflows. Trainees practice the same extraction process they use in the field, against openly-synthetic artifacts that each carry a documented ground-truth manifest.

Tool-ready artifacts

Contacts, call logs, text and picture messages, and photos and video land in the real on-device providers, so forensic tools used in the field, such as MSAB XRY and Magnet GrayKey, can parse them through their normal extraction process. Planned iOS support writes to the equivalent iOS stores, parsed by the same tools and by Cellebrite.

Parse fidelity, checked

Before a device reaches a trainee, Loadout checks artifact parseability with ALEAPP, an open-source forensic parser that reads the same on-device schemas the field tools rely on. ALEAPP serves as an open proxy for Program-of-Record parsing; validation against the field tools themselves is a separate step.

MSAB, XRY, Magnet, GrayKey, and Cellebrite are trademarks of their respective owners. ALEAPP is an independent open-source project. Loadout is not affiliated with, endorsed by, or integrated with these products.

Roadmap

Expanding platforms and coverage

Beyond today's Android artifact set, Loadout is extending to iOS and to additional artifact types. Everything below is planned, and validated on real hardware before it ships.

Android · expanding coverage

  • Browsing historyPlanned

    Rooted injection into the Chrome History database (engine, root-fleet only). Non-root real-activity generation is a separate, roadmap mechanism, not a shipped path.

  • App usage historyPlanned

    Non-root real-activity generation

  • Location historyPlanned

    Photo GPS today; on-device timeline via real-activity generation

  • Third-party chat (WhatsApp)Planned

    Rooted injection into the encrypted message store

  • EmailPlanned

    Synced to the device from a self-hosted synthetic mail server

iOS · under evaluation

Planned

iOS support is on the roadmap and under active evaluation. We are validating the approach on real hardware before committing a capability or a date.

Coverage under evaluation

  • Messages
  • Contacts
  • Photos

Coverage targets the same on-device stores that Cellebrite, Magnet GrayKey, and MSAB XRY parse on iOS. Specifics are confirmed by real-hardware validation before release.

Some Android artifacts are produced by real-activity generation: Loadout drives the device's own apps so the activity is genuine and openly-synthetic by construction. Extended artifacts surface in a full-filesystem extraction, the same one the Program-of-Record tools perform.

Operator surfaces

Interfaces and connections

Interfaces

  • Control Station (desktop)Available now
  • Command-line interfaceAvailable now
  • Android companion appAvailable now
  • Hosted APIAvailable July 2026

Connections

  • Direct USBAvailable now
  • Wi-Fi / wireless ADBAvailable now
  • WebUSB in-browserAvailable July 2026

Trust and safety

Responsible use, by design

Loadout is built for controlled training environments. Every design decision prioritizes transparency, containment, and clean removal. The following principles are hard-coded into the product, not optional settings.

Openly-synthetic by design

Every artifact is openly-synthetic. A ground-truth manifest ships with each persona, recording exactly what was placed, where, and when.

Training devices only

Loadout targets lab-owned training devices managed by the instructor cadre. It is not for third-party, evidentiary, or personal devices.

Clean teardown

Every injected artifact is logged in a ledger and removed when an exercise ends, verified by read-back, so nothing carries into the next exercise.

Accessible by standard

Automated checks (axe-core) pass on every build against Section 508 and WCAG 2.1 AA. Conformance is self-assessed; a VPAT is available on request.

Loadout is intended for use on training devices within lab-owned, instructor-controlled environments. It is not for use on evidentiary, personal, or third-party devices. Any use outside a supervised training context is outside the intended scope of the product.

Deployment

Deployment options

Loadout runs on an operator workstation, fully offline and airgap-friendly. Containerized deployment is planned: hardened Iron Bank images and AWS GovCloud delivery are design-complete and releasing August 2026.

See installation options →
  • Local, offline operationAvailable now
  • Python core, no proprietary runtimeAvailable now
  • Containerized images for local, remote, and cloudPlanned
  • Hardened container images built on Platform One Iron Bank base imagesAvailable August 2026
  • Cloud deployment for AWS GovCloud (containers and serverless)Available August 2026

Availability refers to the deployment package itself. GovCloud and Platform One IronBank base images target those environments; this does not imply an existing Authority to Operate (ATO) or Iron Bank registry acceptance, which are established per deploying program.

Built with

  • PythonPython
  • DockerDocker
  • AWS GovCloud
  • Platform One IronBank

Trademarks are the property of their respective owners. Their appearance indicates technical compatibility or base-image lineage only, and does not imply endorsement, partnership, or approval. Loadout is not affiliated with, endorsed by, or sponsored by the U.S. Department of Defense or the Platform One program.

Contact

Request a capability briefing

Loadout is delivered through an Accelera Solutions engagement, not as a self-serve product. To discuss your training requirements, request a capability briefing and a member of the team will follow up.

Request a capability briefing

Company background, contract vehicles, and past performance:accelerasolutions.com.

byAccelera Solutions