Actually Cellebrite themselves have been victim of some kind of hack last month and had a load of their internal documents leaked online. So no, if any, this firm is _not_ the right hands.
Any place which hoards 0-days is a prime target. Even if they are considered to be the "right hands", the "wrong hands" could grab those exploits eventually.
When the target holds a lot of $1 million dollar 0-day exploits, the target is worth hacking into.
The only "right hands" for a 0-day exploit is the device manufacturer.