SignalTrace can link wireless device signatures to a passing car’s license plate

SignalTrace can link wireless device signatures to a passing car’s license plate

SignalTrace changes the meaning of a roadside vehicle observation because it adds radio sensing to a familiar camera workflow. Leonardo US Cyber & Security Solutions says the system passively detects publicly broadcast Bluetooth, Wi-Fi, RFID and other supported wireless emissions, then correlates recurring groups of those emissions with time, place and, where available, automatic license plate reader records. The important point is that the plate camera is only one part of the system. The radio sensor does not need to read a message, open a phone or obtain the contents of a smartwatch. Its investigative value comes from noticing that certain electronic traces are present at the same place and time, then finding the same combination again elsewhere. Leonardo markets that recurring combination as an electronic fingerprint.

Table of Contents

A roadside sensor that listens as well as looks

That distinction matters because claims that a new camera can “scan every electronic device in a car” are too broad. Leonardo’s own current material describes strategically placed sensors that collect electronic communication patterns and device identities, while independent security engineer Ryan O’Horo argues that the visible hardware, radio propagation, intermittent transmissions and modern address-randomization features impose real limits on what can be captured. Some Wi-Fi and Bluetooth emissions are plausible targets; other categories advertised in earlier material are technically harder to detect at road speed or useful range. SignalTrace is therefore better understood as a correlation system than as an all-seeing scanner. Its power is statistical and cumulative: a single roadside encounter may be ambiguous, but repeated encounters can turn weak observations into a pattern investigators consider distinctive.

The product also moves beyond the traditional logic of automatic license plate recognition. A conventional ALPR observation usually begins with a visible vehicle identifier: the camera captures a plate, software reads the characters, and the record is associated with a time and location. SignalTrace is designed to add another searchable layer. Leonardo says investigators can use an electronic signature to recognize a vehicle even when its plate is unavailable, and its patent describes systems that correlate electronic signatures with visual identifiers and then track targets through later captures. That reverses the normal direction of the search. Police do not necessarily need to start with a known plate. They may start with a recurring cluster of wireless observations, ask where that cluster has appeared, and use associated vehicle observations to develop a lead.

The privacy dispute begins at precisely this point. Leonardo says SignalTrace creates anonymous signatures, does not identify individuals, does not access communications and does not retrieve information stored on personal devices. Those are meaningful limits, and they distinguish the system from tools that intercept message content or impersonate a cellular base station. Yet anonymity at the moment of collection is not the same as lasting anonymity after correlation. NIST defines personally identifiable information broadly enough to include information that can distinguish or trace a person when combined with other linked or linkable information. A nameless radio trace can become identifying once it is repeatedly tied to a registered vehicle, a home, a workplace or another known device. That possibility is not a claim that every SignalTrace observation identifies a person; it is the mechanism that makes the product useful to investigators in the first place.

The present evidence also requires restraint about deployment. SignalTrace is a newly named version of technology previously marketed as EOC Plus, and Leonardo announced the SignalTrace name in August 2026. New York State procurement documents dated June 2025 list EOC Plus field-control hardware and an annual EOC Plus license, showing that the predecessor product was available through a state contract. O’Horo has identified equipment in Maryland that he believes matches SignalTrace installations, but public reporting notes that imagery alone cannot prove operational status, retention practices or investigative use. The technology is real and marketed to law enforcement, but its actual public deployment is less documented than the marketing claims. No reviewed source establishes that SignalTrace is deployed by Czech police, and this article does not assume that it is. That gap between capability and deployment is central to evaluating the risk. A system can deserve scrutiny before it becomes routine because procurement, technical integration and data-retention rules shape what searches can reveal. At the same time, criticism should not promote the vendor’s expansive claims as fact. The relevant questions are narrower: which emissions are observable, how reliably they can be linked across encounters, who can query the resulting records, how errors propagate, and what legal safeguards apply when a recurring signature is converted into a person-centered investigation.

SignalTrace is a sensor system, not a magical camera

The hardware story is easier to understand once the camera and radio functions are separated. Leonardo sells automatic license plate readers under the ELSAG brand, but SignalTrace is described as an electronic signal intelligence system that can work beside those readers or without a reader at every collection point. The company says sensors at selected sites capture supported emissions from nearby consumer electronics and send observations into its Enterprise Operations Center software, where they can be stored, queried and correlated with other records. A plate image and a wireless observation are different inputs that software can join through common time and location. Treating them as one super-camera obscures both the system’s capability and its limitations.

That architecture also explains why a single photograph cannot tell an investigator which phone was inside which car. A radio receiver hears energy arriving from an area; it does not see the physical boundary of a passenger compartment. Directional antennas can narrow reception, signal strength can support inference, and synchronized plate observations can provide a candidate vehicle, but nearby cars, cyclists, pedestrians and roadside devices may be transmitting at the same moment. O’Horo’s technical review emphasizes this attribution problem and argues that the system would benefit from repeated passes or multiple collection points. The association is produced by correlation, not by a radio beam that proves physical possession. That difference becomes especially important when police use the output as an investigative lead rather than merely as a traffic statistic.

The patent family makes the multi-sensor design explicit. U.S. Patent 11,941,716 describes collection systems that can capture visual identifiers, electronic signatures or both, with an intelligence system determining relationships based on factors that include frequency of capture, proximity and time. It names Bluetooth, Wi-Fi, RFID and other RF antennas among possible sensors and describes vehicle identifiers that can extend beyond a license plate to other visible characteristics. Leonardo’s 2024 announcement for the predecessor EOC Plus likewise said roadside sensors could capture frequencies emitted by consumer devices and, where plate readers were co-located, match timestamps to associate a plate with a signature. The patented concept is data fusion across observations, not extraction of private files from devices.

That does not make the collection trivial. Metadata about presence, timing and repeated co-occurrence can carry substantial information even when content remains untouched. The Federal Trade Commission has repeatedly treated precise location data as sensitive because movement records can reveal visits to homes, clinics, places of worship and other revealing locations. SignalTrace is technically different from commercial mobile-location datasets, and the FTC orders do not govern it by analogy. Still, they illustrate a broader privacy principle: information about where a device appears and which other identifiers appear beside it can reveal facts that no individual packet of radio traffic states directly. The privacy consequence comes from aggregation and inference.

The radio side is also more heterogeneous than popular descriptions imply. Wi-Fi, Bluetooth and RFID are not one technology, and devices use different frequencies, power levels, advertising behaviors and privacy protections. Some transmit often; some remain silent until queried; some rotate addresses; some expose more stable identifiers; some are difficult to detect at meaningful distance. A vehicle itself may add infotainment, hotspots or wireless accessories to the mix, while passengers contribute phones, watches, earbuds and trackers. SignalTrace does not need every device to be perfectly stable if the combined pattern remains distinctive enough across observations. Conversely, if identifiers rotate rapidly or the passenger mix changes, correlation becomes harder and confidence should fall. Leonardo does not publish an independent, public accuracy study establishing how often those conditions produce correct or incorrect associations.

This architecture frames the rest of the debate. An investigator may see a plate read, a group of radio observations and a software-generated relationship among them. Each layer has its own uncertainty. The plate can be misread or attached to the wrong jurisdiction; a radio identifier can be temporary; a nearby device can be attributed to the wrong vehicle; and a recurring cluster can reflect a family, carpool, rental car or shared equipment rather than one person. The responsible description is therefore neither “just a camera” nor “a machine that identifies everyone.” It is a multi-sensor association system whose usefulness rises with repeated, well-correlated observations and whose privacy risk rises for the same reason. Those two properties cannot be separated: stronger correlation makes a lead more useful while also making supposedly anonymous traces easier to connect to identifiable people.

Repetition turns loose signals into an electronic fingerprint

Leonardo’s current description of SignalTrace rests on recurrence. A roadside sensor does not need to know that one Bluetooth advertisement belongs to Alice or that one Wi-Fi emission belongs to Bob. It records supported signals that appear together at a place and time, and software looks for combinations that repeatedly reappear. Leonardo calls a predictably recurring mix an electronic fingerprint. The fingerprint is therefore a relationship among observations, not a biometric imprint taken from a person. The company’s own example imagines a specific phone variant, car radio, headphones, sports watch, key finder and license plate occurring together often enough that the combination becomes distinctive even though common device categories by themselves are not.

Repeated passage matters because roadside radio sensing begins with ambiguity. Suppose ten vehicles pass a sensor during a short interval and the receiver observes dozens of wireless transmissions. One encounter may offer little basis for assigning each transmission to a particular car. If a subset of signals appears again at another sensor alongside the same plate, the candidate relationship becomes stronger. If that pattern repeats on different days and routes, software can raise its confidence that the signals belong to a stable traveling group. Correlation converts coincidence into a probabilistic association by accumulating matching time-and-place observations. Leonardo’s patent describes relationship determination using factors including capture frequency, proximity and timing, which is consistent with that general mechanism.

This is also why the user’s “after a few weeks” description should be treated as an illustration rather than a fixed product specification. Public Leonardo material does not state that a fingerprint requires a particular number of days, trips or observations. A recurring cluster could emerge quickly on a repetitive commute or remain uncertain for much longer if the vehicle carries changing passengers and devices. There is no verified public threshold saying that SignalTrace needs exactly weeks of data before it can associate a signature with a plate. The time needed depends on collection density, transmission behavior, traffic, the stability of identifiers and whatever confidence rules the software applies. The absence of a published threshold is important because it prevents outsiders from independently judging when the product considers an association sufficiently reliable.

The same statistical logic explains both the investigative promise and the collateral risk. A commuter’s phone may often travel with the same vehicle, but so may a child’s tablet, a spouse’s watch, a company laptop or an aftermarket dashboard device. Some of those items identify a person more closely than others; some remain with the car when the driver changes. A cluster could therefore be highly stable while still being a poor proxy for the identity of the person behind the wheel. Stability answers “does this group recur?” more readily than it answers “who was carrying each device on this trip?” Nicole M. Bennett’s analysis emphasizes that a borrowed device, a device left in a car or a roadside bystander can complicate attribution even when the underlying detection is correct.

Modern privacy features make recurrence still more complicated. Android uses MAC randomization to reduce the ability of passive listeners to build a persistent Wi-Fi activity history, while Apple devices randomize MAC addresses during Wi-Fi scanning and use private addresses for networks. Bluetooth Low Energy also supports private and randomized addressing. These mechanisms do not guarantee invisibility: implementation varies, other radios may expose different features, and a combination of weaker or changing identifiers may still be correlatable. But identifier randomization directly attacks the assumption that one observed address is a stable long-term device label. A system seeking persistence may have to rely on other characteristics, repeated combinations or devices with weaker privacy protections.

A useful mental model is therefore a graph rather than a list. Each observation can connect a plate, a timestamp, a sensor site and one or more radio features. Repeated observations add edges. Some edges grow stronger because they recur; others fade because they appear once. Investigators may then search for the cluster later, even at a location where no plate reader is present, because Leonardo says SignalTrace can operate independently of LPR at collection sites. The privacy significance comes from the graph’s persistence across time and places. A signal that was anonymous in isolation may gain meaning through its connections, while an incorrect early association can also acquire false credibility if the system repeatedly sees the same confounded environment.

The data is useful because it can be linked

Leonardo’s privacy language focuses on what SignalTrace does not do. The company says it does not decrypt device content, access communications, retrieve stored personal information or directly identify individuals from the wireless emissions it observes. Those limits matter: content interception is more intrusive than passive observation, and nothing in the reviewed product material describes SignalTrace as a cell-site simulator that forces phones to connect. But the absence of a name inside a radio observation does not make the resulting record permanently anonymous. SignalTrace is expressly built to correlate recurring electronic signatures with locations, vehicles and other operational data, so its usefulness depends on turning otherwise sparse observations into relationships that investigators can search.

NIST’s definition of personally identifiable information helps explain the disagreement. NIST includes information that can distinguish or trace an individual either by itself or when combined with other linked or linkable information. That is broader than a rule under which data becomes personal only when a legal name appears in the original record. Linkability is the decisive concept. If a recurring electronic signature repeatedly travels with one plate, and a vehicle-registration database links that plate to a registered owner, an investigator may have a plausible route from a nameless pattern to a person. The inference can still be wrong—the owner may not be driving—but the absence of a name at the sensor does not stop the investigative linkage from being made.

The same principle appears in European data-protection law, although SignalTrace’s U.S. deployment status and European legal applicability are separate questions. EU law defines personal data to include information relating to an identified or identifiable person and expressly names location data and online identifiers among examples of identifiers that can support indirect identification. Court of Justice case law has repeatedly read the concept broadly when information is linked to an identifiable person by its content, purpose or effect. Pseudonymous or indirect identifiers can still be personal data when re-identification is reasonably possible. That does not automatically answer whether any particular SignalTrace dataset is personal data under EU law, but it shows why the vendor’s “does not identify individuals” statement is not the end of a legal privacy analysis.

Vehicle registration provides one obvious bridge because license plates are designed to identify vehicles within government records. A plate observation does not prove who was driving, yet law enforcement can commonly use authorized databases to determine the registered vehicle and owner information. SignalTrace adds a second bridge: repeated device co-occurrence may suggest which wireless traces usually accompany that vehicle. The combined record can narrow an investigator’s search even when neither component independently names the current driver. This is why Bennett argues that a person may become part of an investigation because of where a device repeatedly appeared and which vehicle or known subject it appeared near, rather than because police began with that person’s identity.

Linkage can proceed in the opposite direction too. Leonardo says an electronic signature may allow police to recognize a vehicle without seeing its plate, and the patent contemplates tracking targets through successive captures of visual identifiers or electronic signatures. If a recurring cluster has previously been associated with a known plate, a later detection of the cluster could suggest that the same vehicle—or at least some of the same equipment—is present despite a missing, changed or obscured plate. That is precisely where anonymous collection becomes operationally consequential. The system does not need to output “Jane Doe” to change who police follow, which records they request, where they search next or which vehicle they regard as connected to an investigation.

The strongest privacy analysis therefore separates three questions that are often collapsed. First, does the sensor read message content? Leonardo says no. Second, does the initial signal necessarily contain a person’s legal identity? Again, the company says no. Third, can repeated observations be correlated with other records until investigators infer a likely person, vehicle or association? The product is marketed to do exactly that kind of correlation. Accuracy, legal authority and evidentiary weight remain separate issues, but calling the raw signal “anonymous” does not erase the later analytical process. The more persistent the database and the richer the linked records become, the more important retention limits, query controls, audit logs and independent accuracy testing are to determining the real-world privacy impact. in practice.

Wi-Fi privacy features weaken simple tracking assumptions

Wi-Fi is an obvious target for a roadside sensing system because phones, laptops, tablets, hotspots, cameras and vehicle electronics all use it. Yet a modern phone does not necessarily expose one permanent Wi-Fi hardware address every time it scans the air. Android has supported MAC address randomization specifically to prevent listeners from using a stable address to build a history of device activity, and Android 10 made randomized MAC addresses the default in several client modes. Apple likewise uses randomized addresses during Wi-Fi scanning and private Wi-Fi addresses for network associations. A passive observer therefore cannot safely assume that every visible Wi-Fi address is a lifelong device identifier. Any surveillance system that relies on Wi-Fi persistence has to cope with address changes, intermittent transmissions and differences between operating systems and device states.

That does not make Wi-Fi useless for correlation. Randomization policies have scope and exceptions, devices behave differently depending on whether they are scanning, associated with a network, offering a hotspot or using peer-to-peer functions, and older or embedded products may expose more stable identifiers. Apple’s security documentation, for example, distinguishes randomized scan addresses from private addresses used for particular networks and also describes separate randomization for peer-to-peer services. Android documentation similarly sets requirements across client mode, Wi-Fi Direct, Wi-Fi Aware and ranging. The radio environment is a moving collection of temporary and sometimes persistent clues rather than one clean serial number per device. A system can attempt to correlate those clues across time without being able to guarantee that each observed address maps one-to-one to the same physical product.

SignalTrace’s public material does not disclose enough technical detail to show exactly which Wi-Fi fields its current implementation uses for long-term correlation. Leonardo says it detects publicly broadcast Wi-Fi and other supported emissions and creates electronic signatures, while its patent is intentionally broader than a product manual. Independent researcher O’Horo argues that modern randomization makes persistent phone identification harder than some marketing language implies. There is no reviewed public independent test showing SignalTrace’s Wi-Fi re-identification rate across current iPhones, Android phones, laptops and vehicle systems. That absence matters because a demonstration that detects a device once is not the same as evidence that the product can reliably recognize the same device days later while privacy protections are active.

Wi-Fi also illustrates the difference between device detection and occupant attribution. A sensor may receive a probe, hotspot beacon or other frame near a passing car, but the radio packet does not announce that the transmitter is physically inside that specific vehicle. Traffic density, antenna pattern, roadside geometry and signal strength influence the candidate set. Repeated co-occurrence with one plate can make one explanation more likely, yet probability is not proof of possession or identity. A pedestrian on a parallel sidewalk, a phone in a neighboring lane or a fixed access point can contaminate an observation window. If software later groups those observations into a recurring signature, investigators need confidence measures and enough context to distinguish a real traveling cluster from radio background.

The practical consequence is that privacy settings can reduce trackability without creating a guaranteed invisibility switch. Keeping operating systems updated and leaving private-address features enabled can remove some simple persistence signals, but SignalTrace is explicitly designed to combine multiple emissions. A car radio, earbuds, a watch, a hotspot and another accessory may together form a recognizable pattern even if one phone rotates its Wi-Fi address. Correlation can exploit the stability of the group when individual identifiers are unstable. Conversely, a changed device set can make a previous fingerprint less reliable, which is why a serious investigative system should disclose how it handles cluster drift rather than treating an electronic signature as immutable.

Wi-Fi therefore cuts both ways in the SignalTrace debate. It is widespread enough to provide abundant observations, but modern privacy engineering was expressly developed to frustrate passive tracking by stable network addresses. The existence of randomization does not disprove Leonardo’s broader concept, and the existence of SignalTrace does not mean those protections have failed. The unresolved issue is empirical performance under realistic road conditions. Public buyers and courts would benefit from independent testing that reports capture rates, persistence rates, false associations, performance by device class, effects of speed and traffic density, and the behavior of current randomized-address implementations. Until such results are public, claims that SignalTrace can identify every phone in a passing car should be treated as marketing shorthand, not a verified technical fact.

Bluetooth signals are common but not automatically permanent

Bluetooth is central to Leonardo’s description because modern cars are crowded with Bluetooth-capable products: phones connect to infotainment systems, watches synchronize with phones, earbuds advertise for pairing, trackers emit low-energy signals and some vehicle accessories use Bluetooth for control or telemetry. SignalTrace says it can passively detect publicly broadcast Bluetooth emissions and use them as ingredients in recurring electronic signatures. Detection, however, is not the same as obtaining a permanent identity for the device. Bluetooth Low Energy includes privacy mechanisms that allow devices to use random and private addresses, and manufacturers such as Apple use address randomization to reduce long-term tracking. A roadside observer may see a useful signal without receiving a stable address that remains unchanged indefinitely.

The Bluetooth Core specification distinguishes public device addresses, static random addresses and private addresses. Resolvable private addresses are designed so trusted peers with the appropriate key can recognize one another while passive outsiders cannot simply treat the transmitted address as a permanent public label. The Bluetooth SIG has continued developing randomized private-address update behavior, reflecting the privacy importance of address rotation. This technical design directly complicates any claim that a Bluetooth address alone can serve as a persistent roadside tag. It does not prevent every form of correlation, because advertising payloads, device behavior, timing and companion signals may offer additional clues, but it means the surveillance problem is richer than recording one MAC address and following it forever.

Implementation differences also matter. A smartwatch may advertise differently when paired than when searching for a connection; earbuds may expose information when a case is opened; a tracker is designed to be discoverable; an older head unit may use comparatively stable identifiers; a phone may suppress or rotate values under conditions that newer privacy specifications anticipate. SignalTrace is dealing with a population of radios with different privacy behavior, not a uniform fleet of beacons. O’Horo’s analysis argues that some categories of Bluetooth and Wi-Fi devices remain practical targets even while modern phones are harder to track consistently. That is plausible because the fingerprint model only needs enough stable features across a group to create recurrence; it does not require every component to be equally persistent.

Bluetooth also introduces the “ownership versus presence” problem. A detected pair of headphones may belong to a passenger, a child or someone walking near the road. A car’s infotainment system may remain with the vehicle even as drivers change. A smartwatch usually travels with a person, but it can be left in a bag or loaned. The sensor can observe radio presence more readily than human possession. Repeated co-travel can support an inference that a device and vehicle are associated, yet it cannot by itself establish who wore the watch, who paired the earbuds or who drove at a specific moment. Bennett’s privacy analysis emphasizes precisely this gap between a recurring electronic clue and a justified conclusion about an individual.

The distinction has evidentiary consequences. If investigators use a Bluetooth-related signature to generate a lead, the prudent next step is corroboration through independent evidence rather than treating the radio match as conclusive. Leonardo’s own 2026 press release says SignalTrace observations can complement other operational data, and the company’s privacy explanation says output should be used within established legal and governance frameworks. That framing is closer to intelligence analysis than to a forensic identity test. Publicly available sources reviewed for this article do not provide a false-positive rate, a false-negative rate or a standardized confidence scale for Bluetooth-based SignalTrace associations. Without those measures, outsiders cannot quantify how much weight a particular match deserves.

Bluetooth therefore demonstrates both why SignalTrace can work and why sweeping descriptions overstate it. Bluetooth emissions are abundant and often travel with people and vehicles, making them useful correlation material. Privacy features, intermittent advertising, radio congestion and device diversity make persistent observation imperfect. A cluster of several recurring Bluetooth and non-Bluetooth signals may be more distinctive than any single device. That is the conceptual strength of Leonardo’s system and also the privacy concern: even when standards reduce the durability of one identifier, a multi-device pattern can provide another route to persistence. Independent testing would need to examine whole-cluster re-identification, not merely whether one Bluetooth address rotates, to establish what the system can reliably infer in real traffic. It would also need to publish performance across speed, distance, traffic density and device generation rather than relying on controlled demonstrations.

RFID claims need especially careful technical reading

RFID is the broadest and most easily misunderstood part of the SignalTrace story because “RFID” covers multiple technologies operating at very different frequencies and ranges. Leonardo’s current page says the system supports RFID signals, while its older EOC Plus marketing listed examples that included tags associated with consumer or vehicle contexts. The 2024 product announcement also referred to RFID among device signatures that could help identify people of interest. Those statements establish that RFID is part of the marketed capability, but they do not establish that every RFID tag can be read from a moving car at roadside distance. Frequency, antenna design, tag type, power source and protocol all determine whether a particular tag is detectable.

Passive UHF RFID tags can be read at distances useful for logistics and tolling when the reader, antenna geometry and tag orientation cooperate. Low-frequency implantable animal microchips are a very different case: they are passive and normally require a nearby interrogating reader to energize them. O’Horo argues that Leonardo’s earlier references to pet microchips are technically implausible for the visible roadside antenna configuration and suggests the company may have meant wireless pet collars instead. That criticism is material because a pet microchip is not equivalent to a Bluetooth tracker worn by a pet. The former does not continuously broadcast a long-range identifier into the street; the latter may actively transmit radio signals that a receiver can plausibly detect.

The same caution applies to library books and access cards. Some library systems use RFID, but implementations vary by frequency, power and reader distance. A marketing list that includes “RFID tags” should not be converted into a universal claim that any tagged object inside a vehicle will be detected. The correct question is whether the specific tag technology is transmitting or can be interrogated effectively by the specific SignalTrace hardware under actual road conditions. Publicly reviewed Leonardo material does not provide a matrix of supported RFID protocols, antenna gain, transmit power, read range by tag class, vehicle speed limits or measured success rates through glass and vehicle bodies. That missing detail prevents an evidence-based assertion that the system can inventory every tagged item in a passing car.

Vehicle electronics introduce another category of radio observations. The patent and product materials contemplate electronic signatures associated with vehicles as well as people, and independent analysis discusses tire-pressure monitoring systems, key fobs, hotspots and infotainment equipment among possible sources. These technologies also differ widely. Some tire-pressure sensors transmit intermittently on frequencies that may not match the visible antenna’s practical coverage; infotainment Bluetooth and Wi-Fi are more conventional targets. A vehicle-level signal can be highly useful even if it says nothing about the current occupant. If a radio component remains installed in the car, it may help recognize that car when a plate is obscured or changed, which is one of Leonardo’s stated use cases.

This distinction between person-carried and vehicle-fixed devices should shape any privacy or accuracy assessment. A stable dashboard radio might strengthen vehicle re-identification while contributing little to identifying the driver. A phone or smartwatch may follow a person across cars but may use stronger privacy protections. A company laptop may alternate between home, office and several vehicles. SignalTrace’s “electronic fingerprint” can blend signals that describe the vehicle with signals that describe whoever happens to be traveling in it. The mixture may be operationally useful because it increases distinctiveness, but it also makes semantic interpretation harder: the same fingerprint can change when passengers change, accessories are replaced or a vehicle is sold.

RFID therefore supplies a useful test for responsible reporting. The existence of a vendor claim should be reported as a vendor claim; a technically plausible subset should not be inflated into universal detection; and an independent critique should be identified as analysis rather than treated as laboratory proof. The strongest verified statement is that SignalTrace is designed to collect supported radio emissions from several technology families and correlate recurring observations. The reviewed evidence does not show that it can scan “all electronics” in every passing vehicle, identify all RFID objects, or defeat the physical limits of passive tags. Those limitations do not eliminate the privacy issue. They narrow it to the signals the system can actually observe reliably—and make independent performance testing more important before agencies rely on its output. Procurement documents should specify that supported subset rather than repeating category names without measured operating conditions.

Marketing claims and verified limits belong side by side

SignalTrace is unusual because its public marketing is specific enough to describe ambitious use cases but not detailed enough to let outsiders reproduce its performance. Leonardo says the system passively detects Bluetooth, Wi-Fi, RFID and other supported wireless emissions, groups signals that routinely travel together and can correlate those groups with license plate observations. It also says SignalTrace can work without an LPR at every site and can be used in places such as subways and malls. Those are verified statements about the product’s intended functions, not independent proof that every advertised signal class performs equally well in the field. The difference between a capability description and measured performance needs to remain visible throughout any assessment.

Independent technical review supplies some of the missing skepticism. O’Horo examined apparent hardware, common radio characteristics and Leonardo’s patent and literature. He concludes that ordinary Wi-Fi and Bluetooth collection is plausible, but questions claims involving low-frequency pet microchips and some tire-pressure signals because the visible antennas and expected read distances do not align with those use cases. He also points to intermittent transmissions, channel coverage and modern address randomization as obstacles to universal capture. His work is engineering analysis, not a controlled validation test of SignalTrace. It should therefore constrain extravagant claims without being misrepresented as a definitive measurement of the proprietary system’s error rates.

Table 1. SignalTrace claims, evidence and caveats

Claimed or described functionWhat reviewed sources supportMain unresolved issue
Detect Bluetooth and Wi-FiLeonardo explicitly markets passive detectionPersistence varies because devices transmit intermittently and may randomize addresses
Detect RFIDRFID appears in Leonardo’s current product materialSupported protocols, ranges and tag classes are not publicly specified
Link signals to plate readsProduct page and patents describe time-location correlation with LPR dataPublic false-association rates are unavailable
Recognize a vehicle without its plateLeonardo lists this as an investigative featureA signature may change with devices and passengers
Operate without LPR at every siteLeonardo says standalone collection sites are possibleReal-world deployment scale is not publicly established
Read device contentsLeonardo says SignalTrace does not do thisMetadata and associations can still become identifying

The table separates documented product claims from the technical and evidentiary questions that remain open; it does not treat unverified marketing performance as measured fact.

One strong claim is well supported: SignalTrace does not need to read message content to produce investigative information. Leonardo says it stores observations that can be queried later, and its patent describes databases of visual identifiers and electronic signatures that support target tracking. That architecture explains why privacy risk can arise from metadata. Repeated co-occurrence, timestamps and locations can reveal relationships even when communications remain encrypted and untouched. NIST’s broad approach to linkable information and the FTC’s enforcement work on location data both illustrate why an identifier’s informational value depends on what it can be combined with, not merely on whether the first record contains a name.

Another claim needs firmer qualification: that the technology identifies “suspects” through devices. Leonardo’s 2024 release for EOC Plus used language about helping law enforcement identify people of interest, while its 2026 SignalTrace announcement stresses anonymous electronic signatures and says the system does not identify individuals. Those formulations are not identical. The most coherent reading is that the sensor produces non-name signatures that can become leads toward identifying people when correlated with other records. That interpretation matches the patent’s target-tracking logic and Bennett’s analysis of how a recurring signature can be connected to a registered vehicle, known location or case file. It avoids falsely claiming that a radio receiver directly extracts a subscriber’s name.

Deployment claims also need separation from procurement evidence. New York’s 2025 contract price list includes multiple EOC Plus hardware configurations and an annual software license, proving that the predecessor system was available for public procurement through that contract. O’Horo has identified apparent installations in Maryland using visual evidence and comparisons with Leonardo material, while Biometric Update notes that operational status and data use have not been confirmed through public agency records. Availability for purchase is not proof of active surveillance at every eligible agency. Likewise, photographs of matching hardware are evidence worth investigating but do not establish what was collected, how long it was retained or whether investigators queried it.

The largest unsupported leap is the phrase “all electronic devices in a car.” No reviewed source provides a universal device-coverage claim backed by an independent field test. Vehicle structure, speed, antenna placement and competing traffic add further uncertainty. SignalTrace can be privacy-significant without being omniscient. In fact, focusing on realistic capabilities produces a stronger analysis: recurring Bluetooth, Wi-Fi and supported RFID observations, combined with plate data and stored over time, can create useful investigative associations even if many devices are missed.

A responsible procurement process would ask for performance evidence before operational use. Agencies should know detection rates by protocol, false-association rates in dense traffic, how randomized addresses are handled, what confidence score supports a match, how cluster changes are treated and whether independent evaluators can inspect the methodology. Without those answers, the public can verify the architecture but not its reliability. That gap is especially important because the product is intended to generate leads: a modest error can redirect attention toward an innocent passenger, neighboring vehicle or bystander long before a court has an opportunity to evaluate the evidence.

A nameless signature can still point toward a person

Leonardo’s current description says SignalTrace creates anonymous electronic signatures rather than direct identity records. That distinction is technically meaningful: a roadside radio receiver does not need to obtain a subscriber name, address book, message body or account profile merely to observe a Bluetooth, Wi-Fi or supported RFID emission. Yet anonymity at the moment of collection is not the same as durable anonymity after correlation. SignalTrace is expressly designed to associate recurring signatures with vehicle observations and other operational data. Its patent describes relationships among electronic signatures, visual identifiers and targets of interest, including vehicles and people. Once a recurring cluster is repeatedly seen beside a particular plate, the record has acquired an external reference that investigators may be able to connect to ordinary government or investigative records.

That is where the debate over the manufacturer’s privacy language becomes concrete. A license plate ordinarily identifies a registered vehicle, not necessarily the person driving it at any given moment. Police may nevertheless use authorized registration records, case files, witness information and other evidence to learn who is associated with that vehicle. Linkability, not a name embedded in the radio packet, is the central privacy issue. NIST’s definitions of personally identifiable information explicitly recognize information that can distinguish or trace an identity when combined with other linked or linkable information. The principle does not automatically decide whether a particular SignalTrace record is legally regulated as PII in every jurisdiction, but it explains why calling an identifier anonymous does not settle the question. An identifier can begin as pseudonymous or unlabeled and later become person-associated through other data.

A simple hypothetical shows the mechanism without assuming powers that the reviewed sources do not establish. Suppose a recurring signature is observed with the same car on commuting routes, then appears beside another vehicle on a later day. The correlation supports an inference, not a verified identity. Leonardo markets precisely this ability to notice a recurring signature appearing with different vehicles. None of that means a phone has disclosed its owner’s name over the air. It means stored observations can become more informative when a separate fact supplies the missing identity link.

The same logic appears in other location-data contexts. The FTC has taken action against data brokers whose datasets associated mobile advertising identifiers with precise locations, emphasizing that supposedly device-centered data could be used to trace visits and, through available matching services or other records, connect activity to individuals. SignalTrace is a different technology with a different source of data, so the FTC cases do not establish rules for Leonardo’s system. They do demonstrate a broader technical fact: an identifier’s privacy significance changes when it is combined with location and reference data. A sequence of observations can expose routines, associations or sensitive destinations even if the first record lacks a conventional name field. This is why privacy analysis has to examine the complete data flow rather than the radio capture in isolation.

There are also limits to what a plate link proves. A registration record points to a registered owner, not necessarily a driver, passenger or person carrying a detected device. Cars are shared, rented, borrowed and sold. Phones and watches may be borrowed or left behind. Employer devices can move among workers. A stable in-car radio may identify the vehicle more reliably than anyone inside it. If analysts silently turn “signature appeared with registered vehicle” into “registered owner carried this device,” they cross an evidentiary gap. Good investigative practice requires corroborating the human attribution separately. That is especially important where a device signature becomes the basis for a stop, interview, search request or placement of a person at a sensitive location.

The practical question, then, is not whether SignalTrace stores a literal name beside every observation. Leonardo says it does not identify individuals through the signal itself, and that statement should be represented accurately. The practical question is what authorized users can infer after the system has created a persistent searchable association and that association meets records from elsewhere. The patent’s tracking logic and Leonardo’s LPR integration make that second stage part of the system’s intended value. Privacy rules, agency policies and judicial review therefore need to address both collection and subsequent correlation. A safeguard that governs only direct content interception would miss the feature that makes the product operationally interesting: finding relationships in metadata that looked unremarkable when observed one event at a time.

Passengers can become investigative collateral

A vehicle is rarely a reliable one-person container. Families share cars, colleagues carpool, taxis and ride-hailing vehicles carry strangers, children bring tablets, and visitors leave headphones or trackers in a seat pocket. SignalTrace’s analytical premise is to identify signals that repeatedly travel together, but co-travel does not establish common ownership or common intent. A plate observation describes the vehicle. A radio observation describes a detectable emission near the collection point. An algorithm can estimate that the two are associated because of time, proximity and repetition, as Leonardo’s patent describes, yet the system cannot infer human possession merely from electromagnetic presence. That gap matters most for people who are not the subject of an investigation but happen to travel with someone who is.

Consider a recurring commute shared by two coworkers. One owns the car and its plate; the other carries a smartwatch and work laptop. Repeated roadside captures may make the passenger’s devices part of the vehicle’s electronic fingerprint. If the passenger later rides with a different colleague, the recurring device pattern could provide a bridge between two cars. Leonardo specifically advertises the ability to identify electronic signatures that appear with different vehicles and signatures that frequently travel together. That feature widens the circle of observable people as it creates new investigative links. A passenger who has done nothing suspicious can become a connective data point simply because a personal device is repeatedly present near a vehicle under scrutiny.

The risk is not limited to false technical detection. The radio match may be accurate while the social interpretation is wrong. A teenager’s watch in a parent’s car does not prove the teenager was present on every subsequent pass if the watch was left in the vehicle. A company laptop moving between a depot van and an employee’s car may indicate equipment logistics rather than a human relationship. Wireless earbuds passed between family members can blur ownership. A correct signal association can still support a false story about people. Technical accuracy and inferential accuracy are separate questions. Independent evaluation would need ground truth about vehicles, devices and occupants so it could distinguish a missed radio, a wrong vehicle assignment and a mistaken conclusion about the person involved.

Passengers also have less practical control over the infrastructure they encounter. Some device platforms reduce trackability through rotating addresses and other privacy techniques, yet those protections differ by protocol, device generation and operating state. Turning off radios may disable navigation, wearables, audio or other ordinary functions. Privacy should not depend on every passenger understanding radio-layer behavior before accepting a ride. Leonardo describes SignalTrace as passive and says it observes publicly broadcast signals rather than accessing communications or stored content. That architecture is narrower than content interception, but the person passing the sensor is not making a meaningful transaction in which to accept or reject collection. Apple and Android documentation also shows that platform designers treat passive tracking of stable wireless identifiers as a privacy problem worth mitigating.

Retention changes the stakes. A single fleeting observation may have little consequence. A searchable archive can make that observation relevant later when an investigator starts with a plate, a signature or a location and asks which records connect. Leonardo’s product page says data can be stored on the SignalTrace server and queried; the broader EOC description says collected data may be archived for future queries and analysis. People who were incidental at collection can become relevant retrospectively. The Supreme Court’s location-privacy cases concern different data sources and legal questions, but they show judicial concern with digital systems that make past movements cheaply reconstructable. That analogy is not a holding that SignalTrace collection is itself a Fourth Amendment search.

Agencies can reduce collateral harm by treating passenger ambiguity as a normal operating condition. Search interfaces can distinguish “observed with” from “owned by.” Analysts can document corroboration before attaching a device cluster to a named person. Retention can be shorter for records unrelated to a specific investigation. Query logs can expose broad association searches. Policies can forbid treating a passenger-like association as the sole factual basis for coercive action. The point is not that every correlation is wrong. It is that the database should not silently convert proximity into identity. The most consequential error may not be a sensor hearing the wrong radio; it may be a user reading a technically correct association as proof of who was in the car, who possessed a device and why that person traveled.

Nearby pedestrians and adjacent vehicles create attribution risk

Roadside radio collection has a geometry problem that plate cameras do not share in quite the same way. A camera can frame a plate and associate pixels with a lane position. A radio receiver hears energy within an antenna’s effective field, shaped by power, frequency, obstructions, reflections and receiver design. A detected signal does not carry a built-in label saying which vehicle contained its transmitter. SignalTrace addresses that uncertainty through correlation: time, proximity, repeated captures and combinations of signals can increase confidence that an emission belongs with a particular vehicle or target. Leonardo’s patent describes relationships based on capture frequency, selected proximity and time, and contemplates a relative certainty value and threshold. Association is therefore an analytical inference, not direct observation of physical possession.

At an empty rural road, temporal separation may make attribution easier. At a multilane intersection, a queue outside a school or a crowded downtown curb, several vehicles and pedestrians can occupy radio range together. Phones search for networks, earbuds advertise, watches synchronize, cars expose infotainment interfaces and nearby buildings contain their own wireless equipment. Dense radio environments create competing candidates for the same timestamp. A system may reduce ambiguity by observing which signals recur with the same vehicle across several sites, but a one-off capture can remain difficult to attribute. Leonardo’s public materials explain the clustering concept but do not publish a tested false-association rate by traffic density, lane spacing, pedestrian volume, antenna placement or signal class. That missing measurement prevents outsiders from quantifying how often environmental clutter is rejected correctly.

Repeated observation is a powerful filter, but it has its own failure modes. Two commuters traveling the same corridor at the same time may be repeatedly co-located without knowing each other. A school bus and a parent’s car may pass the same reader on a regular schedule. A resident standing near a fixed sensor each morning could generate a recurring local signal while many cars pass. Recurrence can mean shared movement, shared schedule or shared place. An algorithm needs a way to distinguish among those explanations. Leonardo’s patent describes proximity, frequency and time as inputs, but the public record reviewed here does not disclose the commercial product’s feature weighting, rejection rules or confidence calibration.

Radio physics adds complication. The strongest signal need not be the closest transmitter, and the closest transmitter need not be inside the target car. Vehicle glass, metal bodywork and antenna orientation can attenuate or reflect emissions. Protocols operate at different frequencies and powers. Security engineer Ryan O’Horo argues that some advertised categories are much more plausible to collect at roadside distance than others and stresses channel coverage, intermittent broadcasting and antenna characteristics. His work is not an independent laboratory validation, so it cannot supply a product error rate. It gives a technical reason to demand protocol-specific testing instead of one universal accuracy claim. Reporting should preserve the difference between informed engineering analysis and measured commercial performance.

Attribution errors matter because later analysis can magnify them. If an unrelated phone is incorrectly attached to a plate once and the system later treats that association as part of a signature, subsequent searches may pull the wrong vehicle or person into an investigative graph. A confidence threshold can filter low-quality matches, but without published calibration outsiders cannot know the tradeoff between missed associations and false ones. A database can make a small sensor-level uncertainty look authoritative after repeated copying and querying. Records should therefore preserve provenance: sensor location, time window, associated plate read, protocol, confidence and whether a relationship was algorithmic or independently confirmed. Leonardo’s patent expressly contemplates certainty values for associations, supporting the idea that matches are not all equally strong.

GAO’s review of federal public-space monitoring technologies found that operational policies do not always implement key privacy protections and recommended stronger policy controls. SignalTrace was not the subject of that report, so GAO’s findings are not evidence about Leonardo’s accuracy or deployment. They are relevant to the institutional problem: automated collection is only one stage, followed by matching, search and human interpretation. A defensible implementation would test crowded scenes, audit error metrics, preserve confidence and provenance, and require corroboration before a radio association becomes a claim about a person. Without those controls, someone waiting on a sidewalk or traveling in the next lane can become a digital fellow traveler of a vehicle they never entered.

Repeated observations can strengthen both matches and mistakes

SignalTrace gains analytical value from repetition. One Bluetooth advertisement or Wi-Fi frame near one plate can be ambiguous; the same cluster repeatedly appearing near the same vehicle across separate times and locations is harder to dismiss as coincidence. Leonardo’s product page says its algorithms determine which mix of devices is predictably moving together, while the patent describes correlations using frequency, proximity and time as relationship signals. repeated independent observations can raise confidence that two things travel together. The problem is that repetition improves confidence only when the underlying observations and assumptions are well specified. If the sensor repeatedly makes the same systematic attribution error, or if two unrelated travelers share a routine, recurrence can reinforce a mistaken association instead of correcting it.

A useful way to think about the system is as an evidence accumulator. Each passage may add a timestamped plate read, several radio observations, location information and a calculated relationship score. The patent contemplates a “relative certainty value” for associating captured electronic signals with an identified target and a threshold above which a signal or combination can become an electronic signature. A threshold converts uncertainty into an operational category, but it does not make uncertainty disappear. A threshold set too low may admit coincidental neighbors; one set too high may miss real associations when addresses rotate or devices stop transmitting. Public Leonardo material does not reveal the commercial threshold, calibration dataset, receiver sensitivity or measured receiver-to-target error distribution, so outsiders cannot assess where that tradeoff has been placed.

Repetition can also create feedback. Suppose an early association causes a device cluster to be labeled as belonging to a particular vehicle. Later observations may be interpreted in light of that label, and analysts may search specifically for the known cluster. If the initial label was wrong, each later match can appear to confirm it. Independent ground truth is needed to prevent circular validation. A rigorous test would seed known vehicles with known devices, include neighboring traffic and pedestrians, vary speed and lane geometry, and then compare the system’s inferred relationships with what was actually present. It would also distinguish per-observation detection, cluster formation, vehicle association and person attribution. The public record reviewed for this article does not contain such an independent field study with published confusion matrices or confidence calibration.

Modern wireless privacy features make the accumulation problem more interesting. Android and Apple both document techniques intended to reduce persistent tracking through stable Wi-Fi identifiers. Bluetooth specifications also provide private address mechanisms. Those features can fragment a device’s apparent identity across time. SignalTrace’s multi-device fingerprint approach may compensate by looking at combinations rather than one permanent address, but cluster persistence becomes a probabilistic claim rather than a simple serial-number lookup. A changing cluster could be the same car after software updates, a new passenger, a replaced watch or randomized identifiers; two similar clusters could belong to different cars. Independent testing would need to measure how often the system joins records that should remain separate and separates records that should be joined.

The consequences depend on how investigators use the result. As a low-confidence lead, a recurring association may simply tell an analyst where to look next. As justification for a traffic stop, search request, watchlist alert or assertion that two people traveled together, the same output carries more weight. Reliability standards should rise with the consequence of the decision. Leonardo says SignalTrace provides observational data to complement existing technologies and operate within legal and governance frameworks. That framing supports treating its output as context rather than self-proving identity evidence. Agency policy should preserve confidence values and require stronger corroboration as the operational impact grows, especially where a person was not previously a target.

Repetition is therefore neither inherently sinister nor automatically reliable. It is the mechanism that makes sparse radio emissions analytically useful, and it is the mechanism that can make a mistaken link look increasingly persuasive. Good governance has to ask whether observations are sufficiently independent, whether systematic environmental factors are modeled, whether clusters can split and merge, and whether analysts can see the uncertainty beneath a neat search result. The patent shows that Leonardo’s inventors anticipated uncertainty by including proximity, frequency and certainty values in the architecture. The next question is empirical: how those concepts perform on real roads with mixed traffic and modern devices. Until independently measured results are public, recurring associations should be described for what they are—algorithmically strengthened relationships, not infallible proof of possession, identity or intent.

Storage and search architecture determine the real privacy impact

The roadside sensor is only the front end. SignalTrace becomes operationally powerful because observations can be retained, correlated and searched after the moment a vehicle passes. Leonardo’s product page says the system stores data on a SignalTrace server where investigators can query and analyze it, and the ELSAG Enterprise Operations Center description says collected data may be uploaded and archived for future queries. The patent describes a memory containing databases of visual identifiers and electronic signatures, search inquiries, movement records and maps of captured locations. Privacy impact therefore depends as much on server rules, retention and search permissions as it does on what the antenna can hear during one second at the roadside.

A short retention window and a long one create different systems even if the sensors are identical. With brief retention, most uninvolved records disappear before anyone has reason to search them. With extended retention, investigators can begin from a later event and reconstruct earlier associations that were unknown at collection. Retrospective search changes the value of ordinary observations. Leonardo’s page says all collected data may be archived in EOC, while also describing a workflow in which an electronic signature is alerted after it has been identified during an investigation. Those statements leave agencies with important policy choices: what exactly is retained, for how long, under what legal authority, whether nonmatching records are deleted, and when historical records become searchable. The reviewed public product material does not state a universal retention period imposed on all customers.

Search design also matters. A database that only lets an officer retrieve a known plate is narrower than one that supports reverse association queries such as which plates appeared with this signature, which signatures co-traveled, or where a target was observed over time. Leonardo’s patent expressly contemplates searching known visual identifiers or electronic signatures and generating records of movement. Reverse and relationship searches are the core expansion beyond traditional plate lookup. They can reveal that a recurring device cluster changed vehicles, that two signatures frequently appeared together, or that a target’s signature was captured at successive locations. Those capabilities may be useful in legitimate investigations, but they also increase the number of ways uninvolved people can become visible through association. The public product page likewise markets convoy and travel-pattern discovery.

Access controls are a partial safeguard. Leonardo says its EOC software supports multilevel access and user auditing so activity can be reviewed. Those are important design features because a searchable archive creates insider-use and mission-expansion risks that a live-only sensor would not. Auditability is useful only if somebody actually reviews the logs and enforces rules. Agencies need role-based permissions, case or purpose fields, limits on bulk queries, alerts for unusual searches and disciplinary consequences for misuse. GAO’s 2024 review of DHS monitoring technologies found that high-level privacy assessments do not always translate into technology-specific operational policies, and recommended policies that implement protections for users. SignalTrace was not evaluated by GAO, but the governance lesson applies directly to any law-enforcement database.

Data architecture also shapes cybersecurity consequences. The more historical associations a server contains, the more revealing unauthorized access could become. The risk is not limited to a stolen list of plates; a breach could expose repeated locations, device clusters, inferred relationships, query histories and investigative interests, depending on what an agency stores. Data minimization reduces both privacy exposure and breach value. Public descriptions reviewed here do not disclose SignalTrace’s complete security architecture, encryption implementation, vulnerability-management process or customer-specific network configuration, so it would be improper to claim either that the system is insecure or that it is immune from compromise. A responsible assessment asks what information exists, who can reach it, how long it survives and how recovery or breach notification would work.

The policy debate should therefore resist fixation on the physical camera pole. Two agencies can buy the same sensor and create very different privacy outcomes through retention, search scope, sharing, alerting and oversight. Leonardo states that LPR data collected by an agency belongs to that agency and that the agency decides whether and with whom to share it. That makes local governance a central part of the effective system specification. Procurement should document server ownership, retention defaults, deletion processes, query capabilities, audit-log duration, administrator privileges, interagency access and export functions before deployment. The meaningful surveillance unit is not the antenna alone. It is the complete pipeline from capture to correlation, storage, search, alert, sharing and eventual deletion.

Leonardo’s privacy argument is narrower than the policy question

Leonardo makes a clear privacy claim about SignalTrace: the system observes publicly broadcast electronic signals and does not decrypt communications, read message content or retrieve information stored on personal devices. That is an important boundary and should not be blurred. A passive receiver that records broadcast identifiers and timing is different from malware, a phone search, wiretap or cellular interception system that accesses content. The company’s 2026 announcement also says SignalTrace does not identify individuals and creates anonymous electronic signatures. Those statements describe what the sensor is not designed to collect. They do not, by themselves, answer whether stored metadata, repeated locations and correlations with other records can create information about an identifiable person.

Privacy law and security practice routinely distinguish content from metadata without assuming metadata is harmless. NIST’s PII definitions include information that can distinguish or trace a person when combined with linked or linkable information. The FTC’s location-data cases show a regulator treating device-linked location histories as sensitive because they can reveal movements and visits even when the underlying dataset is organized around identifiers rather than a person’s message content. No-content collection can still be highly informative collection. SignalTrace is not the same as a commercial location broker, and the FTC orders do not govern it merely by analogy. The relevant lesson is about data structure: persistent identifiers, timestamps and locations can acquire personal meaning through correlation.

The manufacturer also compares the product’s privacy model with license plate readers, which capture plate numbers rather than driver information. That comparison is useful but incomplete because SignalTrace is marketed specifically to add another dataset to LPR. The combined system is more informative than either observation considered alone. A plate can anchor a vehicle; a recurring device cluster can persist when the plate is absent or changed; a person-carried device may appear in another vehicle; repeated co-occurrence can suggest relationships. Leonardo presents those capabilities as investigative benefits. Privacy analysis must therefore evaluate the combined inference, not just whether the initial radio packet includes a name. The same correlation that creates utility is the mechanism that can transform unlabeled signals into person-associated leads.

Another part of Leonardo’s argument concerns public broadcast. Wireless devices emit radio energy into shared spectrum so nearby receivers can perform functions such as discovery and connection. Yet operating a protocol in public does not automatically resolve every legal or ethical question about systematic collection and long-term analysis. Observability is not identical to unlimited secondary use. U.S. Fourth Amendment doctrine has historically treated some public movements differently from private records, but Carpenter and the Supreme Court’s 2026 Chatrie decision show that technology-assisted aggregation of digital location information can trigger constitutional protection in contexts involving provider-held phone location data. Those holdings do not directly decide passive roadside radio sensing; they show why duration, comprehensiveness, source and method matter to the legal analysis.

European law approaches the issue through a different statutory framework. The Law Enforcement Directive applies to processing of personal data by competent authorities for criminal-law purposes, uses a technologically neutral approach, and requires lawful, fair processing for specified purposes with data adequacy, relevance and retention limits. Whether a particular SignalTrace signature is personal data would turn on identifiability and the surrounding means of linkage under applicable law. Calling a signature anonymous is a factual and legal claim that must survive the full linkage context. If an agency routinely joins the signature to a plate, registration information and movement history, regulators would examine the processing operation as a whole rather than only the raw radio value. National implementation and specific legal authority would still matter.

The productive policy discussion begins after accepting Leonardo’s narrow claim on its own terms. Assume the system does not decrypt content and does not extract a name from a phone. The remaining questions are still substantial: which broadcasts are captured, how persistent the signatures are, how accurately they are matched to vehicles, when a cluster becomes person-linked, how long records remain searchable, who can run association queries, what outside databases are joined, and what evidentiary weight officers give the output. Those questions do not accuse the product of capabilities it lacks. They examine the capabilities it advertises. Privacy is not only secrecy of message content; in a correlation system, it is also the governance of relationships inferred from repeated observations that individual devices reveal as they move through public space.

The patents describe tracking targets across locations

SignalTrace’s public marketing explains the user-facing idea, but Leonardo’s patent provides a more detailed view of the underlying analytical model. U.S. Patent No. 11,941,716 describes systems and methods for identifying and tracking targets using visual identifiers and electronic signatures. Its collection systems can include cameras and radio receivers, with examples such as Bluetooth, Wi-Fi and RFID antennas. The intelligence system receives observations, extracts identifiable electronic signatures, determines relationships between signals and targets, and can track targets through later captures. The patent does not prove that every claimed implementation is deployed or that every signal can be collected reliably in real traffic. It does show that cross-location tracking and relationship inference are central to the protected invention, not a speculative interpretation added by critics.

The claims are especially revealing about correlation. They describe relationships based on the frequency with which visual identifiers and electronic signatures are captured, their selected proximity and the time of capture. A target may be a person or a vehicle, and the system can assign a relative certainty value to an association before treating a signal or combination of signals as an electronic signature. The patented logic is explicitly probabilistic and relational. This matters because a plate read and a radio emission are not inherently tied together. Software creates that tie from repeated observations. The patent’s certainty threshold therefore marks the point where a collection of observations becomes operationally classified as belonging with a target, even though public product literature does not disclose the commercial threshold or calibration method.

The patent also describes user searches and movement records. Claims cover interfaces that can search known visual identifiers, known electronic signatures or combinations, and then provide records of movement using subsequent captures. Other claims refer to maps showing routes or predicted routes and associations between targets and electronic devices. SignalTrace’s privacy significance lies partly in this searchable history, not simply in the instant a roadside sensor detects a broadcast. A police user who begins with one known plate could, in principle within the patented architecture, look for electronic signatures associated with it, then follow later sightings of those signatures even if a visual identifier is unavailable. Conversely, a known electronic signature could become the starting point for identifying related vehicle observations.

A continuation of the patent family was issued in April 2026, showing that Leonardo continued pursuing protection around the same electronic-signature tracking concept. Patent documents are legal descriptions of inventions and claim scope; they are not field-test reports, procurement records or proof of actual customer configuration. Patent breadth must not be mistaken for verified operational reach. Engineers often draft claims to cover multiple embodiments and future implementations. The correct use of the patent in reporting is therefore narrow but important: it establishes that Leonardo has formally claimed architecture for correlating visual identifiers and electronic emissions, tracking targets over successive locations and displaying relationships. It does not establish how many agencies use those functions, which protocols are enabled at a particular site or how accurately a commercial installation performs.

The patent language also clarifies a point about people who have no plate of their own. Some claims contemplate collection systems at locations accessible or inaccessible to vehicles and tracking based on electronic signatures associated with devices. Leonardo’s product page separately says SignalTrace can work in off-road areas such as subways and malls and without plate readers at every collection site. The conceptual unit is the recurring signature, not the license plate. LPR supplies a powerful anchor, but once a signature has been associated with a target, the patented system can use later electronic captures as part of the tracking process. That design explains why the technology cannot be understood merely as an upgraded plate camera. It is a multi-sensor correlation platform in which the plate is one possible identifier among several.

For oversight bodies, the same architecture raises questions about purpose, retention, accuracy and legal thresholds. A narrowly targeted query for a known target is different from building years of searchable associations for every passerby. The patent itself does not prescribe those governance limits. It describes what the system can be designed to do. Policy therefore has to sit outside the patent: deciding which collection modes are authorized, how a target is established, when confidence is sufficient, whether non-target observations are retained and what independent evidence is required before a relational match affects a person. The technical document supplies the map of possibilities; lawful operational rules determine which paths agencies may actually take.

Deployment evidence remains limited and uneven

Public interest in SignalTrace has grown faster than the public evidence about where it is operating. Leonardo has marketed the technology, first as EOC Plus and now as SignalTrace, and public procurement material shows that predecessor hardware and licensing were available through at least one government contract. Independent researchers have also identified roadside equipment in Maryland that appears consistent with the product. Yet availability, physical resemblance and operational use are three different facts. None should be substituted for another. The public sources reviewed for this article do not provide a comprehensive, verified list of police agencies actively collecting SignalTrace data, their installation counts, their retention rules or the number of investigative queries they have run.

Ryan O’Horo has documented equipment he believes to be SignalTrace installations in the Oxon Hill area of Prince George’s County, Maryland, comparing visible hardware with Leonardo materials and pursuing public records. Biometric Update reported on those apparent installations while noting that their operational status and data use had not been publicly confirmed. That is evidence worth investigating, not a basis for declaring a confirmed surveillance program. A photograph may show a field control unit and antennas, but it cannot reveal software configuration, which receivers are active, whether records are stored, who has access or whether the equipment is being tested rather than used operationally. Responsible reporting should keep those unanswered questions attached to the claim.

The New York State procurement record creates a different kind of evidence. A state price list dated in 2025 included EOC Plus hardware configurations and software licensing among Leonardo products available under contract. That proves a procurement channel existed for the predecessor system. A catalog entry does not prove that any particular eligible agency bought or deployed it. Government framework contracts routinely list products that buyers may purchase later, and price schedules can outlive individual buying decisions. To establish actual use, researchers need purchase orders, invoices, installation records, acceptance documents, network diagrams, training materials, policy documents or agency confirmation. Without such records, the most that can be said is that the technology was commercially and contractually available.

Leonardo’s 2026 announcement broadened the product’s framing beyond law enforcement, describing transportation analytics, infrastructure monitoring, security, research and public safety. The current product page, however, continues to present SignalTrace as an investigative tool for law enforcement and describes integration with ELSAG’s operations software. The buyer universe may be broader than police, but police use remains a stated market. That distinction matters because legal authority, data-sharing rules and public-record obligations differ among police departments, transportation agencies, private facilities and research organizations. A sensor installed on a roadside should not automatically be attributed to a police agency solely because the technology has a law-enforcement use case. Ownership and operator should be verified independently.

Deployment opacity also makes prevalence claims risky. Existing ALPR networks are widespread, and a radio-sensing add-on could theoretically reuse locations, power and network connections, but that does not mean current plate-reader poles have SignalTrace. Most license plate readers should not be described as device scanners. SignalTrace requires separate sensing capability and software designed to collect and correlate wireless emissions. The ordinary ALPR model remains image-based: cameras read plates, record time and location, and store searchable vehicle observations. Conflating the technologies exaggerates present deployment and makes it harder to identify the specific sites where expanded collection actually occurs. EFF’s ALPR overview is useful for that baseline even though its broader policy positions are advocacy rather than vendor-neutral testing.

The most defensible status statement in August 2026 is therefore modest. SignalTrace is a real, patented, actively marketed technology with an earlier product name and documented procurement availability. Independent analysts have reported apparent installations, but the reviewed record does not establish a nationwide installed base or routine police use at scale. That uncertainty is not a reason to ignore the product. It is a reason to ask better questions of agencies: whether they own or lease it, when sensors were installed, whether wireless collection is active, what frequencies and protocols are enabled, how much data has been retained, which databases are joined, how many users can query it, and whether any alerts or investigative actions have relied on its output. Those answers should come from records and officials, not inference from a roadside box alone.

Until agencies release those records, deployment claims should remain tied to evidence that can be inspected, with unknown operational status stated plainly rather than filled by assumption.

Procurement availability is not proof of operational use

Government procurement documents are attractive evidence because they are official, dated and often specific about model names and prices. They are also easy to overread. New York’s Office of General Services published a Leonardo contract price list that included EOC Plus, the predecessor name of SignalTrace, in several hardware configurations. The list showed field-control-unit options and a software license, establishing that eligible public buyers had a contractual path to obtain the product. This is stronger evidence than a marketing brochure for one narrow proposition: the system was offered through a government purchasing vehicle. It still does not identify which agencies placed orders, where equipment was installed, whether installation reached acceptance or what operational policies governed use.

A framework contract works more like an authorized menu than a receipt. Public agencies may negotiate a catalog of eligible products and discounted prices so later purchases can occur without rebuilding every contractual term. Presence on the menu proves eligibility, not consumption. Researchers looking for actual deployment should follow the procurement chain to purchase orders, task orders, invoices, shipping records, installation work, maintenance tickets and payment data. Each document answers a different question. A purchase order can show intent to buy; an invoice can show billing; a site survey can identify planned locations; an acceptance record can show delivery or commissioning. None alone necessarily proves that sensors are currently collecting data. The distinction matters when reporting surveillance technology, where an unsupported claim of active monitoring can alarm residents and damage credibility.

The same discipline applies to product names. Leonardo’s August 2026 announcement says SignalTrace is the new name for the technology formerly known as EOC Plus. That linkage permits older procurement records to illuminate the product’s history. It does not mean every EOC Plus line item equals the current SignalTrace configuration. Leonardo described the rebrand as accompanying years of refinement and expanded capabilities. Hardware revisions, software versions and supported signal classes can change. A researcher should record the exact model, contract date, quoted options and firmware or license version where available instead of assuming that a 2025 configuration has every capability marketed in 2026. Product evolution is especially relevant when technical criticism focuses on antennas, receiver bands or protocol support.

Pricing itself can mislead without context. A contract schedule may contain list prices, discounts, optional modules, annual licenses and hardware variants with or without particular radios or modems. The cheapest line is not the cost of a complete operational site, and the most expensive line is not proof of what an agency paid. Installation may require mounting, power, network backhaul, server capacity, maintenance and integration with LPR or EOC systems. Conversely, agencies with existing infrastructure may reuse components. The New York price list should therefore be cited as a historical procurement artifact, not converted into a universal per-camera cost. A precise budget estimate would require the actual bill of materials and contract for a specific project.

Procurement records are still valuable for accountability because they reveal what officials contemplated buying and which vendor terms may apply. They can lead to privacy assessments, statements of work, data-ownership clauses, insurance requirements, cybersecurity exhibits and records-retention schedules. The policy documents around the purchase may matter more than the price. Leonardo’s current page says an agency controls its LPR data and chooses whether to share it, while EOC provides access controls and auditing. An actual contract can show whether those general statements are reflected in customer-specific obligations, cloud architecture, support access and deletion terms. Public-record requests should therefore seek the complete contracting package rather than only the product invoice.

The evidentiary hierarchy is straightforward. Vendor marketing proves what the vendor says the product is designed to do. Patents show claimed invention architecture. Price lists prove commercial availability under stated terms. Purchase records show acquisition. Installation and network records show deployment. Audit logs, policies and case records show use. Independent testing shows performance. No single layer substitutes for the others. SignalTrace reporting becomes more reliable when claims are tagged to the layer that supports them. At present, the public record supports strong statements about the product’s design, patent and procurement availability, while broader claims about operational police prevalence remain much less certain. That distinction is not pedantry; it is the line between documenting a capability and inventing a deployment history the evidence has not established.

For that reason, a procurement document should be treated as one evidentiary layer, then followed through to records that show delivery, configuration, policy and actual queries.

Police incentives favor richer searchable associations

License plate readers became useful to police because they convert fleeting vehicle sightings into searchable records. SignalTrace adds another class of observations that can persist when a plate is unknown, altered or absent. From an investigative perspective, a recurring electronic signature creates another key for searching the same movement problem. Leonardo markets the system as a way to identify groups of devices that travel together, correlate signatures with vehicle observations, recognize recurring associations and follow signatures that appear with different vehicles. Those functions address real investigative difficulties: vehicles can be shared or switched, plates can be obscured, and a target may move through locations where a camera cannot obtain a plate.

The incentive to collect more is therefore structural. Every additional sensor observation can reduce uncertainty later, even if it has no immediate relevance at collection. A plate reader database is more useful when it contains many ordinary vehicle passages because investigators can search backward after a crime. SignalTrace follows the same retrospective logic with wireless emissions. Records about uninvolved people create investigative value precisely because their future relevance is unknown. That creates tension with data-minimization principles, which favor retaining only information necessary for defined purposes. The tension cannot be resolved by saying one side is irrational: detectives value historical coverage, while privacy rules seek limits on indiscriminate accumulation. Governance has to choose how much retrospective power is justified and under what threshold.

Existing ALPR experience shows why purpose limits deserve attention. EFF’s 2026 analysis of millions of Flock Safety search records argued that plate-reader databases were used for matters extending beyond serious crimes, including school residency checks, background checks and noise complaints. Flock is a different vendor and those findings do not describe Leonardo customers. The example demonstrates mission expansion in a neighboring technology class, not a proven SignalTrace practice. When a searchable system is convenient and already available, agencies may find new uses that were not central to the original public justification. A SignalTrace policy should therefore define authorized purposes before routine access, rather than relying on the product’s marketing examples as a permanent boundary.

National and interagency sharing can increase that incentive. GAO reported that selected DHS law-enforcement agencies had agreements to query or view information from third-party ALPR sources, providing access to a nationwide source of plate data. SignalTrace’s current product page says an agency controls its collected LPR data and decides whether and with whom to share it. Local collection can acquire a much larger practical reach through sharing. The public materials reviewed here do not establish a nationwide SignalTrace sharing network, so such a network should not be asserted. The relevant governance question is whether device-signature records can be exported, federated or queried by outside agencies, and whether audit logs preserve the purpose and identity of external users.

Analysts also have an incentive to connect datasets because correlation is the product’s value proposition. Registration records, known plates, case files, maps and other sensor observations can turn an unlabeled signature into a useful lead. Yet each join can increase both information and error. Richer association graphs create more hypotheses, not automatically more truth. A weak radio-to-vehicle match can become more persuasive after it is displayed alongside a name and route, even if the underlying link remains uncertain. Good interface design should preserve confidence and provenance instead of flattening every association into the same visual status. Supervisors should be able to see whether a relationship came from a direct record, repeated algorithmic co-occurrence, user annotation or independent corroboration. Leonardo’s patent contemplates certainty values, making this distinction technically compatible with the claimed architecture.

The institutional challenge is to preserve the legitimate benefit of searchable associations without allowing the database to become a general-purpose record of everyone’s movements and companions. That requires policy choices that technology cannot make: target criteria, retention periods, query authorization, sensitive-location rules, supervisory review, external sharing, disclosure obligations and consequences for misuse. GAO’s work on public-space monitoring emphasizes that policies must implement privacy protections at the technology-use level. SignalTrace’s own marketing says use should occur within established legal, operational and governance frameworks. Those two perspectives meet at the same point. A richer sensor does not remove the need for investigative judgment. It increases the number of facts and apparent facts that judgment must handle responsibly.

That restraint preserves investigative utility while making purpose, access and proportionality visible decisions rather than defaults created by the mere existence of a searchable archive.

U.S. and European law ask different threshold questions

SignalTrace raises different legal questions depending on jurisdiction because there is no single global rule for roadside wireless observation. In the United States, the immediate constitutional issue is usually framed through the Fourth Amendment: does a particular government collection or later acquisition amount to a search, and if so was it reasonable? Supreme Court cases such as Carpenter and Chatrie protect certain digital location information, but neither case decides the legality of passive SignalTrace sensing. State constitutions, statutes, local surveillance ordinances and agency policies may add protections beyond the federal floor. In the European Union, police processing of personal data is principally addressed through the Law Enforcement Directive as implemented by member states, with attention to legal basis, purpose, necessity, proportionality, accuracy, retention and security.

Table 2. Legal questions the same SignalTrace record can raise

StageU.S. legal questionEU law-enforcement data question
Roadside captureDoes passive collection implicate a reasonable expectation of privacy or another applicable rule?Is the observed or linked information personal data processed by a competent authority under a lawful basis?
Historical aggregationDoes scale, duration or retrospective tracking change the Fourth Amendment analysis?Is retention necessary, proportionate and limited to the stated law-enforcement purpose?
Identity linkageDoes joining signatures to other records trigger statutory, constitutional or policy restrictions?Can the data identify a person directly or indirectly, and is the linkage compatible with the authorized purpose?
Search and alertsWhat process is required before querying or acting on stored associations?Are access, purpose, accuracy and safeguards appropriate for the processing operation?
SharingWhich federal, state, local or contractual rules control disclosure and outside access?Do the Directive’s rules and national law permit the recipient, purpose and any onward transfer?
Error correctionWhat disclosure, evidence and due-process protections apply when a match affects a person?Are inaccurate personal data corrected or erased and are decisions supported by appropriate safeguards?

The comparison is a framework for analysis, not a legal ruling on SignalTrace; actual requirements depend on the facts, jurisdiction, purpose and applicable national or state law.

The U.S. analysis cannot be reduced to “it happened in public, so no warrant is ever needed.” Carpenter stressed that digital technology can alter the privacy consequences of location tracking, even though earlier doctrine allowed limited observation of vehicles on public roads. In June 2026, Chatrie held that police conducted a Fourth Amendment search when they acquired an individual’s Google Location History data because people have a reasonable expectation of privacy in cell-phone location information. Chatrie involved a warrant to a third-party provider and a detailed stored location service, not a roadside receiver listening to broadcast radio. That factual difference is substantial, and a court considering SignalTrace would need to analyze its own collection method, precision, duration, aggregation and later use.

The European framework begins from processing of personal data rather than the U.S. constitutional search concept. The Law Enforcement Directive states that protection should be technologically neutral and applies to competent authorities processing personal data for prevention, investigation, detection or prosecution of crime and related public-security purposes. It requires processing to be lawful and fair, tied to specified purposes, and limited through principles such as adequacy, relevance and storage limitation. A supposedly anonymous radio signature may still require analysis of indirect identifiability when it is routinely correlated with a plate, location history or other records. Whether a specific identifier is personal data depends on the surrounding means and national implementation, so a definitive conclusion cannot be made from the product name alone.

The two systems also differ in institutional structure. U.S. police powers are fragmented among federal, state and local authorities, with privacy rules varying markedly across states and cities. European member states implement the Directive through national law under an EU rights framework and supervisory authorities. A deployment that is lawful in one place cannot be assumed lawful elsewhere. Procurement officials therefore need jurisdiction-specific legal review before collection starts, not a generic vendor assurance that the system observes public-domain emissions. The review should cover initial sensing, storage, linkage, search, automated alerts, sharing, retention and use as evidence or investigative justification. A narrow answer about the first radio packet can miss later processing that creates the stronger privacy effect.

Legal analysis also changes with purpose. A short-lived traffic-engineering count based on nonpersistent signals presents a different case from a police archive designed to track recurring signatures and identify relationships. SignalTrace is marketed for multiple sectors, while its law-enforcement page describes investigative leads and historical querying. Purpose determines which authority, safeguards and proportionality arguments are relevant. The same hardware can support distinct legal regimes depending on who operates it and what records are retained. Courts and regulators will also care about facts that public marketing does not answer: data precision, persistence, false associations, retention period, user permissions and whether people can be identified through ordinary linked records.

For readers, the safest conclusion is precise rather than dramatic. Neither U.S. Supreme Court precedent nor EU legislation reviewed here creates a one-sentence rule declaring SignalTrace categorically lawful or unlawful. The U.S. constitutional question remains fact-dependent because the closest high-court cases concern different forms of digital location data. European deployment would require analysis under the Law Enforcement Directive and relevant national law where police processing involves personal data. Agencies should document that legal reasoning before use and revisit it if software changes increase persistence, expand signal classes or connect new databases. A technology built around correlation can cross legal thresholds through accumulated capability even if no single hardware replacement is dramatic.

That review should also identify who owns the data, which users can search it, what legal process applies to historical queries, and whether a person can challenge an erroneous association once the system has connected a recurring signature to a case.

Fourth Amendment doctrine now treats some digital location data as protected

The U.S. Supreme Court’s location-privacy doctrine matters to SignalTrace because the product is built to create and search movement associations, but the precedent must be handled carefully. In Carpenter v. United States, decided in 2018, the Court held that government acquisition of historical cell-site location information was a Fourth Amendment search. The majority focused on the revealing nature of a long-term digital record of physical movements and the way cell phones accompany people. Carpenter rejected a mechanical assumption that disclosure to a third party always eliminates privacy in digital location records. It did not hold that every observation of movement in public is a search, and it expressly described its decision as narrow.

Carpenter contrasted its facts with older vehicle-tracking doctrine. In United States v. Knotts, police used a beeper to help follow a vehicle during a discrete journey on public roads, and the Court found no reasonable expectation of privacy in movements exposed to public view. Later, United States v. Jones involved GPS tracking of a vehicle for twenty-eight days; the majority resolved that case through physical trespass, while concurring justices raised broader concerns about long-term monitoring. Duration and technological power became part of the constitutional conversation. Carpenter drew on those concerns when it treated an automatically generated historical location archive as different in kind from limited visual surveillance. SignalTrace similarly invites questions about accumulation, but its direct passive sensing remains factually distinct from carrier records or a government-installed GPS device.

The Supreme Court added a major new piece in Chatrie v. United States on June 29, 2026. Police had obtained Google Location History data through a geofence warrant surrounding a robbery location. The Court held that acquiring Chatrie’s location data from Google was a Fourth Amendment search because an individual has a reasonable expectation of privacy in cell-phone location information. Chatrie confirms that even a relatively short slice of highly detailed phone location history can receive constitutional protection. The opinion emphasized precision, retrospective capability and the intimate character of location information. It then returned the case for further proceedings on the validity of the warrant rather than deciding every issue around geofence warrants.

SignalTrace differs in at least three ways that could matter legally. It passively receives broadcast wireless emissions rather than compelling a provider to disclose a user’s stored location journal. The initial signal may not identify a person. Its location precision is tied to the fixed sensor site rather than continuous phone positioning. Those differences make Chatrie an analogy, not a direct rule for SignalTrace. On the other hand, Leonardo’s patent and product materials contemplate storing observations, tracking recurring signatures across locations, correlating them with plates and generating movement records. A court could care about the practical result of sustained aggregation even if the technical path differs. No reviewed Supreme Court decision squarely resolves that combination.

Another unresolved issue is the significance of a device broadcasting radio information into public space. Traditional doctrine often treats what a person knowingly exposes to public view differently from information kept private, and police can ordinarily observe a car traveling on a road. Wireless emissions complicate the intuition because devices communicate automatically, often without users understanding each transmission or identifier. Modern Apple and Android systems deliberately randomize Wi-Fi identifiers to reduce passive tracking. Technical broadcast does not necessarily equal informed human disclosure, but whether that fact changes a Fourth Amendment result for a particular passive collection method remains a legal question rather than an established holding. Courts may examine social expectations, automation, persistence and the scope of aggregation.

For agencies, uncertainty is a reason for cautious process, not a license to choose the most convenient interpretation. A warrant, court order or other legal process may be prudent for certain historical or person-linked searches even if initial sensing occurs without one, depending on jurisdiction and facts. Local ordinances and state constitutions may impose separate rules. Policy can set a higher internal threshold than the minimum federal constitutional floor. A defensible system should log the legal basis for sensitive queries, preserve data provenance, limit retrospective searches and obtain counsel review as capabilities change. The constitutional risk grows most clearly when a system moves from isolated public observations toward a durable, person-linked record of movements and associations—the very transformation that correlation technology is designed to make possible.

The constitutional boundary will depend on facts that courts can test, including sensor range, identifier persistence, aggregation period, search capability and the degree to which a signature becomes linked to a specific person.

Open-air radio capture remains a legally unresolved step

The hardest U.S. legal question for SignalTrace may arise before the database has built a history: does government reception of a device’s ordinary broadcast radio emission itself constitute a Fourth Amendment search? The Supreme Court cases most relevant to digital location privacy do not answer that question directly. Carpenter involved historical records held by wireless carriers. Chatrie involved Google Location History obtained through legal process. Kyllo involved thermal imaging directed at a home, and Jones involved a tracking device physically attached to a vehicle. SignalTrace, by contrast, is marketed as a passive receiver of signals already broadcast into public space. Each precedent contributes a principle, but none maps neatly onto that architecture.

The government would have arguments on one side. Courts have long permitted officers to observe what is exposed to public view, and Knotts treated limited tracking of a vehicle on public roads as outside the reasonable expectation of privacy asserted there. Leonardo emphasizes that SignalTrace does not access stored device information or communications and listens only to public-domain emissions. A single noncontent radio observation at a public roadside may look more like enhanced observation than a search of private storage. The strength of that analogy would depend on exactly what technical information is captured and whether collection reveals something that ordinary observers could not practically obtain. Product marketing alone cannot resolve the constitutional classification.

Privacy advocates and defendants would have different arguments. Modern phones and wearables emit signals automatically as part of normal operation, and operating-system vendors have added randomization specifically to frustrate passive tracking by observers. A person may have little practical choice but to carry a connected device for ordinary life without intending to publish a persistent identity. Automated machine observability is not obviously equivalent to deliberate disclosure by the user. Carpenter cautioned against applying older third-party concepts mechanically to pervasive digital location technology, while Chatrie extended protection to detailed location history despite the user’s relationship with Google. Whether those principles reach direct radio reception will depend on future litigation and the factual record.

Aggregation can create a second legal step even if the first capture is allowed. A court might treat one roadside observation differently from weeks or months of searches that reconstruct a person-linked route. SignalTrace’s patent contemplates successive captures, movement records and maps, while the product page describes stored data and recurring travel patterns. Constitutional analysis may turn on the system’s practical surveillance capacity rather than one packet in isolation. Carpenter’s reasoning about the comprehensive nature of historical tracking and Chatrie’s focus on detailed retrospective location records give defendants material for that argument. Still, both cases involved provider-held location datasets with characteristics not established for SignalTrace. Any prediction about how the Supreme Court would rule on the latter would be speculation.

Statutes and state law may fill gaps before federal constitutional doctrine does. Some jurisdictions regulate surveillance technology procurement, automated plate-reader databases, electronic communications or location information more strictly than the federal baseline. A federal Fourth Amendment answer is not the whole legal answer. The reviewed sources do not support a fifty-state survey specific to SignalTrace, so this article does not claim uniform rules. Agencies considering deployment need local counsel to map radio collection, database linkage and query practices onto state constitutions, statutes, municipal ordinances, collective policies and evidence rules. A product sold nationally can encounter materially different legal conditions from one city or state to another.

The responsible editorial conclusion is therefore deliberately limited. SignalTrace’s current public design raises a serious Fourth Amendment question, especially once recurring signatures become linked to people and searched historically, but no reviewed U.S. Supreme Court case adjudicates this exact passive-radio system. Legal uncertainty should be stated as uncertainty, not converted into a verdict. Police agencies can reduce risk by narrowing collection, limiting retention, requiring articulated investigative purpose for association searches, documenting legal process and obtaining independent review before treating long-term signature tracking as routine. Courts will eventually need a factual record about what the sensors actually capture, how persistent signatures are and how records are used. Until then, confident claims that the system is categorically constitutional or categorically unconstitutional outrun the available precedent.

A future court may distinguish live detection from database querying, or may treat the combined process as one surveillance practice. The answer will depend on evidence about persistence, coverage and linkage rather than the marketing description alone, making transparent technical documentation especially important for litigation and oversight.

European rules would focus on identifiability, necessity and purpose

For police use in the European Union, the central framework is not the GDPR in its ordinary commercial form but the Law Enforcement Directive, Directive (EU) 2016/680, as implemented in member-state law. It covers competent authorities processing personal data for purposes such as preventing, investigating, detecting or prosecuting criminal offences and safeguarding against threats to public security. The Directive is technologically neutral, so a novel radio identifier does not escape scrutiny merely because legislators did not name SignalTrace. The first legal questions would include whether the data relate to an identified or identifiable person, what legal basis authorizes the processing, whether collection is necessary for the law-enforcement task and whether safeguards match the risks.

Identifiability is especially relevant because Leonardo describes SignalTrace signatures as anonymous. A raw radio observation may contain no name, but the system is designed to correlate recurring signatures with plate observations and other operational data. Data can become person-related through indirect linkage. EU data-protection law generally treats identifiability as a contextual question, and the Law Enforcement Directive requires attention to processing of personal data throughout the operation rather than only the original collection format. If a police agency can reasonably connect a recurring signature to a registered vehicle, known address, case file or other identifier, it would need to assess that linkage in deciding whether the information is personal data under applicable law. A vendor label cannot substitute for the controller’s legal analysis.

Purpose limitation is another pressure point. The Directive says personal data should be processed lawfully and fairly for specified purposes, and its recitals emphasize that data should be adequate, relevant and not excessive. A SignalTrace deployment justified for a defined serious-crime investigation presents a different proportionality case from continuous retention of every detectable signature for undefined future use. Collection scope and retention have to be justified against the stated purpose. Leonardo’s own product materials describe both stored historical querying and multiple potential sectors, so a European authority would need to document the exact law-enforcement purpose rather than relying on the technology’s general versatility. National legislation may specify additional conditions, including authorization and supervisory requirements.

Accuracy also matters because SignalTrace creates inferred relationships. The Directive includes principles concerning accurate data and correction or erasure where necessary. A radio observation may be technically accurate while the inferred relationship to a vehicle or person is uncertain. The confidence of an algorithmic association should not be flattened into a categorical fact. Records should preserve whether a linkage was direct, repeated, inferred or independently corroborated, and systems should allow correction when later evidence disproves an association. This is particularly important for passengers, neighboring vehicles and people who repeatedly occupy the same area. The public product materials do not reveal a universal false-association rate, so European controllers would need their own evidence that accuracy is suitable for the intended operational use.

Retention and sharing are equally concrete. The Directive stresses that personal data should not be kept longer than necessary and sets rules for transfers and onward transfers. Leonardo’s page says collected data may be archived in EOC and that agencies decide whether to share their LPR data. A technical ability to archive or share does not itself supply legal authority. An EU police deployment would need retention schedules, access controls, deletion procedures, logging and rules for recipients grounded in national law implementing the Directive. Where data move across borders or outside the Union, additional transfer provisions may apply. The exact result depends on controller, recipient and legal basis, so a generic product policy cannot answer it.

European law therefore forces attention onto the complete processing chain: capture, correlation, identifiability, purpose, accuracy, access, storage, sharing and deletion. It does not make every new police sensor unlawful, nor does public radio transmission automatically make every processing operation lawful. Necessity and proportionality have to be demonstrated for the actual use. A strong deployment record would explain why SignalTrace is needed, which crimes or threats justify it, which signal classes are collected, how non-target data are handled, how long records remain, how matches are validated and what oversight exists. Those questions are not bureaucratic extras. They define whether a system that starts with anonymous-looking emissions becomes a lawful targeted investigative tool or an unjustified database of linkable movements.

Procurement records and operational policies should make those limits reviewable before data accumulate, because later deletion cannot fully undo investigative decisions, alerts or associations already generated from records that should not have been retained.

Retention limits and audit trails matter as much as sensors

SignalTrace’s privacy consequences are determined after collection as much as during it. Leonardo says the product stores data on a server for query and analysis, while its EOC software offers user auditing and can archive collected data. Those are operational capabilities, not a complete retention policy. The agency decides whether a fleeting roadside observation becomes a durable historical record. A system that deletes unmatched signatures quickly exposes fewer innocent travelers to retrospective searching than one that preserves years of movements. The sensor hardware can be identical in both deployments. For oversight, the decisive documents are therefore the retention schedule, deletion logic, access-control matrix and audit policy rather than only the equipment brochure.

Retention should distinguish among investigative states. A record associated with an active case may justify a different period from an uncorrelated observation collected from ordinary traffic. A signature that was algorithmically attached to a plate but never confirmed may deserve stricter treatment than evidence preserved under a warrant. One retention period for every record ignores differences in purpose and confidence. Leonardo’s public page does not specify a mandatory customer-wide duration, leaving room for agency policy and applicable law. European law-enforcement rules expressly stress storage limitation, while U.S. practices can vary by jurisdiction. A defensible policy should state the trigger for preservation, automatic deletion dates, litigation holds, exceptions and who can extend a record’s life.

Audit trails answer a different question: who used the data and for what reason. Leonardo says EOC supports multilevel access and user auditing. That is a useful foundation, because a broad searchable archive creates opportunities for curiosity searches, personal misuse and purpose expansion. Logging every query is not the same as governing every query. An effective audit program records the user, time, search terms, case or purpose, records returned, exports made and any alert created. Supervisors need a routine for reviewing those logs, not merely the ability to retrieve them after a scandal. Unusual behavior—bulk searches, repeated queries involving acquaintances, sensitive locations or out-of-jurisdiction cases—should generate review.

The distinction matters because public-space surveillance systems can drift toward uses that were not central to their original justification. EFF’s 2026 analysis of Flock ALPR searches reported examples involving low-level matters such as residency checks and noise complaints. That analysis concerns another vendor and cannot be used to claim SignalTrace customers behave the same way. It does demonstrate why purpose fields and audit review are concrete safeguards rather than paperwork. If an agency promises that electronic-signature searching will be limited to serious crimes or defined investigations, query logs are the evidence that can test the promise. Without usable logs, public oversight depends on policy text alone.

Deletion also needs verification. An agency may remove a record from the user interface while backups, exports, partner copies or derived intelligence remain. A complete policy should specify whether deletion propagates to indexes, backups and shared systems, and how long technical recovery copies persist. Derived associations can outlive the raw observation that created them. If a device-to-vehicle link is saved in a case file, deleting the original sensor packet does not erase the conclusion. Agencies should therefore record provenance and correction status so an invalidated link can be withdrawn wherever it was used. European accuracy and storage principles support this kind of lifecycle thinking, and good evidence practice supports it even where no identical statutory rule applies.

GAO’s 2024 review of DHS monitoring technologies reached a related institutional conclusion: privacy protections need to appear in technology-use policies that users actually follow. SignalTrace was not assessed in that report, but its architecture makes the lesson particularly relevant. Retention, access, query purpose, sharing and deletion are settings that turn a passive sensor into a continuing surveillance capability. Oversight should measure those settings and their use, not infer safety from the absence of message interception. Procurement approval can require a published retention period, periodic access review, independent audit sampling, public statistics on queries and documented deletion tests. Those measures do not settle every legal question, but they make the system’s real scope observable to the people responsible for authorizing it.

Independent oversight can test whether those controls work in practice. Reviewers can sample queries against case files, verify that expired records are actually deleted, compare administrator privileges with job roles and publish aggregate findings without exposing active investigations. A retention promise becomes credible only when its implementation can be checked against system behavior.

Data sharing can multiply the consequences of a local collection

A sensor may sit on one local road while its data travel much farther. Leonardo’s current page says LPR data collected by an agency belongs to that agency and the agency chooses whether to share it and with whom. That statement places a major privacy decision at the customer level. If SignalTrace-derived associations are exportable or shared through connected systems, a local collection can become useful to investigators who never operated the original sensor. The reviewed materials do not establish a nationwide SignalTrace exchange, so it would be inaccurate to claim one exists. They do establish that data ownership and customer-directed sharing are part of Leonardo’s broader ELSAG model, making sharing policy a necessary deployment question.

Existing ALPR practice shows the scale that interagency access can reach. GAO reported in 2024 that the three DHS law-enforcement agencies it examined had agreements to query or view third-party automated license plate reader information, giving personnel access to a nationwide source of plate data. A local plate record can already enter a wider investigative environment. SignalTrace adds potentially different information: recurring device signatures and inferred relationships. GAO did not report a federal SignalTrace network, and the distinction must remain clear. The comparison matters because an agency evaluating the product should ask whether these newer fields can be federated, exported with plate records or searched by partners under existing agreements that were drafted for conventional ALPR data.

Sharing also magnifies errors. If one agency incorrectly associates a device cluster with a vehicle or person, a second agency may receive the relationship without seeing the confidence score or original sensor context. A copied lead can look like a verified fact after passing through several systems. Provenance must travel with the data. Shared records should identify the collecting agency, sensor, timestamp, protocol, confidence, method of association, retention status and any later correction. If the recipient receives only a simplified label—“device associated with subject”—it may not know that the relationship came from probabilistic co-occurrence rather than direct identification. Leonardo’s patent includes certainty values in its association logic, reinforcing the technical importance of preserving uncertainty downstream.

Purpose restrictions can also weaken during transfer. The collecting agency may authorize a search only for a robbery investigation, while a recipient sees the same dataset as available for immigration enforcement, intelligence analysis or a low-level administrative matter. Data-sharing agreements should bind recipients to defined purposes and deletion rules. The European Law Enforcement Directive contains explicit rules for transfers and onward transfers of personal data and seeks to preserve protection across borders. U.S. requirements vary more by law, contract and agency policy, but the governance problem is similar: once a copy leaves the original system, the collector’s internal access controls no longer provide complete protection. A useful agreement specifies permitted uses, onward disclosure, audit rights, security, retention and correction procedures.

Cross-database joining creates another expansion. A SignalTrace signature may be relatively opaque alone. Combined with a plate, registration record, historical ALPR database and case information, it can become much more revealing. NIST’s PII definitions recognize that identity can be inferred through linked or linkable information. Sharing increases the number of datasets available for re-identification. The FTC’s actions against location-data brokers illustrate the privacy consequences of connecting persistent device identifiers to location histories, though those commercial cases are not legal precedent for police SignalTrace use. They are evidence that linkability changes informational power. Agencies should inventory not only who receives raw records but which systems automatically enrich them after transfer.

A responsible local policy therefore cannot end with “we do not share outside the department” unless the technical architecture verifies that claim. Backups, vendor support, regional fusion centers, task forces, exports to prosecutors and responses to outside requests all create potential paths. The policy should identify each path and publish aggregate information where lawful. A person affected by a mistaken association also needs a way for a correction to reach every recipient. Otherwise a local error can persist in distant systems after the source record has been fixed. The practical lesson is straightforward: the privacy footprint of SignalTrace is bounded not by the sensor’s radio range but by the institutional network that can retrieve, copy and act on what the sensor helped create.

Before sharing starts, agencies should decide whether outside users receive observations, inferred signatures, plate links or only case-specific results. Each layer carries error and privacy consequences, so permissions should be narrower than the technical export function whenever the investigative purpose allows.

Sensitive associations can emerge without reading communications

A person’s messages can remain encrypted and untouched while movement metadata reveals intimate facts. The FTC’s actions involving commercial location data emphasized that precise device-linked locations could expose visits to medical facilities, places of worship, domestic-abuse shelters and other sensitive sites. SignalTrace uses a different collection method and public sources do not establish comparable precision or coverage, but the privacy mechanism is similar at a structural level: repeated location-linked identifiers can reveal patterns without message content. A recurring signature seen at a clinic entrance, political gathering, religious institution or another person’s vehicle may create an inference about activity or association even if the sensor never reads a single communication.

Leonardo’s product page specifically markets the ability to reveal signatures that frequently travel together and to identify travel patterns. That can be valuable in an investigation of a coordinated criminal group. The same relational technique can also expose ordinary relationships. Association data are powerful because people rarely move in isolation. A spouse’s device cluster, a child’s watch, a coworker’s laptop or a friend’s phone may recur near the same vehicle. If a signature later appears with another car, an analyst can form hypotheses about social links. Those hypotheses can be correct, partly correct or wrong for mundane reasons such as carpooling, borrowed equipment or devices left behind. The system’s value and its privacy risk come from the same correlation step.

Sensitive-place inference depends on sensor location and retention. A sensor positioned at a generic arterial intersection says less than one positioned at the only entrance to a particular facility. Multiple sensors can reveal direction and repeated visits even if none follows a device continuously. Placement choices are privacy choices. Agencies should therefore assess sites not only for investigative yield but for the likelihood of collecting sensitive associations unrelated to crime. Policies can restrict installations or historical searches around clinics, houses of worship, schools, protests, shelters, legal offices and other locations where association itself can be revealing. Such restrictions would be policy safeguards, not claims that every jurisdiction legally requires the same list.

The concern becomes stronger when signatures are linked to names indirectly. Leonardo says SignalTrace itself does not identify people, but its LPR integration is intended to correlate electronic signatures with vehicle observations. A known plate can lead investigators to registration or case information under applicable authority. The absence of a name in the raw signal does not prevent later person-level inference. NIST’s definitions make the broader point that linked or linkable information may allow an identity to be traced. That does not mean every radio identifier is automatically PII under every law; it means privacy analysis must include the realistic linkage tools available to the controller.

Sensitive associations also raise accuracy problems. A vehicle seen outside a hospital does not prove its owner was a patient. A phone near a protest does not prove participation. A watch traveling with two cars does not prove their drivers know each other. Location evidence describes presence before it describes meaning. Investigators need corroboration before converting a pattern into a statement about health, religion, politics, relationships or wrongdoing. This evidentiary caution is especially important for automated alerts, where a system may elevate a recurring pattern before a human examines alternative explanations. Leonardo’s patent contemplates relative certainty for device-target relationships, but public materials do not provide a certainty scale for social conclusions drawn from those relationships.

The policy response should focus on the information the system can create, not only on content it promises not to collect. Agencies can limit sensitive-location queries, shorten retention for uninvolved records, require supervisory approval for relationship analysis, preserve confidence and provenance, and ban inference about protected activities without independent evidence. Courts may impose additional rules depending on jurisdiction and the specific use. The FTC’s commercial enforcement and the Supreme Court’s digital-location cases show that location information can be deeply revealing, though neither directly governs every SignalTrace deployment. A noncontent sensor can still become a map of routines and relationships when observations are persistent, linked and searchable. That is the privacy question the phrase “we do not read your phone” does not answer.

A useful safeguard is to separate detection from interpretation in the record itself. The database can store that a signature was observed near a location without assigning a sensitive label to the person. Any later inference can then require a documented investigative basis and separate approval.

Investigative leads are not the same as evidence of guilt

Leonardo consistently frames SignalTrace as a source of investigative context and leads. That framing is appropriate because the system infers relationships from recurring observations rather than proving human conduct directly. A plate may be correctly read while someone other than the owner drives. A Bluetooth signature may be correctly detected while the device sits in a passenger’s bag. A cluster may recur with a vehicle while one component belongs to a child, employee or borrowed accessory. Each step can be technically accurate without establishing who committed an act. Treating a SignalTrace association as a lead preserves room for alternative explanations; treating it as guilt collapses several inferential steps into one unsupported conclusion.

The patent reinforces this distinction by describing certainty values and correlations based on frequency, proximity and time. A system that calculates confidence is acknowledging uncertainty. Probabilistic association should remain visibly probabilistic when officers act on it. Interfaces should show the strength and source of a match, not merely produce a binary “associated” label. Reports should explain whether a relationship came from one capture or many, whether a plate was present, whether the signature changed, and whether independent evidence confirms possession. If investigators later present the result to a prosecutor or court, those details matter to evaluating reliability and weight. The public product material reviewed here does not provide a standardized evidentiary protocol for courts.

Investigative workflows can also introduce confirmation bias. Once a device cluster is connected to a suspect, analysts may interpret later observations as confirmation and give less attention to contradictory records. A signature appearing with another car might indicate a vehicle switch; it might also show that the original human attribution was wrong. Disconfirming observations deserve the same analytical weight as confirming ones. Systems can support this by flagging cluster changes, presenting confidence over time and preserving alternative candidate associations rather than rewriting history around the latest theory. Supervisors can require analysts to document competing explanations before a relationship becomes part of an official investigative narrative.

The consequences become more serious when a lead triggers coercive action. A database hit might contribute to surveillance, a stop, an interview request or an application for legal process. The law governing those actions varies by jurisdiction and context, so SignalTrace cannot be assigned one universal evidentiary threshold. The more consequential the action, the stronger the need for corroboration. An agency policy can require independent facts before a device-signature association is used as the sole basis for an intrusive step. That safeguard is not an admission that the technology is unreliable; it recognizes that the product observes devices and vehicles, while legal decisions frequently concern people, intent and probable cause.

Disclosure is another issue. If SignalTrace contributes materially to a prosecution, defense counsel and courts may need enough information to test the method, subject to applicable discovery rules and protective orders. Relevant material could include sensor logs, confidence values, software versions, calibration records, error testing, query history and the method used to attach the signature to a person. A proprietary algorithm does not erase the need to assess evidentiary reliability. The reviewed public record does not show how often SignalTrace has been offered in court, challenged or validated under evidentiary standards. Claims about courtroom acceptance would therefore be premature. Public agencies should plan for disclosure questions before relying on proprietary correlation in case-critical decisions.

The safest investigative culture treats SignalTrace as one instrument among several. Plate records, witness accounts, conventional surveillance, physical evidence, lawful device records and interviews can confirm or contradict an electronic-signature lead. Leonardo’s own announcement says SignalTrace observations can complement other operational data. That word “complement” captures the right posture. Correlation is a starting point for inquiry, not a substitute for proof. Used that way, the system may narrow investigative effort while preserving the distinction between a machine-detected relationship and a factual conclusion about a person. Used without that distinction, even a technically impressive matching engine can amplify ordinary ambiguity into an official accusation.

Error handling should continue after an investigation ends. If later evidence shows that a device belonged to a passenger, an employee or an unrelated traveler, the correction should reach reports, alerts and partner systems that inherited the earlier association. Analysts should be able to see that a conclusion was withdrawn rather than merely lose the original record. That prevents a disproved relationship from resurfacing in a later case as if nothing had changed.

Independent testing is the missing reliability layer

The largest factual gap around SignalTrace is not the existence of the technology but its measured performance. Leonardo’s patent and product material explain the architecture, supported signal families and intended investigative uses. Independent engineering analysis raises credible questions about radio range, device behavior, address randomization and some advertised signal categories. Yet the public record reviewed here contains no independent field evaluation reporting SignalTrace detection and false-association rates under realistic traffic conditions. Without that layer, it is possible to describe what the product is designed to do, but not to quantify how reliably it does it across roads, devices and environments. Vendor demonstrations and patents cannot substitute for a controlled test with known ground truth.

A useful evaluation would separate several metrics that are often collapsed into “accuracy.” First is radio detection: did the sensor hear a device that was actually present? Second is classification: did it recognize the relevant protocol or signature correctly? Third is vehicle association: did the system attach that signal to the correct passing vehicle? Fourth is cluster persistence: did it recognize the same traveling group across later observations despite devices appearing, disappearing or changing identifiers? Person attribution is a fifth and distinct problem. Even perfect vehicle association cannot prove who carried a watch or phone. Publishing one overall success percentage would hide these stages and make it impossible to diagnose where errors enter.

Testing also needs realistic negative cases. A quiet test track with one instrumented car can show that reception is possible, but it says little about a city intersection full of radios. Evaluators should include adjacent lanes, pedestrians, cyclists, buses, stationary access points and repeated commuters whose schedules overlap. They should vary speed, weather, antenna placement, vehicle body type and device mix. Crowded scenes are where correlation has to reject plausible but wrong neighbors. Ground truth can document every seeded device and occupant so researchers can calculate false positives, false negatives and confidence calibration. Tests should also examine how long an erroneous association persists after the confusing condition disappears.

Modern privacy features deserve a dedicated test plan. Apple and Android use Wi-Fi address randomization to frustrate persistent passive tracking, and Bluetooth standards support private addresses. SignalTrace may compensate by correlating multiple attributes or devices, but the public sources do not explain the complete proprietary fingerprint. An evaluation should test current operating systems, not only older devices with stable identifiers. It should record whether a phone remains trackable when disconnected from Wi-Fi, when connected, when Bluetooth accessories change and after operating-system updates. Results need to distinguish protocol behavior from product inference so readers know whether persistence comes from a stable identifier, a cluster-level fingerprint or another observable feature.

Independence matters because the stakes extend beyond product comparison. If an agency uses a match to redirect surveillance toward a person, the error rate affects civil liberties and investigative efficiency. False positives waste resources and can burden innocent people; false negatives can create false reassurance or missed leads. Reliability should be known before the output receives high evidentiary weight. An evaluator needs access to hardware configuration, software version, scoring output and enough methodology to reproduce the test. Results can protect sensitive implementation details without reducing the public report to unsupported assurances. Agencies can also commission recurring validation after major software, antenna or device-ecosystem changes.

Until such evidence is available, claims should remain tiered by certainty. It is verified that Leonardo markets passive collection of supported Bluetooth, Wi-Fi and RFID signals, correlation with plate observations, recurring electronic signatures and historical analysis. It is verified that the patent describes certainty values, relationships and target tracking. Independent technical critics have raised plausible limits. What remains unverified publicly is the field performance that connects those layers. Absence of a published test does not prove the product fails; it means confidence should stop where evidence stops. Procurement decisions should make independent validation a contract deliverable, with protocol-specific metrics, realistic traffic scenarios and disclosure sufficient for oversight bodies to judge whether the system is fit for the use agencies intend.

Test results should also be reported by use case. A configuration acceptable for traffic analytics may not be sufficient for identifying a vehicle in a criminal investigation, where the consequence of a false association is higher. Evaluators should predefine success criteria, publish sample sizes and avoid selecting only favorable routes or devices. Independent reviewers need enough raw or summarized results to recompute key rates and examine failures, because average performance can hide categories that behave very differently.

Device privacy features reduce exposure but do not erase correlation

People concerned about passive radio tracking naturally ask whether phone settings can stop SignalTrace. The answer is partial, not absolute. Apple and Android both implement Wi-Fi privacy features that randomize MAC addresses in important situations, specifically reducing the ability of passive observers to build persistent device histories. Bluetooth also supports private address mechanisms. These features make simple long-term tracking by one stable hardware address harder. They do not guarantee that every wireless emission becomes unlinkable, nor do they describe how SignalTrace’s proprietary clustering behaves across all devices. A car can contain older radios, infotainment systems, wearables, trackers and accessories with different privacy behavior.

Apple’s security documentation says its platforms use randomized MAC addresses for Wi-Fi scans when not associated with a network, and it describes additional frame-level randomization intended to reduce fingerprinting. Android documentation says MAC randomization is enabled by default in several Wi-Fi modes from Android 10 and explicitly identifies resistance to activity-history tracking as a privacy goal. The operating systems are designed with passive tracking in mind. That matters when evaluating sweeping claims that every modern phone can be followed indefinitely from roadside broadcasts. A vendor would need to show which observable characteristics remain stable despite those mitigations and how frequently the system can reconnect changing observations to the same underlying device or cluster.

Bluetooth creates similar complexity. Devices can use random and private addresses, but actual behavior depends on device role, pairing state, implementation and version. Some accessories advertise frequently because discoverability is part of their function; others transmit intermittently or change identifiers. There is no single “Bluetooth signature” behavior shared by all electronics. A vehicle’s fixed infotainment radio may be more persistent than a current phone, while a small tracker may follow a person across vehicles. This diversity can work in SignalTrace’s favor because a cluster needs only enough recurring features to become distinctive, but it also makes universal detection claims implausible. Testing has to describe the actual protocol and device population rather than treating “Bluetooth” as one stable identifier source.

Turning radios off can reduce some emissions, but that is not a complete privacy prescription. Many people rely on Bluetooth for hearing devices, vehicle audio, watches and safety accessories; Wi-Fi supports connectivity and location functions. Vehicle-installed components may continue transmitting independently of the phone. RFID tags behave differently again. The burden should not be shifted entirely onto travelers to disable ordinary technology whenever they enter public space. From a policy perspective, system operators control retention, correlation, search and sharing even when individuals cannot control every transmitter around them. Device settings are one layer of defense, not a substitute for limits on institutional collection.

Privacy features can also change over time. Operating-system updates may alter randomization schedules, close fingerprinting channels or introduce new discovery behavior. Vendors may update algorithms in response. An association technique that works well against one software generation may degrade against another, and a technique that once failed may improve. Performance is a moving target because both trackers and anti-tracking mechanisms evolve. Agencies should therefore retest after major software releases and avoid assuming that procurement-era accuracy remains valid indefinitely. Public documentation should identify tested device generations and dates so a later reviewer can tell whether results still represent the traffic population.

For individuals, the practical conclusion is limited. Using current operating systems and privacy-preserving wireless settings can reduce exposure to simple stable-identifier tracking, and disabling unused radios may reduce broadcast opportunities. It cannot guarantee invisibility from a multi-sensor correlation system whose full fingerprinting method is not public, especially when other devices in the vehicle continue transmitting. SignalTrace is designed to exploit the group pattern, not merely one phone identifier. That is precisely why independent testing should measure cluster persistence after individual identifiers rotate. Personal hygiene can lower some signals; the larger question remains whether public authorities should retain and link the signals that remain.

There is another limitation to personal countermeasures: the traveler does not control every transmitter in a shared vehicle. A rental car, employer vehicle or taxi may contain its own radios, aftermarket trackers or infotainment system. Another passenger may carry devices with stable behavior. Even if one phone reduces its identifiable emissions, the remaining cluster may still recur. The product concept is explicitly collective, making the privacy question partly social rather than only a matter of one user’s handset configuration.

Independent audits should therefore test whole-vehicle signatures under realistic sharing conditions, not assume one privacy setting determines the result.

Responsible deployment requires rules before routine use

SignalTrace is best understood neither as an all-seeing scanner nor as a harmless extension of a plate camera. It is a real multi-sensor correlation technology designed to collect supported wireless emissions, group recurring signals, connect them with vehicle observations and make those relationships searchable. Its power lies in accumulation and linkage, not in secretly reading the contents of every device. That distinction clears away the most exaggerated version of the story while leaving the serious policy issue intact. Police can gain new leads from devices that accompany vehicles and people; passengers and bystanders can also become part of the resulting association graph before anyone suspects them of wrongdoing.

Rules should begin with a precise statement of purpose. An agency should identify the crimes, threats or operational objectives for which electronic-signature collection is authorized, the locations where sensors may be placed and whether collection is targeted or continuous. A general promise to use data “for public safety” is too elastic to control later mission expansion. The policy should also say which signal classes are enabled and prohibit claims that the system scans electronics beyond what configuration and testing support. Procurement documents can require a technical inventory so oversight bodies know which radios, antennas, software modules and databases form the deployed system rather than relying on brand-level descriptions.

Retention needs its own limits. Unmatched observations from ordinary travelers should not automatically receive the same preservation as records attached to an active case. Historical searches should require a documented purpose, and more intrusive person-linked or sensitive-location queries should receive higher approval. Shorter retention reduces both retrospective surveillance and the consequences of error or breach. Leonardo’s EOC provides auditing capabilities, so agencies have a technical basis for recording user activity. The policy should require regular audit review, not merely logging, and should publish aggregate statistics on queries, alerts, sharing and misuse findings where law permits.

Accuracy rules are equally important. A match should preserve confidence, sensor provenance and the facts used to connect a signal with a vehicle. A person should not be identified solely because a device cluster appeared near a plate registered to that person. Every human attribution needs independent corroboration before it carries coercive weight. Agencies should commission independent field testing in dense traffic, publish protocol-specific performance metrics and retest after material software or hardware changes. They should also maintain a correction process that propagates invalidated associations to alerts, reports and partner systems. The patent’s explicit use of certainty values makes clear that the underlying relationships are not inherently binary.

Legal review must cover the whole lifecycle. In the United States, no reviewed Supreme Court case squarely decides passive SignalTrace collection, while Carpenter and Chatrie establish protection for other forms of detailed digital location information. State and local rules may add constraints. In the European Union, law-enforcement processing would require analysis under the Law Enforcement Directive and national implementing law, including identifiability, necessity, purpose, accuracy, retention and sharing. Vendor privacy language cannot replace jurisdiction-specific legal authority. An agency should document its legal basis before deployment and repeat the review if later updates expand persistence, add databases or change search capabilities.

Finally, deployment should be transparent enough for democratic oversight without publishing details that would compromise legitimate investigations. Officials can disclose vendor, product, general sensor locations or policies where appropriate, retention periods, sharing partners, audit structure, performance testing and the legal framework authorizing use. Independent inspectors can review more sensitive details. The burden of proving reliability and proportionality belongs with the institution using the system, not with every person carrying a phone past the sensor. SignalTrace illustrates a broader shift in surveillance: ordinary machines emit enough metadata that correlation can create new knowledge without opening a device. The responsible response is not to pretend that the capability does not exist or to exaggerate it beyond evidence, but to govern the verified capability before it becomes an invisible routine.

Public reporting can also separate effectiveness from raw collection volume. Agencies should measure whether SignalTrace materially contributed to investigations, how often leads were corroborated, how often associations were rejected and whether less intrusive methods could have achieved the same goal. Those measures create a factual basis for renewal decisions. A program that collects large quantities of data but rarely produces validated leads should not be justified merely by the theoretical possibility that the archive might prove useful someday.

Periodic renewal forces evidence of necessity and performance back into the authorization decision instead of allowing the original purchase to settle the question indefinitely.

Questions readers are likely to have about SignalTrace

Does SignalTrace read messages or files from a phone?

No. Leonardo says the system passively observes supported wireless emissions and does not decrypt communications, retrieve stored files or read message content. SignalTrace is described as a metadata and correlation system, not a phone-content extraction tool. That distinction matters, but metadata collected repeatedly can still reveal associations and movement patterns.

Does SignalTrace scan every electronic device in a passing car?

No reliable public evidence supports the claim that it detects literally every electronic device. Leonardo lists Bluetooth, Wi-Fi, RFID and other supported wireless signals, while independent technical analysis argues that detectability depends on radio protocol, frequency, transmission behavior, antenna design and surrounding conditions. Devices that are silent, shielded, outside supported bands or using privacy features may not produce a usable observation.

Is SignalTrace part of the license plate camera itself?

Not necessarily. Leonardo describes SignalTrace as a sensing technology that can be deployed alongside license plate recognition and can also operate independently. The plate reader and radio sensor are separate data sources that can be correlated when both are present.

Which wireless signals does Leonardo say SignalTrace detects?

Leonardo publicly names Bluetooth, Wi-Fi, RFID and other supported wireless emissions. Its patent materials describe collection hardware and correlation of electronic signatures with visual identifiers, but public marketing does not disclose a complete protocol-by-protocol detection matrix or independently measured success rate for every device category.

Does SignalTrace identify a person by name?

Leonardo says it does not identify individuals and calls the electronic signatures anonymous. The privacy concern is that an anonymous or pseudonymous signature can later be linked with other records, such as repeated plate observations, case information or other identifiers. NIST’s definition of personally identifiable information expressly recognizes that information can become identifying when combined with linked or linkable data.

Can police connect a signature with a named person later?

Potentially, yes, depending on the available records and legal authority. A plate can lead investigators to vehicle-registration information, while recurring device associations may add a second layer of inference. A technical signature does not need to contain a name to become useful in identifying or narrowing attention toward a person. A plate still does not prove who was driving at a particular moment.

Can SignalTrace follow a vehicle after its plate changes?

Leonardo markets that capability as an investigative use: recurring electronic signatures may help recognize a vehicle even without the expected plate, and the patent describes tracking targets across successive collection sites. Whether a real deployment achieves a reliable match in a particular case would depend on the signals observed and the system’s association logic.

Can the system track a device when no plate reader is present?

Leonardo says SignalTrace can operate without an LPR at every collection site and can also be deployed as a standalone sensor. That means later observations can, in principle, be associated with a previously learned electronic signature even when no contemporaneous plate image is available. Public materials do not establish the accuracy of every such association.

Can passengers be associated with the wrong car?

Yes. A recurring signal observed with a vehicle may belong to a passenger, a borrowed device, an item left in the car or another person who regularly travels with the driver. Co-occurrence is evidence of proximity and repetition, not proof of ownership, identity or guilt. Investigators need independent corroboration before treating an inferred association as a fact about a person.

Can nearby pedestrians be picked up?

A passive radio receiver can hear transmitters within its effective receiving environment, not only devices physically enclosed by one photographed vehicle. Public SignalTrace materials do not provide a universal rule for separating every nearby pedestrian or adjacent vehicle from the target car. This is one reason independent testing of false associations and crowded-road conditions matters.

Do iPhone and Android privacy features stop SignalTrace?

They can frustrate simple persistent tracking, but they do not make every device radio-silent. Android and Apple both document MAC-address randomization or related Wi-Fi privacy behavior intended to reduce passive tracking. SignalTrace may also use combinations of observations rather than a single fixed address, so the practical effect depends on protocol, device state and the system’s implementation.

Does Bluetooth address randomization make tracking impossible?

No. Bluetooth specifications include private and changing addresses designed to reduce tracking, and Apple documents Bluetooth address randomization as a privacy protection. A changing address weakens straightforward long-term identification by one static address, but other recurring features or correlated signals may still provide clues. Public evidence does not establish a universal SignalTrace success rate against modern Bluetooth privacy mechanisms.

Can SignalTrace read pet microchips?

Leonardo’s broader materials have referred to RFID tags, but independent radio analysis has questioned whether some commonly imagined tags, including passive pet microchips, would be detectable in ordinary roadside conditions without the appropriate excitation and close-range reader setup. The claim that SignalTrace can remotely inventory every passive RFID tag in a moving car is not established by the reviewed public evidence.

Has SignalTrace been independently tested?

No public independent performance study was identified in the reviewed sources that establishes detection rates, false-association rates or protocol-by-protocol accuracy under representative road conditions. Biometric Update likewise noted the absence of public independent accuracy evaluation. Vendor materials and patents explain intended operation, but they are not substitutes for external validation.

Is SignalTrace already widely used by police?

The reviewed public evidence does not establish widespread police deployment. Leonardo markets the system for law enforcement and public safety, and procurement documents show earlier EOC Plus components were available for purchase. Reporting has discussed apparent installations, but that is not the same as a verified nationwide inventory of active police systems.

Did New York’s procurement list prove deployment?

No. The New York Office of General Services pricing document shows that EOC Plus hardware and licensing were listed under a state contract, including specific contract prices. A catalog or contract schedule proves procurement availability, not that a particular agency bought, installed or actively used the equipment.

Is SignalTrace legal in the United States?

There is no single yes-or-no answer for every deployment. Federal constitutional doctrine, state constitutions, statutes, warrants, local policies, retention practices and the precise technical collection method can all matter. Carpenter and Chatrie protect certain forms of digital location information, but neither case squarely decides whether passive roadside reception of SignalTrace-style broadcast emissions is itself a Fourth Amendment search.

Would the same deployment be lawful in the EU?

Lawfulness would depend on the member state, competent authority, purpose and safeguards under the Law Enforcement Directive as implemented nationally. If collected or linked signatures relate to an identifiable person, rules on lawful processing, purpose limitation, necessity, accuracy, security, retention and rights become relevant. A vendor’s description of signatures as anonymous does not by itself settle that legal classification.

What safeguards matter most if police deploy it?

Rules should address collection scope, allowed investigations, retention, confidence scores, corroboration, audit logs, access, sharing, correction, deletion and independent testing. The strongest safeguard is to treat a recurring electronic signature as an investigative lead with documented uncertainty, not as proof that a named person was present or committed an offence. Public reporting and government reviews of adjacent location and ALPR systems show why retention and sharing controls deserve the same attention as the sensor itself.

Author:
Jan Bielik
CEO & Founder of Webiano Digital & Marketing Agency

SignalTrace can link wireless device signatures to a passing car’s license plate
SignalTrace can link wireless device signatures to a passing car’s license plate

This article is an original analysis supported by the sources cited below

SignalTrace™
Leonardo’s current product page describes SignalTrace’s sensors, electronic fingerprints, integration with license plate recognition, server storage, querying, auditing and customer-controlled LPR data sharing.

Leonardo US Cyber & Security Solutions, Inc. Introduces SignalTrace™, the Next Evolution in Electronic Signature Detection Technology
Leonardo’s August 4, 2026 announcement explains the EOC Plus rebrand and says SignalTrace passively detects publicly broadcast Bluetooth, Wi-Fi, RFID and other supported wireless signals.

US11941716B2 – Systems and methods for electronic signature tracking – Google Patents
The patent record describes collection systems that associate electronic signatures with visual identifiers and use time, location and proximity to identify or track targets.

Systems and methods for electronic signature tracking
The USPTO Patent Gazette records Leonardo’s continuation patent issued on April 28, 2026 for electronic-signature tracking systems and methods.

Leonardo US Cyber and Security Solutions receives a patent for their new electronic signature tracking system for law enforcement
Leonardo’s 2024 release describes the earlier EOC Plus product and its intended law-enforcement use before the SignalTrace name was introduced.

Thinking Critically About SignalTrace
Ryan O’Horo’s independent technical analysis examines which advertised wireless detections appear plausible and identifies claims that require more technical evidence or testing.

License Plate Camera Companies Want You to Believe They Can Track Everything. An Expert Explains Why They Can’t
The Drive reports on O’Horo’s radio-frequency critique and distinguishes plausible Wi-Fi and Bluetooth sensing from broader device-detection claims.

SignalTrace pairs wireless device signals with license plate records
Biometric Update covers SignalTrace’s plate-and-device correlation model and notes the lack of a public independent accuracy or false-association evaluation.

A new surveillance tool can trace people through the devices they carry
The Independent’s report examines re-identification, passenger and bystander risks, and the difference between a device signature and a verified human identity.

EQUIPMENT PRICING GROUP 38232 AWARD 23173 – HAZARDOUS INCIDENT RESPONSE EQUIPMENT (HIRE)
A New York Office of General Services contract price list shows EOC Plus components and licensing available for procurement, without proving that any particular agency deployed them.

personally identifiable information – Glossary | CSRC
NIST’s glossary explains that information may be personally identifiable on its own or when combined with other linked or linkable information.

Implement MAC randomization | Android Open Source Project
Android’s documentation explains MAC randomization and its role in reducing the ability to build persistent Wi-Fi activity histories.

Privacy features when connecting to wireless networks – Apple Support
Apple documents Wi-Fi privacy features, including randomized addresses used during scanning and measures intended to reduce passive tracking.

Bluetooth security – Apple Support (PH)
Apple’s security documentation describes Bluetooth privacy protections including address randomization intended to make long-term passive tracking harder.

Part C Generic Access Profile
The Bluetooth Core Generic Access Profile defines public, random and private device addressing behavior relevant to passive observation and tracking.

Law Enforcement: DHS Could Better Address Bias Risk and Enhance Privacy Protections for Technologies Used in Public
The U.S. Government Accountability Office reviews DHS law-enforcement use of technologies including third-party ALPR data and recommends stronger privacy and bias safeguards.

FTC Order Prohibits Data Broker X-Mode Social and Outlogic from Selling Sensitive Location Data
The FTC action illustrates how device-linked location information can reveal visits to sensitive places and why linkability matters even without message content.

FTC to Ban Kochava and Subsidiary from Selling Sensitive Location Data to Settle Charges They Sold Location Data Linked to Millions of Mobile Devices
The FTC’s May 2026 settlement addresses the sale and retention of device-linked precise location data and provides current regulatory context for sensitive movement information.

Data Driven: What Is ALPR?
The Electronic Frontier Foundation explains how automated license plate readers capture plates, time and location and place observations into searchable databases.

More License Plate Reader Mission Creep: School Residency Verification, Background Checks, and Noise Complaints
EFF’s 2026 analysis documents secondary uses of a different ALPR system, providing a comparison for retention, purpose limitation and audit-policy risks.

16-402 Carpenter v. United States (06/22/2018)
The U.S. Supreme Court’s Carpenter opinion held that government acquisition of historical cell-site location information was a Fourth Amendment search and limited automatic reliance on third-party doctrine.

25-112 Chatrie v. United States (06/29/2026)
The U.S. Supreme Court’s June 29, 2026 Chatrie opinion held that obtaining the defendant’s Google Location History was a Fourth Amendment search while leaving other geofence-warrant issues for further proceedings.

Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016
The EU Law Enforcement Directive sets rules for competent authorities processing personal data for criminal-law and public-security purposes, including purpose, accuracy, security and retention requirements.

62021CJ0487
The Court of Justice judgment addresses the broad concept of personal data and supports the article’s discussion of indirect identification and linkability under EU data-protection law.

Citing this article? Brief excerpts are welcome. Please credit Webiano.digital, name the author where stated, and include a link to https://webiano.digital and to this original article. Full or substantial republication requires prior written permission. Read our Copyright and Content Use Policy.

This article was prepared with the assistance of artificial intelligence tools. The content underwent expert human review, and Webiano Digital & Marketing Agency assumes editorial responsibility for its final version and publication.