
A surveillance system marketed by the security company Leonardo is designed to do something that would have seemed like science fiction a decade ago: silently associate the wireless signals broadcast by your phone or smartwatch with the license plate of the vehicle you travel in — and store that association for future law enforcement queries. The system is called SignalTrace, and its emergence marks a meaningful expansion in how police may be able to build investigative profiles of individuals before those individuals are ever suspected of a crime.
How SignalTrace Works
SignalTrace is engineered to operate alongside existing automatic license plate readers (ALPRs). As a vehicle passes a roadside sensor, the ALPR captures the plate, which can then be cross-referenced with vehicle registration records to identify the registered owner. What is new is the additional sensor component that detects wireless signals broadcast by nearby devices — including Bluetooth emissions from smartphones, smartwatches, and other consumer electronics — and correlates those signals with the plate being captured at the same moment.
According to Leonardo’s own product materials, the system can recognize groups of consumer devices that regularly move together, then associate them with license plate records and time-stamped locations. After enough repeated co-occurrences, the software begins treating those device signals as a recurring electronic signature linked to the vehicle. That pattern can then be searched in the system’s database — even when an investigator does not know the plate number they are looking for.
The practical implication is significant. If your phone’s Bluetooth signal is detected traveling alongside a particular vehicle multiple times, the system may build an association between your device and that plate. Weeks or months later, if that same device signal appears near a different vehicle connected to an investigation, the stored association becomes an investigative lead — all without authorities ever capturing your name directly from the signal.
Already Deployed, Not Yet Standard Practice
SignalTrace is not a theoretical concept. According to reporting reviewed for this article, several of the devices have already been installed in Oxon Hill, Maryland. The company’s predecessor technology also appears on an official New York state contract price list, indicating the system has cleared government procurement channels in at least one major state. Leonardo describes SignalTrace as a tested and marketed capability, though it has not yet become a standard feature of police investigations nationwide.
The system’s patent, filed under US patent number US11941716B2, describes targets that may be people or vehicles and outlines searchable signatures that can be correlated with visual identifiers and used to track a target across locations. A separate Leonardo product sheet states the technology helps identify suspects through the mix of devices they carry. Leonardo’s SignalTrace product page further states the system stores electronic fingerprints for later queries and can recognize a vehicle even without capturing its license plate.
The Company’s Privacy Framing — and Its Limits
Leonardo has proactively addressed privacy concerns through a dedicated explanatory sheet. The document states that SignalTrace “does not identify people” and that the system “only collects electronic signatures” from signals already being broadcast publicly, such as Bluetooth or radio frequency identification tags. The company acknowledges that these signatures do not, by themselves, disclose a person’s identity, and says the output must be corroborated through ordinary investigative methods.
That framing, however, rests on a narrow definition of identification. A sensor may not extract a legal name from a phone signal, but law enforcement could still determine who likely owns a device by cross-referencing its signal with other available records. For example, the same signal might repeatedly appear alongside a car registered to one person, detected outside that person’s home, or appearing in proximity to another device already connected to a known subject. Under that logic, a person could enter the scope of a law enforcement investigation based entirely on where their device repeatedly appeared and who it appeared near — even if authorities had no initial reason to suspect that individual.
What Federal Privacy Guidance Says
The company’s “no identification” claim also runs against established federal privacy frameworks. The National Institute of Standards and Technology (NIST) defines personally identifiable information as data that can distinguish or trace a person’s identity, either alone or when combined with other information. A device signal that is consistently co-located with a registered vehicle, a known address, or an existing case file is precisely the kind of data that, in combination, can trace a person’s identity — regardless of whether a name was ever directly extracted from the signal itself.
This distinction matters for how investigators use the technology and, potentially, for how courts may eventually evaluate evidence derived from it. The absence of a name in the raw signal data offers diminishing privacy protection once that signal has been cross-linked with vehicle records, time-stamped location data, and other investigative files.
A Shift in Investigative Logic
What makes SignalTrace notable from a civil liberties perspective is not just what it collects, but how it reshapes the sequence of investigation. Traditionally, law enforcement begins with a suspect or a crime and then gathers evidence. Systems like SignalTrace invert part of that logic: they passively accumulate associations between devices and vehicles across the general population, storing those associations in a searchable database. An individual’s movements and associations are recorded before any suspicion exists, and that pre-collected data can then be pulled into an investigation retroactively.
This architecture means that passengers, not just drivers, may be drawn into investigative data pools. If you regularly carpool with someone whose vehicle later becomes connected to a police inquiry, your device’s electronic signature — harvested during those routine morning commutes — may surface as an investigative lead, linked to a vehicle and a person you simply happened to ride alongside.
The Broader Surveillance Infrastructure
SignalTrace does not exist in isolation. It is designed to augment a license plate reader infrastructure that has expanded significantly over the past decade. Automatic license plate readers are already deployed by police departments across the country, capturing plate numbers, locations, and timestamps for vehicles — including those of individuals who are never suspected of any wrongdoing. That existing database of location records now becomes a foundation onto which device-level signals can be layered, creating a more granular and cross-referenceable picture of individual movement patterns.
The combination raises questions that existing law has not fully answered. Courts have addressed the privacy implications of prolonged location tracking — most notably in Carpenter v. United States (2018), in which the Supreme Court held that long-term cell-site location data constitutes a search under the Fourth Amendment. Whether the passive, pattern-based association method employed by SignalTrace would meet a similar constitutional threshold remains an open legal question, particularly given the company’s framing that no identity is directly captured.
What Comes Next
For now, SignalTrace occupies a space between deployed hardware and established legal framework. Devices are in the field. The technology is on state contract lists. The patent is granted. But the policies governing how long the data can be retained, who can query it, under what circumstances, and with what oversight have not been publicly articulated — at least not in any documentation available through the sources reviewed here.
For individuals who move through public spaces — which is to say, everyone — the system’s logic means that the wireless signals your devices broadcast as a routine function of their operation may be silently catalogued, associated with vehicles and locations, and held in a searchable database for potential future use. The technology does not require you to have done anything wrong to be included. It only requires that you were there.
This article draws on reporting from Ars Technica, The Conversation, and UPI.



