All capabilities
Airspace Watch — RF Noise, Rogue Emitters & Jamming Shared-family mapped

The blackout has a transcript

Blackout Occupancy Ledger

Keeps writing down whether anyone was in the room, even while the radios are being drowned out.

Contested Space · Contested capability

What this capability does not do.

Does not act.

Latent emits a reading. It does not switch cameras, unlock cages, cut power or open a ticket. Your VMS, PoE switch or access controller does that, on your side of the boundary. A Latent blueprint contains no executable code, no remote URLs and no device secrets — by schema, not by policy.

Does not identify.

No face, no plate, no MAC, no device identity, no payload. A movement signature is a shape moving through a room, not a person. Nothing stored here resolves to an individual.

Does not survive everything.

Cone-scoped: an intruder outside the radar cone during blackout yields an honestly-empty ledger that must never be read as “nobody was on site”. Physical destruction or power cut of the node ends the record — and that truncation is itself the finding.

Across Airspace A jammer already running when you took the baseline is invisible. The baseline must be captured in a verified-quiet window, and a baseline of unknown provenance is worth nothing.

Observable
Per-link CSI amplitude variance across subcarriers, sampled at the mesh frame rate (about 6–9 Hz on ESP32-S3). No phase, no waveform, no audio.
Retention
A presence score and its state transitions. Raw CSI is consumed on the node and in your browser; it is never written to disk and never exported.
Node minimum
1 node
Export policy
Conditional — Exportable into a signed release, subject to the deployment’s own preflight.
Chain of custody

Node identity

Each node mints its own key over USB, in your hand. Physical possession is the root authority: a device that cannot prove physical presence is refused enrollment outright. A cloud pairing PIN is a weaker ownership claim and is never treated as liveness.

Reading provenance

Every reading is attributable to a device id, profile id, hardware id and firmware version recorded at install and verified by mutual HMAC-SHA256 proof over an LFW1 nonce exchange. A node whose proof did not verify is marked untrusted, not merely offline.

Install attestation

Completing an installation is a high-risk action. It requires your explicit browser approval, an approval snapshot that still matches, an idempotency key, and heartbeats less than three minutes old. There is no silent commissioning.

How enrollment works

Properties you can map to your own controls

  • No optical sensor is present in this capability’s node set.
  • Raw CSI does not leave the node. Only derived event rows are stored or exported.
  • No stored identifier resolves to a person. Where access events are correlated, that correlation happens in your systems, against your logs.
  • The runtime executes on the node and in your browser. This capability has no cloud inference path.

These are properties, not certifications. Latent does not assert compliance with any framework on your behalf.

A capability description, not an incident record.
Readiness Shared-family mapped

Mapped to a shared offline runtime family and usable with a recording or compatible ESP32 CSI stream.

Evidence Strong theory Supported hypothesis

Published physics or adjacent results support the hypothesis; capability-specific product and site validation are still required.

Runtime family Presence

Calibrated motion and presence score from CSI variance and change statistics.

When no ESP32 is connected

No compatible ESP32 stream is connected. Use the bundled Airspace recording; it demonstrates the shared Presence runtime, not independent proof of this capability.

Intended capability

Pilot this intended outcome through the shared Presence family, then validate it against site-specific ground truth: When the mesh goes dark — jam verdict or unexplained silence — the node keeps writing the radar's presence-and-range timeline to local flash and back-fills the airspace journal on recovery, so a blackout becomes a recorded interval with occupancy truth in it, never an evidence void.

This describes the intended outcome. Readiness is shared-family mapped, evidence is class B, and a catalog mapping or recording is not proof of this outcome at a real site.

Solution blueprint

See the environment before installing it.

This exact kit is one of 191 first-class designs. It includes geometry, objects, nodes, wording, scenarios, installation, limitations, and catalog-bound readiness.

Shared-family mapped

No rendered revision is available yet.

Bundled recording

A related Airspace scene

This is one recorded vertical scenario. It is not separate validation of every capability in the catalog.

01 The physics

The LD2410C's 24 GHz FMCW chain is fully independent of the jammed 2.4 GHz band, and its per-gate moving/static energies arrive over UART regardless of link state; flash logging needs no radio at all. The node cannot egress during broadband jam — it senses and records, and the journal's silence-is-an-alarm doctrine covers the live gap.

02 Shared processing path

Jam/silence verdict from link-denial-tripwire -> switch LD2410 stream to local flash ring -> timestamped presence/range ledger through the blackout -> journal back-fill + gap annotation on link recovery

This is a capability design path. Components may be shared with other catalog entries; it is not presented as a unique algorithm.

03 Validation plan

Chamber tests: full 2.4 GHz denial with scripted occupancy in the cone; ledger completeness and clock integrity across the blackout; faithful journal back-fill; power-loss-during-blackout recovery test.

04 Commercial hypothesis

'The blackout has a transcript' — for security teams who need to know whether anyone was in the room while the RF was down.

A quiet reading is not an all-clear. If nodes are stale, degraded or jammed, this runtime says so explicitly. It never infers safety from missing data.