All capabilities
Airspace Watch — RF Noise, Rogue Emitters & Jamming Shared-family mapped

Is the attacker in the building?

Injection-Zone Presence Confirm

When an attack is running, checks whether a body is actually standing in the zone the attack seems to come from.

Contested Space · Contested capability

What this capability does not do.

Does not act.

Latent emits a reading. It does not switch cameras, unlock cages, cut power or open a ticket. Your VMS, PoE switch or access controller does that, on your side of the boundary. A Latent blueprint contains no executable code, no remote URLs and no device secrets — by schema, not by policy.

Does not identify.

No face, no plate, no MAC, no device identity, no payload. A movement signature is a shape moving through a room, not a person. Nothing stored here resolves to an individual.

Does not survive everything.

RSSI attribution is 3–8 m zone-grade and the radar covers one cone: an attacker in an uncovered or mis-attributed zone reads as “planted/remote”, so “no body seen” must never close the incident. The camera adds nothing in darkness without illumination.

Across Airspace A jammer already running when you took the baseline is invisible. The baseline must be captured in a verified-quiet window, and a baseline of unknown provenance is worth nothing.

Observable
Per-link CSI amplitude variance across subcarriers, sampled at the mesh frame rate (about 6–9 Hz on ESP32-S3). No phase, no waveform, no audio.
Retention
A presence score and its state transitions. Raw CSI is consumed on the node and in your browser; it is never written to disk and never exported.
Node minimum
1 node
Export policy
Conditional — Exportable into a signed release, subject to the deployment’s own preflight.
Chain of custody

Node identity

Each node mints its own key over USB, in your hand. Physical possession is the root authority: a device that cannot prove physical presence is refused enrollment outright. A cloud pairing PIN is a weaker ownership claim and is never treated as liveness.

Reading provenance

Every reading is attributable to a device id, profile id, hardware id and firmware version recorded at install and verified by mutual HMAC-SHA256 proof over an LFW1 nonce exchange. A node whose proof did not verify is marked untrusted, not merely offline.

Install attestation

Completing an installation is a high-risk action. It requires your explicit browser approval, an approval snapshot that still matches, an idempotency key, and heartbeats less than three minutes old. There is no silent commissioning.

How enrollment works

Properties you can map to your own controls

  • No optical sensor is present in this capability’s node set.
  • Raw CSI does not leave the node. Only derived event rows are stored or exported.
  • No stored identifier resolves to a person. Where access events are correlated, that correlation happens in your systems, against your logs.
  • The runtime executes on the node and in your browser. This capability has no cloud inference path.

These are properties, not certifications. Latent does not assert compliance with any framework on your behalf.

A capability description, not an incident record.
Readiness Shared-family mapped

Mapped to a shared offline runtime family and usable with a recording or compatible ESP32 CSI stream.

Evidence Strong theory Supported hypothesis

Published physics or adjacent results support the hypothesis; capability-specific product and site validation are still required.

Runtime family Presence

Calibrated motion and presence score from CSI variance and change statistics.

When no ESP32 is connected

No compatible ESP32 stream is connected. Use the bundled Airspace recording; it demonstrates the shared Presence runtime, not independent proof of this capability.

Intended capability

Pilot this intended outcome through the shared Presence family, then validate it against site-specific ground truth: Fuses a live deauth or jam verdict with radar occupancy of the RSSI-attributed injection zone to classify on-site versus planted/remote attack — and wakes the camera for one bounded snapshot of the zone while the attack is still running.

This describes the intended outcome. Readiness is shared-family mapped, evidence is class B, and a catalog mapping or recording is not proof of this outcome at a real site.

Solution blueprint

See the environment before installing it.

This exact kit is one of 191 first-class designs. It includes geometry, objects, nodes, wording, scenarios, installation, limitations, and catalog-bound readiness.

Shared-family mapped

No rendered revision is available yet.

Bundled recording

A related Airspace scene

This is one recorded vertical scenario. It is not separate validation of every capability in the catalog.

01 The physics

Management-frame counting and RSSI zone ranking are this vertical's proven observables; the LD2410C confirms a human-scale moving or static target in the attributed zone's cone at ms latency on a band the attack cannot touch. Capture and TFLite person detection run locally and cloud-free; no streaming representation exists.

02 Shared processing path

deauth-storm/jam verdict + RSSI zone rank -> LD2410 occupancy check of the attributed zone -> on-site vs planted/remote classification -> camera wake, bounded snapshot, local store -> journal event carrying all three verdicts

This is a capability design path. Components may be shared with other catalog entries; it is not presented as a unique algorithm.

03 Validation plan

Red-team exercises: scripted deauth from in-zone, adjacent-zone and planted-device positions; classification accuracy and snapshot hit rate measured; storage audit proving zero captures without a live attack verdict.

04 Commercial hypothesis

'Is the attacker in the building?' — for security operations turning an RF verdict into a physical-response decision.

A quiet reading is not an all-clear. If nodes are stale, degraded or jammed, this runtime says so explicitly. It never infers safety from missing data.