All capabilities
Airspace Watch — RF Noise, Rogue Emitters & Jamming Research concept

Band Witness

Sub-GHz & Cellular Emitter Watch (Host SDR Tier)

A separate little appliance that listens to the low radio bands the nodes physically cannot hear.

Contested Space · Contested capability

What this capability does not do.

Does not act.

Latent emits a reading. It does not switch cameras, unlock cages, cut power or open a ticket. Your VMS, PoE switch or access controller does that, on your side of the boundary. A Latent blueprint contains no executable code, no remote URLs and no device secrets — by schema, not by policy.

Does not identify.

No face, no plate, no MAC, no device identity, no payload. A movement signature is a shape moving through a room, not a person. Nothing stored here resolves to an individual.

Does not survive everything.

An RTL-SDR (R820T2, ~24 MHz–1.77 GHz) cannot tune 2.4 GHz. This tier is deaf in the band the rest of this vertical watches, and it needs a Raspberry Pi 5 class host that is not part of the ESP32-S3 package contract.

Across Airspace A jammer already running when you took the baseline is invisible. The baseline must be captured in a verified-quiet window, and a baseline of unknown provenance is worth nothing.

Observable
Not defined. This capability has no reviewed runtime adapter, so nothing is measured yet.
Retention
Nothing is computed, stored or exported: there is no runtime path for this entry yet.
Node minimum
1 node
Export policy
Research only — Cannot enter a release. Documented so the limit is visible, not so it can be sold.
Chain of custody

Node identity

Each node mints its own key over USB, in your hand. Physical possession is the root authority: a device that cannot prove physical presence is refused enrollment outright. A cloud pairing PIN is a weaker ownership claim and is never treated as liveness.

Reading provenance

Every reading is attributable to a device id, profile id, hardware id and firmware version recorded at install and verified by mutual HMAC-SHA256 proof over an LFW1 nonce exchange. A node whose proof did not verify is marked untrusted, not merely offline.

Install attestation

Completing an installation is a high-risk action. It requires your explicit browser approval, an approval snapshot that still matches, an idempotency key, and heartbeats less than three minutes old. There is no silent commissioning.

How enrollment works

Properties you can map to your own controls

  • No optical sensor is present in this capability’s node set.
  • Raw CSI does not leave the node. Only derived event rows are stored or exported.
  • No stored identifier resolves to a person. Where access events are correlated, that correlation happens in your systems, against your logs.
  • The runtime executes on the node and in your browser. This capability has no cloud inference path.

These are properties, not certifications. Latent does not assert compliance with any framework on your behalf.

A capability description, not an incident record.
Readiness Research concept

A frontier proposal with a validation plan, not an implemented detector.

Evidence Frontier Unvalidated concept

An early research proposal with no capability-specific product validation yet.

Runtime family Not mapped

No browser runtime is assigned to this capability yet.

Why live sensing is unavailable

This is a research concept, not an implemented detector. Show its physics and validation plan without generating synthetic claims.

Intended capability

Research whether the field could support this proposed outcome: A sparse escalation tier that adds the bands the ESP32 mesh physically cannot hear: sub-GHz ISM at 433/868/915 MHz and cellular uplink energy, watched by an RTL-SDR on a host appliance and reduced to the same bounded event rows as the rest of the vertical. It is a witness, never an authority — one expensive spectral point per floor cluster against many cheap spatial points, and its events never override node evidence. It is deaf at 2.4 GHz, which is the band this vertical's own threat model centres on.

This describes the intended outcome. Readiness is research concept, evidence is class C, and a catalog mapping or recording is not proof of this outcome at a real site.

Solution blueprint

See the environment before installing it.

This exact kit is one of 191 first-class designs. It includes geometry, objects, nodes, wording, scenarios, installation, limitations, and catalog-bound readiness.

Research concept

No rendered revision is available yet.

Bundled recording

A related Airspace scene

This is one recorded vertical scenario. It is not separate validation of every capability in the catalog.

01 The physics

An R820T2-based RTL-SDR tunes roughly 24 MHz to 1.77 GHz, which covers the sub-GHz ISM allocations and cellular uplink but stops well short of 2.4 GHz. Energy detection across a swept span is the honest claim at this tier: it sees that something is transmitting in a band and roughly where in that band, and it does not demodulate proprietary protocols or identify devices.

02 Shared processing path

Host-side swept-span power spectral density -> per-bin rolling baseline with a diurnal term -> CUSUM on band-occupancy departure -> classification limited to band and duty-cycle shape (never device identity) -> event row joined into the airspace journal at the host, keyed to the host's floor cluster rather than to any node's zone.

This is a capability design path. Components may be shared with other catalog entries; it is not presented as a unique algorithm.

03 Validation plan

Own-hardware: one Raspberry Pi 5 with three RTL-SDR dongles per floor cluster, baselined a week, then exercised with a 433 MHz remote, an 868 MHz sensor and a cellular handset placed at surveyed distances; report minimum detectable emitter power against distance per band and the false-alarm rate from the building's own legitimate sub-GHz estate. No public dataset covers this geometry — this is the frontier experiment.

04 Commercial hypothesis

Requires an RTL-SDR and a Raspberry Pi 5 class host outside the ESP32-S3 package contract — priced and installed as a separate appliance, not as a node. An RTL-SDR (R820T2, ~24 MHz–1.77 GHz) cannot tune 2.4 GHz: this tier adds sub-GHz and cellular-band energy detection and is explicitly not a sensor for the band the rest of this vertical watches.

A quiet reading is not an all-clear. If nodes are stale, degraded or jammed, this runtime says so explicitly. It never infers safety from missing data.