Leonardo’s SignalTrace is not merely another license-plate-reader upgrade. It is a system designed to turn the phones, watches, earbuds, RFID tags, and vehicle electronics around us into a passive, location-linked surveillance network.
For years, Americans have been told that automated license plate readers are a narrowly tailored tool: a way to find stolen cars, locate missing people, or identify a vehicle connected to a serious crime. SignalTrace points toward something much broader. It is surveillance that no longer depends on a license plate—or even necessarily on a car.

Leonardo markets SignalTrace as an “integrated signal intelligence system” for law enforcement. It captures signals emitted by consumer devices, correlates the devices that repeatedly travel together, and creates what the company calls an “electronic fingerprint.” The system can associate that fingerprint with license-plate-reader data when available, but Leonardo says it can also operate in places without plate readers, including malls and subways.
That distinction matters. A license plate belongs to a vehicle. An electronic signature can follow the person carrying the same phone, smartwatch, headphones, key finder, or work badge from one vehicle to another—and potentially into spaces where a plate-reader camera has no role at all.
Leonardo’s own example makes the point: an iPhone, car radio, headphones, sports watch, key finder, and plate number can form a combination unique enough to distinguish one vehicle from many others. In practice, that means the system is built to identify not just a machine on the road, but a recurring cluster of devices tied to a person’s everyday life.

Leonardo emphasizes that SignalTrace does not decrypt communications or read files and messages on a person’s device. That is an important technical boundary—but it is not the same as privacy.
The central privacy problem is metadata: who was where, when, with whom, how often, and in what pattern. SignalTrace is explicitly designed to store data for later query and analysis, identify the movement of devices and vehicles, and reveal groups of devices that regularly travel together.
A government agency does not need access to the content of your texts to learn a great deal about your life. Repeated appearances at a medical clinic, mosque, union hall, political protest, immigration office, gun shop, addiction-treatment center, or the home of a particular person can sketch an intensely personal portrait. Existing ALPR systems already create this risk by collecting plate, time, and location records at scale; adding device-linked signatures makes the picture more persistent and more personal.

SignalTrace’s danger is not simply that it collects another category of data. It is that it fuses categories that have traditionally been separate:
License plates and vehicle descriptions.
Phone, Bluetooth, Wi-Fi, and RFID-related signals.
Time-and-location records.
Co-travel and association patterns.
Historical search and analytical tools.
Each piece alone may be framed as limited. Together, they can create a searchable record of a person’s movements and social connections—without a warrant, without notice, and potentially without any initial suspicion that the person committed a crime.
SignalTrace also weakens the basic protective friction of older surveillance systems. If police want to follow a specific vehicle, they ordinarily need its plate, a physical description, or an officer on the street. But Leonardo says SignalTrace can help recognize a vehicle within a known electronic signature even when its plate number is unavailable. In other words, swapping cars, borrowing a vehicle, or avoiding a camera’s view may matter less if the devices in your pocket become the identifier.

The usual justification for surveillance tools is that they help solve crimes. But the relevant question is not whether a system might assist an investigation. Almost any surveillance system can do that. The question is whether the state should build and retain a searchable record on everybody first, then decide later whom to investigate.
That is already the structural problem with ALPR networks. They automatically capture plates, locations, dates, and times for vehicles that enter their view; over time, this can reveal travel histories, relationships, routines, and visits to sensitive locations. EFF notes that such systems collect information on millions of people who are not connected to a crime, and that an analysis of data from 63 California law-enforcement agencies found only 0.05 percent of captured ALPR data was relevant to a public-safety interest at the moment it was collected.
SignalTrace expands that dragnet from “Which car passed this camera?” to “Which devices were present, which moved together, and where else has that combination appeared?”
That is a substantial change in the balance of power between individual citizens and the institutions watching them.

If agencies deploy this technology, basic privacy protections should be mandatory—not optional promises in vendor marketing:
Require a warrant based on probable cause before an agency can search a historical electronic signature or link it to a person.
Ban indiscriminate, long-term retention of device-signature data from people not tied to a specific investigation.
Prohibit use for monitoring protests, religious attendance, immigration enforcement, reproductive-health care, labor organizing, or other protected activity.
Require public notice, legislative approval, independent privacy-impact assessments, and published deployment maps before installation.
Limit data sharing across agencies and forbid sale, commercial reuse, or contractor access outside tightly defined technical support.
Require immutable audit logs, meaningful penalties for misuse, regular independent audits, and a mechanism for people to challenge wrongful identification.
Make clear that a device-signature match is an investigative lead—not proof and not a standalone basis for a stop, search, or arrest.
Leonardo says the system includes access controls and auditing, and that agencies determine whether and how their data is shared. But “the customer controls the data” is not a civil-liberties safeguard. It simply shifts responsibility from the vendor to thousands of agencies with widely different policies, retention rules, technical competence, and accountability.
SignalTrace is a warning about where modern surveillance is headed: away from targeted observation and toward ambient collection. The threat is not that the government suddenly gains the ability to read every phone. The threat is quieter—and, in some ways, more consequential. It is the construction of a system that can recognize the digital traces surrounding ordinary people, store them indefinitely, and reconstruct their lives after the fact.



