The short version: a defense contractor, Leonardo, is marketing a system called ELSAG SignalTrace that bolts sensors onto automatic license plate readers so the cameras capture more than your plate — they sweep up the electronic identifiers of the phones, smartwatches, earbuds, AirTags and car systems moving past, then tie that “electronic fingerprint” to a specific vehicle and plate. It is the convergence of two tracking layers into one: where your car goes and which devices travel with it. Crucially, it can identify a vehicle by its devices even when the plate can’t be read. As of mid-2026 it is newly marketed, not confirmed as widely deployed — Leonardo has not named the agencies using it — but the patent is granted, the product sheet is public, and the sales calls are happening.
What SignalTrace actually is
The story was first reported by 404 Media’s Joseph Cox, who described a plan to add sensors to ALPRs that would sweep up the unique identifiers of mobile phones, wearables, and other Bluetooth-enabled devices in passing vehicles, potentially letting law enforcement identify specific drivers or passengers. The product is marketed by Leonardo US Cyber and Security Solutions — a company already in the license-plate-reader business through its ELSAG systems.
Leonardo’s own description is unusually clear about the mechanism. Per the company’s product page, electronic devices such as fitness trackers, smartwatches, RFID tags and mobile phones emit signals into the air, and SignalTrace creates an electronic fingerprint for groups of signals the system determines are frequently emitted together, using strategically placed sensors to build an additional data set that enhances the records captured by nearby LPR cameras. In plain terms: it watches which devices keep showing up together, calls that cluster a person, and staples it to a plate.
How the two systems work together
This is the part you asked about, and it is the whole design goal — SignalTrace is not a standalone gadget, it is a layer on top of ALPR. The mechanism, straight from the patent that underpins it: if LPR cameras are deployed at the same sites as the electronic-signature sensors, officers can match the date and time stamps from both systems to associate a specific license plate number with a device signature. Two independent readings — the camera sees the plate, the sensor sees the devices — are joined on a shared timestamp and location. The output is a single record: this plate, this car, these devices, here, then.
Jalopnik’s walk-through makes the result concrete: pass one associated ALPR-plus-SignalTrace site and authorities could know you operate a specific make and model in a specific state, carry a particular smartwatch, and a particular phone — an “electronic fingerprint” that can then be used to track movements or flag when multiple suspects are traveling together. The plate identifies the machine; the device signature identifies the people in it. Fused, they convert a car-tracking network into a people-tracking network.
The plate becomes optional
The most consequential detail is the one that gets least attention. Because the device signature is an independent identifier, the system doesn’t need the plate at all. Leonardo’s patent announcement states the technology allows law enforcement to recognize a specific vehicle by electronic signature even if the license plate is removed, obscured, or changed. Every physical countermeasure people have reached for against ALPR — a dirty plate, a cover, a swap — is defeated by a system that was never looking at the plate to begin with. The camera becomes optional; the surveillance does not.
Why the “bolt-on” design is the real story
SignalTrace matters less as a gadget than as a strategy. One analysis put it precisely: surveillance growth here comes less from dramatic new hardware than from attaching fresh data layers to systems cities and police already bought, and the strategic advantage for agencies is adoption friction — it can be pitched as an extension of an existing ALPR ecosystem rather than a wholly separate surveillance buildout.
That is the same pattern the Flock-to-Axon vendor story exposed from a different angle: the expensive, visible fight is over the cameras, while the capability quietly expands through the plumbing already in the ground. A city that debated its ALPR contract for months may never get a second debate before a device-signature sensor is added to the same pole. There is no camera to spot, no new pole to notice at the council meeting — just a firmware-and-sensor upgrade to infrastructure the public already lost the argument about.
The privacy problems this raises
Stacking a persistent device identity on top of a location network changes the privacy calculus in specific, documented ways.
- You cannot opt out. As Jalopnik notes bluntly, like ALPRs, you can’t just “opt out” — the collection happens as you pass, with no notice and no consent, to anyone carrying a powered-on device.
- It identifies people, not just cars. 404 Media’s framing is the core shift: the technology would turn ALPR cameras from devices focused on tracking cars into ones that can more readily track the location of particular people. A passenger who never owns the car is now in the record.
- “We don’t read content” sidesteps the actual harm. Leonardo emphasizes that SignalTrace captures device signals but does not decrypt or read the contents of the devices or their communications. True — and beside the point. The privacy injury from persistent location-and-association tracking doesn’t require reading a single message; knowing who went where, with whom, how often is the harm.
- The abuse track record is already there. ALPR data specifically has a documented history of misuse — officers arrested for stalking with plate data, dozens of agencies using it to track activists, and location data fed into immigration enforcement. Layering permanent device identities onto that same infrastructure raises the stakes of every one of those failure modes. Max Intel keeps the running accountability file of documented ALPR misuse.
Who Leonardo is — and why that matters
Context worth having: this is not a startup. Leonardo is a large publicly traded Italian defense and security company, with a market capitalization well above $17 billion, and its US arm markets SignalTrace as integrating with its Enterprise Operations Center to support identification of suspect people or vehicles even when a license plate number is not known. The lineage runs from defense to local policing — the capability being pitched to a county sheriff descends from a patent, US 11,941,716 B2, granted March 26, 2024 for “Systems and Methods for Electronic Signature Tracking”, built for finding “people of interest” by the signals their devices emit.
How widely is it deployed? (Be precise here)
This is where accuracy matters, because the topic invites overstatement. The honest status as of mid-2026: SignalTrace is newly marketed rather than widely deployed, Leonardo has not publicly named the agencies or states using it, and most drivers are unlikely to encounter it today. The patent is real, the product sheet is public, and it is being actively sold — but a granted patent and a marketing push are not the same as a camera on your commute. Anyone telling you this is already tracking every driver is ahead of the evidence. The correct posture is watchfulness, not alarm: the infrastructure and the intent are documented; the deployment footprint is not yet.
What actually reduces your exposure
Because the system reads what your devices emit, the only real mitigations are on the emission side — and they are the same device-hygiene steps that limit any passive wireless tracking:
- Cut needless radios in transit. A phone with Bluetooth and Wi-Fi off emits far less for a roadside sensor to fingerprint. AirTags, wearables, and always-on earbuds are the loudest, most persistent beacons you carry — each one is a stable identifier.
- Keep MAC randomization on, per-network. It doesn’t defeat every technique, but a stable MAC or a fixed Bluetooth device name is the easy identifier; removing it forces any tracker to work harder.
- Understand the limits. Randomization is not a force field — active research shows Wi-Fi devices can be re-identified through behavioral patterns even with randomized MACs. This is about reducing your footprint, not achieving invisibility.
- Aim the real fight at policy. Device-signature collection tied to plates is precisely the kind of persistent, warrantless association tracking that the mosaic-theory / Carpenter line of Fourth Amendment argument targets — and, like ALPR, the durable limits will come from state law and local procurement oversight, not from a setting on your phone.
Bottom line
SignalTrace is the logical next step of the ALPR business model: having saturated the country with cameras that identify cars, the vendors are now adding sensors that identify the people and devices traveling with them — and joining the two on a timestamp so a plate and a pocket full of electronics become one record. It defeats plate-based countermeasures because it was never watching the plate. It is not yet widely deployed, and honesty about that is part of taking it seriously. But the patent is granted, the product is being sold, and the design intent is explicit. The meaningful response is the same one that works against the rest of this ecosystem: emit less, and push the fight to the statutes and contracts that bind whatever sensor goes on the pole next.
Primary sources: 404 Media (Joseph Cox, original reporting); Leonardo US — ELSAG SignalTrace product page and EOC Plus product sheet; BusinessWire / Silicon UK (patent US 11,941,716 B2 announcement, Mar 2024); Jalopnik, The Drive, CarPro, Military.com, The Deep Dive (secondary reporting, Jun 2026); deployment-status characterization per contemporaneous reporting that the product is newly marketed and not yet widely deployed. Claims describe a marketed capability and its documented design; they do not assert a specific agency’s current use.