Methodology

What actually happens during a professional sweep.

Most people have never seen one and have no way to judge whether they are getting a real inspection or an expensive performance. So here is the whole process, start to finish, including the parts that are dull. If a firm you are considering cannot describe their own version of this, that tells you something.

Read this before you call anybody

If you believe an area may be compromised, do not discuss it in that area, and do not use a telephone you suspect. A conversation about hiring a sweep team is the single most valuable thing a listening device will ever capture — it tells whoever is on the other end exactly when to come and collect it. Call us from somewhere else, or we will happily meet you somewhere neutral.

01

Before anything else

Confidential intake

We talk first — and not from the room you are worried about, and not on a telephone you suspect. We will happily arrange to meet you somewhere neutral, or speak while you are out of the building.

What we need to understand: what happened that made you call, who has had access and when, what a hostile party would gain, and who inside your organisation knows you are considering a sweep. That last question matters more than any other.

Why we will not discuss this in the room

If a device is present, a conversation about hiring a sweep team is the single most valuable thing it will ever capture. It tells whoever is listening exactly when to retrieve the device — and a device removed the night before is a sweep that finds nothing and proves nothing. Every case is handled on the assumption that the location is already compromised until we have established otherwise.

02

Before arrival

Threat model and scope

Who is realistically interested, what would they gain, and what could they plausibly deploy? A domestic case and a corporate espionage case call for different searches. A jealous ex-partner buys something off a marketplace. A competitor with real money behind them may field equipment that only transmits for a few milliseconds at a time.

Out of that comes the scope: which rooms, which vehicles, which telephone and data lines, which devices, on what date, and at what hour. We agree it in writing before we arrive, so nobody is surprised by either the invoice or the coverage.

03

Usually out of hours

Arrival, discreetly

We arrive in plain vehicles and plain clothes. No livery, no branded cases in the lobby, no announcement. If a cover story helps — IT contractors, an air-quality survey, an insurance inspection — we will agree one with you in advance and stick to it.

Before we touch anything we photograph the space. Every item we move goes back precisely where it was. When we leave, the room looks untouched, because the wrong person noticing that a sweep happened is itself a leak.

04

1–2 hours

Radio-frequency baseline and spectrum analysis

We establish what the radio environment in your building normally looks like — Wi-Fi, cellular, two-way radio, wireless microphones, the building's own systems, the broadcast towers outside. Without that baseline every reading is meaningless, because a busy office is full of perfectly legitimate signals.

Then we look for what does not belong. A spectrum analyser sweeps from the low kilohertz up into the gigahertz range and shows every carrier present. Anything unexplained gets demodulated and listened to, and correlated against sound we generate in the room.

What 'correlation' means, and why it is the moment that matters

Finding an unexplained signal is interesting. Proving it is coming from inside your room is conclusive. We introduce a known sound into the space and check whether it appears, in step, inside the suspect transmission. When the instrument reports 'Correlates: Yes', that is no longer a theory — the room you are standing in is being transmitted out of it. From there it is a matter of walking the signal down to the object.

Spectrum analyser display: a carrier at 417.990 MHz stands well above the noise floor, and the correlation panel reads Correlates: Yes
What a find looks like on the instrument. The tall spike is a carrier at 417.990 MHz sitting roughly 47 dB above the surrounding noise. Bottom left, the correlator reports “Correlates: Yes” — sound introduced into the room is present inside that transmission.
05

1–3 hours

Wiring, telephone and data-line analysis

A great many devices never touch the airwaves at all. They ride the cabling that is already in the building: telephone pairs, network runs, alarm and intercom loops, and the mains wiring itself.

We test telephone instruments and their lines for hook-switch bypass (which turns a handset on the cradle into a live microphone), for series and parallel taps, and for voltage and current that does not match a clean pair. We use a time-domain reflectometer to find physical anomalies along a cable run — an unexpected junction eighty feet down a wall reads on the trace as plainly as a knot in a rope. We examine the AC wiring at very low frequency for carrier-current devices, which use your own mains as their aerial.

06

2–5 hours

Physical search, non-linear junction and infrared

This is the longest part, the least glamorous, and the part that finds the devices nothing else can. A recorder that stores to a card emits nothing. A transmitter that is switched off emits nothing. Neither will ever appear on a spectrum analyser — they have to be found by hand.

A non-linear junction detector solves the hard half of that. It responds to the semiconductor junctions inside any electronic circuit, powered or not, so it will register a dormant device buried inside a wall, a chair, a book or a light fitting. Infrared and optical examination covers lenses, laser and infrared links. Then we take the room apart carefully and put it back: fittings, vents, voids, furniture, frames, plates and plugs.

Why a hand-held detector from the internet will not do this

Those devices do one thing: they light up near a strong, continuous radio signal. They cannot find a recorder that never transmits, a burst device that transmits for a few milliseconds an hour, a voice-activated device that is silent while you sweep, a carrier-current device on the mains, a tap on a telephone pair, or a camera storing to a memory card. They will, however, light up enthusiastically near your own Wi-Fi router and give you the comforting impression that you have done something.

Flight cases of detection instruments opened out before a sweep
Instruments staged before a commercial sweep. The physical search phase draws on most of them — non-linear junction detection, optical and infrared inspection, and borescopes for wall voids and ducts.
07

Same day, then in writing

Findings, evidence and counter-measures

If we find nothing, we tell you that clearly and we tell you what 'nothing' covers: which areas, which frequencies, which lines, on which date. An honest negative is a real result, and it is the result most of the time.

If we find something, we do not simply rip it off the wall. What you want from that object depends entirely on what you intend to do next, and that decision is yours to make with your attorney. It can be left in place and fed, documented and removed under chain of custody, or neutralised on the spot. We will explain the trade-offs before anyone touches it.

You receive a written report: areas covered, instruments used, frequency ranges examined, lines tested, anything recovered, photographs, and our recommendations — including how often this site should realistically be swept again.

Plain limits

What a sweep cannot do.

Anyone who tells you a sweep guarantees you are safe is overselling. Here is the honest shape of it.

It is a snapshot, not a shield

A sweep tells you the state of a room on the day we swept it. If the access that allowed a device is still open, the room can be compromised again the following week. That is why we push physical security assessment as hard as we do.

It cannot prove a negative forever

We can state exactly what we examined, over which frequency ranges, on which lines, on which date. That is a strong and useful statement. It is not the same as 'you have never been bugged', and we will not pretend otherwise.

It does not tell you who

Recovering a device rarely identifies the person who placed it. Establishing that is investigative work — access records, timelines, interviews, forensics — which is available here, but it is a separate exercise from the sweep.

Still have questions about the process?

Ask them. The consultation costs nothing and we will give you a straight answer, including if that answer is that you do not need us.