Sign it before you transmit.
SignalLab turns an offensive RF or Wi-Fi test into a signed, auditable engagement. Build an authorization manifest that pins the exact frequency envelope, power ceiling, required containment, and test fixture; the app hashes and verifies it, then records your bench pre-flight and every session against it. It is a paperwork-and-proof layer — deliberately not a transmitter. The public app never exposes a transmit button.
The problem
RF testing lives or dies on authorization.
Transmitting into the spectrum — even in a lab — is legally fraught. The difference between legitimate red-team RF work and an FCC violation is a defensible, specific, countersigned authorization that proves the envelope was bounded and the signal was contained. Most teams track that in a spreadsheet nobody can verify.
SignalLab makes the authorization the product: policy-as-code that refuses to issue an insufficient manifest, a canonical hash anyone can re-verify, and a session log that records permitted-versus-done.
The hard boundary
- No transmit control in the public app — ever
- Fixture policy forces shielding for risky classes
- Refuses to issue an under-scoped authorization
- Integrity + revocation + countersignature = chain of custody
- Wi-Fi tier is receive-only detection from a capture file
Capabilities
A defensible record, end to end.
Manifest builder
Pin an RF envelope — start/end MHz, a hard +10 dBm max, attenuation, and the required containment — into a structured authorization.
Policy-as-code fixtures
Fixture classes (garage, gate, vehicle) are forced to a shielded enclosure; the app refuses to issue a manifest whose containment is insufficient for its scope.
Countersignature
An authorization isn't valid on one signature — it carries a countersignature so no single person can self-authorize a transmit test.
5-step bench pre-flight
A hashed-in pre-flight checklist captures the physical bench state before a session, so the record reflects reality, not intention.
Canonical hash + verifier
An SHA-256 canonicalization with an 11-point verifier — anyone can independently re-verify that the manifest they hold is the one that was signed.
Revocation (CRL)
A certificate-revocation-list model retires an authorization; a superseded or revoked manifest is detectable, not silently reused.
Session records
Each session logs permitted-versus-done, with manifest diff, supersede, and a printable report for the engagement file.
Link-budget calculator
Built-in link-budget math and ISM-band presets so the envelope you sign is the envelope you reasoned about.
Wi-Fi tier (receive-only)
Signed 802.11 test plans plus in-browser, receive-only detection of rogue APs, deauth, and karma attacks by parsing an airodump capture — never by transmitting.
Make your RF work defensible.
Bounded envelope, forced containment, countersigned authorization, and a hash anyone can verify — before a single watt leaves the bench.