For penetration testers, RF researchers, MSPs, and anyone who has to prove a test stayed in scope
Security teams & authorized testers
You have the skills and the authorization letter. What you do not have is a way to prove, six months later, that the RF envelope you transmitted in was the one the client signed, that the scan was read-only, or that the device you blocked was blocked for a documented reason.
Most teams keep that record in a spreadsheet nobody can verify and a chat thread nobody can find. When a client, an auditor, or a regulator asks "show me", the answer is a shrug and a screenshot.
The products on this path
In the order most people adopt them.
SignalLab
Security & RF intelligenceSigned, bounded authorization for lab-only RF and Wi-Fi testing, plus a monitor-mode bench kit for your own workstation.
Who it is for: Product security and RF test labs validating garage, gate, vehicle-keyless, and sub-GHz controller fixtures on a bench
Explore →BandSight
Security & RF intelligenceSee what is actually transmitting around you — a receive-only radio survey run from a phone and a low-cost USB receiver.
Who it is for: Security consultants and field assessors who get asked "is anything transmitting here that shouldn't be?" and need a defensible answer
Explore →ASL Scan
Security & RF intelligenceSigned-scope security assessments your client authorizes, your analyst verifies, and no one can quietly edit after the fact.
Who it is for: Managed service providers who assess client systems and need proof, not promises
Explore →Aegis
Security & RF intelligenceHost intrusion detection and measured response for one Internet-facing Linux server. Watches by default; blocks only when you say.
Who it is for: The solo developer or founder who runs one Internet-facing Linux server for a product, store, or client app and has no security team behind them
Explore →Network Sentinel
Security & RF intelligenceA running record of every device on your network, and an alert the moment something new joins.
Who it is for: A small-business owner who runs the office Wi-Fi and has no IT department
Explore →ASL X-Ray
Security & RF intelligenceRead what an Android app can do before you install it, without ever running it.
Who it is for: The one person at a small company who gets asked "is this app safe to put on the work phones?"
Explore →ASL Timestamp Anchor
Data protection & digital trustIndependent proof that your file existed at a moment in time, without uploading the file.
Who it is for: A therapist whose progress notes could be reviewed by a licensing board years after they were written
Explore →ASL Vault
Data protection & digital trustA credential store you can add to while it is locked. Only your passphrase opens it.
Who it is for: The one person who ends up holding every key for a small company: API keys, app signing material, account recovery codes, backup passphrases
Explore →Objections
The questions you are already asking.
We already use commercial scanners.
Keep them. ASL Scan is about the authorization and evidence around a test, not about replacing a vulnerability database. SignalLab and BandSight cover RF work no commercial scanner touches at all.
Does any of this transmit or exploit on its own?
No. SignalLab is a paperwork-and-proof layer with no transmit control. BandSight is receive-only. Aegis fails into monitoring, never into a lockout. Active adversary emulation in Scan runs only inside a signed plan with bounded traffic.
What happens to our data if we stop paying?
Your manifests, reports, and receipts are files you hold. They verify with standard tools after the service is gone. Nothing is held hostage.
How it starts
Proof first, breadth second.
Map
Name the users, the problem, the outcome, who has authority, and where the boundaries are.
Prove
The smallest useful version, with a visible test of success you define.
Accept
Review the result, the remaining risk, and the exit terms in writing.
Expand
Add only the products or capabilities that improve the outcome.
Define an authorized review.
One conversation. No specification needed. No customer data needed for the first call.