602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Technical Surveillance Countermeasures (TSCM)

Professional bug sweeps and electronic countermeasures to detect eavesdropping devices and protect sensitive communications and boardrooms.

How Honeybadger delivers Technical Surveillance Countermeasures (TSCM)

You retain a single accountable command. In Arizona, this service is executed by our own wholly-employed personnel; nationwide, we deliver through our Elite Managed Network of vetted operatives under Honeybadger’s unified command, oversight, and chain of accountability. Digital and financial intelligence supporting the engagement is handled in-house.

Who it’s for

Technical Surveillance Countermeasures (TSCM) is built for executives, legal teams, and organizations handling sensitive information.

Coverage

Available nationwide. See our service areas, or explore our Arizona command. Related: Physical Security · Executive Protection · Investigations.

What a TSCM sweep actually is

Technical surveillance countermeasures is the discipline of finding devices and conditions that allow someone to listen to, watch or read what happens inside a space. It is not a man with a wand walking a room. A defensible sweep is a structured inspection of the radio-frequency environment, the physical fabric of the space, the wiring and telecommunications infrastructure, and the network and endpoints inside it — because a modern eavesdropping problem is at least as likely to be a compromised phone, a rogue access point or a conferencing system with a forgotten account as it is a transmitter under a desk.

A proper sweep runs in layers. The radio-frequency survey characterises what is transmitting in and around the space and compares it against what should be — the signals that live in an office building are numerous, and the skill is in knowing what belongs. Non-linear junction detection finds semiconductor material inside walls, furniture and fittings whether or not it is powered or transmitting, which is the answer to devices that only wake on a schedule or on sound. Thermal inspection finds what is drawing power where nothing should be. Physical inspection covers the places devices actually live: power outlets and strips, smoke detectors, thermostats, light fittings, ceiling voids, furniture voids, picture frames, wall plates, and gifts. Telecommunications inspection covers instruments, punch-down blocks, patch panels, unused pairs and the cabling that runs out of the room. And a network and endpoint review covers wireless infrastructure, conferencing and camera systems, and any device with a microphone and a route to the internet.

The output is a written report: what was inspected, with what equipment, what was found, what was ruled out, and the conditions that make the space vulnerable regardless of whether anything was found today. That last section is usually the most valuable one.

When a sweep is worth doing, and when it is not

We will tell you when it is not. A sweep is a point-in-time result: it tells you the state of the space at the moment it was inspected, and it does not immunise the room afterwards. If the space is accessible to cleaners, contractors and visitors between sweeps, one sweep a year is theatre.

Sweeps earn their cost in specific situations. Before and during sensitive negotiations, board meetings, litigation strategy sessions and deal rooms. After a specific indicator: information appearing where it should not have, a competitor or counterparty who knows too much, a departure on bad terms, an unexplained entry, a device or gift of uncertain origin. On a periodic basis for spaces that host recurring sensitive discussion — executive offices, boardrooms, legal and HR suites. And in domestic and family-law situations where a person has reason to believe they are being monitored, which is a large and growing part of this work and often involves a vehicle and a phone rather than a room.

What matters as much as the sweep is what happens around it. Scheduling a sweep by email to the room’s own distribution list, or discussing it inside the space being swept, gives away the one advantage you have. We agree the communication protocol before anything is booked, and where the situation warrants it we work outside business hours and without prior notice to the site.

Vehicles, phones and the domestic cases

A meaningful share of real monitoring today involves no bugs at all. It is a tracker on a vehicle, an application installed on a phone by someone with physical access and the passcode, a shared cloud account that was never separated, a location-sharing setting left enabled, or a smart-home or camera account still linked to a former partner or employee.

Vehicle inspection covers the places trackers are actually placed — wheel wells, bumper cavities, under-seat and boot voids, the on-board diagnostics port, and factory telematics with an account attached to somebody else. Device and account work covers stalkerware indicators, account access review, connected-device and camera audits, and the separation of shared services. Where an account or device is involved, it moves to digital forensics so the evidence is preserved properly rather than destroyed by a well-meant factory reset.

One caution we give every client in a domestic situation: removing a device tells the other party you found it. Sometimes that is exactly right. Sometimes the better sequence is to document, preserve and take advice first. We will lay out both and let you decide with your attorney rather than making the choice for you in the driveway.

The legal frame, and the lines we do not cross

Countermeasures work sits close to laws that are easy to break by accident. Federal wiretap law and Arizona’s own statutes govern the interception of communications; Arizona is a one-party-consent state for recording a conversation you are part of, which is not the same thing as permission to record other people’s conversations, and it is a distinction people get wrong constantly. Placing a tracking device on a vehicle you do not own, or installing monitoring software on a device you do not own or lawfully control, carries real exposure.

So: we find and document. We do not intercept communications, we do not deploy monitoring on your behalf, and we do not access accounts or devices without documented lawful authority from someone entitled to give it. Where a finding suggests a criminal offence, the right next step is law enforcement and your attorney, with the evidence preserved rather than pulled apart.

In Arizona, investigative work is licensed under A.R.S. Title 32, Chapter 24 and guard services under Chapter 26. Honeybadger holds Private Investigations Agency licence 1759795 and Security Guard Agency licence 1759798. Reports are written to be usable by counsel, and where a matter is heading for court the inspection is documented to support testimony rather than to summarise a walkthrough.

How a sweep is scoped and priced

Sweeps are quoted per engagement, built from the number and type of spaces, square footage and construction, the telecommunications and network scope, whether vehicles and devices are included, whether work must be done outside hours or covertly, and travel. A single executive office is a different job from a floor of a building, and a boardroom with a video conferencing system is a different job from a boardroom without one.

Included: pre-engagement consultation and communication protocol, the inspection itself across the agreed layers, and a written report covering findings, exclusions and vulnerability conditions. Quoted separately: recurring sweep programmes, forensic examination of any device or account found, ongoing monitoring, and remediation work such as access control and policy changes — which is usually where the durable fix actually sits.

Frequently asked questions

Will a sweep guarantee my office is clean?

It will tell you the state of the space at the time it was inspected, and it will tell you the conditions that leave it exposed. Nobody can honestly guarantee a room stays clean afterwards if cleaners, contractors and visitors have access to it. Any firm promising otherwise is selling certainty it does not have.

How should I contact you if I think my office or phone is compromised?

Not from inside the space, and not from the device in question. Use a different phone or a different network, and do not put it in an email to a list that includes the room. We will agree the communication protocol at the first contact — that conversation is part of the work.

Do you sweep vehicles and phones as well as rooms?

Yes, and in domestic and family-law matters they are more often the answer than a room is. Vehicle inspection covers the placements trackers actually use, including the diagnostics port and factory telematics. Device work covers stalkerware indicators, account access and connected-device audits.

You found something. Should I remove it?

Not necessarily, and not before you have taken advice. Removal tells the other party you found it and can destroy evidence that would have been useful. We will set out the options — document and preserve, or remove and secure — and you make that call with your attorney.

Can you monitor someone for me, or recover their messages?

No. We find and document surveillance; we do not conduct it. Intercepting communications, installing monitoring on a device you do not lawfully control, or placing a tracker on a vehicle you do not own carries serious legal exposure, and no legitimate firm will do it for you.

How often should a boardroom be swept?

It depends on who can get into it between sweeps, not on the calendar. For a space with controlled access and sensitive recurring discussion, a periodic programme tied to the meeting cycle makes sense. For a space anyone can walk into, access control will buy you more than sweep frequency will.