Continuous RF environment intelligence. Replace periodic walk tests with permanent, distributed survey infrastructure.
Understanding a cellular RF environment means sending someone with a phone and a scanner. Walk tests and drive tests produce point-in-time snapshots that start going stale the moment the crew leaves.
Meanwhile, the environment keeps changing:
For any organization that needs to know — continuously — what carriers are visible, what signal levels look like, and whether expected coverage is actually present, the only answer has been to keep sending people. There hasn't been an automated alternative.
CellAudit is a distributed monitoring platform that turns RF survey work into permanent infrastructure. A network of small nodes — each behaving like a synthetic cellular phone — continuously probe the carrier environment and report findings over an independent LoRaWAN backhaul.
Every node periodically scans for all visible carrier networks (PLMN enumeration, no SIM required), attempts registration on each detected carrier, measures engineering-grade RF metrics, attempts a data session to verify end-to-end connectivity, then transmits a compact result payload via LoRaWAN. Results are timestamped, stored, and surfaced on a dashboard. What used to require a technician's time produces continuous, automated data instead.
The cellular interface is the system under test. The LoRa network is the independent reporting path.
Using cellular data to report on cellular conditions conflates the measurement path with the reporting path. CellAudit uses a LoRaWAN backhaul on the 902–928 MHz ISM band, physically separate from the spectrum being measured. Nodes report faithfully from locations with no usable cellular coverage — which is exactly where the interesting data is.
Deploy nodes throughout a building, campus, or facility for ongoing coverage validation. Set a threshold; get alerted when a location drops below it. What previously required sending a technician with a scanner produces automatic, continuous data instead.
Each node registers against every visible carrier independently, producing side-by-side signal quality data for AT&T, T-Mobile, and Verizon at the same physical locations over time. See which carrier wins where — and when that changes.
When something in the RF environment shifts — a new interferer, a carrier frequency update, a hardware failure in nearby infrastructure — nodes detect the change automatically. No manual baseline re-testing required.
Managed Access Systems (MAS) — deployed in correctional facilities to block contraband cellular phones — are commissioned and spot-tested, but rarely monitored continuously. Carrier network modifications, hardware degradation, and RF environment changes can all erode suppression effectiveness between tests, and operators have no way to know until after a security incident.
CellAudit is well-suited to this problem because of a property that matters acutely here: the LoRaWAN reporting path is immune to cellular suppression. A node inside an active MAS zone can report "no carriers detected" — or, critically, report a breakthrough if a carrier registers when it shouldn't. The monitoring system cannot be defeated by the condition it is monitoring.
A planned MAS spoof detection layer will cross-reference Cell IDs against the OpenCelliD community database, flag suspiciously sparse neighbor cell lists, detect RAT downgrades (LTE/5G jammed but 2G still served), and identify signal geometry anomalies. This moves the platform from "did suppression work?" to active MAS integrity verification.
Most cellular monitoring tools report only whether data connectivity succeeded or failed. CellAudit uses the modem's full AT command interface to extract diagnostic information that is invisible to application-layer tools:
| METRIC | WHAT IT TELLS YOU |
|---|---|
| RSRP / RSRQ / SINR | Quantitative signal strength per carrier — trending reveals degradation before it becomes an outage |
| Cell ID + TAC | Which specific tower is serving the node — distinguishes the macro network from local infrastructure |
| ARFCN / Band | Exact frequency and technology in use — detect carrier reconfigurations and band additions |
| Registration reject cause | Distinguish "no coverage" from "suppressed" from "authentication failure" — the difference matters |
| Neighbor cell list | Real macro towers advertise 6–12 neighbors; sparse lists indicate non-standard serving infrastructure |
| PLMN scan (no SIM) | Enumerate every visible carrier network without requiring an active subscription on each one |
CellAudit is a working prototype on commercial off-the-shelf hardware.
The hard part wasn't wiring a modem to a LoRa radio. It was understanding the RF semantics well enough to extract meaningful signal from raw AT command output — knowing which fields are diagnostic, which are noise, and what each registration state actually means in context.
The MAS verification case sharpens this further: you need to distinguish a correctly-suppressing system from one with simply no coverage, a rogue base station from a legitimate distant tower, and a transient condition from a persistent failure. That kind of domain-specific judgment shapes the data model, the anomaly detection logic, and the dashboard design. It's the work that requires RF domain knowledge, not just software.
Whether you're auditing carrier coverage, validating a DAS deployment, or verifying a Managed Access System, we'd like to hear what you're trying to measure.
info@bandpassconsulting.com