Someone arrives at your boardroom with a handheld unit, walks the perimeter for twenty minutes while a light on the device stays green, tells you the room is clean, and invoices you. You feel better. Nothing has been established.
That is the most common shape of the service sold in Canada as a "bug sweep", and it is close to unfalsifiable. The finding is almost always nothing, nothing is what a worried client hopes to hear, and the visit leaves behind no record anyone could later examine. A service whose normal output is reassurance can be performed badly forever without anyone noticing.
Technical surveillance countermeasures — TSCM — is the real discipline underneath. It is not a gadget. It is a documented physical, radio-frequency and infrastructure inspection of a defined space, performed against a scope agreed in writing, by people who record what they examined, what they found, and what they could not reach. On most engagements the report is the entire deliverable, because most engagements find nothing.
Why this service attracts theatre
Three things make TSCM unusually easy to fake. The customer is frightened — sweeps are commissioned after a leak, during a hostile negotiation, mid-litigation or through a divorce, and frightened buyers accept confidence in place of method. The equipment looks decisive: a screen, a needle, a light. And the expected result is negative.
That last one does the damage. If a plumber says the leak is fixed and it drips tomorrow, you know. If a sweep says the room is clean and the room really is clean, nothing distinguishes a thorough inspection from a walk-through — and nothing distinguishes them next week either, when the information keeps leaking, because it was never leaving that room to begin with.
None of that makes the discipline fake. It means the buyer has to judge the engagement rather than the outcome, because the outcome is uninformative by design.
A real engagement starts with a written scope
Before anyone attends, a professional engagement settles the same things a professional investigation does — and if you have read what a BC private investigator can and cannot legally do, the shape will be familiar. The question is always what decision the work is meant to support.
A scope worth signing states:
- The exact spaces, room by room, and the boundary of each. "The head office" is not a scope. A named boardroom, a named private office and the corridor between them is.
- What is included beyond the rooms — furnishings, fixtures, ceiling and floor voids, connected equipment, the network and communications infrastructure serving those rooms, and any vehicle or residence in play.
- What is excluded, and why. Space the client does not control, tenanted areas, live equipment that cannot be taken offline. Every sweep has exclusions; a provider claiming none has not looked at the building.
- Who has authority to consent to inspection of each space and each device — which matters enormously in leased premises, shared floors, and anywhere employees keep personal effects.
- The conditions of attendance — timing, who inside the organization knows, and how access happens without announcing the engagement to the whole floor.
- The deliverable — a written report, who receives it, and how long it is retained.
- What happens if something is found, agreed in writing before anyone is under pressure. This is the clause most often missing and the one that matters most.
If the conversation beforehand is only about price and duration, you are buying a visit, not an engagement.
What is examined, and how you know it was
A sweep has three inspection surfaces, and the report should show its work in all three.
Physical. A methodical, hands-on examination of the space and its contents against the agreed scope. The professional marker is not what was searched but that the search is enumerated — you should be able to reconstruct which rooms, voids, fixtures and items were examined, which were not, and why not.
Radio-frequency. A survey and characterization of the radio environment in and around the space, recorded rather than glanced at. The useful output is a record of what that environment looked like at that date and time, not a verdict from a light on a handheld unit. A single visit has no baseline; an environment surveyed twice tells you something a first visit cannot.
Infrastructure. The wiring, communications and connected systems serving the space, examined for anything inconsistent with how the building is documented to be built. Modern exposure sits here far more often than in the drama of a hidden device — an unmanaged network path, connected equipment nobody owns, a cloud service quietly relaying what a room's own systems already capture. Much of that is the discipline that keeps video systems off the open internet.
Notice what is absent from all three: any account of technique. That is deliberate here, and it should be deliberate in your provider's marketing too. A firm publishing detailed method is publishing a manual for evading the search.
The report is the deliverable
On a clean engagement the report is not a summary of the service. It is the service. A usable one contains the scope as executed and every deviation from it; the date, times, personnel and conditions of attendance; an enumeration of areas and items examined; the recorded results of each inspection surface, in a form a future visit can be compared against; the exclusions and limitations, stated plainly; findings that separate observation from inference; and ranked recommendations.
The recommendations deserve emphasis, because most real remediation after a sweep is procedural rather than technical: which conversations happen in which rooms, who holds keys, how visitors and contractors are escorted, and which devices are permitted in a sensitive meeting. A report that recommends only equipment is selling equipment.
What a negative result actually means
A negative result means: at the date and time of the inspection, within the scope as executed, using the methods applied, nothing inconsistent was identified.
It does not mean the room is clean. It does not mean the room was clean yesterday, and it says nothing about tomorrow — a space is only as secure as its access control from the moment the sweep ends, which is why the recommendations about who can enter the room matter more than the sweep did.
It also does not address the most likely explanation for a leak, which is that the information never left by technical means at all. It left through a person, an email, a document, a shared file, a phone somebody was invited to bring in, or a conversation held somewhere other than the room you had swept. A provider who lets you walk away believing a clean report has eliminated those is doing you a disservice.
The honest framing is narrow and useful: a sweep reduces one category of uncertainty, on one date, within one boundary, and leaves a baseline that makes a future inspection worth considerably more than a first one.
The legal frame, and why it constrains a legitimate provider
A serious provider is careful about what it does and does not do because the surrounding law is criminal, not merely regulatory.
Criminal Code s.184 makes it an offence to knowingly intercept a private communication by means of an electro-magnetic, acoustic, mechanical or other device. The exceptions sit at s.184(2) and they are narrow: consent, express or implied, of the originator of the communication or of its intended recipient; interception carried out under a judicial authorization or other lawful authority; and defined operational exceptions for those providing a telecommunications service and for federal radiocommunication management. A commercial security firm holds none of that authority. What it can lawfully do rests on the consent branch and on the ordinary right of an occupier to inspect premises they control.
Section 191 reaches the equipment itself: it is an offence to possess, sell or purchase a device knowing that its design renders it primarily useful for the surreptitious interception of private communications, and the exemptions run to those acting under lawful authority and to holders of a federal Ministerial licence. Countermeasures equipment is not that — its design is not primarily useful for intercepting anything. But the line exists, and a provider casual about which side of it their kit sits on has told you how they operate.
BC's Privacy Act supplies the civil half. Section 1(2) measures privacy by what is reasonable in the circumstances, and s.1(4) confirms that privacy may be violated by eavesdropping or surveillance whether or not there is any trespass. That is why the consent question in the scope is not paperwork: inspecting a space where others have a reasonable expectation of privacy, without the authority to do it, creates the exact exposure the client hired you to reduce. Where a device is discovered, Criminal Code s.342.1 — unauthorized use of a computer — is often closer to the facts than anything else.
One consequence is the hardest to sell. If something is found, the right next move is usually to stop, preserve, document and take legal advice — not to remove it, not to power it down, and not to start your own investigation inside a live scene. A provider who agreed that sequence with you in writing beforehand has thought about the day it happens.
Questions that separate an engagement from a performance
Ask any provider these before you sign.
- What is in scope, and what is excluded? A provider who cannot name an exclusion has not surveyed your building.
- What will the report contain, and can I see a redacted sample? If the answer is a certificate or a one-page letter, you are buying a prop.
- What are the limitations of a negative result? If they will not state them plainly, they are selling reassurance.
- What happens if you find something — what is the sequence, and who is called? It belongs in the proposal.
- What are your legal limits, and which section numbers do they come from? You now have three of them from this page.
- What do you recommend that costs nothing? A provider whose only recommendations are purchases has an incentive problem.
- Are you licensed under BC's Security Services Act, and what is the business licence number? Ours is in the footer of every page on this site.
Frequently asked questions
How often should a sweep be repeated?
No interval means anything on its own, because the value of repetition is comparison rather than frequency. Sweeps are best tied to events — a sensitive negotiation, a change of tenancy or contractor access, the start of litigation, a senior departure — with the earlier report as the baseline. Recurring visits with no baseline and no event are a subscription to reassurance.
If something is found, can you tell me who put it there?
No, and a provider who implies otherwise is overselling. Attribution is an investigative and often a legal question, resolved from access records and timelines — not from the discovery itself. What a good engagement gives you is a preserved, documented scene a later investigation can use.
Can I just buy a detector myself?
You can, and it will show you the same green light it would have shown the person you were going to hire. Equipment used without a method, a baseline or a record generates confidence, not information. If your risk is real enough to buy equipment, it is real enough to buy documentation.
If you are considering one
The useful conversation does not start with a price per room. It starts with what you believe is leaking, what decision the answer is meant to support, and which spaces the sensitive conversations really happen in. From there the scope, the exclusions and the found-something sequence get written down before anyone attends.
Guard Nation is licensed in British Columbia and holds a private investigator licence. Talk it through with us and we will tell you plainly what a sweep of your space could and could not establish, and what the report would contain.
Sources
- Criminal Code, RSC 1985, c. C-46, s.184 (interception of private communications) — https://laws-lois.justice.gc.ca/eng/acts/C-46/section-184.html
- Criminal Code, s.184(2) (saving provision — consent and other exceptions) — https://laws-lois.justice.gc.ca/eng/acts/C-46/section-184.html
- Criminal Code, s.191 (possession of a device primarily useful for surreptitious interception) — https://laws-lois.justice.gc.ca/eng/acts/C-46/section-191.html
- Criminal Code, s.342.1 (unauthorized use of a computer) — https://laws-lois.justice.gc.ca/eng/acts/C-46/section-342.1.html
- Privacy Act, RSBC 1996, c. 373, s.1(2) and s.1(4) (reasonable privacy; violation by eavesdropping or surveillance) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/96373_01
- Security Services Act, SBC 2007, c. 30 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/07030_01
