Surveillance Watch Benicia

← All findings

16 The City produced the record of its own search — and it shows the search was run on a bare keywordnew

Asked about SignalTrace device-identifier correlation, the City ran an unqualified keyword search that returned Leonardo.Ai marketing, Leonardo da Vinci and Leonardo DiCaprio. Its own tasking emails were produced along with the results.

Agencies are not usually required to describe how they searched. Benicia described it anyway, by including its own internal tasking emails in the production.

July 23, 2026, 1:05 PM — Records Supervisor Suzie Kaluza to IT staff Jeremy Karagan and Andrew Gailey (PR-2026-189 Email_Text Search):

“Please provide an email/text search for the following terms: Leonardo / Leonardo DRS / Leonardo US Cyber and Security Solutions / ELSAG / SignalTrace The time frame is January 1, 2022 to the present.”

1:28 PM, twenty-three minutes later (RE: PR-2026-189 Email/Text Search):

“Can you please also include: MAC addresses / Bluetooth / Wi-Fi Identifiers / RFID

July 27, 2026, the day before the response was due:

“This request is due tomorrow, could you please move this one to the front of the multiple requests I sent over? I left you a phone message, as well.”

What came back. All 29 documents match on the bare token Leonardo. Run unqualified across all City mail rather than scoped to the defence contractor, it retrieved:

What matched Count The “Leonardo” in question
Canva marketing blasts 13 Leonardo.Ai, Canva’s AI image-generation partner
CNN and SFGATE newsletters 2 Leonardo da Vinci’s Mona Lisa; Leonardo DiCaprio’s new film
Site Selection investor newsletter 1 Leonardo S.p.A.’s plant near Florence
IWCE trade-show promotion 1 Leonardo, listed among two-way-radio vendors

Seventeen of twenty-nine documents — 59% of the production — have no connection to the request. The search also returned the City’s own JustFOIA notifications of this request, because the request text lists the search terms and therefore contains the word “Leonardo.”

Nothing responsive to most of the request. The request had five parts. Items 1, 3 and 4 — contracts and purchase orders; records evaluating or piloting device-identifier collection on Benicia’s Flock network; any retention schedule specific to MAC addresses, Bluetooth IDs, Wi-Fi identifiers or RFID tags — produced no record at all. Only the email-search items returned anything.

The one substantive staff answer is from Senior Management Analyst Wendy Stratton Monahan (Re: Horton PRA -- PR-2026-189, July 23):

“I can look in MUNIS for the vendors as soon as I have access to my laptop this afternoon. Honestly, I don’t even understand what he is asking for in question 4. I personally haven’t received any requests for contract or agreements that allow any access to Flock or community cameras and I certainly haven’t processed any.”

Important limit on this finding: that is one analyst’s personal recollection, hedged with “I personally,” written before she had checked MUNIS. It does not establish that no such agreements exist — only that this staff member has not handled one. Whether the MUNIS check happened, and what it returned, is not in this production.

Stated fairly: an over-broad keyword search is a competence problem, not evidence of concealment. Nothing in this record shows that responsive documents exist and were withheld, and the City was under no obligation to hand-filter its own search results before producing them. Releasing the noise unfiltered is arguably the more transparent choice. The City also kept its statutory clock: the request was filed July 18 and answered July 28.

Not claimed here: that Benicia has acquired, piloted, or been offered SignalTrace. It has not been shown to have done any of those things.

Why it matters. The production cannot support the conclusion that Benicia has no records about device-identifier collection, because the search that produced it was not built to find them. Items 1, 3 and 4 called for procurement and policy systems — MUNIS, the contract file, the retention schedule — and the record shows only an email keyword sweep being run, five days after the request and expedited the day before it was due. A “nothing found” result carries weight only in proportion to the search behind it, and here the search is on the record.

What did reach Benicia PD

Six of the 29 are genuinely responsive, and all six are unsolicited vendor marketing or third-party journalism:

  • Weak Access Controls Leave Enterprise Networks at Risk — Daily Tech Insider to a City address, 2026-06-26, one month before the request:

    New License Plate Reader Tech Could Track Phones, AirPods, and Smartwatches — “Roadside cameras just got smarter — and more invasive. Leonardo’s SignalTrace pairs ALPR with Bluetooth/Wi-Fi/RFID detection to link phones, AirPods, or smartwatches to vehicles.”

  • Solar-powered plate readers find vehicles fast — Police1 Product Alert to a named BPD inbox, 2026-03-17, marketing the ELSAG® Street Sentry fixed LPR and footed “© Copyright Leonardo US Cyber and Security Solutions, LLC is a Leonardo company.”

  • Four Police1 RTCC features to two named BPD inboxes between 2025-04-08 and 2026-03-17, each carrying “Thank you to Flock Safety, Leonardo and Peregrine for supporting this content” or “Thank you to Leonardo for their support of this critical guide.”

Important limit on this finding: receiving a newsletter is not evaluating a product. None of these is a City record of a decision, and no inference about Benicia’s intentions can be drawn from an inbox. What they establish is narrower and still worth stating: the technology was described in front of Benicia PD staff, by name, before the City was asked about it — so the question is not hypothetical to the department.

A note on the redactions. The City’s cover letter states that records “have been redacted under the public interest exemption, as the public interest of disclosure of personal information is outweighed by the public interest in non-disclosure (Gov. Code 7922.000).” No redaction was applied to any of the 29 documents. The production released a staff member’s direct line and the requester’s personal email address. This is very likely not a violation — CPRA exemptions are permissive, not mandatory — but it sits against a record in which the City did redact private residents’ personal emails elsewhere, and the boilerplate describes a review this production did not receive. Both identifiers are masked on this site; the archive copies are intact.

Evidence: PR-2026-189/pdf/PR-2026-189 Email_Text Search.pdf, PR-2026-189/pdf/RE_ PR-2026-189 Email_Text Search.pdf, PR-2026-189/pdf/RE_ PR-2026-189 Email_Text Search(1).pdf, PR-2026-189/pdf/Re_ Horton PRA -- PR-2026-189.pdf, PR-2026-189/pdf/Weak Access Controls Leave Enterprise Networks at Risk.pdf, PR-2026-189/pdf/Solar-powered plate readers find vehicles fast.pdf, PR-2026-189/production-manifest.csv

The documents behind this

Read them yourself — that is the point.

Full write-up source: FINDINGS-2026-07-25.md in the records archive. Every quotation is transcribed from a PDF the City produced under the California Public Records Act. Redacted and image-only scans were run through OCR, so minor spacing artifacts may remain; wording is unchanged.