Flock Investigation

Community Technology Investigation: 1

What we conclude.

FLOCK / AUTOMATED LICENSE PLATE READERS

We did not begin this investigation with the conclusion that Flock should be rejected. We reached a conclusion by following the evidence.

After examining the architecture, actual uses, documented misuse, safeguards, information flows, contractual terms, vendor representations, and the mechanisms available to prevent abuse, we do not believe the benefits of the system as it currently operates outweigh the risks it creates.

Our assessment

We do not currently consider Flock Safety a sufficiently trustworthy steward of this kind of surveillance infrastructure.

That is our assessment—not a claim that every employee acts improperly, every deployment is abusive, or every statement the company makes is false.

It is a judgment about the whole record. A company asking communities to deploy infrastructure capable of observing movement at scale should, in our view, be held to an unusually high standard of technical restraint, transparency, accuracy, and independently verifiable safeguards.

The evidence we reviewed does not persuade us that Flock currently meets that standard.

Conclusion 01

Flock’s reassurances repeatedly answer a smaller question than the one the public is actually asking.

Again and again, reassuring language collapsed under scrutiny. “A reason is required” did not mean the reason was verified. “Searches are audited” did not mean misuse was prevented—or even that anyone consistently reviewed the logs. “No facial recognition” did not mean no computational search for people, and it did not prevent exported imagery from undergoing facial recognition elsewhere. “Deleted after 30 days” did not mean every copy, export, evidence record, or derived result disappeared. “You own your data” did not establish exclusive control over its use, movement, or transformation. The words may be technically defensible. The impression they create is dangerously incomplete.

Conclusion 02

The system is built to document misuse after access—not reliably stop it before the information is exposed.

Flock has demonstrated that stronger preventive controls are technologically available. Yet the architecture we examined still relies heavily on users declaring their own purpose, systems recording what they did, supervisors reviewing it later, and consequences arriving after the search. That is accountability after access, not protection before access. Once sensitive information has been returned, viewed, shared, downloaded, or acted upon, no audit, suspension, or disciplinary proceeding can make the exposure unhappen.

Conclusion 03

Officials may approve a camera network and unknowingly authorize a surveillance system that can keep expanding around it.

The government-owned cameras visible in a proposal are only the physical front door. Private cameras can become searchable. Agencies can gain access across jurisdictions. Integrations can connect additional databases and investigative tools. Software updates can introduce or expand capabilities long after the hardware has been approved. The effective system is defined not by the number of cameras officials purchased, but by every camera, user, agency, database, integration, search capability, and downstream workflow the platform can reach.

Conclusion 04

Once information leaves Flock, Flock’s retention policy stops describing its actual lifespan.

Flock information can be downloaded, exported, transferred through APIs, incorporated into evidence systems, shared with other agencies, combined with outside records, and transformed into alerts, reports, associations, and investigative conclusions. Those copies and derived records can persist under entirely different rules. A promise that information is deleted from one platform after 30 days says little about what survives elsewhere—or how long the consequences of that information remain in motion.

Conclusion 05

Flock’s assurances cannot be treated as evidence. Consequential claims require independent verification.

We found consequential representations about system capabilities, access, and safeguards that did not survive government review, direct testing, or later correction. This investigation does not assume that every Flock statement is false. It establishes something more important: Flock’s description of its own system is not an adequate substitute for examining what the system can actually do. Claims about access, searches, safeguards, sharing, retention, deletion, and technical limits must be independently tested before officials rely on them—and before the public is asked to trust them.

Our judgment

Flock can help solve crimes. That does not end the analysis.

We found real investigative capability and real public-safety benefit. The question is not whether Flock can produce useful evidence. It can.

The question is whether those benefits justify the surveillance reach, misuse risk, information persistence, network expansion, downstream data movement, and level of institutional trust the current architecture requires.

Based on the record we examined, our answer is no.

Before voting

Ask the question the reassurance does not answer.

Not only:

Does it have a safeguard?

Ask:

Where does the safeguard actually stop the prohibited action?

Not only:

Is the data deleted?

Ask:

Which data, from which systems, and what copies or derived records survive elsewhere?

Not only:

Does Flock use facial recognition?

Ask:

What can the system do to search for people, and what can exported imagery be used for?

Not only:

Who owns the data?

Ask:

Who can use it, retain it, derive information from it, and for how long?

Not only:

What does Flock say?

Ask:

How was the claim independently verified?

You may examine this evidence and reach a different conclusion. That is why we published the findings, limitations, unresolved questions, Works Cited, and full Research Bibliography.

A community cannot meaningfully consent to a technology it has not been allowed to fully understand.

Continue