Flock’s New Privacy Guardrails Are Meh...Its Retreat From Transparency Isn’t.
Flock is rolling out new privacy guardrails under growing national pressure. Some are real improvements. But stronger internal controls are not the same thing as independent transparency or democratic accountability.
Flock Safety is finally admitting something privacy advocates have been saying for years: when you build a nationwide surveillance network capable of tracking where millions of people drive, “trust your local police department” (or corporate surveillance tech vendor) is not a serious privacy policy.
On August 14, 2026, and in response to significant national opposition to their products, Flock Safety CEO Garrett Langley started off a nationally coordinated white-washing campaign with one hell of an admission: “You will see over the next six months a dramatic increase in officers being arrested or fired for abusing Flock...” Not content with his current effort to sink flock’s valuation pre-IPO, Langley continued to stick his foot into his mouth. Asked whether it had taken Flock too long to protect tens of thousands of its cameras, license plate readers and drones from police abuse, Garrett Langley said: "Yeah... yes."
Langley said that the success of the changes will be measured by how many officers abusing the technology are arrested and removed. I can’t make this stuff up. The CEO of the current undisputed corporate villain title is proclaiming that the success of his company’s technology will depend upon the number of police officers that commit crimes with it. We are truly in the upside-down world.
Last week, Flock announced a package of new safeguards in response to what can only fairly be described as an exploding national backlash against its license plate reader network. Cities are rapidly canceling contracts and Flock is in all-out panic mode.
Officers have been accused of using the system to stalk people. Journalists and activists keep finding things in Flock audit logs that neither Flock nor its government customers seem especially eager to discuss. A national week of action is underway. And Flock’s CEO, after previously leaning heavily on the “lawmakers should regulate us if they don’t like it” line, is now publicly saying, essentially, yeah, maybe the company bears some responsibility too.
Good. Seriously.
Some of Flock’s announced changes are real improvements, and we’re not going to pretend otherwise just because we have spent years warning about the company and the surveillance architecture it is building. But let’s not confuse “better than before” with “problem solved.”
Because buried underneath the shiny new privacy language is the same basic problem Flock has always had: the company still wants you to trust Flock and its police customers to police themselves. And, perhaps even more remarkably, Flock is touting “transparency” at the same time it has been making parts of its audit trail less transparent.
First, the positive stuff
Let’s start with the changes Flock deserves credit for.
Seven-day default retention
Flock says it is reducing its recommended/default retention period for automated license plate reader (“ALPR”) data from 30 days to seven.
That matters. It was noteworthy when the Bay Area Rapid Transit District (“BART”), in collaboration with Secure Justice, adopted an ALPR use policy in May 2019 with a 30-day retention period. This was the frontier at that time, as to ALPR data retention.
Like Flock’s own internal review, we took a deep look into Oakland’s ALPR database a few years ago, and our research likewise revealed that the overwhelming majority of database queries were performed rather quickly after a reported incident. We found that 90% of queries by OPD officers occurred within three days of an incident, and 99% of all queries occurred within one week of the incident. These lengthier “catch-all” retention periods were never based on a real-world need to preserve the data.
A database containing seven days of location history is meaningfully less dangerous than a database containing 30 days of location history. It creates less historical surveillance capacity. It reduces the amount of information available to an abusive officer, an overreaching agency, an out-of-state law enforcement partner, a hacker, or anybody else who gains access.
Flock is also introducing an “Evidence Mode” allowing particular data to be preserved when needed for an active investigation. On its face, this is a more defensible model than “collect everything, keep everything for a month, and maybe someone will need it.” In practice and having read and/or authored hundreds of ALPR use policies across the country, this tool never would have been needed if police simply followed their own policies on use of the technology. Almost none of the reported scandals that I’ve reviewed are due to poorly written use policies, but rather law enforcement agents that refuse to adhere to them.
But before Flock’s marketing department starts handing itself a civil liberties award, a couple of caveats. This 7-day retention period recommendation is a default, not an absolute retention ceiling, nor a statutory or contractual legal mandate. Existing customers can still operate under different policies, and a week after Flock’s announcement, zero municipalities have announced a move to the 7-day retention period. And of course, investigators can preserve data tied to cases at their discretion, in secret, without real oversight.
Yes, a move away from 30-days retention towards 7 is progress. No, Flock did not suddenly become a privacy company.
Mandatory misuse detection
Flock’s Audit Assistance tool looks for abnormal search behavior and flags it for review. Until now, it was optional. Flock says it will become mandatory for law enforcement customers by the end of the year, along with automatic lockouts when activity appears suspicious.
This is a good thing.
We have now seen allegation after allegation of officers using ALPR systems for personal reasons—former partners, romantic interests, friends, family, curiosity searches, and other conduct that should have surprised absolutely nobody who has ever thought seriously about giving thousands of individual officers access to a nationwide location database.
On August 12, 2026, the Institute of Justice published a report documenting more than 149 officers that have reportedly been accused of misuse in recent cases, leading to suspensions, terminations, resignations, and in at least three cases, criminal charges being filed. By that afternoon, the report was already out of date. Since the release date, we have documented an additional 12 officers that have been terminated for abusing their access to Flock ALPR databases.
And here’s the part worth sitting with: Flock built a system capable of detecting anomalous behavior. It just didn’t care enough to require agencies to turn that protection on. Apparently the “officer might stalk his ex” feature needed to remain optional until enough people got mad.
Mandatory case codes
Flock also says that law enforcement users will have to associate searches with case numbers, with emergency exceptions flagged for review.
Which of the below case numbers is a genuine Oakland case number? If genuine, which are active/open investigations? What is the purpose of the data query for each of the cases?
26918384
XR-39-24113
lalalalala
Haha
Spoiler alert – none of them are legitimate (#3-4 are taken from actual audit logs produced to Secure Justice), and absent any other information, its impossible to answer the other two questions. And this is why, having fielded about 2 dozen media requests last week after Flock made their big “now we are taking things seriously” announcement, we join many other privacy orgs across the country in saying Flock’s moves are mostly performative art meant to placate elected officials that still don’t understand how ALPR systems work.
If you’re searching an extraordinarily powerful government surveillance database, you should at minimum be able to identify the investigation supposedly justifying the search. But a case number is not the same thing as a reason. A case number tells you which file number an officer typed into the system. It does not tell you why this particular person’s car was searched for. That distinction matters a lot more than Flock seems to want people to appreciate.
A case number is only helpful in one scenario: a mandated, funded, full-access independent audit where the auditor can look directly into the law enforcement agency’s record management system and determine what the actual purpose of the query was, whether the request was justified based on the facts of the case, and whether the use was in alignment with the agency’s adopted policy.
Absent the scenario described above (which does not presently exist anywhere in the country) – a case number is meaningless because aside from Tempe, AZ, and San Diego, CA (both cities terminated all third-party access after internal scandals), no human at the host agency is involved in the data transfer. Oakland’s use policy, like all ALPR policies I’ve touched, requires manual case-by-case approval of each request for data. OPD decided they just didn’t like that part, so they ignored those provisions from policy adoption through today’s date, resulting in a second lawsuit from Secure Justice over the same state law and ordinance violations that we previously litigated just 3 years ago.
In real time, no Flock ALPR host agency has knowledge that any specific data is being requested, nor by whom or for what purpose. Modern ALPR practice via Flock technology consists of unfettered direct sharing access provided to third parties by host agencies, with zero oversight and accountability in real time. By our count, more than 90% of the reported scandals across the country only occurred because a member of the public submitted a public record request for Flock audit logs, and for the first time the law enforcement agency looked at who was rummaging through its database. The promises from Flock and law enforcement alike as to trust, transparency and accountability, that they take our privacy rights seriously, are hollow promises that have never been true.
This same criticism applies to Flock’s 2025 move to suppress certain keywords used when searching, such as “immigration” or “abortion.” Keyword suppression sounds reassuring, but it is easy to game, as acknowledged by OPD before the PAC last summer when their own scandal first blew up in the media pertaining to immigration searches. If an agency is blocked from searching another agency’s data for “immigration,” the user can simply select or type a different category—“fraud,” “warrant,” “other,” or whatever else gets the query through. Unless the system independently verifies that the stated reason matches the actual investigation, keyword controls are mostly an honor system with a nicer interface. In practice, it does nothing to protect sensitive data.
The existence of a case number also does not guarantee that the case is active or within policy, nor that the user that entered the case number is even involved in that case. None of these moves by Flock would prevent multiple bad officers from using the same genuine open case number to stalk their exes. The after-the-fact audit log would likewise reveal no obvious misconduct on its face.
More granular controls on who can search what
Flock says agencies will get more granular controls allowing them to restrict outside searches by offense category. Instead of making the decision “share everything” or “share nothing,” an agency could theoretically allow searches for stolen vehicles, murder investigations, missing persons, and similar categories while blocking other uses.
In California, that could matter. We have already seen California agencies discover that their Flock networks were searchable by out-of-state law enforcement when they were not supposed to be. Flock itself acknowledged earlier this year that some California networks had been inadvertently accessible and that, because of limitations in its own earlier logging, it could not always reconstruct how the sharing happened.
Read that again.
A nationwide surveillance company had sharing occur that customers did not understand, and the audit trail was not sufficient to reconstruct what happened.
Which brings us back to why independent auditing matters so much.
Mandatory MFA and security work
Flock is also requiring multi-factor authentication, commissioning an independent security review, and launching a coordinated vulnerability disclosure program.
Great.
Also: this is a company holding an enormous amount of sensitive location data for police departments across the country, collecting approximately 20 billion plate scans and other types of related data per month across the country. Multi-factor authentication should not be viewed as a heroic privacy innovation in 2026. This is basic hygiene. Still, basic hygiene is preferable to no hygiene, so credit where it is due.
I will note that private independent researchers like Benn Jordan have previously offered to audit Flock’s vulnerabilities, at their own cost, and Flock refused.
Flock’s announcement is also an admission
There is another part of this announcement that deserves more attention. For years, surveillance vendors have loved a particular argument: We’re just the technology company. Police departments decide how the technology is used. If lawmakers want restrictions, lawmakers can pass them. If an officer misuses the system, blame the officer. If an agency shares data improperly, blame the agency.
Very convenient arrangement.
The private company gets the contract revenue and the massive network effects. Everybody else gets the accountability. Flock is now quietly conceding that this was bullshit. Because what is Flock changing?
Flock is deciding:
- how long data should be retained by default;
- whether a case number must be entered;
- whether suspicious searches should be automatically detected;
- whether a user should be locked out;
- whether an agency can restrict searches by offense;
- what fields appear in an audit;
- what information gets logged;
- how authentication works;
- which safeguards are optional and which are mandatory.
In other words, the architecture matters. The company matters. Product design is policy. Flock CEO Garrett Langley has now publicly acknowledged that the company has greater responsibility for preventing misuse than his earlier comments suggested.
Good. Now let’s keep following that logic.
If Flock can engineer abuse-prevention controls into the product today, it could have engineered them into the product yesterday.
If Flock can require case codes today, it could have required them before.
If Flock can make misuse detection mandatory today, it could have made it mandatory before.
If Flock can limit retention today, it could have limited retention before.
The only thing that really changed was the political cost of not doing it.
Which is why nobody should miss the most important lesson here: Public pressure works. In today’s political climate, the only effective strategy appears to be brute force. Our elected leaders must fear the consequences of approving and funding these mass surveillance ecosystems.
But guardrails around mass surveillance are still guardrails around mass surveillance
Now for the part Flock would prefer you not linger on. Most of these changes are designed to reduce abuse inside Flock’s existing surveillance architecture. They do not answer whether that architecture itself is appropriate.
There is a difference between:
An officer should not use Flock to stalk an ex-partner.
and:
Thousands of government agencies should have routine unfettered access to a privately operated nationwide location-search network without a warrant.
The first proposition is easy. The second is the actual civil liberties fight. Audit Assistance may catch a creepy officer. Case numbers (with real audits) may deter casual curiosity searches. Shorter retention reduces how much historical data is available. Offense-based controls may stop some forms of cross-jurisdictional access.
All useful. None of them answers the bigger question: Why should an officer be able to search a nationwide database of people’s movements in the first place without independent judicial approval?
Flock’s network operates across 49 states. More than 120,000 cameras are reportedly deployed nationwide. Communities across the country are now reconsidering whether they want to participate in that system at all. And let’s be precise here: the opposition is not demanding a better dropdown menu. People are objecting to mass location surveillance, period. There is a difference.
Now we get to the part that really bothers us: Flock’s definition of “transparency”
Flock’s announcement repeatedly talks about accountability and transparency. Fantastic. We’re big fans of transparency. So let’s talk about the audit logs.
Because while Flock has been telling everyone how seriously it takes auditing, it has also made the Network Audit Logs less useful for—you guessed it—auditing.
There are different Flock audit products.
An Organization Audit Log can provide detailed information about internal searches conducted by an agency’s own users, including operator names, plates searched, reasons, and case numbers.
A Network Audit Log shows searches conducted by outside agencies against another agency’s shared cameras.
And in those Network Audit Logs, Flock now redacts the individual
officer’s name and plate searched. Independent documentation of the
current export format shows those fields replaced with
***.
Flock’s December 2025 customer communications went further, saying Network Audit Logs would no longer include officer names, specific plates searched, vehicle fingerprint information, or open-text search reasons.
Stop and think about how absurd this is. A city buys surveillance cameras. Those cameras collect data on everyone driving through that city. The city shares that data into Flock’s network. Someone from another police agency searches the city’s cameras.
And now the city may receive an audit showing that another agency conducted a search—but not necessarily which officer conducted it or which plate was searched. Flock calls this transparency.
I would call it something else.
If your town’s surveillance data is being searched by an outside agency, shouldn’t your town at least be able to figure out who searched it, what they searched for, and why? Apparently, that’s an unreasonable amount of curiosity – and entirely due to public scrutiny of the audit logs.
Among other things, California law SB 34 (2016) requires recording of the officer’s name, license plate searched for, and the purpose for the search.
“Offense Type” is not the same thing as “purpose”
Flock also introduced a mandatory Offense Type dropdown. To be fair, there is some legitimate value here.
The officer has to select a standardized category before searching. This makes aggregate analysis easier. It avoids a database full of variations like “veh burg,” “burglary veh,” “burg,” and whatever other shorthand officers invent at 2 a.m.
Flock says the categories are based on standardized offense types, and an officer can provide multiple categories. If the officer selects “Other,” the system requires a Search Reason.
Fine. But here’s the trick:
The existing free-text Search Reason is generally optional. And offense category is not purpose.
Suppose an officer selects:
Burglary.
Okay.
Why was Brian’s plate searched?
Was his car seen leaving the scene?
Was he a witness?
Was somebody else driving it?
Was he parked three blocks away?
Was he at a protest near a burglary?
Was the case number simply convenient?
Was there any relationship at all?
“Burglary” does not answer any of that.
It tells us how the officer categorized the search.
It does not necessarily tell us why the officer searched that specific plate.
This is not some academic distinction. California’s SB 34 expressly requires ALPR access records to document “the purpose for accessing the information.” Not merely the general type of crime. Not merely a case number. The purpose.
Flock itself says Offense Type, any optional Search Reason, and Case Number may be included in audit records. Great. California agencies should require all of the information necessary to comply with California law. Flock does not get to redefine a California statute through UX design.
Here’s the accountability paradox
Flock’s pitch is basically: Don’t worry. We’re making the audits better. Audit Assistance will identify suspicious users. Case codes will create accountability. Offense categories will improve oversight. Agency administrators will investigate suspicious activity.
Meanwhile: Network Audit Logs have become less informative about certain outside searches.
So Flock is simultaneously:
increasing the power of internal auditing
while
reducing the information available for independent auditing.
That is a problem. Actually, it’s more than a problem. It tells you exactly how Flock thinks accountability is supposed to work. Flock audits Flock. Police audit police. And the public gets whatever sanitized version is left. We’ve seen this movie before. It doesn’t end well.
Why independent access matters
The overwhelming majority of the Flock controversies driving this national backlash were not discovered because Flock’s compliance team sent out a press release saying, “Hey everyone, you’ll never believe what we found.”
They were discovered because somebody asked questions. Journalists. Researchers. Activists. Lawyers. Residents. People filing public records requests and looking at audit logs.
Right now, those public records are being aggregated into tools allowing people to examine Flock search activity across jurisdictions. Have I Been Flocked? for example, is built using government audit logs obtained through public records laws, and recent reporting describes the database as containing enormous numbers of search records.
Why does this matter?
Because government agencies are terrible at auditing themselves. Corporations are also terrible at auditing themselves. This is not a controversial observation. The incentives are obvious.
An internal auditor asks:
Is this use within our policy?
A journalist might ask:
Why the hell were you searching every car at a protest?
A civil rights lawyer might ask:
Why did an agency in Texas search a California camera network?
A researcher might ask:
Why did the same officer run 900 searches under one case number?
An elected official might ask:
Why did you tell us this system wasn’t shared nationally when the logs say otherwise?
Those are different questions. You need different people asking them.
“Transparency” cannot mean “trust us, we checked”
This is where corporate self-regulation always falls apart.
Flock built the platform.
Flock controls the software.
Flock decides what gets logged.
Flock decides what gets redacted.
Flock defines what behavior its anomaly detection considers suspicious.
Flock maintains the system.
Police administrators decide whether a flagged search was appropriate.
Police agencies decide what their policies allow.
Police agencies frequently decide what the public sees.
And then Flock points to this ecosystem and calls it accountability.
No.
That is internal compliance.
There is value in internal compliance.
But it is not independent oversight.
A bank doesn’t get to say, “Don’t worry, our employees audited our employees.”
A pharmaceutical company doesn’t get to say, “We tested our own product and gave ourselves an A.”
And a surveillance company should not get to say, “Trust us, our surveillance network is accountable because we built an auditing feature into our surveillance network.”
That’s not how democratic accountability works.
Want to prove you’re serious, Flock? Here’s a start.
If Flock really wants to demonstrate that this new announcement is more than crisis-management theater, there are obvious next moves. First, stop building mass surveillance architecture. It is possible to use ALPR in a siloed manner to prevent third party misuse of host agency data. It is also possible to use ALPR in a targeted manner instead of today’s indiscriminate use – using a hot list of identified license plate numbers where some legitimate state interest already exists (warrant, Amber alert, stolen vehicle, etc.) to briefly scan passing vehicles. If no match is found, no data is retained.
Since July 2016, the state of New Hampshire has mandated a maximum 3-minute retention period for all license plate scans, with data only being retained beyond that period if it matches a hot list for an active investigation. No one is publicly arguing that the sky is falling in New Hampshire from this ten-year-old law.
Keep meaningful purpose information
Case numbers are good. Standardized offense categories are useful. Neither should replace a meaningful explanation of why a particular search was conducted. If the officer cannot explain why they are searching for a person or vehicle, maybe they shouldn’t be searching for them.
Crazy idea, I know.
Restore meaningful Network Audit Logs
If another agency searches data collected by your community, your agency should be able to identify:
- the searching agency;
- the individual user;
- the vehicle searched;
- the date and time;
- the case number;
- the actual purpose.
Are there situations where an active investigation requires temporary redaction? Sure. Redact that particular information when there is a legitimate need. Don’t redesign the entire audit system so nobody gets the information.
Make the complete audit trail exportable
A government agency should not have to ask Flock to reconstruct how its own surveillance system was used. Every relevant audit field should be available to the customer in an exportable, usable format.
Make the logs immutable
Users should not be able to edit history after the fact. Neither should administrators. An audit trail that can be rewritten is a suggestion, not an audit trail.
Although we are not prepared today to publicly reveal our findings, stay tuned for a forthcoming report about California agencies caught altering Flock audit logs produced in response to public records requests.
Design for public records compliance
Flock should make it easy for public agencies to export the records they are legally required to produce. Not impossible. Not dependent on a Flock support ticket. Not stripped of the very fields that allow meaningful accountability.
Open the system to genuinely independent auditors
Not just Flock. Not just the police department. Independent auditors. If this network is as well-controlled as Flock says it is, independent review should not scare anyone. As we saw with Benn Jordan, Flock is terrified of real transparency and independent audits. There must be a reason for their fear.
Make sharing restrictions auditable
If a California city says its data cannot be used for immigration enforcement, reproductive-health investigations, protest surveillance, or some other prohibited purpose, the public should eventually be able to verify whether the restriction actually worked.
Not because Flock says it worked. Because the evidence shows it worked.
The backlash is working
There is another conclusion here that I don’t want people to miss. Flock is not making these changes because some product manager woke up one morning and suddenly discovered civil liberties. The company is making them while facing a serious and growing national opposition campaign.
As of August 17, 2026 more than 157 jurisdictions have ended relationships with Flock, including 114 in just the first 7.5 months of 2026.
Groups are organizing protests. City councils are asking harder questions. Journalists are digging through audit logs. Activists are mapping cameras. Researchers are analyzing query patterns. Legislators are considering restrictions. The public is learning what this network actually does. And Flock is changing its product.
That should tell you something. This isn’t evidence that the criticism was overheated. It’s evidence that the criticism was overdue.
Seven-day retention happened because somebody pushed. Mandatory Audit Assistance happened because somebody pushed. Mandatory case codes happened because somebody pushed. Sharing restrictions happened because somebody pushed. Flock is now saying it “got this one wrong.”
Okay. Welcome to the conversation.
The bottom line
Secure Justice is not going to oppose a good privacy change simply because Flock made it. Seven-day default retention is better than thirty. Mandatory misuse detection is better. Automatic lockouts are better. Case codes are better (if an auditor can access the records). Granular sharing restrictions are better. Mandatory MFA is better.
We’ll take the wins. But make no mistake: these reforms do not come close to resolving the central problem. Flock still operates a massive privately controlled mass surveillance architecture connecting thousands of government agencies and tens of thousands of cameras across the country.
The safeguards governing that architecture remain heavily dependent on Flock and the police departments using it. And while Flock is strengthening its internal oversight tools, it has simultaneously weakened portions of the audit trail available to agencies and, by extension, the public.
That is backwards. Privacy without transparency requires trust. Flock has given the public no reason to believe trust alone is sufficient. If Flock wants accountability, then give people the information needed to hold the system accountable. If Flock wants transparency, stop removing useful information from audit logs. If Flock wants communities to believe its sharing controls work, let communities verify that they work.
And if Flock believes these new guardrails make its technology safe enough for democratic society, it should welcome independent scrutiny rather than continuing to decide for itself what outsiders are allowed to see.
Because Flock’s biggest problem isn’t that people don’t understand the product. Increasingly, people understand it quite well. That’s why they’re pissed.