- Flock will cut its recommended ALPR data retention period from 30 days to seven.
- New audit tools, case codes, and account lockouts should make abuse easier to spot.
- The company still relies on agency reviews and policies rather than blocking misuse.
Flock Safety is the nation’s largest automated licence plate reader (ALPR) company. After several misuse scandals surrounding its tech, it’s now launching new rules and recommendations. The company plans to recommend a seven-day data-retention period instead of 30 days, require case codes for police searches, and automatically lock out users whose behavior looks suspicious.
Those are real changes, and some of them are overdue. Cutting down the amount of historical location data sitting in the system is a meaningful privacy improvement. So is making Audit Assistance mandatory for law-enforcement customers after only about one-third voluntarily activated it. Still, Flock’s announcement reads more like a system for catching abuse after it starts than one built to prevent it in the first place. It is finally installing tripwires, but it is not putting the gun back in the safe.
Better Than Optional
Flock says its Audit Assistance tool identifies abnormal behavior and sends it to an agency administrator for review. Its new proactive-lockout feature will automatically suspend a user pending that review. The company says the voluntary version of Audit Assistance has already been linked to the arrests of several officers accused of misuse.
That’s plainly better than requiring a department to manually comb through endless audit logs after someone has complained. The same goes for mandatory case codes, which should make it more difficult for an officer to conduct personal searches without leaving a trail.
Read: Flock Reportedly Pitched Turning 350,000 Ubers And Lyfts Into License Plate Scanners
Flock CEO Garrett Langley has also acknowledged that the company got this part wrong. In an interview with The Verge, he said it was an “obvious way to curb abuse” and that Flock should have required those guardrails sooner.
The catch is that none of this necessarily stops the first improper search. Flock has not said that its system will validate a case code against an active police report, confirm that a stated offense is accurate, or require an independent reviewer before a search is conducted. Officers can also bypass the case-code requirement during emergencies, with those searches flagged for later review.
Don’t forget either that the agency admin isn’t a third-party investigator. Not only could that person misuse the system themselves. Flock’s reform assumes there is somebody inside the agency capable of supervising the user. In the smallest departments, that assumption can fall apart fast. In other words, a bad actor may still be able to run a search, then face consequences only if the software detects a pattern and the agency follows through.
Seven Days, With A Giant Asterisk
The privacy change is welcome, but it’s less sweeping than the headline suggests. Flock is recommending a seven-day retention period. That word “recommending” is doing a lot of heavy lifting. First, existing customers keep whatever they’ve already set up unless they want to change it. Secondly, new customers can set their retention rates to whatever they feel like. Seven days again is just a recommendation.
There’s also a new feature called Evidence Mode, which allows departments to keep data tied to an active investigation longer. In principle, that makes sense. Relevant evidence should not vanish simply because a case takes longer than a week.
But Flock needs to explain exactly what is retained. Is it a specific image and plate read, or every result returned by a search? Who approves it? How long can it remain stored? Does it disappear automatically when a case closes? Those distinctions decide whether Evidence Mode is a narrowly tailored exception or a back door around the new retention limit.
Sharing Filters Don’t Eliminate Sharing Risks
Flock is also allowing cities to limit what other agencies can search for. A department could, for example, permit searches related to stolen cars, missing people, and violent crime while blocking those tied to immigration enforcement. That is a useful tool. It is not a universal prohibition.
The feature depends on agencies choosing to enable the restrictions and on users accurately describing why they are conducting a search. It also does not necessarily resolve “side-door” access, where an officer with authorized access runs a search on behalf of another agency. That has been a central concern in prior reporting about Flock data reaching federal immigration authorities.
There is another gap here involving private customers. Flock says businesses such as Lowe’s and Home Depot cannot search law-enforcement data. At the same time, they can share their own camera feeds with police. Public records have shown officers accessing hundreds of store locations through the system.
More: Why More Cities Are Suddenly Pulling The Plug On Flock Safety Cameras
Yet the new announcement specifically makes Audit Assistance, proactive lockouts, and case codes mandatory for “law enforcement customers” and “law enforcement searches.” It does not say whether equivalent safeguards apply when a private security employee searches a retailer’s own Flock data.
That leaves a pretty obvious question. If a company can operate cameras across hundreds of locations, what keeps one of its own users from misusing that account?
The Accuracy Claim Needs Real Data
The weakest part of Flock’s release is its effort to address accuracy. The company says its layered safeguards result in fewer than nine “human-reported errors” per 1 million alerts. That is not the same thing as an independently measured false-alert rate. It only tells us how often an error was reported by a person. That’s different from how many incorrect alerts occurred, how many went unreported, or how the figure changes by location, camera placement, plate design, or confidence threshold.
And it matters because Roseville, California, police found that 71 percent of 1,427 Flock alerts issued in 2023 and 2024 involved a plate misread, according to records reviewed by Business Insider. Flock said the city’s higher, rear-facing camera placement and older hardware were unusual, so the figures are not directly comparable to the company’s nationwide claim.
But that is precisely why Flock should publish a transparent methodology and independently audited accuracy data instead of a number that is impossible to evaluate from the outside. Mandatory multi-factor authentication and a pending security review by Bishop Fox are both positives, too. But Flock says it will publish only a summary of that review, not the full findings.
Flock deserves credit for moving on several issues it previously left to agencies and lawmakers. The company’s new tools should make misuse easier to spot and harder to conceal. But they remain mostly tripwires, not hard limits.
Until Flock can show that a search is tied to a real case, that restrictions cannot be casually bypassed, and that abuse is reviewed beyond the same department employing the officer, the system will still depend heavily on people using extraordinary surveillance powers exactly as intended. Some suggest every search should require a warrant rather than a case number. What do you think? Let us know in the comments below.

