All news
regulationcybersecurityproduct

Flock Safety's Data Access Practices Spark Trust Crisis

24 Jul 2026

A string of disputes over how Flock Safety accesses and describes its automated license plate reader (ALPR) network is testing the trust of the police departments, city councils, and civil-liberties groups it works with. For founders building products for government or sensitive-data customers, the unfolding situation is a case study in how quickly institutional trust can erode—and how fast contracts can disappear.

What happened

On September 30, 2025, a Flock vice president logged into Dunwoody, Georgia's police department Flock system, which draws on roughly 400 cameras across the city's network. A private community center had shared its cameras with Dunwoody PD under the stated condition that access was "solely for real-time critical incident response." Flock and city officials have since described the September 30 login as an authorized "sales demo"—but the city says it cannot confirm that a demo partner agreement actually exists.

This is not an isolated incident. In April 2025, Oshkosh, Wisconsin's city council approved a Flock contract after the company's CISO told officials the system did not create movement heat maps. The council revoked the contract the very next morning after learning that claim was false—Flock later admitted its ALPR system does produce a heat map of vehicle sightings spanning up to a month.

Similar contradictions have surfaced elsewhere. Loveland, Colorado's police chief raised concerns about federal access to ALPR data; Flock said federal agencies no longer had access, then later admitted active pilot contracts existed with CBP and DHS. Separately, Flock has publicly stated it "does not work with ICE," even as reports found police departments regularly sharing Flock data with ICE and CBP.

In May 2025, press reports said Flock's ALPR system was used by Texas law enforcement to track an Illinois resident who had sought an abortion across state lines—an episode that prompted Flock to introduce a "Proactive Search Term Tool" intended to reduce improper searches, though the tool's actual effectiveness has not been detailed.

Meanwhile, an ACLU audit in September 2025 found that police departments often log vague search-reason entries instead of specific justifications. One Oregon department entered "investigation" as a search reason 111 times in a single month, and "hehehe" 20 times.

Adding to the credibility strain, Flock's public affairs director claimed the company partnered with ACLU New Mexico on ALPR legislation, echoing a 2021 statement to Urbana, Illinois officials that Flock worked with groups like the ACLU to design its system. The ACLU has stated it has never partnered with Flock Safety on any ALPR system design, in New Mexico or anywhere else—invoking its 106-year institutional history as a civil-liberties watchdog to underscore the dispute.

Flock's CEO has acknowledged the company "communicated poorly" and that public statements "inadvertently provided inaccurate information."

Where the story is unresolved

Several key questions remain open. Whether a written demo partner agreement for the Dunwoody access exists has not been confirmed. It's unclear how many other departments or cities have experienced similar undisclosed access or misrepresented capabilities. No details are available on the specific New Mexico legislation Flock claims to have shaped, or whether any ACLU affiliate was involved at all. And beyond individual contract cancellations, it's not clear whether Flock faces any broader regulatory review or penalties.

Sources differ on several fronts: whether the Dunwoody access was a legitimate demo or an unauthorized login; whether Flock's heat-map and federal-access statements were honest mistakes or material misrepresentations; and whether any ACLU partnership—past or present—ever existed in any form.

Why founders should care

For startups selling into government, healthcare, or other trust-sensitive sectors, this saga plausibly illustrates several risk patterns worth internalizing:

  • Sales activity involving live customer data without ironclad, verifiable agreements may create legal and reputational exposure that a single "it was just a demo" explanation likely won't resolve once public.
  • Public misstatements about technical capabilities or data-sharing practices—even when corrected quickly—appear capable of triggering immediate contract termination, as Oshkosh's one-day reversal suggests.
  • Vague internal controls, such as generic audit-log fields, may make it harder to defend against claims of misuse, and could undermine a startup's broader oversight narrative with regulators or customers.
  • Referencing third-party endorsements or partnerships without documentation carries a meaningful chance of public dispute, particularly when the alleged partner is a well-established, reputationally cautious organization.
  • Public-sector trust seems to be fragile and highly reactive to perceived inconsistency—suggesting that rapid, transparent correction of errors, rather than continued ambiguity, is more likely to preserve a working relationship with civic customers.

The takeaway for builders

The opportunities embedded in this story cut both ways. Startups that build transparent, auditable logging for data access—with specific, mandatory fields rather than free-text justifications—may be able to differentiate themselves credibly in government and sensitive-data markets. Similarly, securing genuine, verifiable reviews from independent civil-liberties organizations (rather than referencing informal or disputed collaborations) could become a meaningful trust signal as scrutiny of surveillance and data products intensifies. Flock's experience suggests that in high-stakes public-sector sales, the gap between what a company says and what it can prove is likely to be found—and the cost of that gap can be steep.

Sources