Have You Been Flocked? Your License Plate May Already Be Searchable
You donât have to commit a crime to enter the database.
You drive to work.
The grocery store.
Synagogue.
Your doctorâs office.
Your childâs school.
A restaurant.
Your attorneyâs office.
You arenât being followed.
You havenât been pulled over.
You havenât committed a crime.
But along the way, cameras mounted beside roads may photograph your vehicle, read your license plate, record where and when it was seen and temporarily place that observation into a searchable database.
Thatâs the technology behind Flock Safetyâ .
And Americans are beginning to ask a very reasonable question:
Exactly how much should the government be able to learn about where our cars go?
What Exactly Is Flock?
Flock Safety operates automated license plate recognition cameras, commonly called ALPRs.
Theyâre different from ordinary security cameras.
Rather than simply recording hours of video, an ALPR is designed to identify vehicles passing the camera.
According to Flock, its system can capture:
License plate images.
Vehicle characteristics.
Date and time.
Camera location.
Flock says its ALPR product does not collect facial-recognition or biometric data.
So imagine your car passes one at:
8:13:42 AM.
The system might create a record essentially saying:
Plate ABC123 â observed here â at this time.
One observation sounds boring.
Thousands of cameras are where things become interesting.
One Camera Isnât Really the Controversy
Imagine your local police department puts a camera at the entrance to town.
A stolen car drives past.
The plate matches a hot list.
Police receive an alert.
They recover the vehicle.
Thatâs an easy use case to understand.
Flock and law-enforcement agencies point to cases involving stolen vehicles, wanted suspects and missing people as examples of why ALPRs can be valuable.
But now expand the concept.
Flock reportedly has approximately:
120,000 cameras.
Across:
49 states.
Suddenly weâre not discussing a camera anymore.
Weâre discussing a network.
And networks can answer questions individual cameras cannot.
The Camera Doesnât Need to Follow You
This is the fascinating part.
Imagine cameras record your car at five different locations:
8:02 AM â near your neighborhood.
8:37 AM â near your office.
12:18 PM â across town.
5:41 PM â near a particular building.
6:27 PM â heading home.
No camera physically followed you.
But connect the observations and youâve potentially reconstructed part of your day.
Do that repeatedly and patterns can emerge.
Thatâs why privacy advocates are concerned.
Tracking doesnât necessarily require one camera watching you continuously.
A sufficiently large number of cameras can potentially reconstruct movement from individual observations.
âHave I Been Flocked?â Lets You Search Something Different
Thereâs now a website called Have I Been Flocked?â
It has compiled public-record audit logs containing approximately:
241 million Flock searches
involving roughly:
4.7 million license plates.
You can enter your license plate and see whether it appears in the audit information theyâve collected.
But thereâs an extremely important distinction:
A result does not mean police were investigating you.
The website is searching collected audit logs of searches performed in Flock systems.
And its records arenât necessarily complete because theyâre assembled from public-record requests to agencies.
So donât enter your plate, see a result and immediately conclude:
âThe government was following me.â
Thatâs not what the result establishes.
Can Regular Citizens Search Flock?
Generally, no.
There isnât supposed to be a public Flock law-enforcement search engine where you can type:
âShow me everywhere ABC123 traveled.â
Flock says access is restricted to authorized users, searches are tied to individual accounts, and search activity is logged.
For law-enforcement systems, Flock says searches must have an investigative purpose and the general public cannot browse the database.
The new Have I Been Flocked site isnât giving you direct access to Flock.
Itâs aggregating audit records obtained through public-record requests.
Thatâs an important difference.
So Could Someone Abuse It?
Thatâs one of the biggest concerns.
Any database powerful enough to help find criminals is potentially powerful enough to be misused.
Imagine someone with access searching:
An ex-spouse.
A girlfriend.
A journalist.
A political opponent.
A neighbor.
Someone attending a protest.
Someone visiting a particular medical facility.
Thatâs why audit logs matter.
Flock says every search is associated with a specific account and recorded for review.
And amid mounting criticism, the company has announced additional safeguards scheduled to take effect around the beginning of 2027.
Among them are requirements for stronger search justification, mandatory auditing intended to detect abnormal searches, and the ability to restrict or suspend suspicious users.
Flock CEO Garrett Langley has publicly warned people abusing the system:
âYou will get caught.â
Thatâs reassuring.
But privacy advocates ask a different question:
Should misuse merely be detectableâor should certain searches require stronger authorization before they happen?
Thatâs where this debate becomes much harder.
What If Flock Gets My License Plate Wrong?
This is a legitimate concern.
ALPR systems arenât infallible.
Flockâs own License Plate Reader Policy acknowledges that plate translation can occasionally be incomplete or inaccurate and specifically instructs users to confirm the computer-generated translation before acting on an alert or search.
That safeguard matters enormously.
Imagine your plate is:
ABC1238
and a wanted vehicle is:
ABC1288.
Or perhaps the vehicle has:
The same color.
Similar body style.
Similar make.
A plate that is partially obscured.
An automated match should be an investigative leadânot unquestionable proof.
A computer alert should never magically become probable guilt.
Could an Innocent Person Actually Get Stopped?
Potentially, yes.
Automated plate-reader errors and mistaken vehicle identifications have contributed to wrongful or highly problematic stops in the broader ALPR ecosystem, and recent reporting on Flock has highlighted concerns involving misreads and improper use.
But that doesnât mean:
âFlock sees your car and police will arrest you.â
The appropriate process is for an ALPR hit to be independently verified.
Look at the actual photograph.
Confirm the plate.
Confirm the vehicle.
Evaluate the circumstances.
Then act.
Technology should help an officer investigate.
It shouldnât replace the officerâs judgment.
Do Law-Abiding Citizens Have Anything to Worry About?
This deserves a nuanced answer.
If youâre asking:
âDoes Flock automatically consider me suspicious because it photographed my car?â
No.
The cameras routinely capture vehicles belonging to completely innocent people.
Thatâs inherent to how ALPR systems operate.
But if youâre asking:
âDoes the existence of a searchable record of innocent peopleâs movements create legitimate privacy concerns?â
Absolutely.
Those are two completely different questions.
You can simultaneously believe:
Flock can help solve serious crimes.
and:
Large-scale searchable location databases need extremely strong safeguards.
Those positions arenât contradictory.
âBut Iâm Not Doing Anything Wrongâ
This is where privacy conversations often get stuck.
Someone says:
âI donât care. Iâm not a criminal.â
But privacy isnât synonymous with hiding criminal behavior.
Imagine somebody could request a list showing every vehicle that visited:
An addiction-treatment facility.
A fertility clinic.
A religious institution.
A political meeting.
A divorce attorney.
A mental-health provider.
A domestic-violence shelter.
You donât have to be doing anything illegal for location information to be sensitive.
Privacy is the ability to live an ordinary lawful life without every movement becoming somebody elseâs searchable history.
Donât We Have Constitutional Rights?
Yesâbut the legal question surrounding vehicle movements is complicated.
Courts have long recognized that people generally have a reduced expectation of privacy in license plates displayed publicly on vehicles.
A police officer standing beside a road can obviously see your plate.
The harder question is what happens when technology changes the scale.
Thereâs a meaningful practical difference between:
An officer happened to see your car on Tuesday
and:
A database can potentially reconstruct weeks of your vehicleâs movements across many locations.
American courts have increasingly wrestled with this broader issue in other forms of location surveillance.
The constitutional debate isnât simply:
âCan police see a license plate?â
Of course they can.
The emerging question is:
At what point does automated, aggregated surveillance become something fundamentally different?
That issue is far from settled everywhere.
Can You Opt Out?
For ordinary drivers passing public-facing ALPR cameras, generally there isnât a personal Flock opt-out button that prevents your plate from being captured.
Your license plate is intentionally displayed on your vehicle and visible from public roads.
The âDo Not Sellâ option in Flockâs website privacy policy concerns personal information governed by that privacy policy; it should not be confused with a universal ability to tell roadside ALPR cameras:
âDonât photograph my vehicle.â
If your local government operates Flock cameras, the meaningful controls are largely civic:
Local ordinances.
Police policies.
Retention requirements.
Sharing restrictions.
Public-record laws.
City council decisions.
State legislation.
And ultimately whether your community chooses to deploy the technology at all.
More than 50 jurisdictions have reportedly ended or suspended Flock relationships amid the current controversy.
How Are These Cameras Even Powered?
This part is surprisingly clever.
Many Flock cameras donât require traditional wired infrastructure.
Flock says its cameras can use:
Solar power.
Battery power.
And cellular LTE connections for communications.
That dramatically simplifies deployment.
No fiber connection is necessarily required.
No nearby network closet.
No trenching Ethernet down the road.
Put the camera on suitable infrastructure.
Give it power.
Connect through cellular service.
That architecture is part of what allows ALPR networks to expand relatively quickly.
Flockâs deployment documentation also supports installations using AC power and existing infrastructure such as utility, traffic-signal and light poles.
Does Flock Pay Cities to Use Their Poles?
I wouldnât make that blanket claim.
Installation arrangements vary by municipality and contract.
Flockâs own deployment documentation explicitly contemplates cameras being mounted on existing utility, light and traffic-signal poles, as well as other suitable infrastructure.
But whether Flock pays a particular city for pole access, the city pays Flock under a camera contract, another entity owns the pole, or some other arrangement exists depends on the specific deployment.
Thatâs something residents can investigate through:
Contracts.
Procurement records.
City council minutes.
Public-record requests.
If youâre curious about cameras in your neighborhood, look at the actual municipal contract.
Thatâs far more useful than guessing.
What Happens to Your Data?
Currently, Flock says ALPR information is typically retained for 30 days, although customers and applicable laws can require different retention periods.
But that is changing.
Beginning January 1, Flock has announced plans to reduce its standard retention period from 30 days to seven days as part of its new safeguards.
Thatâs a major reduction.
Thirty days can provide a month-long movement history.
Seven days dramatically shrinks that window.
But critics still argue the fundamental concern remains:
Why should movements of people suspected of absolutely nothing enter a searchable system in the first place?
The Cybersecurity Question Nobody Should Ignore
Now imagine the database itself gets compromised.
This is something I think deserves more attention.
Whenever we create a centralized repository containing sensitive information, we create something attackers may want.
Vehicle movements can potentially reveal:
Where executives work.
Where employees live.
When facilities are occupied.
When someone travels.
Relationships between locations.
Operational routines.
Flock says its data is encrypted during transmission and storage and that criminal-justice information is stored in AWS GovCloud.
Those are important safeguards.
But cybersecurity professionals operate from a simple assumption:
Any valuable database deserves to be treated as a potential target.
The more powerful the database becomes, the more serious access control, logging, MFA, encryption, retention and incident response become.
Thereâs Another Risk: Legitimate Credentials
A database doesnât need to be âhackedâ in the Hollywood sense.
Someone could steal an authorized userâs credentials.
Phish an officer.
Compromise an endpoint.
Abuse an existing account.
Exploit excessive permissions.
Thatâs why every sensitive search should be attributable.
Who searched?
When?
Why?
What did they access?
What happened afterward?
Good cybersecurity isnât merely keeping outsiders outside.
Itâs making sure insidersâand compromised insider accountsâcanât operate invisibly.
This Is the Real Flock Debate
Flock presents an extraordinary example of the tradeoff technology continually forces society to confront.
Imagine a child is kidnapped.
Police know the suspectâs vehicle.
A camera detects it ten minutes later.
Nobody is going to complain that technology helped bring that child home.
Imagine instead that someone searches a journalistâs vehicle because they want to know who sheâs meeting.
Same technology.
Very different use.
Thatâs why the question:
âIs Flock good or bad?â
isnât particularly useful.
Ask better questions.
Who can search?
For what crimes?
With what justification?
For how long is information retained?
Who can share it?
Are searches audited?
Does a warrant ever become necessary?
What happens when someone abuses access?
How are false matches handled?
Can citizens see the policies governing their community?
And who gets to decide when surveillance has gone too far?
Convenience Changes the Scale of Surveillance
A police officer has always been able to stand on a public street and read your license plate.
Thatâs not new.
Whatâs new is making that observation:
Automatic.
Cheap.
Continuous.
Searchable.
Shareable.
And potentially available across enormous geographic areas.
Technology didnât invent surveillance.
It removed much of the friction that used to limit it.
Thatâs the distinction worth debating.
Because friction sometimes protects privacy without anyone realizing it.
It used to require people, time and effort to reconstruct someoneâs movements.
Now software can potentially do portions of that work in seconds.
Before You Decide Whether Flock Scares You, Ask One Question
Donât ask:
âDo I trust the police?â
And donât ask:
âDo I have anything to hide?â
Those oversimplify the issue.
Ask:
âWhat rules would I want governing this database if someone I didnât trust eventually controlled it?â
Thatâs a much better cybersecurity question.
Because governments change.
Employees change.
Technology changes.
Databases get larger.
Capabilities expand.
And once surveillance infrastructure exists, removing it can be considerably harder than installing it.
Flock may help investigators solve crimes.
It may help recover stolen vehicles.
It may help find missing people.
Those are meaningful benefits.
But a network capable of producing extraordinarily useful investigative intelligence also deserves extraordinarily serious oversight.
The debate isnât whether technology can watch us.
It clearly can.
The debate is who gets to look backâand under what rules.
70% of all cyber attacks target small businesses, I can help protect yours.
#Cybersecurity #DataPrivacy #Surveillance #DataProtection #Technology
You donât need to commit a crime to enter a police-searchable database. You just need to drive past the camera.