2026 Safeguard Tracker
A source-balanced, claim-by-claim assessment of Flock Safety's August 2026 privacy, accountability, and security announcements.
On August 13, 2026, Flock Safety announced a package of privacy, accountability, and security changes. Some are concrete improvements; others remain promises whose practical effect depends on implementation, agency policy, and independent testing.
This tracker separates what the vendor announced from what is operationally verified. An announcement is not scored as a completed safeguard merely because it has a deadline.
Seven-day default retention and Evidence Mode
- Vendor-announced operation
- New customers default to seven days; existing customers keep their selected periods; investigators may preserve specific records for active cases.
- Rollout status
- Announced August 13, 2026; Evidence Mode described as rolling out in coming weeks.
- Residual risk
- The shorter default does not bind existing agencies; the scope and duration of Evidence Mode preservation are not yet independently documented.
- Governance control
- Short retention with case-bound preservation
Offense filtering for network sharing
- Vendor-announced operation
- Data owners may specify which offense categories other agencies can use when searching their cameras.
- Rollout status
- Announced August 13 2026 with no public independent effectiveness test identified.
- Residual risk
- Offense labels are user-entered assertions; earlier purpose controls were bypassed with vague or false entries.
- Governance control
- Purpose-bound sharing enforced by deny-by-default access rules
Mandatory Audit Assistance and proactive lockout
- Vendor-announced operation
- All law-enforcement customers must adopt anomaly detection by year-end; flagged behavior may trigger automatic suspension pending review.
- Rollout status
- Audit Assistance was already voluntary; universal adoption and proactive lockout are promised by December 31, 2026.
- Residual risk
- No public sensitivity or false-negative evaluation was identified; vendor and agency administrators remain inside the oversight chain.
- Governance control
- Independent recurring audits with published outcomes and external enforcement
Required case codes with emergency exception
- Vendor-announced operation
- Every law-enforcement search must carry a case code by year-end; emergency bypasses are allowed and flagged for review.
- Rollout status
- Promised for all law-enforcement searches by December 31 2026.
- Residual risk
- A syntactically present code does not establish a lawful purpose; emergency bypass review remains administrator-controlled.
- Governance control
- Validated case binding plus supervisor approval for exceptions
Security program changes
- Vendor-announced operation
- Mandatory MFA is active; a coordinated vulnerability disclosure channel is launching; Bishop Fox findings and remediations are promised for September.
- Rollout status
- MFA described as active in August 2026; public review summary pending September 2026.
- Residual risk
- MFA materially reduces account-takeover risk but does not constrain authorized misuse or data-sharing policy; the external review cannot be assessed until published.
- Governance control
- Mandatory MFA plus public remediation evidence and scoped external testing
Bottom line
The seven-day default, mandatory multifactor authentication, and automatic lockout are directionally meaningful. They do not replace external governance. Existing customers can retain longer storage periods, case codes can be inaccurate, offense labels depend on truthful entry, and Audit Assistance has no published independent sensitivity evaluation identified in this review.
The minimum credible follow-through is therefore observable rather than rhetorical: publish rollout completion, exception rates, false-negative testing, lockout outcomes, preserved-data volumes, and the promised external security-review summary.
On 19 August 2026, WIRED reconstructed OS Investigate, an AI investigation layer that can start from a place and a driving pattern and return commercial identity data. That reporting is logged as LIT-019. It does not change the five-row August 13 tracker above; it is later evidence that the public record does not establish whether advertised retention and case-code controls reach identity workups, or whether the optional suspicious-search audit tool is enabled by default.
Method and scope
- Assessment date: August 17, 2026.
- Each row pairs Flock's own announcement with an independent civil-liberties analysis.
- “Announced” and “promised” do not mean independently verified in production.
- This is a governance-gap analysis, not a claim that the changes have no value.
- The downloadable ledger is versioned with the research repository.
Download the safeguard ledger → · Compare the twelve enforceable controls → · Review documented incidents →