FLOCKWATCH / CHANGE CONTROL

2026 Safeguard Tracker

A source-balanced, claim-by-claim assessment of Flock Safety's August 2026 privacy, accountability, and security announcements.

5 announced changesvendor + independent sourcesimplementation not presumed

On August 13, 2026, Flock Safety announced a package of privacy, accountability, and security changes. Some are concrete improvements; others remain promises whose practical effect depends on implementation, agency policy, and independent testing.

This tracker separates what the vendor announced from what is operationally verified. An announcement is not scored as a completed safeguard merely because it has a deadline.

SG-01 2026-08-17

Seven-day default retention and Evidence Mode

Vendor-announced operation
New customers default to seven days; existing customers keep their selected periods; investigators may preserve specific records for active cases.
Rollout status
Announced August 13, 2026; Evidence Mode described as rolling out in coming weeks.
Residual risk
The shorter default does not bind existing agencies; the scope and duration of Evidence Mode preservation are not yet independently documented.
Governance control
Short retention with case-bound preservation
SG-02 2026-08-17

Offense filtering for network sharing

Vendor-announced operation
Data owners may specify which offense categories other agencies can use when searching their cameras.
Rollout status
Announced August 13 2026 with no public independent effectiveness test identified.
Residual risk
Offense labels are user-entered assertions; earlier purpose controls were bypassed with vague or false entries.
Governance control
Purpose-bound sharing enforced by deny-by-default access rules
SG-03 2026-08-17

Mandatory Audit Assistance and proactive lockout

Vendor-announced operation
All law-enforcement customers must adopt anomaly detection by year-end; flagged behavior may trigger automatic suspension pending review.
Rollout status
Audit Assistance was already voluntary; universal adoption and proactive lockout are promised by December 31, 2026.
Residual risk
No public sensitivity or false-negative evaluation was identified; vendor and agency administrators remain inside the oversight chain.
Governance control
Independent recurring audits with published outcomes and external enforcement
SG-04 2026-08-17

Required case codes with emergency exception

Vendor-announced operation
Every law-enforcement search must carry a case code by year-end; emergency bypasses are allowed and flagged for review.
Rollout status
Promised for all law-enforcement searches by December 31 2026.
Residual risk
A syntactically present code does not establish a lawful purpose; emergency bypass review remains administrator-controlled.
Governance control
Validated case binding plus supervisor approval for exceptions
SG-05 2026-08-17

Security program changes

Vendor-announced operation
Mandatory MFA is active; a coordinated vulnerability disclosure channel is launching; Bishop Fox findings and remediations are promised for September.
Rollout status
MFA described as active in August 2026; public review summary pending September 2026.
Residual risk
MFA materially reduces account-takeover risk but does not constrain authorized misuse or data-sharing policy; the external review cannot be assessed until published.
Governance control
Mandatory MFA plus public remediation evidence and scoped external testing

Bottom line

The seven-day default, mandatory multifactor authentication, and automatic lockout are directionally meaningful. They do not replace external governance. Existing customers can retain longer storage periods, case codes can be inaccurate, offense labels depend on truthful entry, and Audit Assistance has no published independent sensitivity evaluation identified in this review.

The minimum credible follow-through is therefore observable rather than rhetorical: publish rollout completion, exception rates, false-negative testing, lockout outcomes, preserved-data volumes, and the promised external security-review summary.

On 19 August 2026, WIRED reconstructed OS Investigate, an AI investigation layer that can start from a place and a driving pattern and return commercial identity data. That reporting is logged as LIT-019. It does not change the five-row August 13 tracker above; it is later evidence that the public record does not establish whether advertised retention and case-code controls reach identity workups, or whether the optional suspicious-search audit tool is enabled by default.

Method and scope

  • Assessment date: August 17, 2026.
  • Each row pairs Flock's own announcement with an independent civil-liberties analysis.
  • “Announced” and “promised” do not mean independently verified in production.
  • This is a governance-gap analysis, not a claim that the changes have no value.
  • The downloadable ledger is versioned with the research repository.

Download the safeguard ledger → · Compare the twelve enforceable controls → · Review documented incidents →