Confluence Security

License plate recognition

CloudRunner vs Flock Safety: Who Controls Your License Plate Data

Both systems read license plates. The difference is who controls the data. With the platform we deploy, your agency owns the reads, sets the retention, imports its own hotlists, and decides one partner at a time who can see what, with the right to revoke. Nothing is shared by default.

Automated license plate recognition works. It closes cases, it recovers stolen vehicles, and it puts a vehicle in a place at a time in a way that witness statements cannot. This page does not argue that the technology is useless, because that argument is not honest and no agency believes it.

The real question is narrower and more important. Who is the data controller. Who decides what the system looks for. Who can see the reads after they are collected, and can that decision be reversed. Those questions are architectural, and they are settled long before an officer runs a search.

Default retention on the platform we deploy

90 days

Configurable up to one year by the agency.

Default sharing

None

Sharing is an explicit, revocable, agency-initiated act.

Hotlist control

Agency

The agency imports and manages its own lists.

Security certification level

UL 2900-2-3 Level 3

Held by the platform manufacturer alongside ISO and SOC 2 Type 2.

Start by conceding the real point

Plate recognition solves crimes. Agencies that use it well clear cases they would otherwise close unsolved. Any comparison that opens by pretending otherwise is not worth reading, and an experienced chief will stop reading at that point.

The debate that actually matters is about data control. A plate read is a record of a specific vehicle at a specific place and time. Collected at scale, those records describe patterns of movement for people who were never suspected of anything. That is why the governing question is not whether the tool is useful. It is who holds the data, who sets the rules, and whether the agency can prove both to its own community.

How the two architectures differ

One model sells cameras to police departments and to private parties such as homeowner associations, businesses and property managers. Those private cameras can contribute into a wider law enforcement network, which means equipment bought by a private customer becomes part of a data pool that police can query. That is an efficient way to grow coverage quickly, and it is also the source of most of the objections raised about the category.

The model we deploy is a single-tenant agency system. The reads belong to the agency that collected them. There is no default pool. Sharing exists, and it is useful, but it is always an explicit act initiated by the data owner, scoped to a named partner, and revocable at any time.

  • Single tenant, so agency data is not pooled by default.
  • Sharing is initiated by the data owner, one partner at a time.
  • Permissions can be revoked without vendor involvement.
  • Retention is set by the agency, not inherited from a vendor default.

The hotlist question, stated precisely

In the platform we deploy, the agency imports and manages its own hotlists, including federal crime data, by local or remote file import on a manual or scheduled basis. The agency decides what the system is looking for, and the list of what it looks for is an agency record.

By contrast, reporting by the Electronic Frontier Foundation in June 2026 documented that the other platform performs the federal database comparison itself, with local agencies subscribing to FBI-curated topic sets through a dropdown in the vendor's admin console. That reporting documented that the available topic options have included an immigration violator file populated by federal immigration enforcement, and it identified specific departments that had that file enabled, including one department that had it active despite a local transparency policy prohibiting immigration enforcement cooperation.

Why that distinction matters is simple to state and hard to walk back. It is the difference between an agency choosing what it looks for and a vendor choosing what is available to look for. In the first model, the policy question is answered inside the agency. In the second, part of it is answered inside a product menu.

Federal access, reported chronologically

404 Media reported in May 2025 that federal immigration enforcement had no formal contract with the vendor but obtained access through local police departments running lookups on its behalf, and that audit logs contained over 4,000 nationwide and statewide lookups with immigration-related stated reasons.

The same outlet reported in October 2025 that Homeland Security Investigations had performed nearly 200 searches, and that the Secret Service and a Navy criminal investigation division also had access. Customs had previously been reported with access to roughly 80,000 cameras.

The company subsequently acknowledged that it had, in its own words, inadvertently provided inaccurate information about its federal relationships, and said it had ended pilot programs with two federal agencies. Its chief executive stated publicly that the company had communicated poorly and had not created distinct permissions. A United States Senator publicly stated that abuses of the product were not only likely but inevitable.

Audit trails and documented misuse

A statewide audit by the Illinois Secretary of State concluded the vendor did not have proper safeguards in place for data sharing. Reporting in 2026 counted roughly 50 documented cases of officer misuse, and a public-interest law firm maintains a database listing more than 150 alleged abuse cases nationally. Documented patterns in that reporting included officers tracking former partners and out-of-state investigative queries.

An ACLU analysis documented that where search-limiting measures had been added, officers circumvented them by entering generic reasons, and in one documented case the stated reason was the word hehehe. A Los Angeles Police Department audit found that one contract permitted data retention for five years, far beyond the company's then-stated 30-day standard, and the department suspended use pending resolution of data, privacy, security and sharing concerns.

These are records of what people did with a system. They are not claims about anyone's motives, and they should not be read that way. The useful lesson for a buyer is that the audit trail and the permission model are the product, as much as the camera is.

Now be fair about what changed

The company has made substantial changes in response. Public reporting and the company's own material describe added multi-factor authentication, mandatory case codes on searches, a shorter default retention period, and standard audit assistance during 2026. Its current policy states that customers own their data and that sharing is not automatic. Those are real improvements, and an agency evaluating the product today is not evaluating the 2024 product.

The argument that survives that concession is about sequence. Every one of those controls was retrofitted under public and congressional pressure. The platform we deploy was built to a privacy-by-design architecture from launch. An architecture that assumed data control from day one is not the same as an architecture that added it after the fact, because the first one shapes every default and the second one has to fight them.

Contract cancellations as a market signal

Reporting in August 2026 counted 82 contracts ended since 2021, 39 of them in the first five months of 2026, and a crowdsourced tracking effort put the number of cities that deactivated cameras or cancelled contracts at more than 100. Documented reasons included immigration enforcement concerns, objections to mass surveillance, and municipalities discovering that their data had been shared beyond their knowledge.

Cameras have also been vandalized in at least 36 states. Be clear about what that means. It is a public trust problem for the whole category, not for one vendor, and we are not claiming our cameras are immune to public objection. What we are claiming is narrower and more useful: an agency running the platform we deploy can answer the objection, because it can show the retention schedule, the current sharing list and the audit log at a council meeting.

What our platform commits to

The following comes from the platform manufacturer's own published material, and an agency should confirm current terms in its own contract.

  • Full agency ownership and control of the collected data.
  • Privilege-based access management with per-user scope.
  • Audit trails covering searches and administrative changes.
  • Sharing permissions that can be revoked at any time.
  • An explicit restriction that law enforcement cannot share this data with private entities.
  • Default retention of 90 days, with an option up to one year.
  • A distributed multi-tenant architecture hosted in a government-approved cloud.
  • Built following privacy-by-design principles from launch.
  • Manufacturer security credentials including ISO/IEC 27001 and 27017, SOC 2 Type 2, and UL 2900-2-3 Level 3, which the manufacturer states makes it the only video management vendor worldwide to hold that level.

The three sharing models, all agency-initiated

Sharing is the point of plate data in a real investigation. The question is who starts it. In each of the three supported models, the data owner initiates the share and can revoke it.

  • Law enforcement to law enforcement, for a suspect vehicle crossing jurisdictions.
  • Law enforcement requesting data from a school, business or private property owner when a vehicle matches a hotlist.
  • Private entity to private entity coordination, such as two adjacent properties working a pattern of thefts.

Side by side

The table summarizes the published positions described above. Statements about the other platform reflect published reporting and the company's public statements as of the dates given in the sections above.

Comparison of data control characteristics between the platform we deploy and the other platform as publicly reported
QuestionPlatform we deployOther platform, as publicly reported
Who owns the dataThe agencyCompany policy states the customer owns its data
Default sharingNone, sharing is an explicit actNetwork sharing features are central to the product model
Who performs the federal database comparisonThe agency, by importing its own listsThe vendor, with agencies subscribing to curated topic sets, per reporting in June 2026
Documented federal agency accessAgency controlled, no vendor-brokered accessReported access by immigration enforcement, Homeland Security Investigations, Secret Service and a Navy investigative division during 2025
Default retention90 days, configurable up to one yearShortened default retention introduced during 2026, with a five-year term found in one audited contract
Audit trail maturityAudit trails and privilege-based access from launchMulti-factor authentication, case codes and audit assistance added during 2026
Privacy architecturePrivacy by design from launchControls retrofitted under public and congressional pressure
Security certificationsISO/IEC 27001 and 27017, SOC 2 Type 2, UL 2900-2-3 Level 3Confirm current certifications with the vendor
Data residencyGovernment-approved cloud, agency scopedConfirm current residency terms with the vendor

All statements about other companies on this page reflect published reporting and public statements as of the dates indicated. Vendor policies change. Verify current terms directly with the vendor before making a purchasing decision.

Common questions

Who owns the license plate data our agency collects?

On the platform we deploy, the agency does. The agency is the data controller, sets the retention schedule, holds the audit log and decides who else can see a read. We do not hold or broker your data.

Is our ALPR data shared with federal immigration authorities?

Not unless your agency shares it deliberately. There is no default pool and no vendor-brokered federal access. Sharing is created by your agency, scoped to a named partner, and revocable at any time.

How long is plate data kept?

The default is 90 days, and the agency can configure retention up to one year. Retention should be a written policy decision, because short retention lowers privacy exposure while long retention preserves evidence for complaints that surface late.

Can we delete data or revoke sharing?

Yes. The agency can end a sharing permission at any time without vendor involvement, and deletion follows the retention schedule the agency sets, subject to any litigation hold obligations your counsel identifies.

Does the vendor have access to national crime databases?

On the platform we deploy, the comparison happens against lists the agency imports, including federal crime data, by local or remote file import on a manual or scheduled basis. The agency decides what the system looks for.

What happens if a resident objects to ALPR in our community?

Answer them with documents rather than reassurance. Show the retention schedule, the current sharing list, the audit log and the written policy for who may search and why. Most objections are about unknown data flows, and a system that can show its own flows is far easier to defend at a public meeting.

Talk through the practical next step.

If your agency is evaluating plate recognition, we will walk through data ownership, retention and the sharing model with your counsel in the room.

Contact Confluence Security

We'll get back to you ASAP

Kindly provide your contact info and a team member will get in touch shortly.

Address
6105 S. Main St. Suite #200
Aurora, CO 80016

Contact form