# Flock cybersecurity overview > *Audited source extract. The dossier was used only as a lead; the underlying source was independently acquired and checked on 2026-07-20.* ## Source metadata - **Publisher:** Flock Safety - **Original dossier URL:** https://www.flocksafety.com/blog/flock-safety-cybersecurity-how-we-protect-customer-community-data - **Resolved/canonical URL used:** https://www.flocksafety.com/blog/flock-safety-cybersecurity-how-we-protect-customer-community-data - **Publication date:** 2026-03-27 - **Underlying event or version:** 2026-03-27 - **Archived:** 2026-07-20, from unauthenticated public access; no cookies, tokens, or login state retained - **Wayback snapshot:** save failed on 2026-07-20 after the archive service returned HTTP 403; retry pending ## Verification verdict **supported with narrower wording** — Flock says the acquired device was undeployed/unconfigured, calls the findings legitimate but low severity, says fixes were complete or planned through 2025, disputes the Condor report's access claims, and describes compensating controls. Those assertions conflict in part with researcher/reporting accounts and are not a revision-by-revision patch matrix. ## Claim boundary This source is authoritative only within the source class and limitations stated above. ## Extract **Extracted-text lines 303-307:** > an individual reached out to Flock via email, not through our bug bounty program. This bug bounty program is part of our responsible vulnerability disclosure process, which allows independent researchers to ethically research and submit vulnerabilities to Flock for cash compensation. These are very common programs that thousands of companies across the country maintain. > This individual illicitly acquired a Flock LPR camera, which was the focus of their research. Although this fell outside the scope of our bug bounty program, Flock offered to engage in good faith to review their findings, regardless of how the device was acquired illegally. The individual declined to participate in the ethical bug bounty program. Despite this, Flock reiterated its willingness to work in good faith to evaluate the findings. > Flock’s Product Security and Offensive Security teams evaluated the information submitted by this individual and determined that all of the findings were previously discovered by Flock’s cybersecurity team and were already fixed or planned for engineering sprints throughout the remainder of 2025. While the findings were legitimate, > they were all of low severity. > Meaning the risk to customers or customer data was near zero. **Extracted-text lines 312-316:** > Addressing Misleading Claims Made in a January 2026 YouTube Video on Flock PTZ Cameras > In January 2026, another video by the same YouTuber was released regarding Flock PTZ Cameras. As mentioned before, Flock has maintained an ethical vulnerability disclosure program and bug bounty program for many years. This individual did not ethically submit any information to Flock prior to the release of their video. Instead, the YouTuber made this discovery, chose to conceal it, traveled to a location of one of the cameras, filmed themselves reading a statement, then spent time editing their video for YouTube. > Flock devices use private IoT cellular networks to connect to the cloud. In 2025, one of our cellular carrier partners moved a small number of these Flock PTZ cameras from this private IoT network to the public cellular network used by cell phones. This exposed the camera's diagnostic interface to the internet for a short amount of time. This allowed for those cameras to be discovered on open-source services that constantly scan the internet and catalog the information in a searchable website. If you knew what to search for, you could then identify those few cameras on the internet. > This did not allow for any access to our cloud environment whatsoever. The diagnostic interface is just that: a feature used by our field technicians or privileged engineers to set up and troubleshoot these devices. There is no way to control the camera, or modify recorded video. I want to be clear, these cameras are installed in public spaces. You’d see nothing more than what you’d see standing directly under the camera in that public space. > Flock worked with our carrier partner to quickly resolve the network configuration issue. Flock has also built internal detections to detect such a rare change in the future. Flock has also modified the diagnostic interface to require our technicians to log in with a username and password. Again, this interface is intended to be usable when a technician is physically present. Regardless of how rare this network configuration error is, Flock has put in these compensating controls. **Wayback failure**: The bounded Save Page Now pass stopped after the archive service returned HTTP 403 on the first request. This source was not individually retried; retry pending. ## Notes - Tier: 2 — vendor primary/self-description; authoritative only for the vendor's own claims. - The excerpt is bounded to the claims audited here; consult the preserved original for full context. - Cited by: see `citing_pages:` frontmatter; populated after wiki integration.