# Vendor Information Security Posture The set of claims a surveillance vendor makes about the security of the data it collects and stores on a customer agency's behalf — security certifications, breach history, vulnerability handling — together with how those claims are distributed and contested. In the corpus the posture is [[Flock Safety, Inc.]]'s. It matters because the agency holds the vendor's assurances rather than an independent assessment, and because elected officials asked about it directly. ## How it appears in the corpus - **The "Security Claims and Facts" one-pager.** When the [[Conway City Council]] asked Conway PD in April 2026 "specifically about information security and if Flock has ever had any data breaches," the agency turned to the vendor; Flock CSM [[Gena Hatch]] replied with talking points and an attached "Flock Safety Security Claims and Facts" PDF ([[Flock Cameras Apr 2026 City Council QA Thread]]). The one-pager asserts ISO 27001 certification, SOC 2 Type II, NIST 800-53, "Secure By Design" alignment with CISA principles, multi-factor authentication as a default since November 2024, and — centrally — that "Flock has not experienced a data breach or been hacked." - **Proactive political-defense messaging.** [[Vendor PR and Political Communications]] documents Flock distributing the same defensive content proactively as broadcast emails — most notably "Fact Check: No Hack" — rebutting an independent researcher's vulnerability claim. The corpus thus shows the vendor's security posture circulating in two forms: proactive PR broadcasts and reactive talking points handed to a customer facing public questions. - **The vendor's framing of the FOIA pathway.** In the same Council reply, Flock characterized media coverage of Flock data as "based on audit-log information that certain agencies themselves released in response to public-records / FOIA requests" — locating the disclosure pathway with the agency rather than the vendor. - **Insurance as a financial backstop.** Flock's Certificate of Liability Insurance, attached to [[Flock Safety Past Due Balance INV-81961]], carries Errors & Omissions / Cyber coverage — the financial-liability layer behind the security assurances. ## Independent public-record audit (2026-07-20) The earlier “not independently verified” gap is now partly closed. NVD records preserved with their CNA records document version-specific vulnerability disclosures. They do **not** establish that every deployed Flock device has the affected model/build, that every issue is remotely reachable, or that a current device remains unremediated. | Public record group | Affected scope stated by the records | Boundary | |---|---|---| | CVE-2025-47818 through -47821 | Gunshot-detection devices before 1.3 | [47818](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-47818.md), [47819](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-47819.md), [47820](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-47820.md), [47821](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-47821.md); the CNA descriptions and NVD boundaries are preserved together. | | CVE-2025-47822 through -47824 | LPR firmware through 2.2 | [47822](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-47822.md), [47823](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-47823.md), [47824](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-47824.md); “through 2.2” is a firmware boundary and must not be inferred from an “LPR 2.2” sales-SKU label. | | CVE-2025-59402, -59404, -59408 | Bravo build `BRAVO_00.00_local_20241017` | [59402](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-59402.md), [59404](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-59404.md), [59408](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-59408.md); exact-build device/boot controls, not a universal Falcon finding. | | CVE-2025-59403, -59405, -59406, -59407 | Collins 6.35.31; peripheral 7.38.3; Pisco 6.21.11; DetectionProcessing 6.35.33 | [59403](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-59403.md), [59405](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-59405.md), [59406](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-59406.md), [59407](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-59407.md); application/version-specific records. | | CVE-2025-59409 | Falcon/Sparrow production firmware `OPM1.171019.026` | [59409](../../web%20archive/2026-07-20/nvd.nist.gov/cve-2025-59409.md); no inference to later firmware or every deployed camera. | The July 16, 2026 CISA Known Exploited Vulnerabilities catalog contains none of these 15 CVEs (primary public record, [CISA KEV snapshot](../../web%20archive/2026-07-20/cisa.gov/known-exploited-vulnerabilities-catalog-2026-07-16.md)). That absence means only that CISA had not placed them in that catalog version; it does not prove non-exploitation, remediation, or non-deployment. ## Vendor responses and remediation gap Flock's May 2025 advisory addressed the first seven CVEs, characterized them as low-likelihood and dependent on physical access, said the cloud platform was unaffected, and at that time did not identify a need to remediate all deployed units while describing factory and over-the-air changes (vendor primary/self-description, [May 2025 Flock security advisory](../../web%20archive/2026-07-20/flocksafety.com/gunshot-detection-and-license-plate-reader-security-alert.md)). Flock's March 27, 2026 response says the research device was undeployed and unconfigured, calls the findings legitimate but low severity, says fixes were completed or planned through 2025, and describes an over-the-air custom Qualcomm Android platform rather than Android Things. It also supplies the vendor's competing Condor account (vendor primary/self-description, [Flock cybersecurity response](../../web%20archive/2026-07-20/flocksafety.com/flock-safety-cybersecurity-how-we-protect-customer-community-data.md)). Neither response is an independent, revision-by-revision fixed-version and rollout attestation. The Condor exposure dispute is separately preserved at [[T010 - Condor Internet Exposure Competing Accounts]] (web research 2026-07-20, [404 Media report](../../web%20archive/2026-07-20/404media.co/flock-condor-camera-internet-exposure-2025-12-22.md)). ## Oversight implication For an Arkansas deployment, the necessary defensive records are a device/model/revision inventory; firmware and application versions by date; vendor advisories; mitigation or replacement decisions; update deployment and failure logs; exception/risk-acceptance records; network architecture; access logs; and incident/complaint records. Public CVEs create a records target, not proof of an Arkansas compromise. ## Stakeholders - **[[Flock Safety, Inc.]]** — the vendor making the claims. - **[[Conway City Council]]** — the elected body that asked the data-breach question. - **[[Conway Police Department]]** — the agency that relayed the vendor's answer rather than producing an independent assessment. ## Timeline - 2024–2025 — public teardown research led to model/build-specific vulnerability disclosures; the 2026-07-20 audit independently preserved the public records and vendor responses. - 2024-11 — Flock makes multi-factor authentication a default for all users (per the vendor one-pager). - 2025 — Flock's "Fact Check: No Hack" broadcast circulates to customers. - 2026-04 — the Council's questions and Flock's "Security Claims and Facts" reply. - 2026-07-20 — 15 NVD/CNA records, the CISA KEV snapshot, competing Condor accounts, and the two Flock responses archived and reconciled. ## Notes - The Conway corpus still establishes what Flock told the City and what the City possessed; the external records establish public vulnerability descriptions and competing accounts. Neither layer proves the model, build, exposure, or remediation state of a particular Arkansas camera without an Arkansas asset/version/update record. - Exploitation steps, credentials, discovery queries, and precise device locations are intentionally omitted. The preserved public artifacts are used for defensive version, remediation, and oversight analysis only. - The posture sits adjacent to [[CJIS Compliance]] (the criminal-justice-information security regime) and to [[Flock Audit Logs and Retention]] (the audit-log changes Flock framed in security terms).