Volume 4
🎙 Secured Podcast
Episode 29 | Flock and LPR as a Category Are Losing Right Now
Flock isn't the only one with a problem. LPR as a category might be losing right now. In this week's Secured, Lee gets into the growing backlash surrounding Flock, the questions around surveillance and governance, and why every company in the LPR space should be paying attention. Listen here.
🫣 Premium member-only content | Is Physical Security Finally Going Mainstream?
Don't miss Lee's conversation with LVT's Steve Lindsey and Derek Boggs. They get into what it will take for our industry to finally go mainstream, why prevention has to come before reaction, and how a company out of American Fork, Utah ended up on an NBA jersey patch with the Utah Jazz
✍🏻 Articles
Lee Odess | The Temple and the Lockmaker
Sometimes the most important stories in this industry are sitting right in front of us. A green sign on a walk through Tokyo led Lee to MIWA, one of the world's oldest and most important lock manufacturers, and a bigger story about legacy, reinvention, and the companies we may not be paying enough attention to.
Tony Dong | 12 Years a Small Cap: Why Alarm.com (ALRM) Hasn’t Grown Like a Unicorn
Alarm.com has beaten the small-cap market and built a billion-dollar business, but it hasn't become the platform powerhouse its early promise may have suggested. This piece looks at what may be holding the company back, from its acquisition strategy to a bigger question: is Alarm.com actually worth more as one company or in pieces?
Chris Wilson | When "Smart" Surveillance Meets Not-So-Smart Governance
The technology behind modern surveillance is getting smarter, but are the systems governing it keeping up? From Flock to Axon, this piece looks at what happens when powerful capabilities are deployed without the guardrails, transparency, and accountability needed to support them.
Mike Gillespie | Flock Safety and UK ANPR: What Security and Privacy Professionals Need to Know
The concerns surrounding Flock Safety will sound familiar to many security and privacy professionals in the UK. This piece compares Flock's model with UK ANPR and looks at why the real difference may come down to governance, accountability, and who is responsible for the data.
🔓 The Electronic Locksmith
A new dedicated section for electronic locksmiths, built around the growing opportunity in smart locks and wireless access control. Dave O’Toole shares how the Electronic Locksmith Group came together, why locksmiths are uniquely positioned to lead in this space, and how the community will help locksmiths learn, connect, and grow alongside manufacturers, in partnership with The Access Control Collective.
🚨 Breaking News
![]()
Podcast | Secured: Episode 29
In this episode, Lee gets into dormakaba's acquisition of Apollo Security and Azure Access Technology, and why he sees this as much more than a simple acquisition. He also breaks down Verkada's announcement with Hard Rock Stadium and what happens when a security system starts to become a much larger operational platform. And with the growing conversation and backlash surrounding Flock, Lee covers two stories that directly tie into the broader discussion around Flock, Axon, LPR, surveillance, and governance. From the way these technologies are being deployed to the questions being asked around oversight and public trust, there is a lot happening around this conversation right now. Lee gets into all of that and more in this week's episode of Secured. Listen here.

Find these podcasts ONLY in the 'Conversations with Lee' Channel.
Still haven't checked this one out? Lee's conversation with Steve Lindsey and Derek Boggs gets into everything from competition entering the category and the changing security buyer to why the scarecrow eventually stops working, outdoor security, and what happens when security technology becomes part of a much larger IT and operational stack.

(3 hours into my flight delay coming home IYKYK )… My most recent trip was not a work trip. My wife and I took our kids to Japan for two weeks, and outside of a few photos I took of some interesting doors and locks, I did not plan to write anything about the trip…I needed a break from writing (seeing that I wrote this and Brief #151 on the ninja temple last week, I’ll label it as what I needed was to feel inspired. And I was). But on a walk on the last day before heading to the airport for my flight home near Tokyo Tower, in the Shiba neighborhood of Minato Ward, I looked up past a temple called Myojoin (it’s stunning) and saw a green sign on top of a mid-rise building. The sign said MIWA. I did what I usually do…stopped and took a pic. My wife, on the other hand, kept going, assuming I had spotted another door or look that I wanted to document (I, like many of you, have the same problem). But without knowing, what I actually just did was walk past the global headquarters of one of the oldest and most important lock manufacturers in the world. There it was… sitting quietly behind a modest hedge, next to a Buddhist temple, and across the street from a group of children about to play an early morning game of baseball.
That single image of Miwa is so fitting of Japan and such a better summary of Japan than anything I could write, so I am going to build the Brief around it.
If you read the last Brief, you already know this was a trip full of these moments for me. I wrote about Myoryu-ji, the ninja temple in Kanazawa built with nightingale floors and hidden staircases, and how the whole place was, in fact, a 400-year-old lesson in security by design. MIWA is the same lesson from a completely different angle. One is a temple that used architecture as control because it didn’t have locks. The other is a company that has spent 80 years perfecting their locks. Put them together, and you get the two ends of our entire industry, environment, and hardware, both quietly telling the arc or, better yet, another amazing industry story that needs to be told.
Sometimes you just have to know where to look (or at least get curious).
The last time I wrote to you from Japan was a while ago. Early members of the Access Control Executive Brief will remember Brief #2, which I wrote on a work/personal trip to Tokyo. I was there for only 8 days, mixing business with the gift of my parents watching our kids back home. I met with many people from the industry, like Toshiro Sakai from Ryobi over yakitori, thanks to an introduction from Travis Willis at LEGIC/dormakaba, and as I wrote, I walked away from that trip changed. I said then that our industry, beyond the wasted resources spent on GSX and technical sales decks we love so so much, is impressive, gracious, and welcoming, and that the community in Japan opened its arms to me in a way I did not expect.
This trip was the opposite kind of visit. No meetings, no introductions, and no work. Just my wife, our two kids, and 14 days moving through Tokyo, Kanazawa, Osaka, Hiroshima, Okinawa, and back to Tokyo. It was, without exaggeration, one of the best trips we have taken as a family.
And yet it was fitting to end the trip by looking at a lock company's sign behind a hedge. It actually made me smile.
So who exactly is MIWA? MIWA traces back to 1935, when a man named Wake Ichiro started a small manufacturing operation called Miwa Kogyo. The company was formally incorporated in 1945, the same year the war ended and Japan began the long process of rebuilding. Like many Japanese manufacturers of that era, the early years were not about locks at all. The factory made whatever the country needed to get back on its feet before it settled into precision hardware. From that foundation, MIWA became Japan's second-oldest lock manufacturer and, by most accounts from my conversations, its most trusted one.
The company has remained family-owned and privately held throughout its history, which is rare for an industry who consolidates often and for a manufacturer that now employs over 1,500 people and operates in roughly 50 countries (I have heard from many that it’s not from a lack of companies trying). It built its reputation the slow way, through decades of mechanical locks used in homes, schools, hospitals, and government buildings across Japan. Then in 1981, MIWA did something that quietly reshaped the hospitality industry worldwide and their company. It developed the first offline electronic hotel locking system, well before some other brands that get credit for that category today. That single product line is the reason MIWA now sits inside Marriott, Hilton, Hyatt, and IHG properties around the globe, and why anyone who has spent time in hospitality operations, property management, or global hotel security already knows the name, even if it’s not well known beyond the vertical in North America, Europe, and other regions.
Miwa is nearly invisible to a large share of the industry. That is not a knock on MIWA, but a reminder of how regional hardware is, and how it shapes our view as an industry, even as we talk constantly about it going global and mainstream. It also shows a company that has not invested in branding the way it should to meet the opportunity where it is.
MIWA is a beautiful story of endurance, craftsmanship, and quiet global reach. It’s also an onion that by the numbers I could find, still is primarily a hardware and mechanical lock company that has added electronic and Bluetooth capability onto a business built for a different era. This is not a criticism unique to MIWA, but the exact tension I write about constantly in this Brief under the ideas of the Platform Squeeze and Sailing Ship Syndrome. A company can be excellent at building the best version of the old model and still be vulnerable to a newer one built for the Intelligence Era where software, identity, and data are pivotal pieces. I do not know enough about MIWA's internal roadmap to tell you what they are up to, and I’m not going to pretend a green sign on a walk gave me the full picture of what’s in store for Miwa.
What I can tell you is that a company that has survived from a post-war manufacturing floor to becoming one of the leaders in global hotel security for nearly every major chain on earth has clearly done some of the hard part more than once already. That kind of company has earned the benefit of the doubt on whether it can do it again (but it needs to get moving if it wants to continue its growth).
What I love about Japan is that it does not ask you to choose between its past and its present. It presents you both at once and trusts you to hold them together. You see it walking the streets: the cars and bikes, the kimonos and suits, the bow and the wave, and prominently in the architecture. MIWA's HQ next to a 400-year-old temple is that idea as well. A quality manufacturer that has quietly outfitted hotel rooms and more across the planet, sitting a few feet from a place of worship that predates the company by centuries, both still doing exactly what they were built to do. It too sits side by side: the past and the future.
That is a thread connecting this trip to the last one I wrote about. In Volume 2, it was a meeting over yakitori teaching me that our industry is a genuine global community if you are willing to show up for it. This time, it was a green sign I almost walked past as I wasn’t even looking for anything, teaching me that some of the most important companies in our world do not need to be loud to matter, but they sure do have an amazing story just waiting to be told.
They need to be told. We need to tell them.
I plan to reach out to MIWA directly and see if there is a an opportunity to learn more about their history, their transition, and where they are headed next. If that happens, I’ll be sure to write about it and let you know.
Thank you,
Lee

In the last brief, we looked at the curious case of Napco Security Technologies (NSSC), a company that has been public for more than 36 years and yet still sits at a market capitalization of only $1.34 billion. Napco was caught between two eras. One foot remains in the legacy hardware and dealer-channel world, while the other is moving toward recurring services and subscription economics.
Lee framed this well as a form of platform squeeze. Napco has enough of an installed base to matter, but not enough control of the full platform layer to dictate where the industry goes next. Add in founder and family influence, and independence starts to look both intentional and potentially limiting.
That brings us today to Alarm.com (ALRM), which raises a different version of the same question. Lee’s take was blunt: Alarm.com entered the market as a disruptor, moved into commercial but never seemed to take it seriously, bought a collection of businesses that did not always look strategically coherent, and then appeared to dial back the innovation and aggression that once made it stand out.
In his view, the company could own far more of the access control and connected security market if it wanted to. It has leverage, brand awareness, dealer relationships, and a recurring-revenue model. Yet somehow, a company that once felt like a category-defining name now often feels quieter than it should.
That is the part I want to examine here. Alarm.com is profitable and strategically relevant. But it also has not become the kind of unicorn-like platform winner that its early positioning might have suggested. Why hasn’t management built the kind of company that can deliver parabolic shareholder returns?
As usual, we’ll put some numbers around it. I’m going to benchmark Alarm.com against a small-cap index, look at how the stock has actually performed, and assess whether a realistic ten-bagger path still exists given where the company sits today.
Benchmarking Alarm.com Against Small Caps
Before getting into the qualitative story, I wanted to benchmark Alarm.com against a plain-vanilla small-cap proxy, the iShares Russell 2000 ETF (IWM). we’re asking why Alarm.com hasn’t grown like a unicorn, we first need to know whether shareholders were actually compensated for owning it instead of just investing in small caps broadly.

On a headline basis, Alarm.com did outperform. A $10,000 investment in ALRM grew to about $34,111, compared with roughly $27,037 for IWM. That works out to a 241.1% cumulative return for Alarm.com versus 170.4% for IWM, or an annualized return of 11.62% versus 9.32%. So, yes, the stock beat the small-cap benchmark.
But that headline comes with a lot of pain underneath it. The first thing you notice on the chart is the immediate post-IPO dump. Newly public companies often come out with a valuation that reflects private-market optimism, banker enthusiasm, and a limited public trading history. Then lockups expire, early holders sell, growth expectations get reset, and the public market figures out what it is actually willing to pay. Alarm.com went through that process early.
The bigger issue is what happened after. Alarm.com’s maximum drawdown was 60.9%, compared with 41.1% for IWM. Its average drawdown was also much worse, at 29.9% versus 10.4%. Alarm.com made you more money, but it also kept you underwater for longer and with more discomfort. At one point, investors were underwater for 5.6 years, compared with 3 years for IWM. Volatility tells the same story. Alarm.com’s annualized standard deviation was 38.5%, far above IWM’s 22.7%.
So, Alarm.com beat small caps in absolute terms, but it did not deliver a clean unicorn-style return profile. You were not getting a serial compounder that quickly escaped gravity, but a volatile, founder-era public company that delivered respectable outperformance, but with drawdowns and long underwater periods that made the journey materially harder than the benchmark.
My interpretation after the fact is that Alarm.com has behaved less like a category-dominating platform winner and more like a higher-volatility small cap that occasionally got rewarded for execution, then repeatedly repriced hard when the market questioned the growth ceiling. So, what gives?
The Missing Roll-Up Muscle
To understand where Alarm.com has come up short, it helps to contrast it with the access control companies that do treat acquisitions as a core operating system.
Assa Abloy has completed more than 400 acquisitions since 1994 and explicitly targets 5% acquired growth over a business cycle. It breaks deals into clear buckets: grow the core, extend the core, access new technologies, and grow service and distribution. Allegion uses a similar framework, focusing its mergers and acquisitions strategy on product portfolio expansion, emerging technologies and solutions, and software and services growth.
That is what successful access-control platforms do: they buy distribution, installed base, service revenue, credentials, channel access, and adjacencies that can be pushed through the existing machine. A good tuck-in acquisition should make the parent company stronger in ways that are visible over time: higher revenue per customer, higher recurring revenue attachment, better channel density, more pricing power, or a tighter ecosystem. It goes beyond just expanding product lines.
Alarm.com has acquired businesses, but the pattern looks different. It looks less like a disciplined roll-up strategy and more like a collection of capability purchases. Some were logical, many were probably useful. But taken together, they did not turn Alarm.com into Assa Abloy or Allegion.
The acquisition history is fairly long. Alarm.com bought EnergyHub in 2013 to extend the connected home into demand response and energy efficiency. It acquired assets from Horizon Analog and Secure-i in December 2014, HiValley Technology in March 2015, and ObjectVideo in January 2017.
The bigger post-IPO move was the 2017 acquisition of Icontrol’s Connect and Piper businesses for about $148.5 million, funded with roughly $81.5 million of cash and a $67 million draw on its credit facility. Management expected that deal to accelerate innovation, enhance research and development scale, contribute to revenue growth, and be accretive to non-GAAP earnings per share in 2017.
Then came OpenEye, where Alarm.com acquired an 85% stake in October 2019. Management framed OpenEye as a key piece of the commercial strategy: video-surveillance-as-a-service, enterprise customers, and a broader cloud platform spanning video, access control, intrusion, and automation.
That was followed by Doorport through PointCentral in 2020 for smart intercom capabilities, Shooter Detection Systems in December 2020 for indoor gunshot detection, Noonlight in September 2022 for connected safety and emergency response, EBS in January 2023 for international smart communicators, Vintra assets in April 2023 for AI video analytics, Kapacity.io assets in November 2024 for EnergyHub, CHeKT in February 2025 for proactive video monitoring, Bridge to Renewables in August 2025, and Resideo Grid Services in November 2025.

Some of these clearly worked at the product level. OpenEye gave Alarm.com a credible commercial video platform. ObjectVideo and Vintra strengthened video analytics. CHeKT fits the professional monitoring workflow. EBS gives Alarm.com a way to support legacy panels in international markets.
EnergyHub may actually be the strongest example of an acquisition that became a real platform in its own right, especially after Packetized Energy and Resideo Grid Services expanded its distributed energy resource management capabilities. EnergyHub now says the combined platform manages more than 2.5 million distributed energy resources across one platform.
But that is also the problem. Alarm.com has shown it can buy useful pieces, but has not shown that it can consistently turn those pieces into a larger, consolidated operating platform. The business has grown, but not at a pace that screams platform domination.

In 2025, Alarm.com generated $1.01 billion of total revenue, with SaaS and license revenue of $689.4 million, up at a 10.1% compound annual growth rate from 2023 to 2025. Hardware and other revenue still represented 32% of total revenue in 2025, down from 35% in 2023, but not exactly disappearing. That tells me the subscription model works, but the roll-up machine is not fully proven.
The most generous interpretation is that Alarm.com has been cautious. It prefers majority-stake acquisitions where the acquired company keeps its brand, its team, and some independence.
You can see that language repeatedly: OpenEye continued under its own brand, Noonlight continued independently, EBS continued independently, and CHeKT continues with its existing partner base and workflow. That can preserve entrepreneurial energy, but it can also prevent the hard integration work that creates operating leverage.
The less generous interpretation is that Alarm.com has focused too much on being a mothership platform and not enough on being a capital allocator.
A product company asks, “What can we build or attach next?” A platform company asks, “What can we integrate into the ecosystem?” A capital allocator asks, “Where can each incremental dollar produce the highest return, and how do we compound that across acquisitions and integrations?”
The Platform That May Be Worth More in Pieces
If Alarm.com wants to grow steadily, the current model is probably fine. Keep adding capabilities, deepen the dealer channel, scale SaaS revenue around 10%, and maintain respectable margins. It has objectively done better than the universe of small caps so far.

But if the ambition is to move from small cap into the large-cap range occupied by Allegion and Assa Abloy, then the acquisition strategy cannot just be capability shopping. It has to become a repeatable roll-up system with clearer priorities, harder integration, and more accretive financial outcomes. That is where Lee’s critique lands for me.
Alarm.com had chances to use its leverage more aggressively. It could have consolidated more of the dealer workflow, owned more of multifamily access, and bought or built deeper around smart intercoms before names like ButterflyMX became more visible. It could have treated commercial access control as a market to dominate rather than an adjacent product category to support piecemeal.
The company has not failed in any respect, but it has underused its position. And in a consolidating industry, underused leverage has both opportunity cost and takeover risk. At a current market capitalization of $2.79 billion, Alarm.com is still very much digestible for a much larger strategic acquirer. A public company sitting on recurring revenue in a strategic category, can eventually become someone else’s capital allocation decision.
The more interesting move, though, may not be selling the whole company. Alarm.com might want to take a page from Resideo (RESI), which spun-off ADI Global Distribution (ADIG). I say this because Alarm.com is starting to look like it may suffer from a sum-of-the-parts discount.
The core Alarm.com platform, commercial video, property management, international communicators, and EnergyHub are not all the same business. They do not necessarily deserve the same multiple, and they do not speak to the same investor base. In fact, EnergyHub is the cleanest example.
EnergyHub is not just another connected security feature. It sells demand response and grid-edge services to utilities, with pricing tied to subscribers or aggregate electricity demand made available for control. It has also been built out through acquisitions like Resideo Grid Services, which EnergyHub said strengthened its distributed energy resource management platform and broadened access to connected devices such as thermostats, electric vehicles, and batteries.

That is a different business from home security SaaS. I believe if EnergyHub were valued on its own, investors could underwrite it as a grid flexibility, virtual power plant, or distributed energy resource management platform. Inside Alarm.com, it risks being blended into a broader connected-property story and offset by slower-moving or lower-multiple parts of the business.
In my opinion, Alarm.com shouldn’t buy more companies at all. I’m personally questioning whether Alarm.com should be one company at all. If management wants to stay independent and avoid being rolled up by a larger fish, it needs to make the value easier for shareholders to see.
That could mean clearer segment disclosure, a formal capital allocation framework, or eventually a spinout of the pieces that deserve their own valuation. Otherwise, the market may continue treating Alarm.com as a useful platform, but not a category-defining one. In platform markets like access control, you either become the consolidator, or eventually you become inventory.

Over the past year, Flock Safety's automated license plate readers went from quiet neighborhood fixtures to a national flashpoint — vandalized in at least 36 states, with more than 100 cities canceling contracts and class-action suits piling up in California. Axon's Fusus platform, which stitches public and private cameras, plate data, and drones into one real-time dashboard, does something remarkably similar and has drawn far less scrutiny. Strip away the brand names, and this is as much a security story as a privacy one: surveillance infrastructure outpacing its own governance.
Ethics and security are not separate tracks. The ACLU has documented a pattern of Flock misleading city councils about what the system does — in Oshkosh, Wisconsin, the council approved a contract, learned the next morning it had been misled, and rescinded approval within 24 hours. Councils make risk decisions based on what a vendor tells them; bad information poisons every downstream security decision built on it.
Notice and justification matter most where the stakes are highest. Bartlesville, Oklahoma described its Flock program as general crime prevention, while state law limited ALPR use to verifying vehicle insurance — a gap that surfaced only later. Denver, by contrast, made "no federal or ICE access" a non-negotiable contract term when it switched to Axon, treating purpose limitation as the point, not paperwork.
Sharing PII is never just a checkbox. In Mountain View, a "national lookup" setting was quietly enabled on a city camera without the police department's knowledge; potentially violating a California law barring ALPR shares with out-of-state or federal agencies. Flock's CEO also acknowledged undisclosed pilot programs with CBP and Homeland Security Investigations. An easy toggle doesn't make sharing data less consequential; it just makes it easier to do without anyone noticing.
Private cameras don't get private accountability. HOAs and landlords are folding into these networks with even less oversight than a city council provides. A Saranac Lake, New York village board quietly signed a Flock contract on a state grant; residents only learned once cameras appeared on utility poles, and the board reversed course 4-1 after backlash. Brentwood, California rescinded a permit it admitted approving "by mistake" after a golf-course HOA installed readers in the public right-of-way. California's ALPR law now exposes individual HOA board members to personal liability. None of these cameras were installed by police, but once networked, they're searchable by police anyway, all by people who never had a vote.
Once the public pendulum swings, you can't argue your way back. Feature updates don't restore trust once a community concludes it was misled. Protests, cancellations, and vandalism aren't irrational — they're what happens when oversight channels already feel like they've failed.
And no, there's no patch for a roof rake. Security teams plan for confidentiality, integrity, and availability attacks, but nobody threat-models "the public becomes the adversary because it's angry about a deployment decision." Cameras are being blocked with lawn chairs, cut down with angle grinders, spray-painted by residents, and blocked a few times a week in Crystal, MN, by resident Brady O'Rourke wielding a snow-scraping roof rake. It's a governance failure wearing a security costume, and better encryption won't fix it.
MFA and least privilege are boring- exactly why they get skipped. Researcher Josh Michael found a hardcoded ArcGIS API key across 53 places in Flock's public JavaScript, exposing camera and location data; researcher Jon Gaines ("GainSec") separately documented 67 exposed camera feeds and debug interfaces, building on a tip from fellow researcher Benn Jordan. Flock only made MFA mandatory after months of public pressure. A Milwaukee officer reportedly used the system 124 times to track a romantic partner before anyone noticed, an example of instances that misuse basic audit logging and least-privilege access should have caught immediately. None of it required a sophisticated attacker, just fundamentals a mature program insists on before go-live.
A grant pays the invoice. It doesn't absorb the liability. Bandera County, Texas residents were furious to learn the city still owed money out of pocket despite a grant meant to cover it. Washington cities that paused contracts now face questions about repaying grant funds, and Auburn, New York discovered its Flock agreement had never gone through council authorization at all. A grant changes who writes the check; it doesn't change who's on the hook when something goes wrong.
None of this requires banning the technology — it requires guardrails first. Cities, HOAs, and businesses should treat a written, public usage policy as a condition of activation, spelled out in the contract itself. Purpose limits such as: no federal or ICE access, no national lookup by default - should be the baseline, not a negotiated upgrade only well-resourced cities think to request. MFA, least-privilege access tied to case numbers, and routine search audits should ship as defaults, not patches added after a breach makes headlines. And whoever signs, council, HOA board, or property manager, should cast a formal vote, with liability spelled out up front, grant funding or not.
Flock and Axon aren't uniquely reckless, they're visible examples of a larger pattern: capability acquired without the governance to match it. The technology isn't the problem; treating transparency and security hygiene as optional extras instead of prerequisites is.

What Security and Privacy Professionals Need to Know
Automated Number Plate Recognition (ANPR) technology has become a critical tool for law enforcement and public safety agencies worldwide. In recent years, however, Flock Safety, the rapidly growing US provider of AI-enabled vehicle recognition cameras, has attracted increased scrutiny over privacy, security, and surveillance concerns. While many of the issues raised about Flock are familiar to professionals in the United Kingdom, the key differences lie in governance, data sharing, and accountability.
Understanding Flock Safety
Flock Safety operates a network of cameras capable of capturing vehicle licence plates and identifying vehicle characteristics such as make, model, colour, and distinguishing features. The system enables law enforcement agencies to search and analyse vehicle movements across a large network of cameras deployed throughout thousands of communities in the United States.
The company has promoted its technology as a valuable tool for locating stolen vehicles, finding missing persons, and supporting criminal investigations. However, the scale of the network and the volume of location data it generates have sparked debate among privacy advocates, civil liberties organisations, and security professionals.
The Major Privacy Concerns
The primary privacy concern surrounding Flock is the creation of a large-scale vehicle tracking ecosystem. Even when a system does not directly identify individuals, consistent monitoring of vehicle movements can reveal highly sensitive information about people's lives, including where they live, work, worship, receive medical treatment, or spend their leisure time.
Privacy advocates argue that such systems risk becoming a form of mass surveillance, particularly when data is retained and made searchable across multiple jurisdictions. The concern is not solely the collection of data but the ability to reconstruct a detailed history of an individual's movements and associations.
Another major issue is what privacy professionals describe as "function creep." Data gathered for a specific public safety purpose can gradually be used for broader applications that were not originally envisaged when the system was deployed. This can occur when more agencies gain access to the data or when data-sharing arrangements expand over time.
Insider Misuse: The Greatest Practical Risk
Perhaps the most serious operational concern is not external cyberattacks but abuse by authorised users. Recent investigations in the United States identified numerous instances where law enforcement personnel allegedly used licence plate databases inappropriately, including for personal surveillance and stalking. These reports led to significant public criticism and prompted Flock to introduce additional safeguards.
In response, Flock announced mandatory misuse monitoring, enhanced auditing tools, abnormal activity detection, required case numbers for searches, and automatic reviews of suspicious search behaviour. These controls recognise that the greatest threat to sensitive surveillance data frequently comes from users who already possess legitimate access rights.
For security professionals, this highlights the importance of strong access governance, role-based permissions, audit trails, behavioural monitoring, and regular access reviews.
Data Retention and Security Considerations
Data retention has also been a significant source of controversy. Historically, Flock retained data under a 30-day default model. In August 2026, the company announced a reduction to a seven-day default retention period, while introducing an "Evidence Mode" capability that allows specific data relevant to active investigations to be retained for longer periods.
From a privacy perspective, shorter retention periods reduce risk by limiting exposure in the event of unauthorised access or a data breach. However, concerns remain regarding how frequently retention exceptions are used and what controls exist to prevent the long-term accumulation of location data.
Cybersecurity is another important consideration. Any platform containing large volumes of vehicle location information is an attractive target for attackers. Flock has recently strengthened its security programme through mandatory multi-factor authentication, independent security assessments, and a coordinated vulnerability disclosure programme.
How Does This Compare With UK ANPR?
At first glance, many of the concerns appear similar. Both Flock and UK ANPR systems collect vehicle movement data, both present risks of insider misuse, and both require strong controls around access, auditing, and proportionality.
The crucial difference lies in governance.
The UK's National ANPR Service operates primarily as a policing capability within an established legal and regulatory framework. Its use is subject to UK GDPR, the Data Protection Act 2018, police oversight arrangements, and broader public-sector accountability mechanisms. As a result, questions concerning lawful basis, purpose limitation, accountability, and regulatory supervision have largely defined governance structures. While debate continues regarding proportionality and retention, the legal framework itself is relatively mature.
Flock's model is different because much of the camera infrastructure may be funded or operated by private organisations, residential communities, schools, business districts, and local authorities while still supporting law enforcement investigations. This creates more complex questions about who controls the data, who is responsible for compliance, and how accountability is maintained across numerous independent participants.
A UK Data Protection Officer reviewing a Flock-style deployment would likely focus heavily on controller and processor responsibilities, lawful basis for processing, data-sharing agreements, and Data Protection Impact Assessments. These governance questions tend to be more challenging than those associated with traditional UK police-operated ANPR systems.
Key Lessons for Security and Privacy Professionals
For security and privacy leaders, the debate surrounding Flock demonstrates that surveillance technology should be evaluated as a data governance challenge as much as a technology challenge. The primary risks are not simply camera security or cyberattacks; they are the collection, retention, sharing, and potential misuse of sensitive location data.
Whether assessing Flock, UK ANPR, or any similar capability, organisations should focus on five key questions:
-
Is the collection of data necessary and proportionate?
-
Who has access to the data and how is that access monitored?
-
How long is the data retained?
-
How is data shared with third parties?
-
What safeguards exist to detect and prevent misuse?
Ultimately, the core debate is not whether ANPR technology can be useful. It clearly can. Rather, the challenge is ensuring that powerful surveillance capabilities operate within a framework that delivers public safety benefits while protecting privacy, maintaining accountability, and preserving public trust
References:
-
Flock Tightens Safeguards on Surveillance Cameras After Backlash - Business Insider
-
Flock Updates Privacy, Accountability, Security, and Transparency Safeguards
-
Flock privacy updates: 7-day default for ALPR data, mandatory misuse safeguards
-
Flock’s new privacy rules do little to ease concerns over ALPR surveillance
-
Flock Safety new privacy reforms cut data retention in privacy protection push | Fox Business
🔓 The Electronic Locksmith
About This Section
Welcome to TSB's dedicated locksmith section. A place for the people who install, service, and troubleshoot electronic access every day.
Smart locks, mobile credentials, and cloud-managed access aren't coming. They're here, and clients expect their locksmiths to support all of it. This section exists because electronic locksmiths deserve a seat at the table alongside everyone else in this industry.
It's part of a partnership between ALOA, ELF, and The Access Control Collective, anchored at globallocksmiths.org, the hub for the Electronic Locksmith Community, open to anyone working in the trade.
Dave O'Toole kicks us off below.

Well, it has been a great journey getting to where we are with the Electronic Locksmith Group and the launch of the website and forum. What started off as a chat over coffee with Lee at the Access Control Summit in Zurich about locksmiths and the phenomenal surge in the smart lock and wireless access control business, developed into something deeper. We both concurred that electronics was the way forward for locksmiths to grow and to future proof the locksmith industry globally but they needed help and the support of other locksmiths and the manufacturers to develop it into a new sector of the security industry. Many locksmith business owners may think that they are too old and settled to join this electronic lock revolution but many have employees and family members who would love to get involved and contribute to the growth of the business.
Locksmiths have the necessary skill and knowledge to not only install the locks and hardware but to ensure the door and frame alignment necessary for the smooth operation of the locks. Locksmiths fall into a niche position as they are more than capable of completing the many 1 to 15 door projects that are too small for manufacturers and large integrators to engage in while many locksmith companies would find bigger projects a major challenge to fulfil.
With the support of the boards of ELF (European Locksmith Federation) and ALOA (Associated locksmiths of America with many manufacturers in agreement, the electronic locksmith community was created. The aim being to foster communication and education for locksmiths to learn more about the technology and to work with manufacturers to become the leaders in providing smart locking to home owners and small enterprises.
Thanks to all the support and help from Lee, Hilary and Hailey from The Access Control Community and the two major international locksmith associations, we now have the foundation to grow this industry and support members to foster relationships with other locksmiths and manufacturers from around the world. This free website and forum (courtesy of TACC) will be a great tool to develop the electronic locksmith and I look forward to seeing this community grow and for the participating locksmiths to flourish.
I would like to sincerely thank Lee, Hilary and Hailey for putting so much time and effort into creating this unique opportunity for locksmiths and hopefully many will avail of it.
-Dave O’Toole
đź‘€ As Seen In the Secured Community đź‘€
🤖 AI & Tech — Salvatore D'Agostino shared the latest on Meta's settlement in the social media addiction lawsuit. He also shared Bill Gates' thoughts on the risks surrounding AI. Tony Dong shared a LinkedIn piece on the latest conversation around AI and technology.
🔍 Research — Rodney Thayer asked, “Anybody else here setting up their new Proxmark5?” If you are, reply to him in the 'Research' channel.
👨🏻‍💻 Product/Solution Questions — Lee Odess shared some updates/news from Ambient.ai, with his interest centered around the use of AI agents to do the work. He also shared the company's latest press release.
🤝 Deal Activity — Lee Odess shared, “Shocked there’s not more discussion about this. ScanSource just paid $220.5M for MicroAge.” Read the news here. Jump in on the 'Deal Activity' channel.
📰 Industry News & Insights — Tony Dong shared a look at Raymond James' investment banking focus on the security and safety sector. He also shared this dividend chart for any Allegion (ALLE) investors (or observers).
🔌 Shameless Plugs — Kevin Baldwin went down the rabbit hole of GraphQL and APIs last week, but with a lot changing across the WaveFusion platform recently, he's back with an unedited, raw tour of WaveFusion.
🪪 Identity & Privacy — Salvatore D'Agostino shared Third Version of W3C Web Authentication (WebAuthn) is Now a Standard – Mike Jones: self-issued
📢 Marketing & Branding — Hailey Canady shared, “Most advice on growing LinkedIn ages badly. This one might not.” Check it out here.
💼 Jobs & Opportunities — Lee Odess shared an opportunity for a VP of Sales in North America with a remote monitoring company that recently took on PE capital for growth. DM Lee if interested.
🏠General — Lee Odess shared I'll be at Acre's partner event next week in Austin (presenting the State of the Verticals report and moderating a discussion)... I am told that I can "ask anything"... so ... what do you want me to ask? Reply in the 'General' chat

ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security.
Registration is OPEN NOW! Sign up here.
Speaking at the event? Go here.
On the fence? View some testimonials from previous years here.
🗣️ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here: https://www.tacc.me/secured Thank you!