blog
Latest News
video

Flock Security Testing 2026: What the Bishop Fox Penetration Test Found — Critical and High Findings Fixed and Independently Verified

Chris Castaldo

Flock's 2026 penetration test was conducted by independent security firm Bishop Fox, with critical and high findings fixed and independently verified. See what was found, what's fixed, and how Flock verifies remediation.

by
Chris Castaldo
,
September 22, 2026
15 minutes to read
Community Safety
Elected Officials
Law Enforcement
Technology
Published:
September 22, 2026
  • Bishop Fox is globally recognized as one of the most reputable and established names in offensive cyber security. A penetration test (“pen test”) is security testing conducted by skilled individuals in order to identify critical vulnerabilities that could lead to a breach.
  • Flock pays highly skilled, independent hackers to try to break into our own systems every year, on purpose. Finding issues is the objective of the test.
  • There were 36 issues of varying levels of severity found in the pen test. Of those, 24 are already fixed and independently confirmed; the remainder are in progress to be fixed, or nominal risks Flock decided to watch and manage.
  • An item of note was the introduction of Secure Boot on our legacy ALPR cameras to remediate a finding. Secure Boot implements Android Verified Boot, a security feature that ensures the hardware starts up using only software trusted by the device manufacturer. This solves an issue previously identified in older camera models where the limited images stored on the device could be obtained if the device were illicitly acquired via theft.
  • No customer data or systems were ever accessed by anyone outside of Flock as a result of this testing.
  • Because Flock owns the hardware and infrastructure, fixes are deployed centrally with no customer action required. There is no patch that customers must implement themselves.


Earlier this year, I announced that Flock had engaged Bishop Fox, one of the most respected offensive security firms in the world, to conduct our 2026 annual penetration test. Today, I’m sharing the results at a high level with the public. Customers can download the full report and the retest report at security.flocksafety.com. Over the coming weeks I’ll also be offering webinars for customers and their security teams to attend to discuss and ask questions about this year's penetration test and our cybersecurity roadmap.

Bottom Line Up Front

A penetration test involves engaging a highly skilled team of independent hackers to try to break into our own systems, on purpose. Any worthwhile penetration test reveals vulnerabilities and necessary remediations. Flock gave Bishop Fox's team broad, "open/clear box" access, meaning testers had full visibility into our source code and system architecture, not just the outside-in view an attacker without inside knowledge would have.

Across everything they examined – our cameras, our software, our mobile apps, and our cloud infrastructure – Bishop Fox identified 36 issues. As of today, 24 of those 36 have been fixed and independently confirmed. The rest are either in the final stages of being fixed or represent a risk Flock made a deliberate, documented decision to manage differently, which I walk through below. None of these findings resulted in any customer data or systems being accessed by anyone outside Flock.

One notable remediation worth calling out was the implementation of Secure Boot on our older model LPR camera devices. I believe this clearly demonstrates Flock’s commitment to supporting all customer-deployed systems. Secure Boot, in our case Android Verified Boot, verifies system partitions to make sure they weren’t modified or corrupted. When the device turns on, the initial boot code checks the digital signature of the next boot stage. Each stage verifies the integrity and authenticity of the next stage before handing over control. This ensures only authorized software can run on the device. 

Secure Boot is meaningful because it provides a fix to a publicly reported vulnerability that allowed bad actors who illicitly acquired older LPR devices to break into the device and access the limited number of images stored locally on the device. To be clear, bad actors were never able to access the cloud environment or images stored on the cloud through any of these devices.

What They Tested

Testing window: January 12, 2026 – March 27, 2026

Scope included:

  • Hardware: ALPR cameras, PTZ cameras, Gunshot Detection, Compute Box
  • Software: Nova, Safety Platform, FlockOS, Drone as First Responder.
  • Mobile Apps: iOS, Android
  • Infrastructure: Our AWS cloud environment
  • Source code: All Flock code repositories

What Was Found and Where Remediations Stand Today

2 ‘Critical’ findings: These were fully remediated and independently verified by Bishop Fox.

7 “High” findings: All 7 were fully remediated and independently verified by Bishop Fox before this report was finalized. None resulted in any compromise of customer data or systems. 

16 “Medium” findings: 13 have already been fully remediated,  2 are currently partially remediated. For those two, the majority of the issue identified has already been closed and verified, and Flock is completing the remaining fixes. Neither can be exploited by an outside attacker without first gaining access inside our environment. 

1 not remediated “Medium” finding: This finding relates to an older operating system, Android 8.1, software on our first-generation Falcon hardware, the same general issue Flock publicly acknowledged when an independent researcher identified it in 2025. Flock evaluated a hardware refresh for this device generation and concluded it isn't necessary: Android is open source, and our engineering team has deep in-house expertise with this specific Android version and hardware platform. That means Flock isn’t dependent on an outside vendor's support lifecycle to keep these devices secure; Flock builds and deploys the patches ourselves. Flock already deployed a hardened, custom firmware update to this hardware, and Flock is committed to continuing to backport security patches as needed for as long as these devices remain in service.

3 “Low” Severity findings: All have been remediated. 

Because Flock owns and maintains the hardware and cloud infrastructure Flock provides, most fixes are deployed centrally. In the vast majority of cases, there is no action required on the part of our customers or agency partners.

Why Flock Does This Every Year

Every year, Flock will continue to bring in an independent, third-party firm to try to break our own systems before anyone else can. This isn't a formality, but best practice for technology of this importance. A penetration test doesn't just look for the presence or absence of vulnerabilities; it's a stress test of the maturity of our entire security program, from how Flock designs software to how quickly Flock responds when something is found.

My expectation, as our CISO, is that engagements like this happen annually at minimum, alongside internal red-teaming, continuous vulnerability management, and security controls built directly into our development process. Security is never "done"; it's a continuous practice. A penetration test is a benchmark, a point-in-time measurement Flock uses to keep raising our own bar.

An annual penetration test is one input into a security program that runs continuously, including but not limited to:

  • Threat modeling during product design
  • Automated code scanning as engineers write and submit code
  • Continuous scanning of production applications and infrastructure
  • Ongoing internal red-teaming and offensive security testing
  • A dedicated Offensive Security & Vulnerability Operations team

Questions? Here's Where to Go

If you have questions about this engagement or Flock's security practices generally, our team is here to answer them directly at security@flocksafety.com. You can also find our audits, certifications, and security practices at security.flocksafety.com. Our Vulnerability Disclosure Program can be found here: https://www.flocksafety.com/legal/vulnerability-disclosure-policy

Featured content

Explore More

Latest news
Video
September 22, 2026

Flock Security Testing 2026: What the Bishop Fox Penetration Test Found — Critical and High Findings Fixed and Independently Verified

Latest news
Video
September 8, 2026

What Is Traffic Analytics?

Latest news
Video
September 2, 2026

California SB34: What Private Organizations Using ALPR Need to Know

Protect What Matters Most.

Discover how communities across the country are using Flock to reduce crime and build safer neighborhoods.