


Flock Security Testing 2026: What the Bishop Fox Penetration Test Found — Critical and High Findings Fixed and Independently Verified
Flock's 2026 penetration test was conducted by independent security firm Bishop Fox, with critical and high findings fixed and independently verified. See what was found, what's fixed, and how Flock verifies remediation.
Earlier this year, I announced that Flock had engaged Bishop Fox, one of the most respected offensive security firms in the world, to conduct our 2026 annual penetration test. Today, I’m sharing the results at a high level with the public. Customers can download the full report and the retest report at security.flocksafety.com. Over the coming weeks I’ll also be offering webinars for customers and their security teams to attend to discuss and ask questions about this year's penetration test and our cybersecurity roadmap.
Bottom Line Up Front
A penetration test involves engaging a highly skilled team of independent hackers to try to break into our own systems, on purpose. Any worthwhile penetration test reveals vulnerabilities and necessary remediations. Flock gave Bishop Fox's team broad, "open/clear box" access, meaning testers had full visibility into our source code and system architecture, not just the outside-in view an attacker without inside knowledge would have.
Across everything they examined – our cameras, our software, our mobile apps, and our cloud infrastructure – Bishop Fox identified 36 issues. As of today, 24 of those 36 have been fixed and independently confirmed. The rest are either in the final stages of being fixed or represent a risk Flock made a deliberate, documented decision to manage differently, which I walk through below. None of these findings resulted in any customer data or systems being accessed by anyone outside Flock.
One notable remediation worth calling out was the implementation of Secure Boot on our older model LPR camera devices. I believe this clearly demonstrates Flock’s commitment to supporting all customer-deployed systems. Secure Boot, in our case Android Verified Boot, verifies system partitions to make sure they weren’t modified or corrupted. When the device turns on, the initial boot code checks the digital signature of the next boot stage. Each stage verifies the integrity and authenticity of the next stage before handing over control. This ensures only authorized software can run on the device.
Secure Boot is meaningful because it provides a fix to a publicly reported vulnerability that allowed bad actors who illicitly acquired older LPR devices to break into the device and access the limited number of images stored locally on the device. To be clear, bad actors were never able to access the cloud environment or images stored on the cloud through any of these devices.

What They Tested
Testing window: January 12, 2026 – March 27, 2026
Scope included:
- Hardware: ALPR cameras, PTZ cameras, Gunshot Detection, Compute Box
- Software: Nova, Safety Platform, FlockOS, Drone as First Responder.
- Mobile Apps: iOS, Android
- Infrastructure: Our AWS cloud environment
- Source code: All Flock code repositories
What Was Found and Where Remediations Stand Today
.png)
.png)
2 ‘Critical’ findings: These were fully remediated and independently verified by Bishop Fox.
7 “High” findings: All 7 were fully remediated and independently verified by Bishop Fox before this report was finalized. None resulted in any compromise of customer data or systems.
16 “Medium” findings: 13 have already been fully remediated, 2 are currently partially remediated. For those two, the majority of the issue identified has already been closed and verified, and Flock is completing the remaining fixes. Neither can be exploited by an outside attacker without first gaining access inside our environment.
1 not remediated “Medium” finding: This finding relates to an older operating system, Android 8.1, software on our first-generation Falcon hardware, the same general issue Flock publicly acknowledged when an independent researcher identified it in 2025. Flock evaluated a hardware refresh for this device generation and concluded it isn't necessary: Android is open source, and our engineering team has deep in-house expertise with this specific Android version and hardware platform. That means Flock isn’t dependent on an outside vendor's support lifecycle to keep these devices secure; Flock builds and deploys the patches ourselves. Flock already deployed a hardened, custom firmware update to this hardware, and Flock is committed to continuing to backport security patches as needed for as long as these devices remain in service.
3 “Low” Severity findings: All have been remediated.
Because Flock owns and maintains the hardware and cloud infrastructure Flock provides, most fixes are deployed centrally. In the vast majority of cases, there is no action required on the part of our customers or agency partners.
Why Flock Does This Every Year
Every year, Flock will continue to bring in an independent, third-party firm to try to break our own systems before anyone else can. This isn't a formality, but best practice for technology of this importance. A penetration test doesn't just look for the presence or absence of vulnerabilities; it's a stress test of the maturity of our entire security program, from how Flock designs software to how quickly Flock responds when something is found.
My expectation, as our CISO, is that engagements like this happen annually at minimum, alongside internal red-teaming, continuous vulnerability management, and security controls built directly into our development process. Security is never "done"; it's a continuous practice. A penetration test is a benchmark, a point-in-time measurement Flock uses to keep raising our own bar.
An annual penetration test is one input into a security program that runs continuously, including but not limited to:
- Threat modeling during product design
- Automated code scanning as engineers write and submit code
- Continuous scanning of production applications and infrastructure
- Ongoing internal red-teaming and offensive security testing
- A dedicated Offensive Security & Vulnerability Operations team

Questions? Here's Where to Go
If you have questions about this engagement or Flock's security practices generally, our team is here to answer them directly at security@flocksafety.com. You can also find our audits, certifications, and security practices at security.flocksafety.com. Our Vulnerability Disclosure Program can be found here: https://www.flocksafety.com/legal/vulnerability-disclosure-policy
Protect What Matters Most.
Discover how communities across the country are using Flock to reduce crime and build safer neighborhoods.
.webp)







